Privacy Policy
This Privacy Policy describes how DARC Security LLC, a Delaware limited liability company doing business as “DARC” (“DARC,” “we,” “us,” or “our”), collects, uses, stores, and shares information in connection with:
- Our websites, including darcstandard.org and app.darcstandard.org (the “Sites”).
- The DARC platform, an automated security compliance and certification platform (the “Platform”).
- Our Google applications, DARC Security (Google sign-in) and DARC Auditor (our Google Workspace integration), described in detail below.
If you use the Platform on behalf of an organization that has subscribed to DARC (a “Customer”), your use is also governed by the agreement between DARC and that Customer. Where this Privacy Policy conflicts with that agreement with respect to Customer data, the agreement governs to the extent permitted by law, except that our handling of Google user data will in all cases comply with Section 2 of this Privacy Policy and the applicable Google policies.
1. Information We Collect
Account and contact information. When you create an account or your organization subscribes to DARC, we collect information such as your name, email address, organization name and address, role, and authentication identifiers.
Billing information. When a Customer purchases a subscription, our payment processor collects billing details (such as payment method and billing address). DARC does not store full payment card numbers.
Customer submissions. Customers submit information, evidence, and attestations to the Platform as part of the certification process (“Customer Data”). Customer Data may include information about the Customer’s personnel, systems, and security configuration.
Usage and log data. We automatically collect standard technical information when you use the Sites and Platform, such as IP address, browser type, device information, pages viewed, and timestamps, used for security, troubleshooting, and service operation.
Google user data. If you sign in with Google or connect Google Workspace to DARC, we receive data from Google as described in Section 2.
2. Google User Data
DARC offers two Google applications. This section describes exactly what each one accesses and why.
2.1 DARC Security (Google sign-in)
DARC Security lets you sign in to the Platform with your Google account. It requests the following OAuth scopes:
| Scope | What it gives us | Why we need it |
|---|---|---|
| openid | A unique identifier for your Google account | To authenticate you securely |
| userinfo.email | Your email address | To identify your account and communicate with you |
| userinfo.profile | Your basic profile information (name, profile picture) | To display your name and picture in the Platform |
Scope names other than openid are shortened for readability; each full scope is prefixed with https://www.googleapis.com/auth/.
We use this information solely to create and authenticate your DARC account and to display your identity within the Platform. Sign-in is processed through our authentication provider (Clerk).
2.2 DARC Auditor (Google Workspace integration)
DARC Auditor is authorized by a Google Workspace administrator of a Customer organization. It reads Google Workspace configuration data on a read-only basis in order to automatically validate the Customer’s security controls under the DARC Standard (for example, verifying that two-step verification coverage, administrator account status, and organizational unit structures meet the applicable controls). It requests the following OAuth scopes:
| Scope | What it gives us (read-only) | Why we need it |
|---|---|---|
| userinfo.email | The authorizing administrator’s email address | To identify which account authorized the integration |
| admin.directory.user.readonly | Directory user records (names, emails, account status, admin status, 2SV enrollment) | To validate user-account security controls (e.g., two-step verification coverage, administrator account coverage, suspended or inactive accounts) |
| admin.directory.domain.readonly | Domain configuration | To validate domain-level security settings |
| admin.directory.orgunit.readonly | Organizational unit structure | To validate that policies are applied to the correct organizational units |
| admin.directory.customer.readonly | Basic Workspace customer/tenant profile | To confirm the connected Workspace tenant and its configuration |
Scope names other than openid are shortened for readability; each full scope is prefixed with https://www.googleapis.com/auth/.
DARC Auditor never requests write access. It does not read the contents of emails, files, calendars, or chats. It reads directory and configuration metadata only, and only for the Workspace tenant whose administrator authorized it.
2.3 Google API Disclosure (Limited Use)
DARC Security’s and DARC Auditor’s use and transfer to any other app of information received from Google APIs will adhere to Google API Services User Data Policy, including the Limited Use requirements.
The use of information received from Google Workspace scopes will adhere to the Google User Data Policy, including the Limited Use requirements.
In particular:
- We use Google user data only to provide and improve the user-facing features described above (authentication, and automated validation of Workspace-related security controls), which are prominent in the Platform’s interface.
- We do not transfer Google user data to third parties except to our infrastructure subprocessors as necessary to provide these features (see Section 4), for security purposes (e.g., investigating abuse), to comply with applicable law, or as part of a merger, acquisition, or sale of assets after obtaining explicit prior consent as required by the applicable Google policies.
- We do not allow humans to read Google user data, except (a) with the explicit consent of the authorizing administrator (for example, during a support request), (b) where necessary for security purposes, (c) to comply with applicable law, or (d) where the data has been aggregated and anonymized for internal operations.
