Version 1.0 | Effective 2026-01-25
Privacy Policy & Data Processing Agreement
This combined Privacy Policy and Data Processing Agreement ("Policy") describes how Cogmus (trading as Portarus) collects, processes, protects, and shares personal data when you use Portarus, our AI security gateway platform.
Last Updated: 2026-01-25 | Contact: [email protected]
1. General Principles
Our data processing practices are built on principles of lawfulness, fairness, transparency, purpose limitation, data minimization, accuracy, integrity, confidentiality, and accountability. This policy applies to all personal data processed in connection with Portarus, accessible at https://portarus.com, https://portarus.com, and all related APIs and integrations.
2. Personal Data We Collect
We collect personal data from you in the following categories:
a) Information You Provide Directly:
- Account registration data (name, email, phone number, organization name, job title)
- Billing information (postal address, payment method, invoice preferences)
- Webhook endpoint configurations and security credentials
- Support requests, feedback, and communication preferences
- Any content you upload to your Account dashboard
b) Automatically Generated Data:
- IP addresses, device identifiers, and browser information
- HTTP headers, authentication tokens, and API keys
- Request and response metadata from all gateway traffic
- Event logs, audit trails, security events, and access logs
- Timestamps, geolocation data (country/city level), and bandwidth usage
c) Content You Transmit Through the Gateway:
- Prompts, payloads, and request bodies forwarded through Portarus
- Prompt metadata, security classifications, and processing tags
- Response information and webhook delivery logs
- Deduplication fingerprints and semantic security signals
- Any personal data contained within the content you route through the gateway
3. Legal Basis for Processing
We process personal data under the following legal bases:
- Contract Fulfillment: Processing necessary to provide Portarus, manage your Account, and enforce the Terms of Service
- Legal Obligation: Compliance with regulations (GDPR, CCPA, tax authorities, law enforcement)
- Legitimate Interest: Security monitoring, fraud prevention, platform improvement, and invoice collection
- Explicit Consent: Marketing communications, analytics, and optional integrations (opt-in only)
- Data Subject Consent: Any processing beyond the above requires your prior written consent
GDPR & CCPA Status: This platform is subject to GDPR (for EU residents) and CCPA (for California residents). See Section 19 for your rights.
4. How We Use Your Data
We use personal data for the following purposes:
- Service Delivery: Authenticating users, managing access, processing webhook requests, and maintaining platform functionality
- Rate Limiting & Quota Management: Calculating API call limits, deduplication quotas, and request budgets per your plan tier
- Security & Threat Detection: Performing semantic analysis, identifying malicious payloads, and blocking unauthorized access
- Billing & Payment: Generating invoices, processing payments, managing refunds, and communicating billing updates
- Customer Support: Responding to support tickets, troubleshooting issues, and providing technical assistance
- Legal Compliance: Fulfilling regulatory requests, responding to law enforcement, and protecting legal rights
- Optimization & Analytics: Improving platform performance, analyzing usage patterns, and planning feature development
- Communication: Sending platform notifications, security alerts, service announcements, and policy updates
- Research & Development: Aggregated anonymized analysis to train security models (content not used without your explicit opt-in)
5. Cookies & Tracking Technologies
We use cookies, web beacons, and similar tracking technologies for:
Essential Cookies: Session tokens, authentication credentials, CSRF protection (required for platform function)
Performance Cookies: Anonymous analytics, error tracking, and infrastructure monitoring
Preference Cookies: Theme selection, dashboard layout, and language preferences
You may disable non-essential cookies via your browser settings, though this may impact dashboard functionality. We do not sell personal data to third parties for cookie-based tracking.
6. Third-Party Sharing & Subprocessors
We share personal data with trusted third-party service providers who process it on our behalf, bound by strict data protection agreements:
Cloudflare, Inc.
Purpose: Infrastructure, CDN, Edge Computing
Location: USA
Stripe, Inc.
Purpose: Payment Processing
Location: USA
Supabase
Purpose: Database Services (PostgreSQL)
Location: USA
Upstash, Inc.
Purpose: Redis Cache Services
Location: USA
Subprocessor Changes: We may add or remove subprocessors. You will be notified at [email protected] with at least 10 days' notice. You may object to new subprocessors within 10 business days of notification by sending written notice to [email protected].
7. International Data Transfers
Portarus processes data globally via infrastructure in the United States, European Union, and other jurisdictions. For users in the EU, UK, or other restricted territories, we rely on:
- Standard Contractual Clauses (SCCs) approved by the European Commission
- Binding Corporate Rules (BCRs) where applicable
- Your explicit informed consent for transfers to non-adequate jurisdictions
By using Portarus, you consent to processing in jurisdictions without an adequacy decision and acknowledge the risks associated with international transfer.
