LeapScan ← Back to Home

Privacy Policy

Last Updated: March 27, 2026  ·  Operated by Leaptrix Solutions  ·  Jurisdiction: India (with GDPR compliance for EU data subjects)

Plain English Summary: LeapScan runs entirely in your own environment — all scan data stays on your infrastructure. We only collect contact information needed to deliver your license. We never store your AWS or M365 scan data.

1. Who We Are

LeapScan is an AWS security auditing service operated by Leaptrix Solutions, a technology consulting firm. Our registered point of contact is support@leaptrix.com.

When we reference "LeapScan," "we," "our," or "us," we mean Leaptrix Solutions and any contracted personnel involved in delivering the AWS audit service.

2. What Data We Collect & Why

Data TypeWhat It IsWhy We Collect ItLegal Basis
Contact EmailYour work email addressTo deliver your audit report and communicate findingsContract performance
AWS Account IDYour 12-digit AWS account identifierTo assume the read-only cross-account role and run audit checksContract performance
Audit FindingsConfiguration metadata (not actual data) — e.g. "S3 bucket X has public access enabled"To compile and deliver your security reportContract performance
Form Submission DataData submitted through our web form (relayed via Formspree)To initiate and scope your audit engagementConsent / Contract

We do NOT collect:

3. AWS Access Model & Permissions

We access your AWS environment exclusively through a cross-account IAM role that you create using our CloudFormation template. This role:

You can independently verify the exact permissions granted by reviewing our open-source CloudFormation template at: github.com/manju4k/leapscan-role-template

3a. License Validation

License validation sends only your license ID and machine fingerprint to leapscan.io — no scan data, AWS credentials, or M365 tokens are transmitted. This is solely used to verify your license entitlement.

4. Data Retention & Deletion

Self-Hosted Model: All data remains in your environment. LeapScan does not store your scan data. License validation sends only your license ID and machine fingerprint to leapscan.io — no scan data is transmitted.

DataRetention PeriodHow to Request Early Deletion
License request form data (Formspree)30 days from submissionEmail us at support@leaptrix.com
Audit findings & report artefactsAll data remains in your environment. LeapScan does not store your scan data.N/A — data is stored on your infrastructure only
License validation dataLicense ID and machine fingerprint only — retained for license managementEmail us at support@leaptrix.com

All deletion requests are honoured within 72 business hours. We will confirm deletion in writing by email.

5. Subprocessors

We use the following third-party services to deliver the LeapScan service:

SubprocessorPurposeLocationPrivacy Policy
FormspreeForm-to-email relay (license request contact form only — no scan data)United Statesformspree.io/legal/privacy-policy
Google FontsWeb font delivery (no personal data processed)United Statespolicies.google.com/privacy

6. Data Sharing & Disclosure

We do not sell, rent, or trade your data. We will only share your information:

7. Your Rights (GDPR / CCPA)

Depending on your jurisdiction, you may have the right to:

To exercise any right, contact us at support@leaptrix.com. We will respond within 30 calendar days.

8. Security

We implement industry-standard security practices in our own operations, including:

Ironically, we subject our own AWS infrastructure to the same LeapScan audit on a monthly basis.

9. Cookies & Tracking

Our website does not use tracking cookies, advertising pixels, or analytics beacons. We do not use Google Analytics or any third-party tracking script. The only external resources loaded are Google Fonts (typography) and Font Awesome (icons), neither of which track individual users.

10. Changes to This Policy

We may update this Privacy Policy as our service evolves. Material changes will be communicated by email to active clients at least 14 days before taking effect. The "Last Updated" date at the top of this page will always reflect the most recent revision.

11. Contact & Complaints

For any privacy concern or data request, contact our Data Controller at:
Leaptrix Solutions
Email: support@leaptrix.com
Response time: Within 72 business hours for urgent requests, 30 calendar days for formal GDPR requests.