Privacy Policy
How we collect, use, and protect your information.
Last Updated: August 20, 2026
This Privacy Policy describes how Secure Start Partners ("we," "us," "our," or "Company") collects, uses, discloses, and otherwise processes your information in connection with our website and services, including our SOC 2 Trust Tool, Vendor SAQ Review Tool, AI Transparency Notice Generator, and related consulting services.
1. Information We Collect
Information You Provide Directly
We collect information you voluntarily provide when you:
- Email us directly or book a call through our Calendly scheduling page
- Request information about our services
- Submit documents through our SOC 2 Trust Tool, including SOC 2 reports and related assessments
- Submit documents through our Vendor SAQ Review Tool, including Security Assessment Questionnaires and related files
- Submit answers through our AI Transparency Notice Generator questionnaire, including a required email address where your draft notice is sent
This information may include your name, email address, company name, job title, and other information necessary to provide our services to you.
Information Collected Automatically
When you visit our website or use one of our tools, we automatically collect certain information via standard web server request logs, including:
- IP address
- Browser type and version (user agent)
- Referring website or source
- The page or endpoint requested and the time of the request
When you submit a document or questionnaire through our SOC 2 Trust Tool, Vendor SAQ Review Tool, or AI Transparency Notice Generator, the IP address your submission came from is also stored as a permanent field on that submission record (see "Information from Tool Submissions" below), not just in a temporary server log.
To help prevent automated/bot submissions, all three tools also use Google reCAPTCHA v3, which independently collects information about your device and browsing behavior under Google's own privacy policy. See Section 4 for more detail.
Information from Tool Submissions
When you submit content through one of our three tools, we collect and store the following, tied to a unique submission ID and the submitter's IP address:
- SOC 2 Trust Tool: the uploaded SOC 2 Type II report or attestation document (as extracted text), submission metadata (date, filename), our AI-generated assessment of the report, and, if you choose to enter one at the results-page email prompt, your email address
- Vendor SAQ Review Tool: the uploaded Security Assessment Questionnaire document (PDF, DOCX, XLSX, or CSV, as extracted text), submission metadata, and our AI-generated quality assessment
- AI Transparency Notice Generator: your email address, company and product name, your answers to the ~41-question questionnaire (which may describe your own company's AI systems, data practices, and vendors), the AI-drafted notice we generate from those answers, and a log of each attempt to email that notice to you
2. How We Use Your Information
We use the information we collect for the following purposes:
- To provide, maintain, and improve our services and website
- To respond to your inquiries and fulfill your requests
- To conduct SOC 2 assessments, SAQ quality reviews, and generate AI Transparency Notices
- To process the documents and questionnaire answers you submit using Anthropic's Claude API, a third-party AI service, in order to generate the assessment, review, or draft notice you requested (see Section 4)
- To communicate with you about your submission, and about our services more broadly
- To monitor and analyze trends, usage, and activities for security and fraud prevention
- To comply with legal obligations and enforce our agreements
- To develop new features, products, and services
- To create aggregate and anonymized insights about the state of SOC 2 compliance across industries and company sizes
Aggregate SOC 2 Reporting
We may use aggregated, anonymized, and de-identified data derived from SOC 2 reports and assessments submitted through our SOC 2 Trust Tool to create industry insights, trend analyses, and publicly available reports about the state of SOC 2 compliance. This may include statistical analyses, benchmarking data, and observations about common compliance gaps, best practices, and industry trends. These aggregated insights may be shared publicly or with industry partners to advance cybersecurity and compliance practices.
Important: We will not disclose, publish, or share any specific contents of individual SOC 2 reports, raw report data, company-identifying information, or individual assessment details in any aggregate reporting or public insights. All data used in aggregate reporting is thoroughly anonymized and de-identified to ensure no individual organization, company, or person can be identified from the published insights.
3. Cookies and Local Storage
We do not currently use Google Analytics, advertising cookies, tracking pixels, or web beacons on this website. If that changes in the future, we will update this section and the "Last Updated" date above.
