grydor Trust center

Privacy Notice

How Grydor collects, uses, shares, retains, and protects personal information.

This notice applies to grydor.com, the Grydor Console, account administration, sales, support, and the Grydor device-management service.

Our role

Grydor is a controller for website inquiries, account identity, service administration, security, billing, and direct support records. For device, employee, directory, policy, software, query, and audit data submitted or configured by a customer, the customer determines the purpose of processing and Grydor acts as its processor or service provider. The customer is responsible for notices, instructions, and a lawful basis for managing its people and devices.

Information we process

  • Account and business contact details, authentication events, administrator roles, organization membership, and support communications.
  • Device identity, hardware and operating-system facts, installed software, compliance observations, management-channel state, assigned person, and customer-selected osquery results.
  • Policies, scripts, software deployment records, query definitions and results, administrator reasons, task events, and audit evidence.
  • Network and security metadata such as IP address, user agent, request timestamp, trace identifier, signature status, and rate-limit evidence.
  • Subscription, invoice, tax, and payment-status information. Payment card details are handled by the payment provider and are not stored by Grydor.

Grydor does not intentionally collect consumer health, biometric, precise location, private file contents, message contents, or credentials through default inventory. Customers must not configure scripts, osquery packs, or integrations to collect data that is unnecessary for an authorized device-management purpose.

Why we process information

We process information to provide and secure the service, authenticate users and devices, execute customer instructions, maintain audit evidence, support customers, bill subscriptions, prevent abuse, comply with law, and improve reliability. Depending on the context, our controller processing relies on contract performance, legitimate interests in operating and securing a business service, legal obligations, or consent where required.

We do not sell personal information or share it for cross-context behavioral advertising. We do not use Customer Data to train a general-purpose machine-learning model.

Sources and disclosures

Information comes from administrators, managed devices, authorized identity and directory systems, customer-configured integrations, payment providers, and normal service requests. We disclose it only to authorized customer users, vetted subprocessors, professional advisers under confidentiality, an acquiring entity subject to appropriate safeguards, or authorities when legally required. The current provider list is maintained on the Subprocessors page.

International transfers

Service regions and transfer mechanisms are stated in the Order Form and Data Processing Addendum. Where required, Grydor offers the applicable European Commission Standard Contractual Clauses and supplementary safeguards. Customers must not infer a particular data region from network latency or a public IP address.

Retention and deletion

Operational records are retained for the subscription term and the plan-specific history period. Security and audit evidence may be retained longer when needed to establish, exercise, or defend legal claims. After termination, Customer Data is returned or deleted under the Data Processing Addendum, with live systems targeted within 30 days and protected backup cycles within 90 days, unless law requires retention. Deletion does not rewrite invoices, fraud evidence, or records that Grydor must retain as controller.

Cookies and local storage

Grydor currently uses only storage necessary for authentication, security, language, and requested application behavior. It does not deploy advertising cookies. If optional analytics or marketing technology is introduced, this notice and the consent mechanism will be updated before activation where consent is required.

Rights and choices

Depending on location, a person may request access, correction, deletion, restriction, portability, or objection, and may withdraw consent. For Customer Data, contact the employer or organization that controls the Grydor tenant. Grydor assists that customer under the DPA. For Grydor-controlled data, email [email protected]. We may verify identity and authority before acting. A person may also complain to the competent privacy regulator.

Children

Grydor is a business service and is not directed to children. Customers must not use it to manage a child’s personal device or collect children’s information without an applicable institutional purpose and lawful authorization.

Security and contact

Security measures and incident handling are described in Security and incident response. Privacy questions and requests may be sent to [email protected]. The responsible contracting entity and address appear in the applicable Order Form.

On this page