Privacy policy - "Guardio"

Summary

PII We Collect. In order to provide and improve the Solution, we may collect registration information, browsing and online activity data, and depending on the features and services you elect to use, also SMS and cloud data, social media data, compromised credential scan results and other information as detailed below.

How We Use Your PII. We use your PII in order to provide you with cybersecurity services and to maintain, provide and improve the Solution, to understand the usage trends and preferences of our users, to detect and prevent online threats, risks and vulnerabilities, present our offerings to visitors of our services and to place ads of our services on other websites.

Cybersecurity Monitoring. The Solution monitors your browsing activity and online account settings, and if you choose to use any of the following features and services, also SMS messages, cloud data (e.g. Gmail and Drive), social media presence and search for compromised data sources with your PII in order to detect threats, risks and vulnerabilities and provide you with enhanced protection and privacy awareness.

AI Voice Agents. We may also offer AI voice agents for phone-based interactions, in order to provide you with support and services. In such case we may record calls and use transcriptions to provide the service. We use third party service providers for certain of these features.

Aggregate and Analytic Data. In an ongoing effort to better understand and serve the users of the Solution, we often conduct research on user demographics, interests and behavior based on the PII and other information provided to us. We do this mainly to improve the Solution and develop new services. For more details see below in the policy.

Cookies and Web Beacons. We may use cookies, web beacons, tags and scripts for placing ads of our services on other websites, for log-in purposes, to trace session data and analytics and to personalize the Solution. You can disable cookies but then your online experience on the Solution may be limited or disabled.

Links and Third Party Services. The Solution may contain links to or interactions with other services, sites and applications, all of which are subject to such third party privacy and data protection policies. The Company is not responsible for the privacy practices of third party services.

Children. We do not intend to collect PII from anyone we know to be under 16 years old. If you believe that we might have collected such information, please contact us.

PII Sharing. We grant access to your PII to our affiliates, agents, representatives, and third party service providers for the legitimate purposes set forth herein, e.g. cloud providers, payment and fraud prevention providers and customer communication platforms. In addition, we may share your PII: if required for the provision, maintenance and improvement of the Solution; to satisfy applicable law; when permitted by you; to prevent fraud or harm; or in the event of a merger, acquisition or other structural change or form of sale of part or all of our assets.

PII Security. We follow generally accepted industry standards to protect against unauthorized access, alteration, disclosure or destruction of your PII, however no online solution can guarantee absolute security. We retain your PII only for as long as reasonably necessary to provide you with services and support your use of the Solution. We also retain PII for longer periods if required to investigate wrongdoing, or to fulfill a legitimate business need or to comply with any applicable legal or ethical reporting or document retention requirements.

Data Integrity. We process PII only for the purposes for which it was collected and take reasonable steps to ensure that the PII we process is accurate, complete and current. However, we depend on you to rectify your PII when necessary.

Your Rights. At any time, you may contact us and request to exercise your rights in accordance with applicable law. For more details see Section 10 below.

Enforcement. We will cooperate with the appropriate regulatory authorities to resolve any formal written complaints regarding processing of PII that cannot be resolved between us and the complaining individual.

Transferring of PII. Your PII may be stored and processed in a country outside the country of your residence or from which you access the Solution.

Your U.S. State Privacy Rights. For more details see Section 15 below.

Introduction

IMPORTANT: BY DOWNLOADING, ACCESSING OR USING GUARDIO LTD.'S ("COMPANY" OR "WE") CYBER-SECURITY SOLUTION AND ANY FEATURES OR SERVICES IN RESPECT THEREOF, WHETHER WEB-BASED, MOBILE OR OTHERWISE (the "SOLUTION") YOU ("YOU") CONSENT TO THE TERMS AND CONDITIONS OF THIS PRIVACY POLICY AND CONSENT THAT ALL PERSONALLY IDENTIFIABLE INFORMATION THAT YOU SUBMIT OR THAT IS PROCESSED, USED OR COLLECTED THROUGH THE SOLUTION MAY BE PROCESSED BY THE COMPANY AND ITS AFFILIATES IN THE MANNER AND FOR THE PURPOSES DESCRIBED IN THE FOLLOWING PRIVACY POLICY (“PRIVACY POLICY”). SUCH CONSENT IS NOT IN LIEU OF OTHER LEGAL BASIS OF PROCESSING, WHERE THESE ARE IN EFFECT, AS DETAILED BELOW.

