Skip to main content
Platform Review
PricingSign in
Gecko Security assessment

Gecko Security procurement policy evidence

Only topics backed by verified findings appear below. Each row preserves the platform's exact policy words and capture provenance.

Verified procurement policy findings for Gecko Security
TopicPlan or tierRiskTheir wordsSource
DPA, audit rights & data residencyAll applicable tierslowIn such cases, we ensure the transfer of your Personal Data occurs pursuant to a lawful transfer mechanism under applicable law, which may include without limitation: Standard Contractual Clauses;Captured 2026-07-20Open source →Finding permalink →
DPA, audit rights & data residencyAll applicable tiersunknown This section of our Privacy Policy applies if you use our Services in the European Union (EU) or United Kingdom (UK) and we act as a “controller” (as explained below). With respect to certain operational functions which are part of our Services, we act as a controller (i.e., we determine the purposes and means of processing your Personal Data). Such functions include but are not limited to administering and maintaining your account with us and responding to inquiries that you send to us. You are not obligated to provide us with your Personal Data, however, if you choose not to provide your Personal Data to us, you may not be able to use some or all of our Services. Your Personal Data is processed for the purposes described in the section of this Privacy Policy titled “How We Use Your Information” and is shared with recipients listed under the section titled “Third-Party Recipients & Subprocessors.” Where we process your Personal Data or your Personal Data is processed on our behalf, we rely on one or more of the following lawful bases: Contractual necessity: to perform our obligations under any agreement with you; Legal obligation: to comply with applicable laws and regulations; Legitimate interests: for our business operations (e.g. security, fraud prevention, service improvements), provided your rights do not override those interests; Consent: where you have explicitly agreed to certain processing (e.g. processing to communicate with you). Captured 2026-07-20Open source →Finding permalink →
DPA, audit rights & data residencyAll applicable tiersunknown We maintain independent attestation of our control environment, including SOC 2 compliance. In addition to encryption, penetration testing and regular vulnerability assessments, we undergo annual third-party audits to verify the effectiveness of our technical and organizational measures.Captured 2026-07-20Open source →Finding permalink →
DPA, audit rights & data residencyAll applicable tierslow Other lawful transfer mechanisms under applicable data-protection laws. In cases where we transfer or receive your Personal Data in accordance with Standard Contractual Clauses, you may request a copy of such clauses or be informed of where they are accessible. To make such a request, please contact us at gecko@gecko.security . For details on how long we store your Personal Data, please refer to the “Data Retention” section above. If you have a concern regarding the processing of your Personal Data, you may contact us at gecko@gecko.security or you may lodge a complaint with the applicable data protection authority in the country in which you are located. For a listing of EU data protection authorities and their contact details, please visit https://www.edpb.europa.eu/about-edpb/about-edpb/members_en . If you are located in the UK, you may contact the Information Commissioner’s Office (ICO) via the following link: https://ico.org.uk/make-a-complaint/data-protection-complaints/ .Captured 2026-07-20Open source →Finding permalink →
DPA, audit rights & data residencyAll applicable tiersunknown Legal claims: where processing is necessary for the establishment, exercise or defense of legal claims. To the extent the processing of your Personal Data is based on your consent, you may withdraw your consent at any time. To withdraw your consent for the processing of your Personal Data, you may email us at gecko@gecko.security . As a data subject, you have the following rights: Right to Access: You can request access to or copies of your Personal Data. Right to Rectification: You can request corrections of inaccurate or incomplete Personal Data we maintain about you. Right to Erasure: You can request that we delete your Personal Data under certain conditions. Right to Restrict Processing: You can request that we limit the processing of your Personal Data. Right to Object: You can object to the processing of your Personal Data under certain conditions. Right to Data Portability: You can request that we transfer your Personal Data to another organisation or directly to you under certain conditions. Please note that the rights set forth above may be subject to certain limitations under applicable laws. We will notify you if we are not able to honor your request, in whole or in part, and we will otherwise respond to your request as required by applicable laws. If you wish to exercise any of the rights listed above, please contact us at gecko@gecko.security . Your Personal Data may be transferred or received by us outside the European Economic Area (EEA) or the UK. Captured 2026-07-20Open source →Finding permalink →
Data retentionAll applicable tiersmedium We retain Personal Data only for as long as necessary to fulfil the purposes described in this Privacy Policy. We retain the categories of data described below as follows: Account and profile data: retained for the duration of our customer relationship plus up to 2 years thereafter; Transactional and billing records: retained for at least 7 years to satisfy tax or audit requirements; Support correspondence and logs: retained for up to 3 years to ensure quality and traceability; Analytical/usage data: Non-Personal Data regarding usage of our Services may be retained indefinitely. Upon expiration of the relevant retention period for Personal Data or upon your valid request for erasure of your Personal Data, we will securely delete or anonymise your Personal Data unless we are obligated under applicable law to retain it.Captured 2026-07-20Open source →Finding permalink →
Subprocessors & data sharingAll applicable tiersmedium We may share your information with: Service providers (e.g. hosting, analytics, payment processors) acting on our behalf; Professional advisers (e.g. legal, accounting firms) under confidentiality obligations; Persons or entities with whom you request that we share your information. Courts, law enforcement, regulators, government agencies or other parties where it is reasonably necessary for the establishment, exercise or defense of a claim, protecting our rights or the rights of our users, or is required by laws or regulations to which we are subject. In some instances, we process Personal Data on behalf of our customers and delegate certain functions to service providers that process Personal Data on our behalf (“subprocessors”). A current list of our subprocessors and their roles is available on our website. We conduct due diligence and impose contractual data protection requirements on all of our subprocessors.Captured 2026-07-20Open source →Finding permalink →

Informational only, not legal advice. Terms can change; verify every cited source and capture date during procurement review.

📢 POLICY UPDATES ALERT

AIRIN Brief

Built for compliance officers, legal counsel, and SaaS founders. Subscribe to the email digest — one short brief when a tracked vendor materially changes its terms, training policy, or risk rating. Prefer in-app? Watch platforms in your alerts inbox instead.