Local Storage on the SOC 2 Trust Tool
When you view your SOC 2 Trust Tool results, our results page stores a small flag in your browser's local storage, tied to your submission's unique ID. This flag simply remembers that you've already responded to (or skipped) the optional email prompt, so you aren't asked again if you revisit the same results link. This value is stored only in your own browser, is never transmitted to us or any third party, and you can clear it at any time by clearing your browser's site data.
Google reCAPTCHA
Our SOC 2 Trust Tool, Vendor SAQ Review Tool, and AI Transparency Notice Generator use Google reCAPTCHA v3 to distinguish human visitors from automated bots. reCAPTCHA may set its own cookies and collect information about your device and browsing behavior; that collection is governed by Google's Privacy Policy and Terms of Service, both linked on the relevant submission pages.
4. Information Sharing and Disclosure
We do not sell your personal information to third parties. However, we may share your information in the following circumstances:
Service Providers We Use
We share information with the following named third-party service providers, each of which processes your information only as necessary to provide their service to us:
- Anthropic — When you submit a document or questionnaire through our SOC 2 Trust Tool, Vendor SAQ Review Tool, or AI Transparency Notice Generator, the extracted text or answers you submitted are sent to Anthropic's Claude API to generate your assessment, review, or draft notice, in accordance with Anthropic's API terms.
- Google reCAPTCHA — Used on all three tool submission forms for bot and fraud prevention. Subject to Google's Privacy Policy and Terms of Service.
- Calendly — Used to power the "Book a Call" scheduling link on our Contact page. Information you provide to schedule a call is collected directly by Calendly under its own privacy policy.
- DreamHost — Our web hosting provider and the SMTP relay we use to send transactional and notification emails (e.g. submission confirmations, delivery of your AI Transparency Notice).
We may also share information with other service providers who assist us in operating our website and providing our services, such as additional hosting or email infrastructure providers, under the same contractual limitations described above.
SOC 2, SAQ, and AI Transparency Results
When you use our SOC 2 Trust Tool, Vendor SAQ Review Tool, or AI Transparency Notice Generator, your assessment, review, or generated notice is shared with you (and, for the AI Transparency Notice Generator, delivered only to the email address you provided). We will not share your individual submissions, specific assessment or review details, or company-identifying information with third parties without your explicit consent, except as required by law or as described below.
However, we do use de-identified and aggregated data from all submitted SOC 2 reports and assessments to create industry insights and benchmarking reports, which may be published publicly or shared with industry partners. This aggregate data will be thoroughly anonymized to prevent identification of any individual organization or submission.
Legal Compliance
We may disclose your information when required by law or when we believe in good faith that such disclosure is necessary to:
- Comply with legal obligations, court orders, or government requests
- Enforce our Terms of Service and other agreements
- Protect the security or integrity of our services
- Prevent fraud, abuse, or illegal activities
Business Transfers
If we are involved in a merger, acquisition, bankruptcy, or other business transaction, your information may be transferred as part of that transaction. We will notify you of any such change and any choices you may have regarding your information.
5. Data Storage and Security
We implement appropriate technical, administrative, and physical safeguards designed to protect your information against unauthorized access, alteration, disclosure, or destruction. These measures include:
- Encryption of data in transit and at rest
- Secure server infrastructure and access controls
- Regular security assessments and vulnerability scanning
- Limited access to personal information on a need-to-know basis
- Employee training on data protection and privacy practices
However, no method of transmission over the internet or electronic storage is completely secure. While we strive to protect your information, we cannot guarantee absolute security.
Tool Submission Storage
Documents and questionnaire answers submitted through our SOC 2 Trust Tool, Vendor SAQ Review Tool, and AI Transparency Notice Generator — along with the resulting AI-generated assessment, review, or notice, and the submitter's IP address — are stored securely in our database, tied to a unique submission ID rather than to any user account (our tools do not require you to create one). We maintain these records for the duration described in Section 6 below.
Data from SOC 2 Trust Tool submissions specifically may also be used to generate de-identified, anonymized aggregate insights about SOC 2 compliance trends and industry benchmarks, as described in Section 2, even after an individual report is deleted.
