Legal Documents
SecurePoint USA Compliance and Legal Documentation
Compliance-First Approach
SecurePoint USA is built for organizations that answer to regulators. These documents describe what the platform does, how we handle your data, and where each certification stands, so your compliance team can verify rather than assume.
Privacy Policy & Data Processing Addendum
How we collect, process, and retain data, the rights available to you, and our data processing addendum.
Key Points:
- GDPR Article 28 compliant DPA
- CCPA compliance for California
- ITAR/EAR data retention (10 years)
- Standard Contractual Clauses (SCCs)
Subprocessors
The third parties that process customer data on our behalf, what each does, and which apply only when a customer enables a feature.
Key Points:
- Core platform providers that apply to every customer
- Providers that apply only when a feature is enabled
- Processing location for each provider
- How subprocessor changes are communicated
Data Processing Agreement (DPA)
GDPR Article 28 Data Processing Agreement for customers with EU operations.
Key Points:
- GDPR Article 28 compliance
- Subprocessor transparency
- Data subject rights support
- Breach notification procedures
Compliance Agreement
ITAR/EAR/OFAC compliance framework for defense contractors and aerospace companies.
Key Points:
- ITAR/EAR compliance requirements
- OFAC and BIS restricted-party screening
- NIST 800-171 controls
- Audit and documentation standards
AI Use & Compliance Statement
How SecurePoint USA uses AI, where a person decides, and how that fits ITAR, EAR, and DFARS obligations.
Key Points:
- ITAR/EAR/DFARS compliant AI usage
- Data minimization and redaction
- Complete audit trails
- Fallback mode operation
IP & ID Collection Policy
How we collect, protect, and retain network IPs and visitor ID images for compliance.
Key Points:
- IP purpose limitation & 180-day rotation
- Private storage with signed URLs for IDs
- RLS tenant isolation
Terms of Service
Terms and conditions for using SecurePoint USA services.
Key Points:
- Service usage terms
- User responsibilities
- Limitation of liability
- Dispute resolution
Security Documentation
Our security controls and the current status of each certification, stated plainly.
Key Points:
- NIST 800-171 control mapping
- Data encryption standards
- Access control measures
- Incident response procedures
Compliance Highlights
ITAR/EAR
Screening and access workflows built for export-controlled facilities
DFARS
Evidence packs that support DCSA, DCMA, and C3PAO reviews
NIST 800-171
Control mapping in progress; no assessment report is claimed
Audit Ready
Append-only, hash-chained audit logs
Questions About Compliance?
Our compliance team is available to answer questions about our legal documentation and how SecurePoint USA meets your regulatory requirements.
support@securepointusa.com
privacy@securepointusa.com
sales@securepointusa.com