Last Updated: Dec 04, 2025
Effective Date: Dec 04, 2025
This Privacy Policy explains how Exodos Labs, Inc., a Delaware corporation (“Exodos Labs”, “we”, “our”, “us”), collects, uses, discloses, and protects personal information when you:
We designed this policy to be clear and readable, while maintaining the depth required for GDPR, CCPA/CPRA, UK GDPR, and global privacy compliance.
If you do not agree with this Policy, please discontinue use of our Website and Platform.
Exodos Labs, Inc.
2261 Market Street, STE 22565
San Francisco, CA 94114
United States
We do not operate a German legal entity.
For individuals located in the European Union, Exodos Labs, Inc. has appointed the following EU Representative in accordance with Article 27 GDPR:
esb Rechtsanwälte GmbH
Schockenriedstraße 8A
70565 Stuttgart
Germany
Phone: 0711 4690580
https://www.kanzlei.de
EU data subjects and supervisory authorities may contact our EU Representative for matters related to GDPR compliance, data subject rights, and regulatory communication.
We do not currently have a DPO.
For privacy-related inquiries, contact:
dataprivacy@exodoslabs.com
Exodos Labs provides a platform enabling organizations to:
Some SBOMs may contain personal information (e.g., component authors).
We collect personal information in three main categories:
Information we collect automatically:
Information you provide to us:
Includes structured and unstructured data such as:
We maintain immutable audit logs of:
Retention: logs are kept indefinitely.
We use AI models for:
Third-party AI systems used:
When processed, SBOM and related metadata may be shared with these services.
We do not use your data to train publicly available models.
We use your information to:
We process personal data under:
We use cookies and tracking technologies for:
Users may withdraw consent through the cookie banner.
We do not sell personal information.
We share data only with:
|
Provider |
Purpose |
Region |
|
Hetzner |
Hosting, compute, storage |
Germany (Frankfurt) |
|
Resend |
Email delivery |
US |
|
Hotjar |
UX analytics |
EU |
|
Google Analytics |
Web analytics |
US |
|
HubSpot |
CRM, support, analytics |
US |
|
Stripe |
Payments |
US |
|
Coralogix |
Error monitoring |
EU datacenter |
|
Swan AI |
Lead scoring & profiling |
US |
|
LangSmith + Google Gemini |
AI processing of SBOM-related data |
US |
You may choose to share SBOMs or inventory items with:
This sharing is fully under your control via ABAC permissions.
We never share your SBOMs with third parties unless you instruct us.
We store all Platform data in Hetzner, Frankfurt, including EU-only residency if requested.
Some processors (e.g., Google, HubSpot, Resend, Stripe, AI providers) may transfer data to the United States.
We rely on:
We apply industry-standard measures consistent with SaaS best practices:
Note: At this moment we do not provide encryption at rest.
This will be added as part of future SOC2/ISO27001 controls.
|
Data Category |
Retention |
|
SBOMs & Inventory Data |
As long as your account remains active or legally required |
|
Audit & activity logs |
Retained indefinitely |
|
Communication Hub messages |
Retained indefinitely |
|
API logs |
Retained indefinitely |
|
Account information |
Until deletion request |
|
Backups |
30 days |
|
Marketing & lead data |
Until withdrawn or no longer needed |
You may request erasure of personal data unless laws or audit requirements prevent deletion.
Depending on your jurisdiction (GDPR, UK GDPR, CCPA/CPRA), you may request:
You cannot opt out of AI-based features, as they are core to the Platform’s functionality.
You also cannot download all platform data in bulk, except SBOMs and exports available via the interface.
Our services are not intended for children under 16, and we do not knowingly collect their data.
If a data breach affects your personal information, we will notify you:
The Website may contain links to third-party sites or services. We are not responsible for their privacy practices.
We may update this Privacy Policy to reflect product updates, legal requirements, or operational changes.
If material changes occur, we will notify you via:
For privacy inquiries, data requests, or GDPR/CCPA rights:
Exodos Labs, Inc.
dataprivacy@exodoslabs.com
2261 Market Street, STE 22565,
San Francisco, CA 94114, USA
Join security and engineering teams who are transforming their SBOM management from a compliance burden into a strategic advantage.