- We do not sell Google user data. We do not transfer it to data brokers, advertising platforms, or information resellers. We do not use it for advertising, for credit-worthiness assessment, or for lending purposes.
- We do not use Google user data for any artificial intelligence or machine-learning purposes. Google Workspace APIs are not used to develop, improve, or train non-personalized AI and/or ML models.
Google user data is stored on our servers hosted on Amazon Web Services in the United States, encrypted at rest and in transit; OAuth tokens are stored encrypted and are never exposed in logs.
This Privacy Policy is linked from the darcstandard.org homepage and from within the Platform, including on the screens where you sign in with Google or where a Workspace administrator connects DARC Auditor.
3. How We Use Information
We use the information described above (other than Google user data, which we use only as described in Section 2) to:
- Provide, operate, secure, and maintain the Sites and the Platform.
- Authenticate users and manage accounts.
- Run automated validation of security controls, issue and monitor certifications, and provide the services Customers subscribe to.
- Process payments and manage subscriptions.
- Respond to support requests and communicate with you about the services.
- Monitor for and prevent fraud, abuse, and security incidents.
- Comply with legal obligations.
- Generate aggregated, de-identified statistics that do not identify any person or Customer.
We do not use your information for third-party advertising, and we do not sell personal information.
4. How We Share Information
We share information only as follows:
- Service providers (subprocessors). We use third-party providers to operate the Platform, including Amazon Web Services (hosting and storage), Clerk (authentication), and our payment processor (billing). These providers process information only on our instructions and under contractual confidentiality and security obligations.
- Public certification registry. If a Customer achieves certification, we list the Customer’s name (and, where provided, logo) on the public registry at darcstandard.org, as described in the Customer’s agreement with DARC. The registry does not include personal data of Customer personnel or any Google user data.
- Legal requirements. We may disclose information if required to do so by law, regulation, legal process, or enforceable governmental request, or to protect the rights, property, or safety of DARC, our Customers, or the public.
- Corporate transactions. If DARC is involved in a merger, acquisition, or sale of assets, information may be transferred as part of that transaction, subject to this Privacy Policy and, for Google user data, subject to the consent requirements of the applicable Google policies.
We never sell personal information or Google user data, and we never share it with data brokers, advertising networks, or information resellers.
5. Data Security
We maintain administrative, technical, and organizational measures designed to protect information against unauthorized access, alteration, disclosure, or destruction, including:
- Encryption of data in transit (TLS) and at rest using current industry standards.
- Encryption of OAuth tokens at rest.
- Role-based access controls and the principle of least privilege for internal access.
- Logging and monitoring of production systems.
- Vendor security review of our subprocessors.
No method of transmission or storage is completely secure; if we become aware of a security incident affecting your information, we will notify affected parties as required by applicable law.
6. Data Retention and Deletion
- Account information and Customer Data are retained for as long as the account or Customer subscription is active, and thereafter only as needed for legitimate business purposes (such as legal, tax, or audit obligations), after which they are deleted or anonymized.
- Google user data obtained through DARC Auditor is retained only as long as needed to perform and evidence control validations for the connected Customer. When a Customer disconnects the integration or terminates its subscription, we delete the associated Google user data within 30 days, except where retention is required by law.
- Google sign-in data (your Google account identifier, email, and profile information) is retained while your account exists and deleted when your account is deleted.
You can revoke DARC’s access to your Google data at any time from your Google Account permissions page, and Workspace administrators can revoke DARC Auditor’s access from the Google Admin console. You may also request deletion of your data by contacting us at the address in Section 11.
7. Your Rights and Choices
Depending on your location, you may have rights under applicable data protection law (such as the GDPR or the California Consumer Privacy Act), including the right to access, correct, delete, or receive a copy of your personal information, to object to or restrict certain processing, and to non-discrimination for exercising these rights. To exercise any of these rights, contact us at the address in Section 11. If you are personnel of a Customer, we may direct your request to that Customer where they control the data in question.
8. International Transfers
DARC is based in the United States and processes information on servers located in the United States. If you access the services from outside the United States, you understand that your information will be transferred to and processed in the United States, where data protection laws may differ from those of your jurisdiction. Where required, we rely on appropriate safeguards for such transfers.
9. Children
The Sites and Platform are business services not directed to children under 16, and we do not knowingly collect personal information from children.
10. Changes to This Policy
We may update this Privacy Policy from time to time. We will post the updated version at this URL with a revised “Last updated” date and, for material changes affecting how we handle Google user data or other personal information, we will provide notice through the Platform or by email before the change takes effect.
11. Contact Us
DARC Security LLC
Attn: Privacy
Email: privacy@darcstandard.org
If you have questions about this Privacy Policy or our data practices, or wish to exercise your rights, please contact us at the email above.