Privacy Policy

How we collect, use, and protect your information.

Privacy Policy (Kasbah Labs, LLC)

Effective date: January 1st, 2026

This Privacy Policy explains how Kasbah Labs, LLC (“Kasbah Labs,” “we,” “us,” “our”) collects, uses, shares, and protects information when you visit kasbahlabs.com (the “Site”) and when you use our software and consulting services (collectively, the “Services”). We are based in the United States.

1) Scope

This policy covers:

  • Site visitors (browsing, contacting us, requesting a demo)
  • Business contacts (prospects, partners, vendors)
  • Software users (accounts and usage of our GRC software)
  • Consulting clients (information provided during engagements)

2) Information we collect

A. Information you provide

  • Contact details: name, email, phone, company, job title
  • Inquiry details: messages, form submissions, scheduling details
  • Account details (software): username, password, profile information
  • Support and communications: support tickets, emails, call notes
  • Billing details: billing contact and invoicing information (payment card data is typically handled by our payment processor, if used)
  • Client-provided content: documents, questionnaires, evidence, policies, screenshots, logs, and other materials you upload or share through the Services

B. Information collected automatically

  • Device and usage data: IP address, browser type, device identifiers, pages viewed, time spent, referring/exit pages, clicks
  • Approximate location: inferred from IP address
  • Cookies and similar technologies: described below

3) Cookies and analytics

We use cookies and similar technologies to:

  • operate the Site and Services
  • remember preferences
  • understand usage and improve performance
  • measure marketing effectiveness

You can control cookies through your browser settings and, where available, our cookie controls on the Site.

4) How we use information

We use information to:

  • provide, maintain, and improve the Site and Services
  • create and manage accounts
  • deliver consulting services and respond to requests
  • communicate about updates, security notices, and administrative messages
  • provide customer support and troubleshoot issues
  • personalize your experience
  • send marketing communications (you can opt out)
  • detect, prevent, and investigate security incidents, fraud, or misuse
  • comply with legal obligations and enforce agreements

5) How we share information

We may share information with:

  • Service providers who help us run the business (hosting, analytics, customer support tools, email delivery, CRM, payment processing, security monitoring). They are authorized to use information only as needed to provide services to us.
  • Professional advisors (lawyers, accountants, insurers) as needed.
  • Business transfers if we are involved in a merger, acquisition, financing, reorganization, or sale of assets.
  • Legal and safety when required by law, subpoena, or to protect rights, safety, and security.

We do not sell personal information for money.

6) Client data in our software and consulting work

If you use our software or services through an organization, we often process information on behalf of that organization (“Customer Data”). In those cases:

  • the organization controls the Customer Data and decides how it is used
  • we process Customer Data to provide the Services and as directed by the organization
  • requests to access, correct, or delete Customer Data should usually be directed to the organization first

7) Data retention

We keep information for as long as needed to:

  • provide the Services
  • maintain business records
  • comply with legal obligations
  • resolve disputes and enforce agreements

Retention periods vary based on the type of data and the purpose for processing.

8) Security

We use administrative, technical, and physical safeguards designed to protect information. No system can be guaranteed 100% secure.

9) Your choices

You can:

  • Opt out of marketing emails by using the unsubscribe link or contacting us
  • Control cookies via browser settings and Site controls (where available)
  • Update account information through your account settings (if applicable)

10) U.S. privacy rights (state laws)

Depending on where you live, you may have rights such as:

  • access to personal information we hold about you
  • correction of inaccurate information
  • deletion of certain information
  • obtaining a copy of information (portability)
  • opting out of certain targeted advertising activities (where applicable)

To exercise rights, contact us using the information below. We may verify your request and, if applicable, allow an authorized agent to submit a request on your behalf.

11) International visitors

If you access the Site or Services from outside the United States, your information may be processed and stored in the United States and other locations where our service providers operate.

12) Children’s privacy

The Site and Services are intended for business use and not directed to children. We do not knowingly collect personal information from children under 13.

13) Changes to this policy

We may update this Privacy Policy from time to time. The “Effective date” above indicates when it was last updated. Material changes will be posted on this page.

14) Contact us

Kasbah Labs, LLC

140 West Broad Street

Unit A

Lincolnville, SC 29485

United States

Email: support@kasbahlabs.com