Privacy Policy

Effective Date: 09/22/2026

Effective Date: 9/22/2026

Bayside Solutions, Inc., (“Bayside Solutions, Inc.,” “we,” “us,” or “our”) is committed to protecting personal information.  This Privacy Policy explains what information we collect, how we use it, with whom we share it, and the rights you have.

This Policy applies to our website, the ORQET Post-Delivery Email Threat Response platform and any related services.  If you are a customer, user, partner, or any other person with a signed agreement, that agreement and our Data Processing Addendum (DPA) provide additional terms about how we process personal data on your behalf. 

Our Role

We act in different roles depending on the data:

  • Controller: for personal information we collect directly, including website visitors, prospects, and contacts at our customers and partners (account information, communications, marketing).
  • Processor (or service provider): for Customer Data we process on behalf of our customers when they use ORQET. The customer determines the purposes and means of processing; we follow their instructions and our DPA.

Information We Collect

The table below summarizes the categories of information we collect, why we collect it, and how long we retain it.  “Customer Data” refers to information processed by the ORQET platform from a customer’s connected email environment.

CategoryPurpose / Why We CollectRetention
Account information (name, email, role, organization)Authenticate users; provide and bill for the Services; communicate about service matters.Duration of account + 24 months after termination, then deleted or anonymized.
Email content, attachments, headers, metadata processed by ORQET (“Customer Data”)Analyze reported emails to determine whether they are safe or malicious; support remediation of confirmed threats based on the selected deployment model; provide reporting and dashboards.Per customer’s configuration; default 90 days for submitted emails; logs retained per Documentation.
User-reported phishing submissions (via Phish-button)Analyze reported emails; deliver verdicts; improve future response.Same as Customer Data above; aggregated indicators retained indefinitely as Derived Data.
Derived Data (aggregated, anonymized threat indicators, IOCs, attacker patterns, statistics)Tactical and technical threat intelligence; recognize previously analyzed emails and apply established human-derived verdicts across customer environments. Retained indefinitely; does not include customer-identifying or business content.
Platform usage and audit logsOperate and secure the Services; detect abuse; meet audit and compliance requirements.Up to 24 months, except where longer retention is required by law.
Website analytics and cookiesUnderstand website traffic; improve our marketing; deliver relevant content. See Cookie Policy.Up to 13 months; see Cookie Policy.
Support and communicationsRespond to inquiries; provide support; send service announcements and (with consent) marketing.Up to 3 years from last interaction.

How We Use Information

We use the information we collect to:

  • Provide, operate, secure, and improve the Services.
  • Analyze reported emails, deliver verdicts, and support remediation of confirmed threats based on the selected deployment model. Generate aggregated, anonymized tactical and technical threat intelligence (“Derived Data”) for use across ORQET customer environments. Authenticate users, prevent fraud, and protect the Services and other users.
  • Communicate about service matters, billing, support, and (with consent or as legally permitted) marketing.
  • Comply with legal obligations and enforce our agreements.

Some of these activities involve AI-assisted technology and automation, as described under Automated Decision-Making below.

How ORQET Handles Email Content

When a customer connects ORQET to its email environment, the platform processes email content, attachments, headers, and metadata to identify potential threats. WeWhen a customer connects ORQET to its email environment, the platform processes email content, attachments, headers, and metadata to analyze reported emails and determine whether they are safe or malicious. Where Search and Purge is enabled, ORQET also uses this information to locate and remove matching malicious emails. We treat email content as the customer’s confidential data, with the following commitments:

  • Email content is processed only to provide the Services to the customer that owns the data.
  • Customer Data is logically segregated by tenant and protected by access controls and encryption.
  • Customer Data is not sold and is not provided to advertisers.
  • We do not request or require special categories of personal data (such as data revealing health, race, religion, or similar sensitive information) or “sensitive personal information” as defined under U.S. state privacy laws.  Such data may nonetheless be incidentally present in email content; where present, it is processed under the same technical and organizational safeguards as other Customer Data and is not used for any purpose other than providing the Services.

Aggregated, anonymized threat indicators (such as malicious URLs, file hashes, sender patterns, and attacker techniques) may be used in the ORQET Threat Intelligence Platform and applied across ORQET customer environments.

 These indicators do not identify individuals or our customers..

