Privacy policy for Resec Download Protection
Resec Download Protection by Resec RDP
Browser Protection Privacy Policy
Resec Download Protection (RDP) Privacy Policy
Effective date: 2026-04-07
Resec Technologies Ltd. (“Resec”, “we”, “us”) provides the Resec Download Protection browser extension (“RDP”, the “Extension”). This Privacy Policy explains what data the Extension processes, why it is processed, and the choices available to users and customer organizations.
1) What the Extension does
RDP helps secure file downloads by intercepting download events in the browser, checking policy/authentication, and submitting files to Resec services for sanitization and threat prevention before delivering a safe file to the user.
2) Data we process
Depending on configuration and usage, the Extension and related Resec services process:Authentication data: user sign-in identifiers and authentication artifacts used to verify access to the service (including enterprise identity flow artifacts where enabled).
Download metadata: download URL/domain, filename, file size, timestamps, status, and processing outcome.
File content: downloaded file content submitted for malware/sanitization processing.
Operational and security telemetry: technical logs and diagnostics needed for reliability, abuse prevention, and support.
3) Why we process data
We process the above data only to:provide download security and sanitization services;
enforce customer security policy and access controls;
detect, investigate, and prevent abuse or security incidents;
operate, troubleshoot, and improve service reliability.
We do not process Extension data for advertising targeting or marketing profiling.
3.1) Legal basis (where applicable)
Where data protection laws such as the GDPR apply, Resec processes data on the basis of:performance of a contract (providing the RDP security service to customer organizations);
legitimate interests (network and information security, fraud/abuse prevention, and service reliability);
compliance with legal obligations where required.
4) Sharing and disclosureNo sale of personal data: Resec does not sell personal data processed through RDP.
No advertising sharing: Resec does not share Extension data with third parties for advertising or marketing purposes.
Service operation and legal compliance only: data may be disclosed when required to operate the service, comply with applicable law, or respond to valid legal process.
5) RetentionFile content: retained only as needed for security processing and support, and deleted no later than 30 days, unless a longer period is required for an active incident/support case or legal obligation.
Operational/security logs and metadata: retained for 90 days, unless a longer period is legally required for a specific incident or request.
6) Security safeguards
Resec applies technical and organizational safeguards designed to protect data, including controlled access, secure transmission, and least-privilege operational practices.
7) Your choices and rights
For access, correction, deletion, or other privacy requests regarding data processed by RDP, contact: info@resec.co.
If you use RDP through your employer or organization, that organization may control certain processing decisions; please also contact your administrator.
8) International processing
RDP may process data in locations where Resec or its infrastructure/service providers operate. Resec applies appropriate safeguards for cross-border processing as required by applicable law.
9) Children
RDP is an enterprise security product and is not directed to children.
10) Changes to this policy
We may update this Privacy Policy from time to time. Material updates will be reflected by updating the effective date above.
11) Google API data
RDP does not use Google user data APIs for this workflow. If this changes in the future, this policy and store disclosures will be updated accordingly.
Chrome Web Store Disclosure (Short Form)
Single purpose: Resec Download Protection secures user-initiated downloads by analyzing/sanitizing files and enforcing enterprise download policy before delivery.
Data collected/processed: authentication identifiers/tokens, download metadata (URL/domain, filename, size, status, timestamp), file content submitted for sanitization, and technical/security logs.
Data use: strictly for security processing, policy enforcement, fraud/abuse prevention, troubleshooting, and service operation.
Data sharing/sale: no sale of personal data; no sharing for advertising/marketing.
Retention: temporary file retention for processing/support; operational/security logs retained for 90 days.