8. Security & Data Protection Measures
We implement industry-standard security controls:
- Encryption: AES-256 encryption at rest, TLS 1.3 in transit (minimum TLS 1.2)
- Access Control: Role-based access control (RBAC), principle of least privilege, multi-factor authentication
- Audit & Monitoring: Continuous security monitoring, quarterly penetration testing, annual third-party audits
- API Security: HMAC-SHA256 webhook signatures, rate limiting, request validation, payload encryption
- Incident Response: 24/7 monitoring, breach notification within 72 hours (GDPR), forensic analysis, legal review
- Certifications: SOC 2 Type II in progress, ISO 27001 planned
Important: While we maintain rigorous protections, no security system is impenetrable. You are responsible for protecting your API keys, passwords, and webhooks endpoints. Never share credentials or secrets.
9. Data Retention & Deletion
We retain personal data only as long as necessary:
Active Accounts: Retained throughout the service relationship plus any applicable legal hold period (typically 6 months post-termination).
Logs & Audit Trails: Retained for 30–365 days depending on plan tier and log type (see Terms of Service for SLA specifics).
Backups: Maintained for 30 days after deletion; may be recovered during this window.
Webhook Payloads: Not stored after delivery unless explicitly configured; if stored, subject to plan-specific retention limits.
GDPR Erasure: Upon verified erasure request, we delete or anonymize personal data within 30 days unless legal obligation requires retention.
10. Your Data Subject Rights (GDPR/CCPA)
Depending on your jurisdiction, you have the following rights:
Right of Access
Request a copy of all personal data held. Response within 30 days (GDPR) or 45 days (CCPA).
Right to Rectification
Correct inaccurate or incomplete personal data. You can update most information in your Account Settings.
Right to Erasure ("Right to be Forgotten")
Request deletion of personal data, subject to legal and contractual obligations (e.g., tax records must be retained per law).
Right to Restrict Processing
Limit processing to certain purposes (e.g., during an accuracy dispute). Service may be limited during restriction.
Right to Data Portability
Export your personal data in a structured, machine-readable format (JSON/CSV) for transfer to other services.
Right to Object
Opt-out of processing based on legitimate interest or marketing communications. Essential service processing cannot be objected to.
Right to Withdraw Consent
Withdraw consent for optional processing (analytics, non-essential cookies, marketing) at any time.
Right Against Automated Decision-Making
Request human review of automated decisions that produce legal effects. We do not use automated profiling for account decisions.
To Exercise Your Rights: Send a detailed request to [email protected] with proof of identity. We will respond within applicable legal timeframes. Frivolous or excessive requests may be rejected.
11. Data Processing Agreement – Processor Role
When you use Portarus to process personal data on behalf of your organization, the following terms apply:
a) Controller vs. Processor: You (Account holder) act as the data controller or entity authorized by the controller. Cogmus acts as your data processor, processing data exclusively per your documented instructions and the Terms of Service.
b) Joint Processing: If you are not the controller, you warrant that you are authorized to act on the controller's behalf and agree to indemnify Cogmus against claims arising from unauthorized processing.
c) Processing Instructions: We process data only as instructed through the dashboard, API, and Terms of Service. Any additional processing requires an amendment to this Policy or written Data Processing Addendum (DPA).
d) Data Subject Requests: You are responsible for responding to data subject access requests. Cogmus will provide reasonable cooperation and may charge reasonable fees for access requests exceeding 1 per calendar year per Account.
12. Data Categories & Processing Purposes (DPA)
The following personal data is processed for the stated purposes:
Processed Data Categories
- Names and email addresses (identifiers)
- IP addresses and device identifiers (technical)
- Transaction and billing information (commercial)
- Content transmitted through the gateway (user-generated, may include personal data)
- Activity logs and security events (metadata)
- Webhook configurations and credentials (technical)
Processing Purposes
- Provide security filtering and threat detection ("Security Operations")
- Manage user access, authentication, and authorization ("Access Control")
- Maintain audit trails and compliance records ("Compliance")
- Detect and prevent fraud and abuse ("Fraud Prevention")
- Maintain platform infrastructure and uptime ("Infrastructure")
- Respond to legal process ("Legal Compliance")
13. Security Measures & Subprocessor Details (DPA)
We implement comprehensive security measures to protect personal data from unauthorized access, alteration, disclosure, or destruction:
Technical Security
- End-to-end AES-256 encryption at rest
- TLS 1.3 encryption in transit; minimum TLS 1.2 enforced
- WAF (Web Application Firewall) and DDoS mitigation
- Rate limiting and API throttling
- TLS certificate pinning for critical endpoints
Organizational Security
- Role-based access control (RBAC) with principle of least privilege
- Multi-factor authentication (MFA) for all administrative accounts
- Background checks for staff with access to customer data
- Confidentiality agreements and security training for all employees
- Physical and logical access controls at data centers
Operational Security
- Quarterly penetration testing and vulnerability assessments
- Annual third-party security audits
- 24/7 security monitoring and intrusion detection
- Incident response plan with <72-hour breach notification
- Disaster recovery and business continuity planning
- Regular security patches and dependency updates
Subprocessors Detail:
| Subprocessor | Purpose | Location | DPA Signed |
|---|---|---|---|
| Cloudflare, Inc. | Infrastructure, CDN, Edge Computing | USA | ✓ |
| Stripe, Inc. | Payment Processing | USA | ✓ |
| Supabase | Database Services (PostgreSQL) | USA | ✓ |
| Upstash, Inc. | Redis Cache Services | USA | ✓ |
14. Data Breach Notification & Incident Response
In the event of a confirmed data breach or unauthorized access:
- Notification Timeline: Affected users notified within 72 hours (GDPR) or per applicable state law (CCPA: 45 days)
- Content of Notice: Incident description, data potentially compromised, measures taken, and recommended actions
- Regulatory Reporting: Breaches affecting >100 persons reported to Data Protection Authorities per GDPR Article 33–34
- Investigation: We conduct forensic analysis, document findings, and coordinate with law enforcement if necessary
- Remediation: Affected data secured, access revoked, systems patched, and monitoring enhanced
- Communication Channel: Use [email protected] or [email protected] for incident inquiries
15. Audit Rights & Compliance Verification
We permit reasonable audits to verify compliance with this Policy and applicable data protection law:
Audit Scope: Verification of security controls, subprocessor compliance, data handling procedures, and incident response effectiveness.