WE DEFINE "PII" TO MEAN ANY INFORMATION RELATING TO AN IDENTIFIED OR IDENTIFIABLE NATURAL PERSON; AN IDENTIFIABLE NATURAL PERSON IS ONE WHO CAN BE IDENTIFIED, DIRECTLY OR INDIRECTLY, IN PARTICULAR BY REFERENCE TO AN IDENTIFIER SUCH AS A NAME, AN IDENTIFICATION NUMBER, LOCATION DATA, AN ONLINE IDENTIFIER OR TO ONE OR MORE SPECIFIC FACTORS.

YOU ARE NOT LEGALLY REQUIRED TO PROVIDE US WITH PII, HOWEVER, SOME OF THE FEATURES AND SERVICES IN THE SOLUTION REQUIRE YOU TO DO SO PURSUANT TO THIS PRIVACY POLICY. IN THESE CASES, IF YOU CHOOSE TO WITHHOLD ANY PII REQUESTED BY US, IT MAY NOT BE POSSIBLE FOR YOU TO ACCESS OR USE CERTAIN FEATURES OR SERVICES OF THE SOLUTION. IF YOU DO NOT AGREE TO THE TERMS AND CONDITIONS SET FORTH HEREIN, PLEASE DO NOT DOWNLOAD, ACCESS OR USE THE SOLUTION. YOU REPRESENT AND WARRANT THAT: (I) YOU HAVE ALL RIGHTS, PERMITS AND CONSENTS: TO PROVIDE COMPANY WITH THE PII, AND FOR COMPANY’S COLLECTION AND PROCESSING OF THE PII AS DETAILED IN THIS PRIVACY POLICY; AND (II) YOU SHALL AT ALL TIMES COMPLY WITH ALL APPLICABLE LAWS, RULES AND REGULATIONS.

We recognize that privacy is important. This Privacy Policy applies to all of the services, information, tools, features and functionality available on the Solution and covers how PII that the Company collects and receives, including in respect of any use of the Solution, is treated. Please note that the Solution also makes available certain third party services that are subject to the third party terms instead of this policy, as detailed below.

Please also read the Terms of Use available at: https://guard.io/terms-of-use, which describes the terms under which you use the Solution. This Privacy Policy is subject to the Terms of Use and both documents should be read together. All capitalized terms which are not otherwise defined in this privacy policy shall have the meaning attributed to them in the Terms of Use.

1. Information We Collect and How We Use It

In order to provide and improve the Solution and to understand the usage trends and preferences of our users or for our business purposes, we may collect and process PII, including the following types of information:

Processing which is necessary for the performance of a contract to which you are a party or in order to take steps at your request prior to entering into a contract (GDPR Article 6(1)(b)) OR Processing which is necessary for compliance with a legal obligation to which Company is subject (GDPR Article 6(1)(c)):

1.1. Registration Information.

1.1.1. Registration. When you open an account or register to the Solution we may collect and process PII, as part of the registration process, such as full name, e-mail address, phone number, country, billing information (not including payment card details), 4 last digits of your credit card, card type for paying customers, and other information provided by you.

1.1.2. Platform Sign-in. You may log-in or open an account using Google Sign-in or Apple or any other platform that we authorize. In such case, the platform will share with us your account information that you authorized them to share. Usage and transfer of information received from Google APIs, to any other app, will adhere to the Google API Services User Data Policy, including the Limited Use requirements as defined therein.

1.2. Payment Card. When you pay for any features or services on the Solution, you will be referred to a third party payment service provider. Although the payment form will be presented in the Solution, this service is provided to you directly by such provider, as a controller, and is subject to the provider’s terms of service and privacy policy. We do not retain payment card data.

1.3. Browsing Data. We Collect your browsing history and history of online activity and realtime browsing data, only as needed to provide you with the Services. We do this in order to identify online threats, risks and vulnerabilities and generate recommendations and insights to enhance your security and privacy awareness. If you approved our DNS services, all of your online browsing will run through our DNS server in order to scan suspicious traffic and block it; in such case we retain meta-data of this traffic and browsing data and if we identify suspicious traffic, also the content of the website/ service that was flagged as suspicious. After each browsing session ends, the data is pseudonymized without identifying a specific user, except for cases where a security alert was identified or suspected.

1.4. Online and Third Party Account Preferences. We review your online activity in order to enhance your security. As part of this review we check which browser extensions are installed, what authorizations you provided and whether you defined security measures, such as 2-step authentication on websites and platforms.

1.5. SMS Scans. If you use this service and your device supports it, we will review SMS messages that are flagged as suspicious, before they are uploaded to your device. If we find anomalies or suspicious content, we will let you know. We use third party service providers in order to provide these services.

