Privacy, Terms & Security.
We collect only what is necessary, store it securely, never sell it, and give you full control over your data at any time.
Last updated · 21 August 2026
01 Privacy Policy
Sarouvet Technologies is a security company. We treat the data you give us the same way we treat our clients' systems — as something to be minimised, protected and audited.
This policy explains what we collect through this website and our enquiry, booking, application and careers forms, why we collect it, how long we keep it, and what you can ask us to do with it. It applies to sarouvettechnologies.com and to direct correspondence with our team.
02 Information We Collect
Personal identifiers
Name, email address, phone number, city and country — only where you enter them into a form.
Professional information
Company name, your role, organisation type, and for careers applications your experience, skills and the links you choose to share.
Project details
Services of interest, timeline, budget range and the description of your challenge. This is the only category we ask you to write freely, so please avoid including credentials, personal data about third parties, or anything covered by an existing NDA before one is in place between us.
Automatically collected
IP address, browser and device type, referring page and timestamps. This is standard server log data used for security and abuse prevention.
Retention
| Data | Purpose | Retained for |
|---|---|---|
| Contact & enquiry submissions | Responding to you, engagement records | 24 months |
| Meeting bookings | Scheduling and confirmation | 12 months |
| Careers applications | Hiring decisions and future openings | 12 months |
| Startup & seller applications | Eligibility review and onboarding | 24 months |
| Server logs | Security, abuse prevention | 90 days |
Where an engagement begins, records are retained for the length of the contract plus any period required by applicable law or professional obligation.
03 How We Use Your Information
- Responding to your enquiry with a direct assessment of whether we can help.
- Scheduling, confirming and preparing for meetings you request.
- Reviewing careers, startup program and seller program applications.
- Improving our services, documentation and this website.
- Detecting, investigating and preventing abuse, fraud and security incidents.
- Meeting legal, regulatory and contractual obligations.
04 Data Storage & Security
Form submissions are stored in Supabase (managed PostgreSQL) with encryption at rest. All traffic between your browser, our site and our database is encrypted in transit with TLS 1.2 or higher.
- Access is restricted to the specific team members who need it for the task at hand.
- Administrative access is password-protected and issues short-lived session tokens.
- We run periodic internal security audits and dependency reviews on our own stack.
- Backups are encrypted and access-controlled to the same standard as production.
Breach notification. In the event of a personal data breach that is likely to result in a risk to your rights and freedoms, we will notify the relevant supervisory authority and affected individuals within 72 hours of becoming aware of it, in line with GDPR Article 33.
06 Third Parties
We use a deliberately small number of service providers. Each one is listed below with exactly what it touches.
| Provider | Purpose | Data shared |
|---|---|---|
| Supabase | Encrypted managed PostgreSQL database | Form submissions |
| Gmail (Google Workspace) | Email correspondence | Email address, message content |
| Google Fonts | Web typography delivery | IP address (request-level only) |
| Render | Application and website hosting | Server log data |
We do not share your data with any other third party without your explicit consent, except where we are legally compelled to do so. We do not sell data under any circumstances.
07 Your Rights
Wherever you are, we extend the following rights to everyone who contacts us:
- Access — request a copy of the personal data we hold about you.
- Rectification — have inaccurate or incomplete data corrected.
- Erasure — request deletion of your data where we have no overriding legal basis to keep it.
- Restriction — ask us to limit how we process your data while a query is resolved.
- Portability — receive your data in a structured, machine-readable format.
- Objection — object to processing carried out on the basis of legitimate interests.
- Withdraw consent — at any time, without affecting processing already carried out.
To exercise any of these, email sarouvettechnologies@gmail.com. We respond to all requests within 30 days. You also have the right to lodge a complaint with your local data protection authority.
08 Terms of Service
Acceptance of terms
By accessing this website you agree to these terms. If you do not agree, please do not use the site.
Use of website
You agree not to attempt unauthorised access, disrupt availability, scrape at a rate that degrades service, or use this site to transmit unlawful or malicious content. Security researchers acting in good faith should see the Security Policy below.
Intellectual property
All content, branding, copy, design and code on this website are the property of Sarouvet Technologies unless otherwise stated, and may not be reproduced or redistributed without written permission.
Services & engagements
Nothing on this website constitutes a binding offer. Every engagement is governed by a separate written agreement covering scope, deliverables, timelines, fees, confidentiality and ownership of work product. Where this page and a signed agreement conflict, the signed agreement prevails.
Limitation of liability
To the fullest extent permitted by law, Sarouvet Technologies is not liable for indirect, incidental or consequential damages arising from use of this website. Liability arising from a client engagement is governed by the relevant agreement.
Disclaimers
Website content is provided for general information and is not professional, legal or financial advice. We make no warranty that the site will be uninterrupted or error-free.
Governing law
These terms are governed by the laws applicable at Sarouvet Technologies' principal place of business, without regard to conflict of law provisions. Engagement-specific jurisdiction is set out in the relevant agreement.
Changes to terms
We may update these terms. Material changes will be reflected in the "last updated" date at the top of this page. Continued use of the site after a change constitutes acceptance.
09 Security Policy
Our commitment
We hold our own infrastructure to the standard we apply to our clients' systems. Security is not a feature of this website; it is a precondition for operating it.
Responsible disclosure
If you believe you have found a vulnerability in this website or any Sarouvet-operated system, email sarouvettechnologies@gmail.com with the subject line SECURITY.
- We acknowledge every report within 24 hours.
- We ask that you do not publicly disclose the issue until we have confirmed a fix.
- Please avoid privacy violations, data destruction and service degradation while testing.
- Good-faith researchers who follow this process will not face legal action from us.
Security measures
- HTTPS enforced across the entire site, with HSTS.
- Security headers including Content-Security-Policy, X-Content-Type-Options and Referrer-Policy.
- Rate limiting on all form endpoints.
- Server-side input validation and sanitisation on every submission.
- Dependency audits run periodically against our own stack.
- Administrative interfaces are rate-limited, authenticated and excluded from search indexing.
10 Contact
Questions about this page, your data, or anything security-related go to the same place and reach a real person:
sarouvettechnologies@gmail.com
We respond within 24 hours, for general enquiries and security reports alike.
Work with experts, not overhead.
Tell us your challenge. We respond within 24 hours.