Privacy Policy
Jeturing Inc.
Effective Date: January 1, 2026
Last Updated: June 2026
1. WHO WE ARE
Jeturing Inc. ("Jeturing", "we", "us", or "our") is a corporation incorporated under
the laws of the State of Delaware, United States, with principal offices at:
651 N Broad St, Suite 201, Middletown, Delaware 19709, USA.
We provide IT services, cybersecurity services, consulting, and software-as-a-service
(SaaS) platforms, including Sajet ERP, SEGRD cybersecurity solutions, vCISO services,
and other products and services made available through our websites and partner channels.
This Privacy Policy describes how we collect, use, disclose, and protect personal data
in connection with:
- Our websites, including jeturing.com and sajet.us
- Our SaaS platforms and client portals, including Sajet ERP
- Our cybersecurity, consulting, and managed services
- Any other online services that link to or reference this Privacy Policy
This Policy is primarily intended for business customers (B2B) and their authorized users.
Any dispute arising from this Policy is subject to the dispute resolution provisions in
Jeturing's Terms of Service, available at jeturing.com/terms.
2. DATA WE COLLECT
We may collect the following categories of information:
(a) Account and identification data
- Name, corporate email address, phone number
- Company name, job title or role
- Login credentials and authentication data
(b) Service usage data
- Access logs, timestamps, IP address and approximate location
- Device type, operating system, and browser type
- Pages visited, features used, session duration, and performance telemetry
(c) Transactional and commercial data
- Subscription plans and service tiers
- Billing and payment-related information (invoicing details, transaction metadata)
- Support history, helpdesk tickets, and communications with our teams
(d) Content and business data provided by customers
- Business information uploaded, sent, or stored in our services
- Files, records, and configurations needed to provide and operate Sajet or
other Jeturing solutions
- We process this information only per the applicable service agreement and
the instructions of our business customer.
(e) Security and monitoring data
- Security and audit logs, event records, alerts, and telemetry used for
cybersecurity monitoring
- Signals and metadata to detect and prevent fraud, abuse, or unauthorized access
(f) Cookies and similar technologies
- See Section 7 for details.
3. HOW WE USE THE INFORMATION
We use the information we collect for purposes such as:
- Providing and maintaining our services, accounts, and technical support
- Operating and improving Sajet, SEGRD, and other platforms
- Security and compliance with frameworks such as PCI-DSS, HIPAA, and ISO
- Generating aggregated and anonymized metrics to prioritize improvements
- Sending service-related messages and, where permitted, product information
(always with an option to opt out of non-essential marketing communications;
opt-out requests will be processed within 10 business days)
- Enforcing agreements, resolving disputes, and complying with legal obligations
We do not use customer data to create profiles for sale to third parties.
We do not sell personal data to third parties.
4. LEGAL BASES — JURISDICTION-SPECIFIC
The legal basis for our processing of personal data depends on your location:
(a) European Union / EEA / United Kingdom
Processing is based on:
- Performance of a contract (Art. 6(1)(b) GDPR / UK GDPR)
- Legitimate interests (Art. 6(1)(f))
- Legal obligation (Art. 6(1)(c))
- Consent where required (Art. 6(1)(a))
(b) Brazil
Processing is based on the Lei Geral de Proteção de Dados (LGPD), Articles 7 and 11,
under contract performance, legitimate interest, or legal obligation.
(c) United States — Delaware (Primary Jurisdiction)
Processing complies with the Delaware Personal Data Privacy Act (DPDPA),
effective January 1, 2025, as amended (including the June 5, 2026 AI amendment,
effective January 1, 2027).
(d) United States — Other States
Where applicable, processing complies with state laws including CCPA/CPRA
(California), CPA (Colorado), CTDPA (Connecticut), and other applicable frameworks.
(e) Other Jurisdictions
Where additional local laws apply, we will comply with those requirements
and provide additional notices as required.
Where we rely on consent, you may withdraw it at any time without affecting the
lawfulness of processing before withdrawal.
5. DATA RETENTION
- Account and service data: retained while there is an active contractual
relationship and for a reasonable period afterward for legal, accounting,
audit, or dispute-resolution purposes.
- Content and business data: processed and retained per the specific contract
with each customer, and deleted or anonymized following agreed procedures.
- Security logs and monitoring data: retained per our internal cybersecurity
policies and applicable regulatory requirements.
When data is no longer needed, we will delete or anonymize it unless a longer
retention period is required or permitted by law.
6. HOW WE SHARE DATA
We may share personal data with:
(a) Service providers and infrastructure vendors
Third-party providers (hosting, cloud, analytics, support, communications)
bound by contractual confidentiality and data protection obligations.
(b) Partners and Managed Service Providers (MSPs)
Business partners under our partner-first model, only to the extent necessary
to deliver contracted services, and subject to a signed Partner Agreement with
equivalent data protection obligations.
(c) AI-Powered Sub-Processors
Where we engage AI-powered service providers that may process personal data,
we ensure through contractual obligations that such providers do NOT use
customer data to train AI models without explicit authorization, and that
they comply with all applicable data protection laws. A list of sub-processors
is available upon written request.
