Privacy Policy

Crux Root
Last updated: [19 January 2026]

1. Introduction

ITserv Technology FZE (“ITserv”, “we”, “our”, or “us”) is committed to protecting the privacy and personal data of individuals who use our products and services. This Privacy Policy explains how we collect, use, disclose, and protect personal data in connection with Crux Root, our cybersecurity product, and related services (collectively, the “Services”).

This Privacy Policy applies globally and is designed to comply with applicable data protection laws and regulations, including but not limited to:

  • Regulation (EU) 2016/679 (EU General Data Protection Regulation – GDPR)

  • UK General Data Protection Regulation (UK GDPR)

  • Turkish Personal Data Protection Law No. 6698 (KVKK)

  • California Consumer Privacy Act and California Privacy Rights Act (CCPA/CPRA)

  • Other applicable national and international data protection and privacy regulations

2. Data Controller

For the purposes of applicable data protection laws, the data controller is:

ITserv Technology FZE
Registered Address: Starcamp Global FZE, DWTC The Offices One, Office Number 01.03L
Country of Registration: United Arab Emirates
Email: [email protected]

Crux Root is a product owned and operated by ITserv Technology FZE.

3. Scope of This Policy

This Privacy Policy applies to:

  • Visitors to our websites

  • Customers and authorized users of Crux Root

  • Prospective customers and business partners

  • Individuals who contact us for sales, marketing, or support purposes

This Privacy Policy does not apply to data processed on behalf of customers where ITserv Technology FZE acts as a data processor.

4. Personal Data We Collect

Depending on the nature of your interaction with us, we may collect the following categories of personal data:

4.1 Information You Provide Directly

  • Full name

  • Job title and company name

  • Business email address and phone number

  • Account login credentials

  • Communications with us (e.g. support tickets, emails)

4.2 Information Collected Automatically

  • IP address

  • Device type, operating system, and browser information

  • Log files and access timestamps

  • Usage data related to Crux Root features and functionality

4.3 Security and Technical Data

As a cybersecurity product, Crux Root may process:

  • System and application metadata

  • Security events, alerts, and logs

  • Network identifiers and telemetry data

Where possible, such data is pseudonymized, anonymized, or aggregated to minimize the processing of personal data.

5. Purposes and Legal Bases for Processing

We process personal data only where permitted by law. The legal bases and purposes include:

PurposeLegal Basis
Provision and operation of Crux RootPerformance of a contract
User authentication and account managementPerformance of a contract
Security monitoring and threat detectionLegitimate interests
Customer support and communicationsPerformance of a contract
Product improvement and analyticsLegitimate interests
Legal and regulatory complianceLegal obligation
Marketing communications (where applicable)Consent or legitimate interests

6. How We Use Personal Data

We use personal data to:

  • Deliver, maintain, and secure Crux Root

  • Detect, prevent, and respond to cybersecurity threats

  • Provide technical support and customer service

  • Improve product functionality and performance

  • Comply with legal and regulatory obligations

We do not sell or rent personal data to third parties.

7. Data Sharing and Disclosure

We may disclose personal data only to:

  • Authorized employees and internal teams

  • Trusted third-party service providers (e.g. cloud hosting, analytics, customer support tools)

  • Professional advisors (legal, compliance, audit)

  • Governmental or regulatory authorities where required by law

All third parties are subject to confidentiality and data protection obligations.

8. International Data Transfers

Personal data may be transferred to and processed in countries outside your jurisdiction. Where required, we implement appropriate safeguards, including:

  • Standard Contractual Clauses (SCCs)

  • Data Processing Agreements (DPAs)

  • Equivalent legal transfer mechanisms recognized under applicable laws

9. Data Retention

We retain personal data only for as long as necessary to:

  • Fulfill the purposes described in this Privacy Policy

  • Meet contractual, legal, and regulatory requirements

Retention periods vary based on data type, purpose, and legal obligations.

10. Data Processing on Behalf of Customers

When customers use Crux Root to process data, ITserv Technology FZE acts as a data processor, and the customer acts as the data controller.

Processing activities are governed by a Data Processing Agreement (DPA) that includes:

  • Confidentiality obligations

  • Security and incident response measures

  • Subprocessor management

  • Assistance with data subject rights

11. Security Measures

We implement appropriate technical and organizational measures to protect personal data, including:

  • Encryption of data in transit and at rest

  • Access control and least-privilege principles

  • Secure software development practices

  • Continuous monitoring and vulnerability management

Security is embedded into the design and operation of Crux Root.

12. Data Subject Rights

Depending on your jurisdiction, you may have the right to:

  • Access your personal data

  • Request correction or update

  • Request deletion or anonymization

  • Object to or restrict processing

  • Request data portability

  • Withdraw consent at any time (where applicable)

Requests can be submitted to: [email protected]

13. California Privacy Rights (CCPA/CPRA)

California residents have the right to:

  • Know what personal data is collected and used

  • Request deletion of personal data

  • Opt out of the sale or sharing of personal data (not applicable – ITserv does not sell personal data)

  • Exercise rights without discrimination

14. Cookies and Tracking Technologies

We use cookies and similar technologies to:

  • Ensure website functionality and security

  • Analyze usage and improve performance

You may manage cookie preferences through your browser settings or cookie management tools provided on our website.

15. Children’s Privacy

Crux Root is not intended for individuals under the age of 16. We do not knowingly collect personal data from children.

16. Changes to This Privacy Policy

We may update this Privacy Policy from time to time. Any changes will be posted on our website with an updated “Last updated” date.

17. Contact Information

For questions or concerns regarding this Privacy Policy or our data protection practices, please contact:

ITserv Technology FZE
Email:  [email protected]