BabySOARus Privacy Policy
Version 1.1. Last updated 27 August 2026.
HISN.IO LTD ("we", "us", "our"), a company registered in England and Wales under company number 17215304, with its registered office at 71-75 Shelton Street, Covent Garden, London, WC2H 9JQ, United Kingdom, is the data controller for the personal data described in this policy.
Contact: privacy@hisn.io
1. The most important thing first
The BabySOARus software does not send your data to us.
BabySOARus is installed into your own Splunk deployment and runs there. It has no telemetry, no analytics, and no usage reporting. It does not contact us when it starts, when it runs a search, or when it verifies its licence -- licence verification is a cryptographic signature check performed entirely offline against a licence file you install.
Your Splunk data, your detections, your functions, and the results they produce stay in your environment. We do not have access to them, and we cannot obtain access to them, unless you deliberately send them to us -- for example, by attaching a log or a search result to a support request.
The rest of this policy is about the data we process because you bought the software or contacted us, not because you run it.
2. Data we process
2.1 Purchase and licensing
When you buy a licence, we process:
| Data | Why | Lawful basis |
|---|---|---|
| Name, business email, company name | To issue and support your licence | Performance of a contract |
| Billing address and country | Invoicing and tax compliance | Legal obligation |
| Licence records: key, edition, term, deployment count | To issue, renew, and validate licences | Performance of a contract |
Licence records are held in a self-hosted instance of Keygen, a licensing system we operate ourselves rather than a third-party SaaS.
We do not store your card details. Payments are processed by Stripe, who act as an independent controller for payment data. See Stripe's privacy policy at https://stripe.com/privacy.
2.2 Support and correspondence
If you contact us, we process your message and anything you choose to include in it. Please do not send us production data, credentials, or personal data belonging to your own users unless it is genuinely necessary -- and redact it where you can.
2.3 Website
Our website processes standard server logs (IP address, user agent, pages requested) for security and operational purposes, retained for no more than 90 days. The website is served from more than one region, so these logs may be processed outside the United Kingdom. See section 5.
Cookies. The website sets exactly one cookie, _hvi. It holds a signed
identifier and a trust score used by our hosting platform to tell ordinary
visitors from automated abuse, and to decide whether a request should be
challenged. It is a session cookie -- it is discarded when you close your
browser -- and it is marked Secure and SameSite=Strict, so it is never
sent to any other site.
We consider it strictly necessary for the security of the service, and so it is set without asking, as regulation 6(4) of the Privacy and Electronic Communications Regulations 2003 permits. We do not use it, or anything else, for analytics, advertising, or profiling, and there are no third-party cookies, no trackers, and no advertising or analytics scripts on this site at all. You can block or delete it; the site works without it, though repeated requests may be challenged more often.
3. What we do not do
- We do not sell personal data.
- We do not share personal data for advertising.
- We do not profile you or make automated decisions with legal effects.
- We do not collect usage data from installed software.
4. Sharing
We share personal data only with:
- Stripe Payments Europe, Ltd., for payment processing.
- Fly.io, Inc., which hosts our licensing system and our website.
- Upstash, Inc., which provides the managed Redis our licensing system uses.
- Professional advisers and authorities, where we are legally required to.
We do not otherwise disclose your data to third parties.
5. International transfers
The two are not in the same place, so we state them separately.
Licence and purchase records -- your name, business email, company, billing details and licence history -- are stored only in the United Kingdom, in Fly.io's London region. They are not replicated elsewhere.
Website server logs are not. Our website is served from more than one region, including the United States, so the IP address and request details in section 2.3 may be processed there. Nothing in section 2.1 or 2.2 is served this way.
Our processors -- Fly.io, Inc., Upstash, Inc. and Stripe -- are incorporated in the United States and may access data from outside the UK in the course of operating and supporting their services. For that access, and for the website logs above, we rely on the UK International Data Transfer Agreement or the UK Addendum to the EU Standard Contractual Clauses, as appropriate.
6. Retention
- Licence and purchase records: for the duration of the relationship and then seven (7) years, to meet UK accounting and tax requirements.
- Support correspondence: three (3) years from the last contact.
- Website server logs: 90 days.
7. Your rights
Under the UK GDPR you have the right to access, rectify, erase, restrict processing of, object to processing of, and port your personal data. To exercise any of these, email privacy@hisn.io. We will respond within one month.
If you are unsatisfied, you may complain to the Information Commissioner's Office (https://ico.org.uk).
8. Security
We use encryption in transit, access controls, and least-privilege administration for the systems that hold licensing and correspondence data.
Because the software itself holds none of your operational data, the security of your Splunk data, your detections, and the code you run through BabySOARus is under your control, not ours. Please see the End User Licence Agreement, which sets out that division of responsibility.
9. Changes
We will post any change to this policy with an updated version and date. Where a change is material, we will tell licensed customers by email.