How We Share Information

We share information only as needed and only with the categories below:

  • Sub-processors: vendors that help us provide the Services (such as cloud infrastructure, email connectors, customer support tools, and analytics).  The current sub-processor list is with a subscribe option for change notifications.
  • Customers: for Customer Data, the customer that owns the data controls how it is used and disclosed.
  • Professional advisors: lawyers, accountants, and auditors, under confidentiality obligations.
  • Legal and safety: when required by law, valid legal process, or to protect rights, safety, or the integrity of the Services.
  • Business transfers: in a merger, acquisition, or sale of assets, subject to standard confidentiality protections.

We do not sell personal information.  We do not share personal information for cross-context behavioral advertising.

International Transfers

We are based in the United States and may transfer personal information to other countries to operate the Services.  For transfers of personal information from the European Economic Area, the United Kingdom, or Switzerland, we use Standard Contractual Clauses and, where applicable, the UK Addendum or the EU-U.S. Data Privacy Framework (where applicable).  Details are in our DPA.

Security and Certifications

We maintain administrative, technical, and physical safeguards designed to protect personal information, including encryption in transit and at rest, role-based access controls, monitoring, vulnerability management, employee training, and incident response.

Our security program is independently audited under a SOC 2 Type II examination. We also maintain a GDPR compliance program.

  • SOC 2 Type II
  • GDPR

Current attestations are summarized at our Trust Center. Customers with a signed agreement may request the underlying reports under NDA.  No method of transmission or storage is completely secure, and we cannot guarantee absolute security.

Retention

We retain personal information only as long as needed to provide the Services, fulfill the purposes described in this Policy, comply with legal obligations, resolve disputes, and enforce our agreements.  Specific retention periods for Customer Data are configured by the customer; defaults are in the table above.

Your Rights

Depending on where you live, you may have rights to:Depending on where you live, you may have rights to:

  • Access the personal information we hold about you.
  • Correct inaccurate or incomplete personal information.
  • Delete your personal information.
  • Port your personal information to another service.
  • Restrict or object to certain processing, including direct marketing.
  • Withdraw consent where processing is based on consent.
  • Lodge a complaint with your data protection authority.

To exercise these rights, contact us at [email protected]. We will respond within the time required by applicable law.  If you are an end-user of one of our customers (for example, an employee whose email is scanned by ORQET), please direct your request to your employer or the customer that controls the data; we will assist them as their processor.

U.S. State Privacy Rights

If you live in California, Colorado, Connecticut, Utah, Virginia, Texas, or another state with a comprehensive privacy law, you have rights to request to correct, delete, and (where applicable) opt out of “sale” or “sharing” of personal information.  We do not sell personal information or share it for cross-context behavioral advertising.  To exercise your rights, contact [email protected].

You may also designate an authorized agent to submit a request on your behalf, and we will not discriminate against you for exercising your rights.  If we decline to act on your request, we will explain why, and where required by applicable state law (including in Colorado, Connecticut, Virginia, and Texas) you may appeal that decision by contacting us at the address above; if your appeal is denied, you may contact your state attorney general.

EEA, UK, and Swiss Rights

If you are in the EEA, UK, or Switzerland, you have rights under the GDPR (and equivalent UK and Swiss laws), including the rights listed above.  Our legal bases for processing include performance of a contract, legitimate interests (operating and securing the Services, generating aggregated threat intelligence), legal obligations, and consent (for example, for certain marketing).

Children

The Services are not directed to children under 16, and we do not knowingly collect personal information from them.  If you believe a child has provided personal information to us, contact [email protected] and we will take appropriate steps.

Cookies and Tracking

Our website uses cookies and similar technologies. See our Cookie Policy for details and your choices.

Automated Decision-Making

The ORQET platform uses AI-assisted technology and automation. Cyrebrium, ORQET’s AI-assisted matching and automation engine, applies the verdict previously reached by a human analyst when a reported email matches one already reviewed. Emails that have not been seen before are routed to a security analyst for review, and a human analyst is involved in every verdict. Where enabled, automated Search and Purge removes confirmed malicious emails from affected mailboxes.

Changes to This Policy

We may update this Policy from time to time.  We will post the updated Policy and update the effective date. Material changes will be communicated by reasonable means.  This Policy is a privacy notice describing our practices; it is not a contract.  We encourage you to review it periodically.  Our processing of personal information is governed by applicable law and, where relevant, the legal bases described in this Policy.

Contact Us

Bayside Solutions, Inc.
220 Pasadena Ave South, St. Petersburg, FL 33707
Privacy inquiries: [email protected]