Hector Labs
ProductHow it worksReportsUse casesPricingContact
BOOK A DEMO
ProductHow it worksReportsUse casesPricingContact
REQUEST A DEMO

Privacy Policy

This Privacy Policy explains how HECTORLABS S.R.L. handles personal data when you visit hector-labs.com, use its contact form, or otherwise communicate with us about Hector. It does not cover customer data processed through the Hector product under a customer agreement or data-processing agreement.

1. Who we are

HECTORLABS S.R.L., trading as Hector Labs ("Hector", "we", "us", or "our"), is the controller responsible for the processing described in this policy.

  • Registered office: Strada Șesul de Sus 127M, Florești, Cluj County, Romania
  • Romanian Trade Registry number: J2025072442002
  • Sole Registration Code (CUI): 52560256
  • Privacy contact: dpo@hector-labs.com

We have not appointed a data protection officer or an EU/UK representative because those appointments are not applicable to the processing covered by this website policy. You can send every privacy request to the address above.

2. What we collect

2.1 Information you give us

When you submit the contact form, we receive your name, company email address, company name, phone number, message, and any other information you choose to include. We also keep our correspondence and follow-up records.

Please do not include credentials, secrets, vulnerability details, special-category personal data, or other confidential information that is not needed for your inquiry.

2.2 Website delivery and security data

Cloudflare delivers and protects the website and may process IP address, request time, requested path, browser and device information, user-agent, referrer, network and TLS information, security signals, and diagnostic data. We use Cloudflare Workers and CDN services to serve the site and Cloudflare Email Service to deliver contact-form messages.

The contact form uses Cloudflare Turnstile to distinguish legitimate submissions from automated abuse. Turnstile processes technical signals such as IP address, browser and device characteristics, user-agent, site key, page origin, and a short-lived verification token. The token and visitor IP are sent to Cloudflare for verification; the token is not used for analytics.

2.3 Privacy preferences

We store a strictly necessary first-party cookie named hector_cookie_consent for up to 180 days. It records whether you accepted or rejected optional analytics and the version of the consent notice you answered. It is required so we can remember and respect your choice.

2.4 Optional PostHog analytics

PostHog remains disabled unless you actively accept analytics. After consent, we use PostHog Cloud in the European Union region to understand aggregate website use, performance, errors, and the request-a-demo journey.

Depending on how you use the site, PostHog may receive:

  • page views, page exits, paths without query parameters, referrer, campaign attribution, section views, and scroll-depth milestones;
  • browser, operating-system, device, approximate country-level location, and performance/Web Vitals data;
  • non-sensitive link and button interactions, dead clicks, and heatmap coordinates;
  • masked session-replay data; and
  • sanitized error categories and explicit events such as key navigation choices, use-case and pricing interactions, request-demo clicks, and whether a contact journey started, became ready to submit, succeeded, or failed; and
  • answers to optional on-site feedback surveys, if we run one and you choose to respond.

We configure PostHog not to create person profiles, not to identify visitors, and not to capture IP addresses. A random browser identifier is used only to distinguish pseudonymous visits and sessions. After consent, PostHog may store the first-party cookies ph_hector_analytics and posthog_consent for up to 180 days. Withdrawing consent stops future capture and removes Hector's non-essential PostHog cookies and browser storage.

The contact-form subtree is excluded from autocapture, and every replay input is masked. We do not send contact-field contents, email addresses, phone numbers, message text, checkbox values, Turnstile values, URL query strings, raw error messages, request bodies, or element text containing user input to PostHog.

Analytics events and optional survey responses are retained for no more than 12 months and session recordings for no more than 30 days. After consent, PostHog may also deliver anonymous feature flags, controlled website experiments, or short on-site surveys configured by Hector. Survey responses are voluntary; please do not include personal, confidential, or security-sensitive information. We do not enable advertising integrations or identify visitors on this marketing site.

2.5 Cloudflare Web Analytics

Cloudflare Web Analytics provides aggregate traffic and page-performance measurements. According to Cloudflare, its performance beacon does not use cookies, does not collect or use visitors' personal data, and does not track individuals across Cloudflare customers' sites. Measurements can include page views, referrer, browser/device information, country-level location, load timing, and Core Web Vitals. It does not log query strings or custom events.

Cloudflare retains unsampled beacon data for seven days, then keeps sampled aggregate data; the Web Analytics dashboard makes data available for the previous six months. Cloudflare may separately retain limited operational and security logs under the applicable service settings where necessary to deliver, secure, and troubleshoot the website.

3. Why we use information

We process personal data for these purposes and legal bases:

  • Responding to inquiries and demo requests: to take steps at your request before entering a contract and for our legitimate interest in communicating with prospective business customers.
  • Delivering, securing, and troubleshooting the website: for our legitimate interests in providing a reliable service, preventing abuse, protecting our systems, and establishing or defending legal claims.
  • Remembering your privacy choice: to comply with our legal obligations and demonstrate that choice.
  • PostHog analytics: only with your consent. You can reject or withdraw consent at any time without affecting earlier lawful processing.
  • Aggregate website measurement: for our legitimate interest in understanding website availability and performance. Cloudflare states that its Web Analytics product does not collect or use visitor personal data.
  • Legal compliance: where processing is necessary to meet a legal obligation.

