Effective date: 23 June 2026  |  Last updated: 23 June 2026

1. Who we are

A-count.io (“A-count”, “we”, “us”, or “our”) operates the website at a-count.io (the “Website”) and provides an AI-driven SaaS account-security and license-optimization platform (the “Platform” or “Service”) that helps organizations detect and remediate user-account risks, surface shadow applications, and optimize software-license costs across their connected business tools.

This Privacy Policy explains what personal information we collect, how we use and protect it, and the choices and rights you have.

Controller / contact details:
[Insert registered company name and Israeli company registration number — e.g. “A-Count Ltd., company no. 51-XXXXXXX”]
Gat 3, Jerusalem, Israel
Email: contact@a-count.io (privacy enquiries: [privacy@a-count.io])
Phone: +972 (0) 58-426-2641

2. Scope and our two roles

This policy covers two distinct situations, in which our responsibilities differ:

  • Where we are the “controller.” For visitors to our Website, prospects who contact us, and the individual users of our customer organizations who log in to and administer the Platform, we decide why and how the relevant personal information is processed. This policy governs that processing.
  • Where we are the “processor.” When a customer connects its business tools to the Platform, we process the account and usage information of that customer’s employees and users on the customer’s behalf and under its instructions. For that information, the customer (your employer) is the controller, and its own privacy notice and our agreement with that customer govern. If you are an employee whose data appears in the Platform and you have questions, please contact your employer in the first instance; we will support them in responding to you.

3. The personal information we collect

3.1 Website visitors and prospects

  • Contact and enquiry details you give us — such as your name, business email, phone number, company, and the content of your message — when you fill in a contact or demo-request form or email us.
  • Technical and usage data collected automatically — such as IP address, browser type, device and operating-system information, referring pages, and pages viewed — via your browser and our cookies and similar technologies (see Section 5).

3.2 Platform account holders (administrators and authorized users)

  • Account and profile data: full name, work email address, organizational unit, role/permission level (e.g. admin, security, finance, viewer).
  • Authentication data: a securely hashed password (where local sign-in is used), or your single-sign-on (SSO) identity when you authenticate through an identity provider such as Google, Microsoft/Entra ID, or Okta (we store the provider name and the identifier it returns, not your provider password).
  • Security and session data: last login time, failed-login counts and lockout timestamps, and session tokens, used to operate and secure the Service.

3.3 Data we process on behalf of customers (processor role)

At a customer’s direction, the Platform connects to the customer’s third-party business systems and ingests information needed to audit accounts and licenses. This can include, for the customer’s own users/employees:

  • Account identifiers and profile data — email address, username, display name, job title, team, organizational unit, and (from HR systems) employment type/status;
  • Access and licensing data — roles and permissions, assigned licenses and subscriptions, and associated cost/currency;
  • Activity and usage data — last-activity and last-sign-in timestamps, applications and extensions used, and sync metadata;
  • Findings generated by the Platform — flagged anomalies (e.g. inactive licenses, excessive permissions, duplicate or unknown accounts) and the actions taken on them.

The specific systems and data fields depend on which integrations a customer chooses to enable.

4. How we use personal information, and our legal bases

Purpose Typical legal basis
Responding to your enquiries and demo requests; sales communications you have requested Your consent and/or our legitimate interest in answering you; steps prior to entering a contract
Creating and administering Platform accounts; authenticating and authorizing users Performance of our contract with the customer
Providing, maintaining, and securing the Service, including detecting and remediating account/license risks Performance of contract; our (and our customers’) legitimate interest in security and cost control; the customer’s instructions (processor role)
Operating, debugging, and improving the Website and Platform; analytics and aggregated statistics Our legitimate interest in running and improving our business; consent where required for non-essential cookies
Billing, accounting, and managing the customer relationship Performance of contract; compliance with legal obligations
Complying with law and protecting our legal rights; preventing fraud and abuse Compliance with legal obligations; legitimate interests
Sending service, security, and administrative notices Performance of contract; legitimate interests

We do not sell your personal information, and we do not use the data we process on behalf of customers for our own marketing.

5. Cookies and similar technologies

Our Website uses cookies and similar technologies to function correctly and to understand how the site is used. These typically include:

  • Strictly necessary cookies — required for the Website (and the WordPress platform it runs on) to operate, including security and load-balancing.
  • Functionality cookies — remember your preferences, such as language.
  • Analytics cookies — help us measure traffic and improve the site. [If you use Google Analytics or any other analytics/marketing tool on the Website, name it here and link to its policy; if you use none, delete this bullet.]

The Platform itself uses only the storage strictly necessary to keep you signed in (for example, a session token stored in your browser); it does not use advertising or third-party tracking cookies.