1.6. Cloud Data. If you use our cloud security services, by adding your Gmail account (additional cloud services may be added in the future), we will use sensors that review emails and Google Drive content for risks and abnormalities. This requires us to create a temporary cache of the data and to collect meta data. If we identify risks or abnormalities, we will also retain the actual suspicious email/ file.

1.7. Social Media. If you use our social media security services, we will scan public information of your social media accounts and content and data you upload or that show-up in your feed. We do this in order to scan for risks, data leaks, online vulnerabilities and provide insights and recommendations for privacy settings and security. We use third party service providers in order to provide these services.

1.8. Compromised Data Scans. If you use this service, we will review leaked and compromised data online, including in the dark and deep web, in order to monitor for any of your data or credentials that may have been leaked or became compromised. We only receive reports and an inventory list of such data, in order to report it to you and may agree to attempt to obtain the actual data per your request.

1.9. Security Reports and Alerts. We may send you security scan reports and security alerts from time to time. Such reports and alerts may be sent by various means, including SMS.

1.10. Insurance and Identity Theft. You may acquire form third parties identity theft-related services, including insurance. In such case, Guardio will need to share certain personal information about you with the Identity Theft Service Provider, such as your name, email address, and other account information. In addition, your calls, including your calls to the Ancillary Identity Theft Services may be recorded by the Identity Theft Service Provider and shared with Guardio for purposes of provision of the services and for quality assurance. This is required in order to be able to offer you access to Ancillary Identity Theft Services (whether or not you actually accessed and/or used such services). You acknowledge and agree that Guardio may share such personal information with the Insurance Service Provider for the purpose of and as necessary for facilitating and making available the Ancillary Identity Theft Services to you via Guardio’s services. Ancillary Identity Theft Services are also subject to the terms and conditions and privacy policy of the Insurance Service Provider which you are urged to carefully read prior to using such services.

The data subject has given consent to the processing of his or her personal data for one or more specific purposes; (GDPR Article 6(1)(a)):

1.11. AI Voice Agents. We may offer you the opportunity to engage with our Solution through voice-based interactions, including AI-powered voice assistants (“AI Voice Agents”). When you participate in a phone call with our AI Voice Agents, we collect and process the following information:

1.11.1. Voice Recordings and Audio Data. We may record and store the audio of your conversations to provide the Solution and for quality assurance and security purposes.

1.11.2. Transcriptions. We use third-party service providers to transcribe your voice interactions into text.

1.11.3. Inferred Data. Our AI models may analyze the content of the conversation to provide you the Solution, such as tailored security insights and reports.

We use third party service providers in order to provide these services.

Processing which is necessary for the purposes of the legitimate interests pursued by Company or by a third party (GDPR Article 6(1)(f)) of providing efficient and effective services to our customers, including:

1.12. Third Parties. We sometimes supplement the information that you provide with information that is received from third parties, in order to validate or correct data or provide log-in options.

1.13. User Communications. When you send emails or other communication to the Company, we may retain those communications in order to process your inquiries, respond to your requests and improve the Solution. We may send you push notifications to send you news and updates in respect of the Solution. We may send surveys in order to understand your needs, receive feedback and improve or personalize the Solution. We may also send you newsletters and promotional communications, you may opt-out of this service at any time by submitting a request to the following e-mail: my.privacy@guard.io.

1.14. User Information. When you use the Solution, we will automatically receive and record information from your browser and from screen events on your mobile device, including without limitation information and statistics about your online/offline status, IP address, IP block for general location, internet service provider, search history, type of browser, your regional and language settings and software and hardware attributes, session time, impressions and cookies information. Our systems may automatically record and store technical information regarding your user experience. An IP address is a numeric code that identifies your browser on a network, or in this case, the Internet. Your IP address is also used to gather broad demographic information. The Company uses all of the PII that we collect to understand the usage trends and preferences of our users and to improve the Solution.

1.15. Aggregate and Analytical Data. In an ongoing effort to better understand and serve the users of the Solution, we often conduct research on user demographics, interests and behavior based on the PII and other information provided to us. This research may be compiled and analyzed on a pseudonymized or de-identified individual basis or on an aggregate basis, and we may share aggregate de-identified data with affiliates, agents and business partners. The aggregate information does not identify you personally. We may also disclose aggregated user statistics in order to describe our services to current and prospective business partners or investors, and to other third parties for other lawful purposes.

Please note that to the extent you provide us with PII of third parties you hereby acknowledge and undertake that you have obtained all required approvals, authorization, and consents in respect thereof.

2. Profiling and Automated Decision Making

We may offer your specific offerings based on your demographic and browsing data. These offerings are available also to other users and you are free to choose from our other offerings. We do so for your convenience.

