Privacy policy
Which personal data the service processes, why, where, and your rights.
Last updated: 10 September 2026. This policy explains which personal data Idolbe Patch processes, why, where, for how long, and your rights. Idolbe (idolbe-ai.com) operates the service. For the data your organization collects from its own computers, your organization is the controller and we are its processor; for your console account, we are the controller.
Data we process
| Category | Examples | Source | Purpose |
|---|---|---|---|
| Account data | Name, work email address, role, sign-in method, hashed password | You, or the administrator who invited you | Authentication, authorization, notifications |
| Security data | Sign-in attempts and failures, IP address of sign-ins and API calls, trusted-browser records, MFA codes | Your browser and API clients | Account protection, rate limiting, audit |
| Endpoint data | Hostnames, logged-on user names, IP and MAC addresses, hardware and software inventory, updates, vulnerabilities, command logs | The agent on your organization's computers | The service itself: patch and vulnerability management |
| Audit trail | Who did what and when in the console and the API | The console | Accountability, support, security |
| Support correspondence | Emails you send us | You | Answering you |
We do not collect file contents, documents, browsing history or keystrokes from endpoints, and we do not use tracking pixels or third-party analytics in the console. The only cookies are the session cookie and, if you use email MFA, the trusted-browser cookie.
Legal bases
Performance of the contract with your organization (providing the service), our legitimate interest in keeping the service secure and improving it, and legal obligations. Transactional emails (MFA codes, password resets, alerts and reports you configured, service notices) are part of the service and cannot be opted out of while you keep an account; there is no marketing email.
Where data is processed
The console and its database are hosted by OVHcloud in the European Union. Sub-processors:
| Sub-processor | Role | Location |
|---|---|---|
| OVHcloud | Hosting of the console, database and backups | European Union |
| Brevo | Delivery of transactional email (recipient address and message content) | European Union |
| GitHub (Microsoft) | Read-only source of the third-party version catalog (no customer data sent) | United States |
| NIST NVD, CISA, Microsoft | Read-only vulnerability data (no customer data sent) | United States |
We do not transfer endpoint or account data outside the European Union.
Retention
See Data retention and account closure: inventory lives while the endpoint exists, execution history 180 days and audit trail 365 days by default (configurable by your organization), backups 30 days, and everything is deleted 30 days after an organization is closed.
Security
Encryption in transit (HTTPS), password hashing, multi-factor authentication, per-endpoint agent tokens, role-based access, rate limiting, audit trail, nightly tested backups. Details in Security FAQ and trust model. We notify affected organizations of a personal-data breach without undue delay.
Your rights
You can access, correct or delete your account data in the console (profile, or through your organization's administrator) and export your organization's data at any time. Under the GDPR you may also ask us for access, rectification, erasure, restriction, portability or object to processing, and lodge a complaint with your supervisory authority. Requests about endpoint data (for example a logged-on user name) should go to your organization, which controls that data; we assist it.
Contact
The support address in the console footer, with "privacy" in the subject.
Changes
We announce material changes to this policy by email to organization administrators and on the status page at least 30 days before they take effect.