You may request deletion of your individual submission (document, questionnaire answers, and associated results) subject to legal retention requirements. However, because we may have already extracted de-identified and aggregated data from a SOC 2 submission for use in trend analysis and reporting, deletion of that submission does not remove any aggregated insights already derived from it.
Internal Access
A small number of authorized Secure Start Partners team members can access an internal, key-protected admin dashboard to review tool submissions — including status, submitter IP address, and any logged results or delivery attempts — for troubleshooting, quality review, and customer support purposes. This dashboard is not accessible to the public or indexed by search engines.
6. Data Retention
We retain your personal information for as long as necessary to provide our services, comply with legal obligations, and resolve disputes. None of our tools require you to create an account, so retention is tied to the age of your submission or inquiry, not to any account lifecycle. The retention period varies depending on the type of information and the purposes for which we use it:
- Contact/inquiry details (email or Calendly booking): retained for up to 3 years
- SOC 2 Trust Tool submissions (report text, AI assessment, submitter IP, and any email left at the results-page prompt): retained for as long as necessary to provide the service and to support the aggregate benchmarking described in Section 2, or until you request deletion, subject to the exceptions described in Section 5
- Vendor SAQ Review submissions (document text, AI assessment, submitter IP): retained for as long as necessary to provide the service, or until you request deletion, subject to legal retention requirements
- AI Transparency Notice submissions (email, questionnaire answers, generated notice, submitter IP, delivery log): retained for as long as necessary to provide the service, or until you request deletion, subject to legal retention requirements
- Local storage flag (SOC 2 results email-gate dismissal): stored only in your own browser; persists until you clear your browser's site data, and is not retained on our servers
- Server logs: typically retained for 90 days for security and troubleshooting purposes
7. Your Privacy Rights
Depending on your location, you may have certain rights regarding your personal information, including:
Access and Portability
You have the right to request access to your personal information and receive a copy of the data we hold about you in a portable format.
Correction and Deletion
You have the right to request correction of inaccurate information and deletion of your personal information, subject to certain legal exceptions and our legitimate business needs.
Opt-Out
You have the right to opt out of marketing communications. You can update your communication preferences by contacting us directly at the information below.
Do Not Track
Some browsers include a "Do Not Track" feature. Currently, there is no industry standard for recognition of Do Not Track signals, and we do not respond to Do Not Track browser signals. However, you can use other tools to control data collection and use as described in this policy.
To exercise any of these rights, please contact us at the information provided below. If your request relates to a specific tool submission, including your submission's unique ID (from its results URL) will help us locate it faster, since our tools do not use accounts or logins. We will respond to your request within the timeframe required by applicable law.
8. Children's Privacy
Our website and services are not intended for children under the age of 13 (or the applicable age of digital consent in your jurisdiction). We do not knowingly collect personal information from children. If we discover that we have collected information from a child, we will delete such information promptly. If you believe we have collected information from a child, please contact us immediately.
9. Third-Party Links and Services
Our website may contain links to third-party websites and services that are not operated by us, and, as described in Section 4, relies on named third-party services (Anthropic, Google reCAPTCHA, Calendly, and DreamHost) to operate our tools. This Privacy Policy applies only to our website and services. We are not responsible for the privacy practices of third-party websites or services. We encourage you to review the privacy policies of any third-party services before providing your information.
10. International Data Transfer
Your information may be transferred to, stored in, and processed in countries other than your country of residence. These countries may have different data protection laws than your home country. By providing your information to us, you consent to the transfer, storage, and processing of your information in countries outside your country of residence, including the United States.
11. Updates to This Privacy Policy
We may update this Privacy Policy from time to time to reflect changes in our practices, technology, legal requirements, and other factors. We will notify you of material changes by updating the "Last Updated" date at the top of this page and, in some cases, by sending you a notification email. Your continued use of our website and services after any updates constitutes your acceptance of the updated Privacy Policy.
12. Contact Us
If you have questions, concerns, or requests regarding this Privacy Policy or our privacy practices, please contact us at:
Secure Start Partners
Email: info@securestartpartners.com
We will respond to your inquiry within 30 days of receipt.