AssetObserve
Sign in Start free
Legal

Datenschutz

Last updated: 8 July 2026

Important notice

This Privacy Policy is a practical draft for AssetObserve and must be reviewed against the final company setup, hosting providers, payment providers, analytics tools, support tools, subprocessors, and target markets before public launch. It is designed for a global SaaS service while preserving mandatory rights that may apply in a user's country or region.

Who we are

AssetObserve is operated by AssetObserve, Hofmannstr. 31b

81379 Munich

Germany. You can contact us at contact@assetobserve.com. Where the General Data Protection Regulation, the UK GDPR, the Swiss Federal Act on Data Protection, or similar laws apply, AssetObserve may act as a controller for account, billing, website, marketing, security, and support data, and as a processor or service provider for customer-controlled workspace data.

Scope

This Privacy Policy explains how we process personal data when you visit our public website, create an account, use AssetObserve workspaces, install or operate an AssetObserve agent, contact support, subscribe to a plan, receive invoices, or interact with security, billing, and customer-success workflows.

Customer-controlled workspace data

AssetObserve customers decide what systems, networks, identities, cloud accounts, invoices, reports, credentials, and evidence they add to the platform. For that customer-controlled data, the customer is normally the controller or business, and AssetObserve processes the data on the customer's documented instructions under the applicable subscription terms, data processing agreement, and product configuration.

Categories of personal data

We may process account data such as name, business email, password hash, role, organization, authentication provider, session data, language, and security settings.

We may process billing and commercial data such as company name, billing address, VAT ID, plan, invoices, payment status, payment provider identifiers, tax information, contract history, and support entitlement.

We may process technical and security data such as IP address, device and browser data, log timestamps, session identifiers, audit logs, API activity, error logs, abuse signals, scanner job metadata, agent health data, and security event information.

We may process workspace and asset data such as hostnames, IP addresses, MAC addresses, operating system data, installed software, cloud resource metadata, Microsoft 365 or identity metadata, risk findings, open ports, certificates, warranty and lifecycle data, scan results, screenshots or evidence uploaded by the customer, and report content.

We may process credential-related data if a customer configures credentialed scanning or integrations. Credentials and secrets should be limited to the minimum needed, stored only in the intended vault or secret field, rotated regularly, and removed when no longer needed.

We may process communications data such as contact form submissions, support tickets, email content, call notes, feedback, product requests, and legal or security notices.

Purposes of processing

We process personal data to provide, secure, monitor, and improve AssetObserve; create and administer accounts; authenticate users; operate workspaces, agents, scans, dashboards, alerts, reports, and exports; provide support; manage billing, tax, fraud prevention, and collections; communicate service notices; enforce terms; protect our rights and the rights of customers and third parties; comply with legal obligations; and, where permitted, send product communications.

Legal bases

Where GDPR-style laws apply, our legal bases may include performance of a contract, steps requested before entering into a contract, legitimate interests in operating and securing a B2B SaaS product, compliance with legal obligations, consent for optional cookies or marketing where required, and protection of vital interests in exceptional security or emergency cases.

Authorized scanning and sensitive environments

AssetObserve is a cybersecurity and asset-observation tool. Scans, agents, integrations, and reports can reveal sensitive technical, business, or personal data. Customers are responsible for ensuring that all scans and integrations are lawful, authorized, proportionate, properly scoped, and permitted by their internal policies, customer contracts, employment rules, and applicable law. Customers should avoid scanning third-party systems without written permission and should configure rate limits, schedules, and exclusions to reduce operational risk.

Cookies and similar technologies

We use strictly necessary cookies and similar storage to provide login sessions, security, preferences, and requested product functionality. Optional analytics, marketing, or third-party tracking technologies should only be used where disclosed in the Cookie Policy and, where required, after valid consent. For details, see the Cookie Policy.

Sources of data

We receive personal data directly from users and customers, from authorized administrators, from agents and integrations configured by the customer, from payment and identity providers, from support communications, from security logs, and from public or third-party sources used for asset intelligence, vulnerability enrichment, warranty lookup, sanctions or fraud checks, and similar legitimate business purposes.

Sharing and recipients

We may share personal data with hosting providers, database and storage providers, email and support providers, payment processors, identity providers, analytics or monitoring providers if enabled, professional advisers, auditors, insurers, authorities where legally required, and subprocessors needed to provide AssetObserve. We require service providers to protect personal data and process it only for authorized purposes.