3. Cookies and Web Beacons

In order to collect the data described herein we may use temporary cookies that remain on your browser for a limited period of time. We may also use persistent cookies that remain on your browser until you clear cookies or the Solution is removed, in order to manage and maintain the Solution and record your use of the Solution. We use cookies for placing ads of our services to users on other websites and apps, for log-in purposes, to trace session data and analytics and to personalize the Solution. Cookies by themselves cannot be used to discover the identity of the user. A cookie is a small piece of information which is sent to and stored on your browser. Cookies do not damage your browser. Most browsers may allow you to block cookies but you may not be able to use some features on the Solution if you block them. You may set most browsers to notify you if you receive a cookie (this enables you to decide if you want to accept it or not). We may also use web beacons in order to collect information. Web beacons or "gifs", are electronic images that may be used on the Solution or in our emails. We use Web beacons to deliver cookies, count visits and to tell if an email has been opened and acted upon.

5. Children

If you are a child under the age of 16, you must obtain parental consent prior to using the Solution. The Company will not knowingly contact or engage with children under the age of 16 without said parental consent. If you have reason to believe that a child has provided us with their PII, please contact us at the address given above and we will endeavor to delete that PII from our databases. If you add your child to your account, you hereby provide parental consent to allow us to provide them with the Services and process their PII pursuant to this policy.

6. Information Sharing

In order to provide, maintain and improve the Solution, and for the other purposes set forth herein, certain third parties may have access to your PII, including Company’s corporate affiliates and service providers. The Company may also share PII in the following circumstances: (a) as required for the ongoing operations, provision, maintenance and improvement of the Solution; (b) when permitted by you; (c) if we become involved in a reorganization, merger, consolidation, acquisition, or any form of sale of some or all of our assets, with any type of entity, whether public, private, foreign or local; and/or (d) to satisfy applicable law or prevention of fraud or harm or to enforce applicable agreements and/or their terms, including investigation of potential violations thereof or in response to a court order, judicial or administrative subpoena or warrant, or to otherwise cooperate with law enforcement investigations; (e) to our corporate affiliates or other third party service providers, subcontractors and representatives for the purpose of processing PII on our behalf.

Following is a list of certain third party providers that we use for certain features of the Solution. We provide you with this list, so you can review their privacy policies and terms of service. Use of these features shall be subject to the respective privacy policies of these third party providers, as detailed below. Please review them carefully.

Forter Ltd.: payment optimization and fraud prevention platform
Privacy & Security Hub – Forter

Aircall.io Inc.: customers communications platform.
Privacy Policy | Aircall

7. Information Security and Retention

We follow generally accepted industry standards to protect against unauthorized access to or unauthorized alteration, disclosure or destruction of PII. However, no method of transmission over the Internet, or method of electronic storage, is 100% secure. Therefore, while we strive to use commercially reasonable means to protect your PII, we cannot guarantee its absolute security.

8. Data Retention

8.1. Company will retain PII in accordance with its record retention policy. We retain PII only for the period required in order to use the PII for the purpose for which it was collected. We also retain PII that is required to meet any audit, compliance and business best-practices for the term for which it is required to fulfill these purposes, which may be longer than the above. We retain data related to suspected security threats and risks indefinitely.

8.2. We may retain aggregate or de-identified data indefinitely.

9. Data Integrity

The Company processes PII only for the purposes for which it was collected and in accordance with this Privacy Policy or any applicable service agreements. We review our data collection, storage and processing practices to ensure that we only collect, store and process the PII needed to provide or improve the Solution. We take reasonable steps to ensure that the PII we process is accurate, complete, and current, but we depend on our users to update or correct their PII whenever necessary. Nothing in this Privacy Policy is interpreted as an obligation to store information, and we may, at our own discretion, delete or avoid from recording and storing any and all information.

10. Your Rights

Subject to certain exemptions or derogations, the following rights may apply to certain individuals:

10.1. Right of Access and Rectification. You have the right to know what PII we collect about you and to ensure that such data is accurate and relevant for the purposes for which we collected it. We allow our users the option to access and obtain a copy of their PII and to rectify such PII if it is not accurate, complete or updated. However we may first ask you to provide us certain credentials to permit us to identify your PII.

10.2. Right to Delete PII or Restrict Processing. You have the right to delete your PII or restrict its processing. We may postpone or deny your request if your PII is in current use for the purposes for which it was collected or for other legitimate purposes such as compliance with legal obligations.

