Skip to content

Legal Documents

SecurePoint USA Compliance and Legal Documentation

Compliance-First Approach

SecurePoint USA is built for organizations that answer to regulators. These documents describe what the platform does, how we handle your data, and where each certification stands, so your compliance team can verify rather than assume.

Privacy Policy & Data Processing Addendum

CurrentUpdated: February 14, 2026

How we collect, process, and retain data, the rights available to you, and our data processing addendum.

Key Points:

  • GDPR Article 28 compliant DPA
  • CCPA compliance for California
  • ITAR/EAR data retention (10 years)
  • Standard Contractual Clauses (SCCs)

Subprocessors

CurrentUpdated: September 1, 2026

The third parties that process customer data on our behalf, what each does, and which apply only when a customer enables a feature.

Key Points:

  • Core platform providers that apply to every customer
  • Providers that apply only when a feature is enabled
  • Processing location for each provider
  • How subprocessor changes are communicated

Data Processing Agreement (DPA)

CurrentUpdated: October 12, 2025

GDPR Article 28 Data Processing Agreement for customers with EU operations.

Key Points:

  • GDPR Article 28 compliance
  • Subprocessor transparency
  • Data subject rights support
  • Breach notification procedures

Compliance Agreement

CurrentUpdated: October 12, 2025

ITAR/EAR/OFAC compliance framework for defense contractors and aerospace companies.

Key Points:

  • ITAR/EAR compliance requirements
  • OFAC and BIS restricted-party screening
  • NIST 800-171 controls
  • Audit and documentation standards

AI Use & Compliance Statement

CurrentUpdated: January 16, 2026

How SecurePoint USA uses AI, where a person decides, and how that fits ITAR, EAR, and DFARS obligations.

Key Points:

  • ITAR/EAR/DFARS compliant AI usage
  • Data minimization and redaction
  • Complete audit trails
  • Fallback mode operation

IP & ID Collection Policy

CurrentUpdated: February 14, 2026

How we collect, protect, and retain network IPs and visitor ID images for compliance.

Key Points:

  • IP purpose limitation & 180-day rotation
  • Private storage with signed URLs for IDs
  • RLS tenant isolation

Terms of Service

CurrentUpdated: January 16, 2026

Terms and conditions for using SecurePoint USA services.

Key Points:

  • Service usage terms
  • User responsibilities
  • Limitation of liability
  • Dispute resolution

Security Documentation

CurrentUpdated: September 1, 2026

Our security controls and the current status of each certification, stated plainly.

Key Points:

  • NIST 800-171 control mapping
  • Data encryption standards
  • Access control measures
  • Incident response procedures

Compliance Highlights

ITAR/EAR

Screening and access workflows built for export-controlled facilities

DFARS

Evidence packs that support DCSA, DCMA, and C3PAO reviews

NIST 800-171

Control mapping in progress; no assessment report is claimed

Audit Ready

Append-only, hash-chained audit logs

Questions About Compliance?

Our compliance team is available to answer questions about our legal documentation and how SecurePoint USA meets your regulatory requirements.

Technical Support:
support@securepointusa.com
Compliance Questions:
privacy@securepointusa.com
Enterprise Sales:
sales@securepointusa.com
Legal | SecurePoint USA