Legal
Osto Privacy Notice.
About This Notice
Last updated: 25 August 2026
This notice explains what Osto Cybersecurity Inc. ("Osto", "we", "us") does with personal data. It covers our website at www.osto.one, our sales and marketing, and the accounts our customers hold with us.
Osto is a United States company and does much of its work from India. Your data may be handled in both countries.
Osto Cybersecurity Inc., with its registered office at 28 Geary Street, Suite 650, San Francisco, California 94109, USA
Any question about this notice: email privacy@osto.one.
Who We Are to You
There are two situations, and your rights differ between them.
- Data inside our products belongs to our customer. If your employer or a supplier bought our service, they decide why and how your data is used, and we act only on their instructions. Ask them about it. If you ask us, we will pass your request on and help them answer.
- Data we collect for ourselves is ours to answer for. That means website visitors, people who contact us, subscribers, and the business contact details we keep in order to run a customer relationship. The rest of this notice is about that data.
- When we improve our threat detection from what we see in our products, we work from aggregated and de-identified data. We do not use data that identifies you or your organisation for that, and we stay inside what our agreement with that customer allows.
What We Collect
- What you tell us: your name, work email, phone number, geographical details if you give one, employer and job role, whatever you write to us, and account and billing details if you become a customer.
- What your device tells us: IP address, browser, device identifiers, operating system, which pages you looked at, where you came from, and when you visited.
- Cookies and similar technologies, covered below.
- We do not ask for special category data such as health, biometric or genetic data, racial or ethnic origin, political opinions, religious or philosophical beliefs, trade union membership, or data concerning sex life or sexual orientation. Please do not send it. If it reaches us anyway, we remove it once we no longer need it to answer you.
- We do not collect or store full payment card numbers. Card details go directly to our payment processor. We may see limited information such as the card brand and the last four digits.
- You do not have to give us personal data. If you choose not to, we may not be able to answer your enquiry, open your account, or provide a service your employer has bought.
Where We Get It
- From you, when you contact us, subscribe, ask for a demonstration, or open an account.
- From your employer or colleagues, when they give us your work contact details so we can provide a service they bought.
- From your device, automatically, as described above.
- From business sources. When we look for organisations that may need what we do, we use company websites, professional networking platforms, and business contact data providers. Some of those sources are publicly available and some are commercial subscription services. You have the same rights over data we get this way, and you can ask us which source your details came from. If we get your details this way, we tell you within a month, or in our first message to you, whichever comes first, after identity verification.
Why We Use It
European and United Kingdom law require a legal basis for each use. Here is what we do and why.
| What we do | Personal data used | Legal basis |
|---|---|---|
| Operate, secure and maintain our website | Usage data, IP address, device and browser information | Legitimate interests in running a secure and functioning website |
| Respond to enquiries and provide support | Name, work email, telephone, the content of your message | Legitimate interests in answering people who contact us |
| Provide and administer customer accounts | Account and contact details of the people who administer the account | Legitimate interests in administering our contract with your employer. Where you contract with us in your own name, performance of that contract |
| Send newsletters and marketing about our services | Name, work email, employer and role | Consent, where your country's law requires it. Where that law allows marketing to business contacts without consent, legitimate interests in promoting our services |
| Understand how our website is used, and improve it | Usage data and cookie data | Consent, for preference, analytics and performance cookies and for what they collect. Where we measure usage from server records alone, without placing anything on your device, legitimate interests in improving our website |
| Take payment and manage billing | Contact and billing details. Card details go directly to our payment processor | Contract, if you buy from us in your own name. Otherwise legitimate interests in billing your employer, and legal obligation for tax and accounting records |
| Meet legal, regulatory and audit obligations | Whatever the obligation requires | Legal obligation, where it arises under European Union or United Kingdom law. Legitimate interests in complying with the laws of other countries that apply to us |
| Establish, exercise or defend legal claims | Whatever is relevant to the claim | Legitimate interests in establishing, exercising or defending legal claims |
- India's Digital Personal Data Protection (DPDP) Act, 2023 works differently. It has no legitimate interests basis. Where that Act governs our use of your personal data, we rely on your consent or on one of the specific uses the Act itself lists. Marketing emails and analytics cookies rely on your consent.