Where we rely on legitimate interests, we consider the nature of the data, the context, your reasonable expectations, and the safeguards available to you.

4. Who receives information

We disclose information only where needed for the purposes above:

  • Cloudflare, Inc. and its affiliates provide website delivery, Workers, CDN and security services, Turnstile, Web Analytics, and contact-email delivery.
  • PostHog, Inc. and its subprocessors provide consented analytics through PostHog Cloud's EU region.
  • Our authorized staff, contractors, and professional advisers may access information when their role requires it and they are subject to appropriate confidentiality duties.
  • Authorities, courts, counterparties, or advisers may receive information where required by law, necessary to protect rights and security, or connected with a corporate transaction subject to appropriate safeguards.

We do not sell personal data, share it for cross-context behavioural advertising, or use it for third-party advertising.

5. International transfers

Our Cloudflare and PostHog accounts use European Union regions where those options apply. Their global support, security operations, affiliates, or subprocessors may nevertheless process limited information outside the European Economic Area.

Where applicable, transfers rely on an adequacy decision, the European Commission's Standard Contractual Clauses, or another lawful transfer mechanism, together with contractual and technical safeguards. Contact us if you would like information about the safeguards relevant to your data.

6. How long we keep information

We keep personal data only as long as reasonably necessary for the purpose for which it was collected:

  • Contact inquiries and related correspondence: normally deleted or anonymized within 24 months after the last meaningful interaction.
  • Consent-preference cookie: expires after 180 days, unless you update your choice sooner. We may retain a minimal consent record longer where necessary to demonstrate compliance.
  • PostHog analytics events and session recordings: events are retained for no more than 12 months and session recordings for no more than 30 days.
  • Cloudflare Web Analytics: unsampled beacon data is retained for seven days, with aggregate dashboard data available for the previous six months.
  • Cloudflare operational, email-delivery, Turnstile, and security data: retained under the applicable service configuration and only for as long as necessary for delivery, abuse prevention, troubleshooting, or legal compliance.

We may preserve limited records for longer when required by law or reasonably necessary for contracts, disputes, fraud prevention, or security investigations. When a retention period ends, we delete or anonymize the information unless an exception applies.

7. Your rights and choices

Depending on applicable law and the circumstances, you may have the right to:

  • ask whether we process your personal data and receive a copy;
  • correct inaccurate or incomplete data;
  • request deletion or restriction;
  • object to processing based on legitimate interests;
  • receive portable data where applicable;
  • withdraw consent at any time; and
  • complain to a supervisory authority.

Send a request to dpo@hector-labs.com. We may ask for information needed to verify your identity and protect your data. We normally respond within one month, subject to extensions permitted by law.

To change analytics consent immediately, choose Cookie settings in the website footer. Rejecting analytics does not prevent you from browsing the site or contacting us.

You may lodge a complaint with the Romanian National Supervisory Authority for Personal Data Processing (ANSPDCP) at dataprotection.ro, by email at anspdcp@dataprotection.ro, or with the supervisory authority where you live, work, or believe an infringement occurred.

8. Automated security checks

Turnstile automatically evaluates technical signals to determine whether a contact-form submission appears legitimate. A failed check can prevent the form from being sent. This anti-abuse decision does not produce legal or similarly significant effects about you. If you believe a legitimate submission was blocked, contact dpo@hector-labs.com.

9. Security

We use technical and organizational measures designed to protect personal data, including transport encryption, access controls, data minimization, input masking, restricted analytics properties, and service-provider safeguards. No method of transmission or storage is completely secure, so we cannot guarantee absolute security.

10. Changes to this policy

We may update this policy when our website, vendors, practices, or legal obligations change. We will publish the revised version here and update the date above. If a change materially affects consent-based processing, we will request consent again where required.

11. Contact us

  • HECTORLABS S.R.L.
  • Strada Șesul de Sus 127M
  • Florești, Cluj County, Romania
  • dpo@hector-labs.com

For information about our providers' practices, see Cloudflare's privacy policy, Cloudflare's Turnstile Privacy Addendum, and PostHog's privacy policy.

Last Updated: 02 SEPT 2026

When the release is ready,Hector is ready.

Run black-box autonomous pentesting on demand. Security evidence reviewed by Hector, while the work is still fresh.

REQUEST A DEMO

Site Map

  • Product
  • How it works
  • Use cases
  • Reports
  • Pricing
  • Blog

Connect

  • Contact
  • LinkedIn

Legal

  • Privacy Policy

@2026 Hector Labs . ALL RIGHTS RESERVED.