Privacy Policy
Last updated: June 10, 2026
This Privacy Policy explains how Mithras R&D AS processes personal data when you use Perimeter, our external attack-surface management platform. We process personal data in accordance with the EU General Data Protection Regulation (GDPR) and the Norwegian Personal Data Act.
1. Data controller
Mithras R&D AS, a company registered in Norway, is the data controller for personal data processed in connection with your Perimeter account. For scan results concerning your organization's assets, we generally act as a processor on your behalf; a separate data processing agreement applies to customer-controlled data.
2. Categories of data we collect
- Account data: name, email address, hashed password, two-factor authentication configuration, and tenant/organization membership.
- Usage and security logs: sign-in events, IP addresses, user-agent strings, audit trail entries, and API access logs.
- Scan results: information about the internet-facing assets you authorize us to examine, such as domains, hosts, open services, certificates, and identified findings. These records may incidentally contain personal data published on your assets.
- Billing data: subscription plan, invoices, and payment status (card details are held by our payment provider, not by us).
- Support communications: messages you send to our support and abuse contacts.
3. Purposes and legal bases
- Providing the service, including discovery, scanning, and reporting — performance of a contract (GDPR Art. 6(1)(b)).
- Securing the service, preventing abuse, and maintaining audit trails — legitimate interests (GDPR Art. 6(1)(f)).
- Billing and accounting — legal obligation (GDPR Art. 6(1)(c)) and contract.
- Product communications and service announcements — legitimate interests; marketing communications only with your consent (GDPR Art. 6(1)(a)).
4. Retention
- Account data is retained for the life of the account and deleted within 30 days of account closure.
- Security and audit logs are retained for up to 12 months.
- Scan results are retained per your tenant's configuration and deleted within 30 days of subscription termination.
- Accounting records are retained as required by Norwegian bookkeeping law.
5. Subprocessors and transfers
We use a limited set of subprocessors to operate the service: cloud hosting and infrastructure providers, a transactional email provider, and a payment processor. Subprocessors are bound by data processing agreements. Where data is transferred outside the EEA, we rely on adequacy decisions or EU Standard Contractual Clauses. A current subprocessor list is available on request.
6. Your rights
Subject to the conditions in the GDPR, you have the right to access, rectify, and erase your personal data, to restrict or object to processing, to data portability, and to withdraw consent where processing is based on consent. You also have the right to lodge a complaint with a supervisory authority; in Norway this is Datatilsynet (the Norwegian Data Protection Authority).
7. Security measures
We protect personal data with technical and organizational measures including encryption in transit, encryption at rest for sensitive fields, mandatory two-factor authentication for all accounts, strict tenant isolation, role-based access control, and audit logging of administrative actions.
8. Changes to this policy
We may update this Privacy Policy from time to time. Material changes will be announced by email or in-app notification before they take effect.
9. Contact
Privacy enquiries and data-subject requests can be sent to Mithras R&D AS at privacy@mithras.no, marked for the attention of our privacy officer.