Audit Frequency: Annual audits at your expense conducted by mutually agreed third-party auditors or regulatory authorities.
Confidentiality: Audit reports and findings treated as confidential. We may request editing of commercially sensitive information before sharing with third parties.
Cooperation: We will provide reasonable access to personnel, documentation, and systems during business hours with 10 days' notice.
Cost Allocation: You bear the cost of third-party audits. Regulatory audits (government agencies, DPAs) conducted at our cost.
16. Children & Age Restrictions
Portarus is not intended for individuals under 18 years of age. We comply with COPPA (Children's Online Privacy Protection Act) and similar regulations in other jurisdictions. If we discover an Account registered by someone under the minimum age:
- The Account is immediately suspended
- Personal data is promptly deleted
- Parent/guardian is notified at the email on file
- No further processing occurs without parental consent
If you believe a child's personal data has been processed, please contact [email protected] immediately.
17. Policy Updates & Changes
We may update this Policy when our practices change or for legal/regulatory reasons:
- Notice Period: Material changes communicated at least 30 days in advance via email or dashboard notice
- Effective Date: New version posted at https://portarus.com/privacy with updated version number and effective date
- Continued Use: Your continued use of Portarus after effective date constitutes acceptance
- Withdrawal of Consent: If you object to new terms, you may terminate your Account within 30 days for a prorated refund
- Archive: Historical versions retained for reference
18. Governing Law & Dispute Resolution
Privacy disputes are governed by State of Delaware, United States and resolved as follows:
Informal Resolution (30 days): Before initiating formal proceedings, send a detailed written complaint to [email protected]. We will respond within 30 days and attempt to resolve the dispute in good faith.
Formal Arbitration: If not resolved informally, disputes are submitted to binding arbitration under the Commercial Arbitration Rules administered by the American Arbitration Association (AAA) at Wilmington, Delaware.
Class Action Waiver: All disputes must be arbitrated individually; class actions and class arbitrations are prohibited unless prohibited by law.
Regulatory Complaints: You retain the right to file privacy complaints with the Data Protection Authority in your jurisdiction without waiving arbitration rights.
19. GDPR & CCPA Compliance Summary
GDPR (EU Residents)
- Legal Basis: Contract, Consent, Legal Obligation
- Data Subject Rights: Access, Rectification, Erasure, Portability, Objection
- Jurisdiction: EU Member States + EEA
- DPA Available: Upon request
- Breach Notification: 72 hours to DPA
- Contact DPA: [email protected]
CCPA (California Residents)
- Legal Basis: Disclosed by this Policy
- Consumer Rights: Know, Delete, Opt-Out, Correct
- Jurisdiction: State of California, USA
- No Sale of Data: We do not sell personal information
- Breach Notification: 45 days to affected residents
- Contact Privacy Team: [email protected]
20. Contact Information & Data Subject Requests
For privacy questions, data subject requests, or concerns, contact us via:
Data Protection Officer
[email protected]Privacy Team
[email protected]Legal Matters
[email protected]Company
Cogmus
Website
https://portarus.comResponse Timeframe: We aim to respond to all data subject requests within 15 business days. Complex requests or those requiring clarification may take up to 30 days. You will be notified if your request requires additional time.
Disclaimer: This Privacy Policy is provided for informational purposes. It does not constitute legal advice. Cogmus reserves the right to modify this Policy at any time. In case of conflict between this Policy and applicable law, the more stringent provision applies. If you have questions about our privacy practices or how your data is processed, please contact [email protected].