Privacy Policy
Crux Root
Last updated: [19 January 2026]
1. Introduction
ITserv Technology FZE (“ITserv”, “we”, “our”, or “us”) is committed to protecting the privacy and personal data of individuals who use our products and services. This Privacy Policy explains how we collect, use, disclose, and protect personal data in connection with Crux Root, our cybersecurity product, and related services (collectively, the “Services”).
This Privacy Policy applies globally and is designed to comply with applicable data protection laws and regulations, including but not limited to:
Regulation (EU) 2016/679 (EU General Data Protection Regulation – GDPR)
UK General Data Protection Regulation (UK GDPR)
Turkish Personal Data Protection Law No. 6698 (KVKK)
California Consumer Privacy Act and California Privacy Rights Act (CCPA/CPRA)
Other applicable national and international data protection and privacy regulations
2. Data Controller
For the purposes of applicable data protection laws, the data controller is:
ITserv Technology FZE
Registered Address: Starcamp Global FZE, DWTC The Offices One, Office Number 01.03L
Country of Registration: United Arab Emirates
Email: [email protected]
Crux Root is a product owned and operated by ITserv Technology FZE.
3. Scope of This Policy
This Privacy Policy applies to:
Visitors to our websites
Customers and authorized users of Crux Root
Prospective customers and business partners
Individuals who contact us for sales, marketing, or support purposes
This Privacy Policy does not apply to data processed on behalf of customers where ITserv Technology FZE acts as a data processor.
4. Personal Data We Collect
Depending on the nature of your interaction with us, we may collect the following categories of personal data:
4.1 Information You Provide Directly
Full name
Job title and company name
Business email address and phone number
Account login credentials
Communications with us (e.g. support tickets, emails)
4.2 Information Collected Automatically
IP address
Device type, operating system, and browser information
Log files and access timestamps
Usage data related to Crux Root features and functionality
4.3 Security and Technical Data
As a cybersecurity product, Crux Root may process:
System and application metadata
Security events, alerts, and logs
Network identifiers and telemetry data
Where possible, such data is pseudonymized, anonymized, or aggregated to minimize the processing of personal data.
5. Purposes and Legal Bases for Processing
We process personal data only where permitted by law. The legal bases and purposes include:
| Purpose | Legal Basis |
|---|---|
| Provision and operation of Crux Root | Performance of a contract |
| User authentication and account management | Performance of a contract |
| Security monitoring and threat detection | Legitimate interests |
| Customer support and communications | Performance of a contract |
| Product improvement and analytics | Legitimate interests |
| Legal and regulatory compliance | Legal obligation |
| Marketing communications (where applicable) | Consent or legitimate interests |
6. How We Use Personal Data
We use personal data to:
Deliver, maintain, and secure Crux Root
Detect, prevent, and respond to cybersecurity threats
Provide technical support and customer service
Improve product functionality and performance
Comply with legal and regulatory obligations
We do not sell or rent personal data to third parties.
7. Data Sharing and Disclosure
We may disclose personal data only to:
Authorized employees and internal teams
Trusted third-party service providers (e.g. cloud hosting, analytics, customer support tools)
Professional advisors (legal, compliance, audit)
Governmental or regulatory authorities where required by law
All third parties are subject to confidentiality and data protection obligations.
8. International Data Transfers
Personal data may be transferred to and processed in countries outside your jurisdiction. Where required, we implement appropriate safeguards, including:
Standard Contractual Clauses (SCCs)
Data Processing Agreements (DPAs)
Equivalent legal transfer mechanisms recognized under applicable laws
9. Data Retention
We retain personal data only for as long as necessary to:
Fulfill the purposes described in this Privacy Policy
Meet contractual, legal, and regulatory requirements
Retention periods vary based on data type, purpose, and legal obligations.
10. Data Processing on Behalf of Customers
When customers use Crux Root to process data, ITserv Technology FZE acts as a data processor, and the customer acts as the data controller.
Processing activities are governed by a Data Processing Agreement (DPA) that includes:
Confidentiality obligations
Security and incident response measures
Subprocessor management
Assistance with data subject rights
11. Security Measures
We implement appropriate technical and organizational measures to protect personal data, including:
Encryption of data in transit and at rest
Access control and least-privilege principles
Secure software development practices
Continuous monitoring and vulnerability management
Security is embedded into the design and operation of Crux Root.
12. Data Subject Rights
Depending on your jurisdiction, you may have the right to:
Access your personal data
Request correction or update
Request deletion or anonymization
Object to or restrict processing
Request data portability
Withdraw consent at any time (where applicable)
Requests can be submitted to: [email protected]
13. California Privacy Rights (CCPA/CPRA)
California residents have the right to:
Know what personal data is collected and used
Request deletion of personal data
Opt out of the sale or sharing of personal data (not applicable – ITserv does not sell personal data)
Exercise rights without discrimination
14. Cookies and Tracking Technologies
We use cookies and similar technologies to:
Ensure website functionality and security
Analyze usage and improve performance
You may manage cookie preferences through your browser settings or cookie management tools provided on our website.
15. Children’s Privacy
Crux Root is not intended for individuals under the age of 16. We do not knowingly collect personal data from children.
16. Changes to This Privacy Policy
We may update this Privacy Policy from time to time. Any changes will be posted on our website with an updated “Last updated” date.
17. Contact Information
For questions or concerns regarding this Privacy Policy or our data protection practices, please contact:
ITserv Technology FZE
Email: [email protected]

