Idolbe Patch

Privacy policy

Which personal data the service processes, why, where, and your rights.

Last updated: 10 September 2026. This policy explains which personal data Idolbe Patch processes, why, where, for how long, and your rights. Idolbe (idolbe-ai.com) operates the service. For the data your organization collects from its own computers, your organization is the controller and we are its processor; for your console account, we are the controller.

Data we process

CategoryExamplesSourcePurpose
Account dataName, work email address, role, sign-in method, hashed passwordYou, or the administrator who invited youAuthentication, authorization, notifications
Security dataSign-in attempts and failures, IP address of sign-ins and API calls, trusted-browser records, MFA codesYour browser and API clientsAccount protection, rate limiting, audit
Endpoint dataHostnames, logged-on user names, IP and MAC addresses, hardware and software inventory, updates, vulnerabilities, command logsThe agent on your organization's computersThe service itself: patch and vulnerability management
Audit trailWho did what and when in the console and the APIThe consoleAccountability, support, security
Support correspondenceEmails you send usYouAnswering you

We do not collect file contents, documents, browsing history or keystrokes from endpoints, and we do not use tracking pixels or third-party analytics in the console. The only cookies are the session cookie and, if you use email MFA, the trusted-browser cookie.

Performance of the contract with your organization (providing the service), our legitimate interest in keeping the service secure and improving it, and legal obligations. Transactional emails (MFA codes, password resets, alerts and reports you configured, service notices) are part of the service and cannot be opted out of while you keep an account; there is no marketing email.

Where data is processed

The console and its database are hosted by OVHcloud in the European Union. Sub-processors:

Sub-processorRoleLocation
OVHcloudHosting of the console, database and backupsEuropean Union
BrevoDelivery of transactional email (recipient address and message content)European Union
GitHub (Microsoft)Read-only source of the third-party version catalog (no customer data sent)United States
NIST NVD, CISA, MicrosoftRead-only vulnerability data (no customer data sent)United States

We do not transfer endpoint or account data outside the European Union.

Retention

See Data retention and account closure: inventory lives while the endpoint exists, execution history 180 days and audit trail 365 days by default (configurable by your organization), backups 30 days, and everything is deleted 30 days after an organization is closed.

Security

Encryption in transit (HTTPS), password hashing, multi-factor authentication, per-endpoint agent tokens, role-based access, rate limiting, audit trail, nightly tested backups. Details in Security FAQ and trust model. We notify affected organizations of a personal-data breach without undue delay.

Your rights

You can access, correct or delete your account data in the console (profile, or through your organization's administrator) and export your organization's data at any time. Under the GDPR you may also ask us for access, rectification, erasure, restriction, portability or object to processing, and lodge a complaint with your supervisory authority. Requests about endpoint data (for example a logged-on user name) should go to your organization, which controls that data; we assist it.

Contact

The support address in the console footer, with "privacy" in the subject.

Changes

We announce material changes to this policy by email to organization administrators and on the status page at least 30 days before they take effect.