You can control cookies through your browser settings and, where we present one, through our cookie banner/consent tool. Blocking strictly necessary cookies may stop parts of the Website from working. [If a consent/cookie-banner plugin is installed in WordPress, describe it here and link to the preference center.]

6. How we share personal information

We share personal information only as needed to run our business and provide the Service, including with:

  • Service providers / sub-processors that host and support our infrastructure and operations — for example our cloud hosting and database provider [name your hosting provider, e.g. AWS / Google Cloud / Azure, and region], and email-delivery and support tools we use to communicate with you. These parties may process personal information only on our instructions and under appropriate confidentiality and data-protection terms.
  • Integrated systems chosen by the customer. In our processor role, the Platform reads data from, and may write remediation actions to, the third-party systems a customer connects (for example Google Workspace, Microsoft 365, GitHub, Slack, Okta, JumpCloud, HiBob, and similar identity, productivity, security, and SaaS-management tools). We act on the customer’s configuration and instructions when doing so.
  • Professional advisers, auditors, and authorities where required to comply with law, enforce our terms, or protect the rights, property, or safety of A-count, our customers, or others.
  • Successors in connection with a merger, acquisition, financing, or sale of assets, subject to this policy.

7. International data transfers

We are based in Israel, which has been recognized by the European Commission as providing an adequate level of data protection. Personal information may be processed in Israel and in other countries where we or our sub-processors operate. Where we transfer personal information internationally, we rely on an applicable adequacy decision or on appropriate safeguards (such as the European Commission’s Standard Contractual Clauses) as required by law.

8. How long we keep personal information

We keep personal information only for as long as necessary for the purposes described above, and then delete or anonymize it. Specifically:

  • Website enquiries: kept while we handle your request and for a reasonable follow-up period.
  • Platform account data: kept for the life of the customer’s subscription and deleted or returned afterwards in line with our customer agreement, subject to legal retention requirements.
  • Customer-instructed data (processor role): retained per the customer’s configuration; customers (and authorized administrators) can delete synced accounts, anomalies, and other records, and generated export files expire automatically after a set period.
  • Logs and security records: kept for a limited period for security and troubleshooting.

9. How we protect personal information

We apply technical and organizational measures appropriate to the risk, including:

  • Encryption of data in transit (TLS) and encryption of stored credentials and connection secrets (the OAuth tokens and keys used to connect to customer systems are encrypted at rest);
  • Strong password hashing (Argon2) for any locally stored credentials;
  • Token-based authentication with session expiry and revocation, login rate-limiting, and account lockout after repeated failed attempts;
  • Role-based access controls and the principle of least privilege;
  • Logical separation of customer data in our multi-tenant environment.

No method of transmission or storage is completely secure, but we work to protect your information and to maintain its confidentiality, integrity, and availability.

10. Your privacy rights

Subject to applicable law, you may have the right to access the personal information we hold about you, to correct inaccurate or incomplete data, to request deletion, to object to or restrict certain processing, to withdraw consent, and to request a copy of your data in a portable format.

  • Israel. Under Israel’s Protection of Privacy Law, you may request to review and to correct or delete personal information we hold about you.
  • EEA/UK (GDPR). If you are in the European Economic Area or the United Kingdom, you have the rights described above and may lodge a complaint with your local data protection authority.
  • California. If you are a California resident, you have rights to know, delete, and correct personal information and to opt out of any “sale” or “sharing”; we do not sell personal information.

To exercise your rights, contact us at contact@a-count.io. We will verify your request and respond within the time required by law. If your data is processed by us on behalf of your employer (our customer), we will refer your request to them or act on their instructions.

11. Automated analysis and AI

The Platform uses automated analysis — including AI-assisted methods — to detect patterns such as inactive accounts, excessive permissions, duplicate licenses, and other potential risks, and to suggest remediation. These outputs are presented to a customer’s administrators for review and action; we do not use them to make decisions that produce legal or similarly significant effects about an individual without human involvement. We do not use customer data to train AI models for other customers.

12. Children

The Website and the Service are intended for businesses and are not directed to children. We do not knowingly collect personal information from children under the age of 16.

13. Third-party links

Our Website may link to third-party sites and services that we do not control. This policy does not apply to them, and we encourage you to read their privacy notices.

14. Changes to this policy

We may update this Privacy Policy from time to time. When we do, we will revise the “Last updated” date above and, where appropriate, provide additional notice. Your continued use of the Website or Service after changes take effect constitutes acceptance of the updated policy.

15. How to contact us

If you have questions about this policy or how we handle personal information, contact us at:
[Insert registered company name]
Gat 3, Jerusalem, Israel
Email: contact@a-count.io
Phone: +972 (0) 58-426-2641