1. Overview & Commitment
Wescequre Cybersecurity ("Wescequre", "we", "us", or "our") is committed to protecting the privacy of our users, customers, and visitors. This Privacy Policy outlines our principles regarding the collection, processing, storage, and safeguarding of information when you interact with our website (wesecurex.com), APIs, security scanning engines, and verified trust badge infrastructure.
2. Information We Collect
We collect information strictly necessary to provide, manage, and secure our vulnerability assessment and subscription services:
- Account & Profile Information: Authorized contact name, business email address, telephone number, authentication credentials, and organization name provided during registration or account setup.
- Billing & Transaction Details: When purchasing or managing paid subscriptions (such as Pro or Agency tiers), billing contact information, transaction histories, and partial card details (such as the last 4 digits of your payment card and card brand/network) are recorded for invoicing and accounting. We do not record or store card expiration dates.
- Target Domain & Technical Telemetry: Domain names, IP addresses, HTTP response headers, SSL/TLS certificate chains, and DNS configurations submitted for security evaluation.
- Automated Scan Logs: Findings, vulnerability classifications (CVSS scores), timestamped audit results, and remediation verification records generated during dynamic scans.
- Usage Telemetry: Aggregated system performance logs, browser agent details, and access timestamps to ensure platform stability.
- Cookies & Session Identifiers: Essential session cookies and local tokens strictly necessary for user authentication, session security, and defense against automated attacks.
3. How We Process Scan Data
Target scan data is processed solely to generate vulnerability reports, track security diffs over time, and issue dynamic verification badges. We do not sell, rent, or monetize your scan data or proprietary vulnerability findings to third-party data brokers or advertisers.
4. Payment Processing & Credential Protection
All payment transactions are processed securely through certified, regulated third-party payment gateways, payment aggregators, and PCI-DSS compliant payment service providers.
No Cardholder Data or Payment Credential Storage: Wescequre does not collect, handle, or store complete credit or debit card numbers, CVV/CVC security verification codes, banking PINs, UPI PINs, One-Time Passwords (OTPs), or customer payment credentials on our servers. All sensitive payment details are securely tokenized and transmitted directly from your client browser to the certified payment processor via encrypted TLS 1.3 channels. Our payment processing partners comply with the Payment Card Industry Data Security Standards (PCI-DSS) and applicable regulatory payment aggregator directives.
5. Legal Basis for Processing (GDPR & International Law)
For users subject to the General Data Protection Regulation (GDPR) or similar frameworks, we process personal data under the following legal bases:
- Contractual Necessity: To deliver vulnerability audits, report generation, account management, and process payment subscriptions requested by the user.
- Legitimate Interest: To maintain network security, defend our scanning infrastructure against abuse, and prevent fraudulent transactions and chargebacks.
- Legal Compliance: To comply with applicable cybersecurity reporting regulations, statutory accounting standards, and tax obligations.
6. Third-Party Subprocessors & Data Sharing
We share relevant data with trusted third-party service providers solely to operate our infrastructure, fulfill transactions, and protect users:
- Payment Service Providers & Aggregators: Certified payment gateways, payment aggregators, and acquiring banking partners to securely authorize transactions, manage subscriptions, process refunds, track transactions, detect and mitigate fraud, and fulfill statutory compliance obligations. By initiating a transaction or subscribing to our services, you consent to the transmission of necessary transaction and billing data to these regulated providers for these specific purposes.
- Infrastructure & Hosting: Cloud computing providers, DDoS protection networks, and encrypted database infrastructure operating under signed Data Processing Agreements (DPAs).
- Legal & Fraud Prevention: Banking networks, regulatory bodies, and fraud-monitoring systems to investigate unauthorized charges, comply with lawful authority mandates, and protect against financial abuse.
7. Data Retention & Security Controls
All data in transit is encrypted using modern TLS 1.3 cryptography. Scan results and database records are protected at rest using AES-256 encryption. We enforce automated retention schedules that archive or purge historical scan telemetry in accordance with organizational policies. Invoices, tax records, and transaction histories are securely retained in compliance with statutory financial retention requirements.
8. Your Data Subject Rights
Depending on your jurisdiction, you possess the right to access, rectify, or request deletion (Article 17 GDPR "Right to be Forgotten") of your personal data. You may exercise these rights at any time by contacting our data protection team.
9. Contact Information
For inquiries regarding this Privacy Policy, billing data, or our security practices, contact us at:
Wescequre Cybersecurity
Website: https://wesecurex.com
Privacy & Legal: privacy@wesecurex.com
Billing & Customer Support: support@wesecurex.com
Customer Support Telephone: [Registered Support Phone Number to be provided by Merchant]
Operating / Registered Address: [Registered Physical Business Address to be provided by Merchant]
10. Policy Modifications & Updates
We reserve the right to periodically update this Privacy Policy to reflect changes in our legal obligations, regulatory guidance, or platform functionality. Any modifications will be posted directly to this page with an updated revision date. Your continued use of our platform following the posting of revisions constitutes acceptance of the updated policy.