Legal
Privacy Policy
Last updated 12 August 2026
Sorbe builds data-loss prevention for AI. It would be a poor look to handle your data carelessly, so we don't. This policy explains what we collect, why, and the choices you have.
Who we are
“Sorbe”, “we”, “us” refers to [Sorbe legal entity name], registered at [registered address], the controller responsible for the personal data described here. Questions go to privacy@sorbe.io.
The short version
The Sorbe product is built to not hold your sensitive data. Content is inspected on the device, and what we keep about a detection is a masked preview and a non-reversible fingerprint — never the raw value. This policy covers the personal data we do process: to run our website, to operate your account, and to keep the product working.
Information we process
When you visit the website
- Standard request data your browser sends (IP address, user agent, pages viewed), used for security and aggregate analytics.
- Cookie and consent preferences you set (see our Cookie Policy).
- Anything you choose to send us — for example, an email to our team.
When you use the product
- Account data — the name, work email, and credentials of the people you authorise to sign in, plus organisation and billing details.
- Inspection records — metadata about each decision (which detector fired, the policy applied, the outcome), a masked preview, and a fingerprint. Raw sensitive values are not stored.
- Operational logs — technical logs needed to run, secure, and debug the service.
How we use it
- To provide, secure, and improve the website and the product.
- To authenticate the people you allow to sign in, and to keep an auditable record of decisions.
- To communicate with you about your account, security, and service changes.
- To meet legal, tax, and regulatory obligations.
Legal bases (where GDPR applies)
We rely on: performance of a contract (operating your account); legitimate interests (security, aggregate analytics, product improvement); consent (non-essential cookies and marketing, which you can withdraw at any time); and legal obligation (records we are required to keep).
Sharing and sub-processors
We do not sell personal data. We share it only with vetted sub-processors that help us run the service (for example, hosting and infrastructure), each under a data-processing agreement; with professional advisers; and where required by law. A current list of sub-processors is available on request at privacy@sorbe.io.
International transfers
Where personal data is transferred outside your region, we rely on an appropriate safeguard — such as Standard Contractual Clauses — to protect it. [Confirm hosting regions and transfer mechanism with counsel before launch.]
Retention
We keep personal data only as long as needed for the purposes above, then delete or anonymise it. Inspection records are retained according to your organisation’s configured retention policy; account data is kept for the life of the account and a limited period afterwards.
Security
We apply technical and organisational measures appropriate to the risk — including on-device inspection, masked storage, encrypted transport, access controls, and least-privilege administration. No system is perfectly secure, but not storing raw sensitive values removes the thing most worth stealing. Report a concern to security@sorbe.io.
Your rights
Depending on where you live, you may have the right to access, correct, delete, port, or restrict the processing of your personal data, and to object to it or withdraw consent. To exercise a right, email privacy@sorbe.io. You also have the right to complain to your local data-protection authority.
Children
Sorbe is a workplace product and is not directed to anyone under 16. We do not knowingly collect their data.
Changes
We may update this policy as the product and the law evolve. Material changes will be posted here with a new “last updated” date, and notified where required.
Contact
[Sorbe legal entity name], [registered address]. Privacy enquiries: privacy@sorbe.io.