Legal
Privacy Policy
Effective October 5, 2026
This Privacy Policy explains how SUPERENDPOINT LLC (“Superendpoint,” “we,” or “us”) handles personal information through our website at superendpoint.com, the Superendpoint portal and documentation, the endpoint software and desktop app, our support channels, and our other business interactions.
Superendpoint is a service for businesses. It is not directed to children, and it is not offered for managing personal or household devices.
Our role and your employer’s role
When a business uses Superendpoint to manage its computers, that business (our “customer”) decides which devices to enroll, what to collect and check, and who can see the results. For personal information processed on a customer’s behalf, the customer is the controller (or “business”), and we act as its processor (or “service provider”). Our contract with the customer governs that processing.
If your employer uses Superendpoint to manage your work computer, your employer’s own policies and notices also apply. Please send requests about that information to your employer. If you contact us, we will forward your request to them where appropriate.
We decide how personal information is used for our own purposes, such as operating our website, managing customer accounts, billing, security, and communicating with prospective customers. This policy covers both roles.
Information we collect
| Category | Examples | Source |
|---|---|---|
| Account and organization | Name, business email, role, organization, membership, sign-in history, and two-factor status | Administrators, your employer, the sign-in process |
| Endpoint and technical | Device name and identifiers, user account names, operating system, hardware and installed software, configuration, compliance and security state, performance and diagnostic data, IP address and connection details | Enrolled endpoints and our infrastructure |
| Administrative activity | Fixes, approvals, policy changes, commands, and audit events, with their times | Administrators and the Service |
| AI assistant conversations | Questions asked of the assistant, its answers, and summaries handed off to IT | Administrators and employees who use the assistant |
| Billing | Billing contact, address, customer and subscription identifiers, invoice and payment status, tax details, and endpoint-day usage | Customers and our payment processor |
| Communications | Support requests, legal notices, security reports, and feedback | The people who contact us |
| Early-access requests | Work email, company, approximate number of devices, platforms, and anything you tell us in the form | You, through our website |
| Website and service use | IP address, browser and device details, pages requested, request logs, and diagnostics | Your browser and our infrastructure |
We do not knowingly collect payment card numbers. Our payment processor collects them directly when billing is enabled.
How we use information
We use personal information to:
- provide, authenticate, operate, support, and improve the Service;
- enroll and administer authorized endpoints, deliver configuration and actions, and show device and compliance state;
- answer questions through the AI assistant;
- protect accounts, endpoints, customers, and the Service; investigate abuse and security incidents; and keep audit records;
- process subscriptions, usage, invoices, payments, and taxes;
- send transactional, security, support, legal, and service messages;
- respond to early-access requests and follow up with prospective customers;
- comply with law, enforce our agreements, and establish or defend legal claims.
We do not sell personal information. We do not share it for cross-context behavioral advertising, and we do not use the Service’s data for advertising of any kind.
AI assistant
Superendpoint includes an AI assistant for administrators in the portal and for employees in the desktop app. When someone asks a question, we send the question, recent messages in the conversation, and the device, software, compliance, and diagnostic information needed to answer it, through the Vercel AI Gateway, to a third-party language model provider. We store conversations in our own database so the assistant can continue them and so IT can see requests handed off to them.
We send this information only to model providers that have agreed not to retain it beyond what is needed to answer and not to use it to train their models. If no such provider is available, the assistant does not answer. The Vercel AI Gateway does not retain it either. On the employee side, information about the apps open on a computer is collected only after the employee allows it on screen.
Cookies and similar technologies
We use only the cookies needed for the Service to work and stay secure. These include a session cookie that keeps you signed in to the portal for up to seven days, a short-lived cookie used during two-factor sign-in, and session cookies for our documentation site. The portal also stores small preferences in your browser’s local storage, such as which assistant conversation was open.
Our website does not set cookies. If our early-access form uses Cloudflare Turnstile to check that a submission comes from a person, Cloudflare processes your browser information and IP address for that purpose.
We do not use analytics or advertising cookies, and we do not allow third parties to track you across sites through our website or the Service.
How we share information
We share personal information with:
- Service providers and subprocessors that host our infrastructure, deliver email, run the AI assistant, monitor availability, manage prospective customer records, schedule meetings, and process payments, under contracts that limit their use of the information. A list of our current subprocessors is available on request from privacy@superendpoint.com.
- Our customers, for information we process on their behalf. For example, administrators can see device data and assistant hand-offs from their organization’s endpoints.
- Authorities and others, when required by law or legal process, or when needed to protect the rights, property, or safety of Superendpoint, our customers, or others.
- A successor, in a merger, acquisition, financing, or sale of assets, subject to appropriate confidentiality protections.
- Others at a customer’s direction, or with your consent.
Retention
We keep personal information only as long as we need it for the purposes described above. Detailed operational telemetry is kept for 90 days, and security and sign-in audit events for 365 days. Account, contract, billing, and legally required records may be kept longer, for as long as our contracts, tax and accounting rules, or other legal obligations require.
When a customer’s approved deletion request is processed, we aim to complete deletion within 30 days. Copies in backups expire on our providers’ backup schedule rather than being edited individually, and any data restored from a backup remains subject to the original deletion request. We may keep limited information longer when needed for a legal hold, fraud prevention, security, a dispute, or another legal requirement.
Security
We use administrative, technical, and physical safeguards designed for the nature of the Service. These include organization-scoped access control, encryption in transit, per-device credentials, separation of production from development, and audit logging. No security measure can eliminate all risk. Customers are responsible for protecting their administrator accounts and controlling who can enroll devices. Please report suspected security issues to security@superendpoint.com.
Where information is processed
Superendpoint is hosted in the United States and is intended for use by U.S. businesses. Some of our providers may process information in other countries for support, security, or resilience, under their own contractual safeguards. The Service is not designed for protected health information, payment card data, or government-regulated data.
Your choices and rights
Administrators can update account and organization information in the portal or by contacting us. We send transactional and security messages while an account is active, and you cannot opt out of them. If we send marketing email, every message will include a way to unsubscribe.
Depending on where you live, including in California and other U.S. states with comprehensive privacy laws, you may have the right to:
- know what personal information we collect, use, and disclose, and access a copy of it;
- correct inaccurate personal information;
- delete personal information;
- receive your personal information in a portable format;
- opt out of the sale or sharing of personal information, or of targeted advertising and profiling. We do not engage in these activities.
We do not use or disclose sensitive personal information for purposes that would give California residents a right to limit that use, and we do not make decisions with legal or similarly significant effects about you based solely on automated processing.
To make a request, email privacy@superendpoint.com. We will need to verify your identity, and an authorized agent must provide proof of their authority. We will respond within 45 days, or tell you if we need more time as the law allows. If we deny your request, you may appeal by replying to our decision or by emailing privacy@superendpoint.com with “Appeal” in the subject line. We will not discriminate against you for exercising your rights.
If your request concerns information we process for your employer or another customer, we will refer you to that organization or help it respond.
Changes to this policy
We may update this policy from time to time. We will post the updated version here with a new effective date. If a change is material, we will also notify customer account owners by email or through the Service before it takes effect.
Contact us
Questions and requests: privacy@superendpoint.com
Legal notices: legal@superendpoint.com
SUPERENDPOINT LLC