(d) Corporate transactions
In connection with a merger, acquisition, or sale of assets, personal data may
be transferred as part of the transaction, subject to continued protection
consistent with this Policy.
(e) Legal and compliance purposes
When required by law or valid legal process, or when necessary to:
- Comply with a legal obligation
- Protect the rights, property, or safety of Jeturing, customers, or others
- Detect, prevent, or address security incidents or fraud
We do not sell personal data to third parties.
7. COOKIES AND SIMILAR TECHNOLOGIES
We use cookies, web beacons, and similar technologies to:
- Remember user settings and preferences
- Keep sessions authenticated and maintain security
- Measure and analyze traffic, usage, and performance
- Support customer communications and helpdesk interactions
Cookies may be first-party or third-party (analytics or support providers).
You can manage cookies through your browser settings. If you disable certain
cookies, some features may not function properly.
Jeturing honors opt-out preference signals (such as Global Privacy Control)
for the sale or processing of personal data for targeted advertising purposes,
as required under the DPDPA and applicable law.
8. INFORMATION SECURITY
We apply administrative, technical, and organizational measures including:
- Encryption of data in transit (TLS) and at rest where applicable
- Role-based access controls and least-privilege principles
- Logical segmentation of environments and multi-tenant isolation
- Logging and monitoring via Wazuh SIEM and Microsoft Defender EDR
- Regular backups (Veeam) and business continuity practices
- Cloudflare WAF, Zero Trust, and DDoS protection
Access to personal data is limited to personnel and service providers who need it
and are subject to confidentiality obligations.
No system or transmission method is completely secure. Jeturing's liability in
connection with data security incidents is governed by the applicable service
agreement. Nothing in this Privacy Policy creates liability beyond what is
expressly agreed in such agreements.
9. INTERNATIONAL DATA TRANSFERS
When personal data is transferred outside its country of origin, Jeturing implements:
- Standard Contractual Clauses (SCCs) approved by the European Commission,
for transfers from the EU/EEA
- UK International Data Transfer Agreements (IDTAs) for transfers from the UK
- Equivalent contractual mechanisms for transfers from Brazil under LGPD
- Sub-processor agreements requiring equivalent protections in all jurisdictions
A list of sub-processors and their locations is available upon written request.
10. YOUR RIGHTS
Depending on your jurisdiction, you may have the right to:
- Request access to the personal data we hold about you
- Request correction of inaccurate or incomplete personal data
- Request deletion of your personal data when no longer necessary
- Object to or request restriction of certain processing activities
- Request data portability where provided under applicable law
- Obtain a list of categories of third parties to whom your personal data
has been disclosed (Delaware DPDPA right)
AUTOMATED DECISION-MAKING:
Where Jeturing uses automated decision-making producing significant effects,
you have the right to: (i) request human review; (ii) contest the decision;
and (iii) receive a meaningful explanation of the logic applied, to the extent
required by applicable law.
In many cases, Jeturing acts as a data processor on behalf of its business
customers (data controllers). End users should first direct requests to their
employer or the relevant business customer. We will support our customers
in responding in accordance with our contractual obligations and applicable law.
11. CHILDREN'S PRIVACY
Our services are designed for businesses and professionals and are not directed
to children or minors. We do not knowingly collect personal data from children.
If we become aware of such collection, we will delete it as soon as practicable.
12. DATA BREACH RESPONSE
In the event of a personal data breach, Jeturing will:
- Notify affected business customers without undue delay upon confirmation
- Report to applicable supervisory authorities within 72 hours where required
(GDPR / UK GDPR)
- Comply with U.S. state notification timelines (e.g., 30 days under
California law; applicable Delaware requirements)
- Provide notifications including: nature of the breach, data categories
affected, likely consequences, and remediation steps taken
13. ARTIFICIAL INTELLIGENCE AND AUTOMATED PROCESSING
Jeturing may use artificial intelligence (AI) tools, large language models (LLMs),
and automated processing systems as part of its internal operations, cybersecurity
monitoring, customer support, and service delivery.
- We do NOT use customer business data to train third-party AI models without
explicit written authorization from the business customer.
- Where AI is used in ways that produce significant decisions affecting end users,
we will provide appropriate disclosure and, where required by law, an opt-out
mechanism.
- Our AI-powered sub-processors are contractually prohibited from using customer
data to train their models without explicit consent.
- For EU-based users: Jeturing complies with applicable obligations under the
EU AI Act (effective August 2, 2026), including transparency requirements and
human oversight mechanisms where applicable.
- Effective January 1, 2027 (Delaware AI Amendment): Jeturing will provide
adverse action notices and human review options where AI tools produce
significant effects on individuals, as required by Delaware law.
Customers may contact us to request information about specific automated
processing activities affecting their data.
14. CHANGES TO THIS PRIVACY POLICY
We may update this Policy to reflect changes in our services, legal requirements,
or internal practices. When we make changes, we will post the updated Policy at
jeturing.com/privacy and update the "Effective date." For material changes, we will
provide additional notice via email or in-service messages where required.
15. CONTACT US
Website: https://jeturing.com/contactus
Email: [email protected] | [email protected]
Phone: +1 (401) 648-2327
Address: 651 N Broad St, Suite 201, Middletown, Delaware 19709, USA