Last updated: August 2026
Andeavour ("Andeavour," "we," "us," or "our") provides agentic AI security software that helps enterprises discover, monitor, and govern autonomous AI agents operating across their environments. This Privacy Policy explains what personal data we collect, why we collect it, how we use and share it, and the choices and rights available to you. This policy applies to visitors of our website, prospective and current customers, users of our platform, and individuals whose information is processed through our services. If you have questions about this policy, contact us at info@andeavour.io.
We collect several categories of information depending on how you interact with us:
Account and identity data: name, work email address, job title, employer, phone number, and authentication credentials provided when you create an account, request a demo, or sign up for a trial.
Billing and transaction data: billing address, payment method details (processed by our third-party payment processors; we do not store full card numbers), invoice history, and subscription tier.
Platform and telemetry data: logs, agent activity metadata, API usage, configuration settings, and diagnostic information generated when you use the Andeavour platform to monitor AI agent behavior within your environment.
Communications data: content of support tickets, emails, chat messages, survey responses, and feedback you send us.
Website usage and device data: IP address, browser type, device identifiers, referring/exit pages, pages viewed, and timestamps, collected automatically through cookies and similar technologies.
Customer content: where our services process data on your behalf as a data processor (for example, logs or metadata about your own AI agents and systems), such data is handled under the terms of our Data Processing Agreement, not under this Privacy Policy.
We use personal data to: provide, operate, secure, and improve our services; create and manage accounts; process payments and manage subscriptions; provide customer support; send administrative communications such as security alerts and service updates; develop new features and conduct analytics and research; detect, investigate, and prevent fraud, abuse, and security incidents; market our products to prospective customers (with an opt-out available at any time); and comply with legal obligations, including tax, accounting, and regulatory requirements.
For individuals in the European Economic Area, United Kingdom, and Switzerland, we rely on the following lawful bases under the General Data Protection Regulation (GDPR): performance of a contract (to provide the services you request); legitimate interests (to secure our platform, improve our products, and market our services in a manner that does not override your rights); consent (for certain cookies and marketing communications, which you may withdraw at any time); and compliance with a legal obligation (such as tax and accounting recordkeeping).
For California residents, the California Consumer Privacy Act, as amended by the California Privacy Rights Act (CCPA/CPRA), classifies the categories above as identifiers, commercial information, internet activity, and professional information. We do not sell or share personal information for cross-context behavioral advertising as those terms are defined under the CCPA. Similar state privacy laws in Virginia, Colorado, Connecticut, Utah, and other states provide comparable rights, which we honor for residents of those states.
We use cookies, pixels, and similar technologies to operate our website, remember preferences, and understand how visitors use our site. We use Google Analytics (property ID G-98JP8HSHRP) to collect aggregated and pseudonymized information about website traffic, page views, session duration, and referral sources. Google Analytics may set cookies and collect IP addresses, which Google processes in accordance with its own privacy policy. We do not use Google Analytics data to identify individual users, and we have configured data-sharing settings to limit use for Google's own advertising purposes where such controls are available. You can opt out of Google Analytics tracking using the Google Analytics Opt-out Browser Add-on, or manage cookies generally through your browser settings. Essential cookies required for the website and platform to function cannot be disabled without affecting functionality.
We retain personal data only as long as necessary for the purposes described in this policy. Account and billing data is generally retained for the duration of the customer relationship plus seven years thereafter to satisfy tax, accounting, and audit obligations. Platform telemetry and log data associated with agent monitoring is retained according to the retention period configured in your subscription plan or contractual agreement, typically between 30 and 400 days, after which it is deleted or anonymized. Website analytics data is retained for up to 26 months. Support communications are retained for up to five years to support quality assurance and dispute resolution. Where retention periods are set out in a customer's Data Processing Agreement, those terms take precedence for customer content processed on their behalf.
We engage carefully vetted subprocessors to help us deliver our services, including cloud infrastructure providers for hosting and storage, payment processors for billing, customer relationship management and support-ticketing tools, email delivery providers, and analytics providers such as Google Analytics. Each subprocessor is bound by contractual obligations that are no less protective than those set out in this policy and, where applicable, our Data Processing Agreement. We maintain an up-to-date list of subprocessors and will notify enterprise customers of material changes in accordance with the notice provisions of their agreements. Subprocessors are permitted to process personal data only pursuant to our instructions and for the purposes of providing services to us.
Andeavour is headquartered in the United States and may process personal data in the United States and other countries where we or our subprocessors operate. Where we transfer personal data from the European Economic Area, United Kingdom, or Switzerland to countries that have not been recognized as providing an adequate level of data protection, we rely on appropriate safeguards, including the European Commission's Standard Contractual Clauses (SCCs) and, where applicable, the UK International Data Transfer Addendum. We conduct transfer impact assessments where required and implement supplementary technical and organizational measures, such as encryption in transit and at rest, to protect transferred data.
Depending on your jurisdiction, you may have the right to: access the personal data we hold about you; correct inaccurate or incomplete data; delete your personal data; restrict or object to certain processing; receive a portable copy of your data; withdraw consent previously given; and lodge a complaint with a supervisory authority (for EEA/UK residents) or the California Attorney General (for California residents). California residents also have the right to opt out of the sale or sharing of personal information and to non-discrimination for exercising these rights, though as noted above, we do not sell or share personal information.
To exercise any of these rights, email us at info@andeavour.io with the subject line "Privacy Request." We will verify your identity before fulfilling your request and will respond within the timeframes required by applicable law (generally 30 days for GDPR requests and 45 days for CCPA requests, subject to permitted extensions). You may also designate an authorized agent to submit a request on your behalf, subject to verification.
We implement administrative, technical, and physical safeguards designed to protect personal data, including encryption of data in transit (TLS 1.2+) and at rest (AES-256), role-based access controls and the principle of least privilege, multi-factor authentication for internal systems, network segmentation and continuous monitoring, vulnerability management and periodic penetration testing, employee security training, and vendor security reviews. No method of transmission or storage is completely secure, and we cannot guarantee absolute security, but we continuously evaluate and update our controls to address emerging threats relevant to an AI security company.
Our services are designed for business use and are not directed to children. We do not knowingly collect personal data from individuals under the age of 16. If we learn that we have inadvertently collected personal data from a child under 16, we will take steps to delete such information promptly. If you believe a child has provided us with personal data, please contact us at info@andeavour.io.
In the event of a security incident that results in unauthorized access to, or acquisition of, personal data, we will investigate the incident promptly, take steps to contain and remediate it, and notify affected individuals and applicable regulators as required by law, including within 72 hours of becoming aware of a qualifying breach under the GDPR where feasible. For customers, breach notifications relating to customer content are governed by the notification timelines set out in our Data Processing Agreement.
We may update this Privacy Policy from time to time to reflect changes in our practices, technologies, legal requirements, or other factors. We will post the revised policy on this page and update the "Last updated" date above. For material changes, we will provide additional notice, such as an email to registered account holders or a prominent notice on our website, before the changes take effect.
If you have questions, concerns, or requests regarding this Privacy Policy or our data practices, please contact us at info@andeavour.io. We aim to respond to all inquiries promptly and in accordance with applicable data protection laws.