International transfers

AssetObserve may be provided to customers and users worldwide. Personal data may be processed in countries other than the country where the user or customer is located. Where transfer restrictions apply, we rely on adequacy decisions, Standard Contractual Clauses, the UK International Data Transfer Addendum or Agreement, Swiss transfer safeguards, data processing agreements, supplementary security measures, or another lawful transfer mechanism.

Retention

We retain personal data only as long as reasonably needed for the purposes described in this policy, unless a longer period is required by law, tax rules, audit obligations, dispute handling, security needs, backups, or legitimate business records. Workspace data is generally retained for the subscription term and deleted or exported according to the contract, product settings, backup cycle, and applicable law. Security logs may be retained for a limited period to detect abuse, investigate incidents, and protect the service.

Security

We use administrative, technical, and organizational measures designed to protect personal data, including access controls, authentication, audit logs, encryption where appropriate, secret handling, backup routines, vulnerability management, and least-privilege practices. No system is perfectly secure. Customers must protect their own accounts, endpoints, agents, credentials, and networks, and must notify us promptly of suspected unauthorized access.

Data subject rights

Depending on your location and the relevant law, you may have rights to request access, correction, deletion, restriction, objection, portability, withdrawal of consent, or review of certain automated decisions. You may also have the right to complain to a data protection authority. Send requests to contact@assetobserve.com. We may need to verify your identity and may redirect requests about customer-controlled workspace data to the relevant customer administrator.

EEA, UK, and Switzerland

Users in the European Economic Area, the United Kingdom, and Switzerland may have additional rights under GDPR-style data protection laws. Where AssetObserve acts as a processor, the customer is responsible for providing its own privacy notice and handling requests from its users, employees, contractors, and data subjects. Where AssetObserve acts as a controller, we will handle requests according to applicable law.

United States state privacy notices

If a US state privacy law applies, residents may have rights to know, access, correct, delete, port, opt out of certain targeted advertising, sales, sharing, profiling, or sensitive-data processing, and appeal a denied request. AssetObserve does not sell personal information in the ordinary meaning of selling customer records for money. If optional advertising or analytics later creates a legal "sale" or "sharing" category, we will provide the required notice and opt-out mechanism before using it.

Brazil, Canada, Australia, New Zealand, and other regions

Where laws such as Brazil's LGPD, Canada's privacy laws, Australia's Privacy Act, New Zealand's Privacy Act, or other national privacy laws apply, we will process personal data according to the applicable local rights and obligations. Because AssetObserve is offered globally, users should contact us if they need a region-specific privacy request handled under their local law.

Children

AssetObserve is not directed to children and is intended for business and professional use. Users must not create accounts for children or submit children's personal data unless they have a lawful basis and all required permissions.

Automated decision-making

AssetObserve may generate risk scores, findings, asset classifications, and report recommendations based on customer-configured scans and rules. These outputs are decision-support information for administrators. Customers remain responsible for reviewing results, validating findings, and deciding what operational or employment action, if any, is appropriate.

Security incidents

If we become aware of a personal-data breach affecting data we control or process, we will assess it and notify affected customers, users, regulators, or other parties where required by applicable law and contract.

Changes to this policy

We may update this Privacy Policy when the service, law, providers, or processing practices change. The latest version will be posted on this page with the updated date. Material changes may also be communicated through the product, email, or another appropriate channel.

Contact

Privacy, data protection, and security requests can be sent to contact@assetobserve.com. Please include enough information for us to identify the account, workspace, request type, and jurisdiction involved.

Placeholder notice

Before launch, replace the bracketed company details and verify the final subprocessors, hosting regions, payment providers, analytics tools, retention periods, data processing agreement, and regional notices with qualified counsel.

Contact: contact@assetobserve.com

AssetObserve

AssetObserve helps IT teams and service providers document authorized internal infrastructure, scanner coverage, risk findings and reports from one SaaS workspace.

Platform Platform Capabilities Plans
Compliance NIS2 readiness BSI IT-Grundschutz
Company Help FAQ Contact Support
Legal Impressum Datenschutz AGB Cookie Richtlinie
© AssetObserve
contact@assetobserve.com