Data Compliance
Last updated: 15 June 2026
Posqure is a security product, so we hold ourselves to the standards we help you measure. This page summarizes how Posqure handles data and supports your own compliance obligations. It complements our Privacy Policy.
1. Our role
For your Google Workspace configuration data, you are the data controllerand Posqure acts as your data processor: we process it only on your instruction, to produce your security assessment. For your account data (name, email, billing reference) we act as a controller. A Data Processing Addendum (DPA) is available on request — email posqure@gmail.com.
2. Frameworks we align with
Our data practices are designed to align with the GDPR (EU/UK), India's Digital Personal Data Protection Act 2023, and the CCPA/CPRA (California). To be clear about what this means: Posqure helps you assess and evidence SOC 2, ISO 27001 and GDPR controls — we do not claim to be certified under those frameworks ourselves, and any such certification would be stated explicitly with its report. We will not overstate our posture.
3. Data minimization — what we hold
We are built to hold as little of your data as possible. We request only .readonly Google scopes; we evaluate your configuration in memory and persist only the resulting findings and minimal sanitized evidence (counts and a few identifiers). We never store the contents of your emails, files, calendars, or chats, and we never download your user directory. See the Privacy Policy for the full detail.
4. Where your data is processed
Your primary data is stored in Supabase (PostgreSQL) in AWS ap-southeast-2, Sydney, Australia, and our application compute runs in the same Sydney region. Data is encrypted in transit (TLS). Sensitive secrets — including your Google refresh token — are encrypted at rest with AES-256-GCM using a key held outside our source code.
5. Sub-processors
We use a small set of vendors to run the service. Each processes data only to perform its function, under its own data-protection commitments:
| Sub-processor | Purpose | Location |
|---|---|---|
| Supabase | Primary database (PostgreSQL) | AWS ap-southeast-2 (Sydney, Australia) |
| Vercel | Application hosting & serverless compute | Sydney region (syd1) |
| Resend / Gmail | Transactional & lifecycle email | United States |
| Dodo Payments | Billing (Merchant of Record) | United States |
| The Workspace APIs you connect (read-only) | Per Google's infrastructure | |
| Google Gemini / Groq | Optional AI assistant (sanitized findings only) | United States |
6. Security measures
Read-only by design (a code guard refuses any non-read-only Google scope); tokens encrypted at rest; no secrets in logs or error trackers; least-privilege access to production; findings-only storage; and no third-party advertising or analytics trackers on the product.
7. Your rights
Subject to your jurisdiction, you may request access to, correction of, export of, or deletion of your personal data, and you may object to or restrict certain processing. We never sell personal data and never use it to train AI models. Exercise any right by emailing posqure@gmail.com; we respond within the timeframes required by applicable law.
8. International transfers
Because our vendors operate in Australia and the United States, your data may be processed outside your country. Where required, transfers are covered by appropriate safeguards such as Standard Contractual Clauses.
9. Breach notification
If a personal-data breach affecting your data occurs, we will notify affected customers and, where applicable, the relevant supervisory authority without undue delay and within the timeframes required by law (for example, within 72 hours under the GDPR).
10. Retention & deletion
We keep findings for your plan's retention window. Disconnecting a Workspace immediately deletes the stored refresh token. You may request deletion of your account and all associated data at posqure@gmail.com; we complete it within 30 days.
11. Google API data
Our use of data received from Google APIs adheres to the Google API Services User Data Policy, including the Limited Use requirements, as detailed in our Privacy Policy.
12. Contact
Data-protection questions, DPA requests, or rights requests: posqure@gmail.com.