Privacy Policy

Effective date: July 7, 2025  ·  Last reviewed: July 2026

How Cerbi collects, uses, and protects data — and what we do not do.

Summary

Cerbi LLC (“Cerbi”, “we”, “us”) operates cerbi.io and the CerbiShield and CerbiStream products. This policy explains what personal data we collect through cerbi.io and our support services, how we use it, and your rights as a data subject.

CerbiShield is a governance control plane that you deploy in your own Azure tenant. Cerbi does not act as a log storage vendor, and we do not replace your existing observability tools. Your application log data stays in your environment — Cerbi never receives it.

For enterprise customers who require a signed Data Processing Agreement (DPA) or Data Processing Addendum, see our DPA page.

Scope and data controller identity

This policy applies to:

  • Visitors to cerbi.io and its subdomains
  • Individuals who contact us via forms, email, or calendar scheduling tools
  • Users of Cerbi-hosted marketing or documentation properties

Data controller: Cerbi LLC, Massachusetts, United States. Contact: privacy@cerbi.io

Controller vs processor distinction: For the cerbi.io website and support services, Cerbi acts as a data controller. For CerbiShield deployments inside customer Azure tenants, Cerbi acts as a data processor to the customer's controller, governed by the applicable DPA.

What data we collect

We collect limited data to operate cerbi.io and provide support services:

  • Website analytics (consent-gated): When you accept analytics cookies, we collect pseudonymous usage data about visits to cerbi.io via Google Analytics (GA4) and Microsoft Clarity. This includes pages visited, referral sources, general location data (country/region level), and session heatmaps. This collection requires your consent and can be withdrawn at any time via the Cookie Settings link in the footer.
  • Contact form submissions: When you submit a contact form or request support, we collect your name, work email address, company name (if provided), and any message content you submit.
  • Calendar and scheduling data: If you book office hours or onboarding calls through a scheduling tool, that tool may collect your name, email, and timezone. Refer to the scheduling provider's own privacy policy for their data practices.
  • Optional product telemetry: If you enable diagnostic telemetry in your CerbiShield deployment, we may receive high-level usage statistics about governance profile execution counts and system health metrics. This telemetry is disabled by default, opt-in, and customer-controlled.
  • Server and infrastructure logs: Our hosting infrastructure (Vercel) automatically collects standard server access logs including IP address, request path, user agent, and response codes. These are retained per Vercel's data retention policy and are used solely for security and availability purposes.

Lawful basis for processing (GDPR)

Where GDPR or equivalent legislation applies, we rely on the following lawful bases:

  • Consent (Art. 6(1)(a)): Analytics cookies and product analytics cookies. Consent is collected via the cookie banner on first visit. You may withdraw consent at any time using the Cookie Settings link in the footer.
  • Legitimate interests (Art. 6(1)(f)): Server infrastructure logs, security monitoring, and fraud prevention. Our legitimate interest is to maintain the availability and integrity of cerbi.io.
  • Contract performance (Art. 6(1)(b)): Contact form data used to respond to a support or sales inquiry, and scheduling data required to fulfill a booked meeting.
  • Legal obligation (Art. 6(1)(c)): Data retained to comply with applicable law, tax, or regulatory requirements.

What we do not collect

Cerbi does not collect or store your application logs. CerbiStream runs inside your application process. CerbiShield runs inside your Azure tenant. Neither product sends raw log data to Cerbi.

We do not:

  • Sell personal data to third parties
  • Use personal data for targeted advertising
  • Collect sensitive categories of personal data (health, biometric, political views, etc.)
  • Receive your application logs, raw log data, or governed log metadata from CerbiShield unless you explicitly enable diagnostic telemetry in your tenant settings

Cookies and analytics

We use cookies and similar technologies on cerbi.io. For full detail on each cookie category, the specific cookies set, and your controls, see our Cookie Policy.

  • Strictly necessary cookies: Required for basic site functionality (theme preference, cookie consent preference). No consent required.
  • Analytics cookies (consent required): Google Analytics 4. Loaded only after you accept analytics cookies. Identifies usage patterns to help us improve cerbi.io.
  • Product analytics cookies (consent required): Microsoft Clarity. Loaded only after you accept product analytics cookies. Provides session replay and heatmap data for UX improvement.

We respect the Global Privacy Control (GPC) signal. If your browser sends a GPC signal, analytics and product analytics cookies are not loaded without separate explicit consent.

You can change your preferences at any time using the Cookie Settings link in the site footer.

Customer tenant data and responsibilities

When you deploy CerbiShield in your Azure tenant, you are the data controller for everything inside that environment. Cerbi acts as a data processor on your behalf, subject to the terms of your subscription agreement and, where applicable, a signed DPA.