- We do not use personal data to make decisions about you by automated means alone that produce legal effects for you or similarly significantly affect you.
- You can stop marketing at any time, through the unsubscribe link in any message or by emailing privacy@osto.one. Service and account messages continue, because you need those to use what you have bought.
Cookies
Cookies are small files stored on your device. This section also covers tags, pixels and scripts.
| Type of cookie | What it does |
|---|---|
| Strictly necessary | Keep the site working and secure, including maintaining your session. These cannot be switched off without breaking the site. |
| Preference | Remember choices you have made, such as settings and display options. |
| Analytics and performance | Help us understand how the site is used so that we can improve it. |
- Preference, analytics and performance cookies are not strictly necessary. Our Cookie Policy on our website lists what we set, what each one does and how long it lasts, and explains your choices. We keep it current as our tools change.
- You can control cookies in your browser, including refusing them or deleting the ones already stored. Blocking some may stop parts of the site working.
Who Sees It
We share personal data only where there is a reason to, and only with organisations bound to protect it. We do not sell your data to other companies for their own marketing.
- Service providers who help us run the business: hosting, analytics, support tooling, email delivery and payments. They act on our instructions. A few also act for limited purposes of their own, such as fraud prevention and legal compliance.
- Analytics: Google Analytics, PostHog, Amplitude.
- Payments: Stripe & Razorpay, our payment processors.
- Professional advisers, including lawyers, auditors, accountants and insurers, where they need it to advise us.
- Authorities, where the law, a court or a valid official request requires it. We check each request and give only what is required.
- A buyer, if we are bought or merge. We will require them to keep protecting it.
- Business customers can ask us for the current list of providers that handle personal data on their behalf.
Sending Data Abroad
- Your data may be handled in India and the United States. India has no European Commission adequacy decision. The United States has one, but it covers only companies certified under the EU to United States Data Privacy Framework, and we are not certified. So we use Standard Contractual Clauses for both.
- When personal data leaves the European Economic Area we rely on the Standard Contractual Clauses approved by the European Commission. For transfers out of the United Kingdom we use those clauses with the United Kingdom International Data Transfer Addendum, or the United Kingdom International Data Transfer Agreement.
- We do not rely on your consent as the basis for these transfers.
- You can ask us for a copy of the clauses we use: privacy@osto.one.
How Long We Keep It
- Personal data is kept only for as long as there is a reason to keep it: providing a service, running the business relationship, meeting a legal or regulatory obligation, or establishing, exercising or defending a legal claim.
- We review what we hold and, when that reason ends, we delete it or strip out what identifies you.
- Data held inside our products for a business customer stays for as long as their agreement requires. They can ask us to delete it or return it at any time, and do not have to wait for the agreement to end. We do whichever they choose, within the period their agreement sets, and confirm in writing what we deleted or returned and when.
- We may keep something longer where the law requires it, where it is under legal hold for a dispute or an investigation, or where we need it to defend a claim under the contract. That is the exception, not the rule, and we record it when it happens.
- Backups clear on their own schedule, so deleted data can sit in a backup for a while longer. We do not use it in the meantime.
- You can ask what applies to a particular category of your data: privacy@osto.one.
How We Protect It
- We control who can reach personal data, encrypt it in transit and at rest, log and monitor our systems, manage vulnerabilities, and build security into how we develop.
- Our people are bound by confidentiality, trained on data protection, and given access only to what their job needs.
- We check our providers' security before we engage them, and again when what they do for us changes.
- No system is completely secure, so we cannot promise absolute security. If a breach affects your personal data we act on it, and we tell people and authorities where the law requires.
Your Rights in Europe and the United Kingdom
If the GDPR or the United Kingdom GDPR applies to you, you have the rights below over data we answer for. They are not absolute. Sometimes we may be allowed or required to say no, in whole or in part, and if that happens we will tell you why and how to challenge it.
You can object at any time to our use of your data for our legitimate interests, and you can stop marketing at any time. Email privacy@osto.one.
| Right | What it means |
|---|---|
| Be informed | Be told what personal data we hold about you, why we use it and who we share it with. That is what this notice is for. |
| Access | Ask whether we hold personal data about you and receive a copy of it. |
| Rectification | Ask us to correct data that is inaccurate, or complete data that is incomplete. |
| Erasure | Ask us to delete personal data where there is no longer a good reason for us to keep it. |
| Restriction | Ask us to pause our use of your data, while we check whether it is accurate, or while you need it for a legal claim. |
| Objection | Object to processing we carry out on the basis of legitimate interests. We will stop unless we have compelling grounds that override your interests, or we need the data for legal claims. You can object to direct marketing at any time and we will stop. |
| Portability | Get a copy of the data you gave us in a common file format, and ask us to send it to another company where we can. |
| Withdraw consent | Where we rely on your consent, withdraw it at any time, as easily as you gave it. This does not affect processing carried out before you withdrew it. |
| Automated decisions | Not be subject to a decision based solely on automated processing that produces legal effects for you or similarly significantly affects you. |
To use any of these, email privacy@osto.one. We may need to check who you are first. We reply within one month. If a request is complex, or several have been made, up to two further months, with notice given inside the first month. If you are not satisfied you can complain to your local supervisory authority, and in the United Kingdom to the Information Commissioner's Office.
Your Rights in India
India's DPDP Act, 2023 gives Data Principals in India the rights below over data we answer for.
| Right | What it means |
|---|---|
| Access to information | A summary of the data we hold about you and what we do with it, plus who we shared it with and what we shared. |
| Correction and erasure | Correction, completion, updating and erasure of your personal data. We may decline erasure where we still need the data for the purpose it was collected for, or where a law requires us to keep it. |
| Withdraw consent | Where we process your personal data on the basis of consent, withdraw it at any time and as easily as you gave it. |
| Nomination | Nominate one or more individuals to exercise your rights on your behalf in the event of your death or incapacity. |
| Grievance redressal | Raise a grievance about how we have handled your personal data or your rights request. |
To use a right or raise a grievance, contact our Grievance Officer at grievance@osto.one. We respond within ninety days, and usually much sooner. Please use our grievance process first. If we do not resolve it to your satisfaction, you can then complain to the Data Protection Board of India.
If You Are in the United States
- You can browse our website without telling us who you are. We ask for personal data when you contact us, subscribe or open an account.
- Depending on your state, you may be able to know what we hold, get a copy, ask us to correct or delete it, and opt out of targeted advertising and of the sale or sharing of personal data.
- We do not sell your personal data. Some analytics technologies can still count as a sale or a share under California law, which defines those terms broadly, so we treat them that way.
- California treats some things as sensitive personal information that the GDPR does not, including account log-in details, which we hold for customer accounts. You can ask us to limit our use of it.
- To use any of these, email privacy@osto.one. We reply within 45 days, and we may take up to 45 days more if the request is complex, in which case we will tell you.
- You can appeal a decision by replying to our answer. We give you the outcome and our reasons within 60 days. If we turn the appeal down, you can complain to your state Attorney General.
- You can use an authorised agent. We may ask for proof of their authority and ask you to confirm your identity directly.
- We will not treat you differently for using a privacy right.
Children
Our services are for people at work, not for children. We do not knowingly collect personal data from anyone under 18. If you think a child has given us personal data, email privacy@osto.one and we will delete it, unless a law requires us to keep it.
Changes
We update this notice as our services, business requirements, our providers or the law change. The current version sits at www.osto.one/privacyPolicy with the date at the top. If a change materially affects how we use your personal data, we will give additional notice on the website or contact you directly.
Contact Us
Questions, requests or complaints about this notice or about how we handle personal data: email privacy@osto.one.
Grievances under India's DPDP Act, 2023: grievance@osto.one.
Please tell us what you would like us to do, and enough about yourself for us to find your records.