Inside your tenant, you control:

  • Infrastructure: CerbiShield runs on Azure resources you provision and manage under your own subscription.
  • Storage and data residency: All governance metadata, policy definitions, violation evidence, and audit logs are stored in databases and storage accounts within your tenant. Cerbi does not replicate this data to our own infrastructure.
  • Retention policies: You define how long governance audit logs and metadata are retained, based on your regulatory requirements (GDPR, HIPAA, SOC 2, PCI-DSS, etc.).
  • Access controls: You manage access to your CerbiShield deployment through your identity provider and Azure RBAC. Cerbi support staff access your tenant only at your explicit request for troubleshooting.

Enterprise customers requiring contractual data processing commitments should request a DPA.

Data sharing and subprocessors

We do not sell your data. We do not share your data with third parties for their own marketing purposes.

We share limited data with the following categories of trusted service providers solely to operate cerbi.io and provide support services. A full list of subprocessors is maintained at cerbi.io/subprocessors.

  • Hosting and infrastructure: Vercel Inc. hosts cerbi.io. Standard access logs are processed by Vercel in accordance with their DPA.
  • Analytics (consent-gated): Google LLC (GA4) and Microsoft Corporation (Clarity) process pseudonymous website usage data on our behalf, only after you have provided consent.
  • Email and CRM: We use third-party tools for email delivery and customer support management. Contact form data is transmitted to these tools.
  • Legal requirements: We may disclose personal data if required by law, court order, or a government authority with lawful jurisdiction.

Security

We implement industry-standard technical and organizational measures to protect personal data:

  • TLS encryption for all data in transit to and from cerbi.io
  • Access controls and authentication for administrative systems and support tooling
  • Tenant isolation: CerbiShield customer data never comingles with other customers
  • Regular security reviews and dependency updates

For a full description of security controls, see our Security Overview. To report a vulnerability, email security@cerbi.io.

Data retention

  • Contact form submissions: Retained for up to 2 years or as required to maintain an ongoing business relationship. Deleted upon verified request.
  • Website analytics (GA4): Data retention is set to 14 months within Google Analytics. Anonymized aggregate data may be retained longer.
  • Microsoft Clarity: Session recordings are retained per Clarity's default data retention policy (typically 30 days for replays).
  • Server access logs: Retained per Vercel's infrastructure log retention policy.

You may request deletion of your contact information at any time by emailing privacy@cerbi.io. We process deletion requests within 30 days.

International data transfers

Cerbi LLC is based in the United States. When you visit cerbi.io from outside the United States, contact form data and website analytics may be processed in the United States or by subprocessors operating in other jurisdictions.

For transfers of personal data from the European Economic Area (EEA), UK, or Switzerland to the United States, we rely on Standard Contractual Clauses (SCCs) incorporated into our subprocessor agreements, or the EU-US Data Privacy Framework where applicable.

For CerbiShield deployments, data residency is determined by the Azure region you select at deployment time. Data does not leave your Azure tenant.

Your choices and rights

Depending on your location, you may have rights under GDPR, UK GDPR, CCPA, or other applicable privacy laws:

  • Access (Art. 15 GDPR): Request a copy of the personal data we hold about you.
  • Rectification (Art. 16 GDPR): Request correction of inaccurate or incomplete personal data.
  • Erasure (Art. 17 GDPR / “right to be forgotten”): Request deletion of personal data, subject to legal retention obligations.
  • Restriction (Art. 18 GDPR): Request that we restrict processing of your personal data in certain circumstances.
  • Portability (Art. 20 GDPR): Receive your personal data in a structured, machine-readable format where processing is based on consent or contract.
  • Objection (Art. 21 GDPR): Object to processing based on legitimate interests at any time.
  • Withdraw consent: Withdraw cookie consent at any time via the Cookie Settings link in the footer. Withdrawal does not affect the lawfulness of processing before withdrawal.
  • CCPA (California residents): You have the right to know, delete, and opt out of the sale of personal information. Cerbi does not sell personal information. To make a CCPA request, contact privacy@cerbi.io.

To exercise any of these rights, email privacy@cerbi.io. We will respond within 30 days (or as required by applicable law).

Data processing agreements

Enterprise customers who require a signed Data Processing Agreement (DPA) — for example to satisfy GDPR Art. 28, UK GDPR, or internal procurement requirements — can request one via our DPA page.

Our standard DPA covers: controller/processor relationships, sub-processor obligations, security measures, cross-border transfer mechanisms (SCCs), data subject rights assistance, breach notification obligations, and audit rights.

Contact and complaints

For privacy inquiries, data subject rights requests, or to report a concern:

privacy@cerbi.io

Cerbi LLC
Massachusetts, United States

If you are located in the EEA or UK and believe we have not addressed your concern adequately, you have the right to lodge a complaint with your local data protection supervisory authority.

This policy may be updated from time to time. Material changes will be reflected by an updated “Last reviewed” date above. Continued use of cerbi.io after changes constitutes acceptance of the revised policy.

[ cerbi ] · Start now

One NuGet package. No pipeline changes. Policy-as-code governance that runs in-process before sensitive data ever reaches Splunk, Datadog, or Azure Monitor.

14-day free trial/No credit card/Works with Serilog · NLog · MEL
Privacy Policy | Cerbi