10.3. Right to Withdraw Consent. You have the right to withdraw your consent to the processing of your PII. Exercising this right will not affect the lawfulness of processing your PII based on your consent before its withdrawal.

10.4. Right of Data Portability. Where technically feasible, you have the right to ask to transfer your PII in accordance with your right to data portability.

You may exercise the above rights by sending a request to my.privacy@guard.io.

No fees are required for exercising any of the above rights. However, subject to applicable laws and regulations, we may charge you a reasonable fee, including administration fees, if your request is repetitive or excessive or requires us to bear excessive or expensive efforts.

10.5. Right to Lodge Complaint. You also have the right to lodge a complaint with a data protection supervisory authority regarding the processing of your PII.

11. Enforcement

The Company regularly reviews its compliance with this Privacy Policy. Please feel free to direct any questions or concerns regarding this Privacy Policy or our treatment of PII by contacting us as provided above. When we receive formal written complaints it is the Company's policy to contact the complaining user regarding his or her concerns. We will cooperate with the appropriate regulatory authorities, including local data protection authorities, to resolve any complaints regarding the transfer of PII that cannot be resolved between the Company and an individual.

12. Changes to This Privacy Policy

The Company may update this Privacy Policy. We will notify you about material and significant changes in the way we treat PII by sending a notice to the email address provided by you or by placing a prominent notice on the Solution. We encourage you to periodically review this Privacy Policy for the latest information about our privacy practices.

14. Questions

If you have any questions about this Privacy Policy or concerns about the way we process your PII, please contact our DPO at my.privacy@guard.io.

15. Privacy Rights for U.S. Residents

15.1. Scope. This section of our Privacy Policy (this “U.S. State Privacy Notice”) supplements the information contained in our Privacy Policy and applies to individual residents of U.S. states that have enacted comprehensive consumer privacy laws, including California, Colorado, Connecticut, Delaware, Indiana, Iowa, Kentucky, Maryland, Minnesota, Montana, Nebraska, New Hampshire, New Jersey, Oklahoma, Oregon, Rhode Island, Tennessee, Texas, Utah, and Virginia, together with similar applicable state consumer privacy laws that are in effect or may be enacted in the future (collectively, the “State Privacy Laws”). This Notice addresses the specific disclosure requirements under the State Privacy Laws and provides additional information about how we collect, use, share, and otherwise process your personal information, the rights you have in relation to that personal information, and how to exercise those rights. For purposes of this section, “Personal Information” (or “Personal Data”) has the meaning given under applicable State Privacy Laws, including the California Consumer Privacy Act of 2018 (“CCPA"), the California Privacy Rights Act of 2020 ("CPRA”), and any regulations promulgated under either law, in each case, as amended from time to time. Where other State Privacy Laws use different terminology (e.g., “Personal Data”), those terms are included in this Notice’s references to “Personal Information.” This Section does not apply to:

15.1.1. information exempted from the scope of the applicable State Privacy Laws;

15.1.2. activities governed by a different privacy notice, such as notices we may give to personnel or candidates; or

15.1.3. Personal Information we collect, use, and share on behalf of our customers as a "service provider" or an equivalent definition under applicable State Privacy Laws.

15.2. Your Privacy Rights Under State Privacy Laws. Subject to certain exemptions, if you are a resident of a state with an applicable State Privacy Law, you may have the following rights with respect to your Personal Information:

15.2.1. Right to Information/Know. You can request whether we have collected your Personal Information, and in certain cases, the following information about how we have collected and used your Personal Information during the past 12 months:

15.2.1.1. The categories of Personal Information we have collected.

15.2.1.2. The categories of sources from which we collected the Personal Information.

15.2.1.3. The business or commercial purpose for collecting, sharing, and/or selling Personal Information.

15.2.1.4. The categories of Personal Information that we sold or disclosed for a business purpose.

15.2.1.5. The categories of third parties to whom Personal Information was sold, shared, or disclosed for a business purpose.

15.2.2. Right to Access. You can request a copy of the Personal Information that we have collected about you during the past 12 months.

15.2.3. Right to Correction. You can request that we correct inaccurate Personal Information that we have collected about you.

15.2.4. Right to Deletion. You can ask us to delete the Personal Information that we have collected from you.

15.2.5. Right to Opt-Out of Tracking for Targeted Advertising Purposes. While we do not sell Personal Information for money, like many companies, we use services that help present you with ads regarding the Solution while you visit other products, services and websites. The CCPA may classify our use of some of these services as “sharing” your Personal Information with the advertising partners that provide the services, from which you have the right to opt-out.

15.2.6. Right to Nondiscrimination. You are entitled to exercise the rights described above free from discrimination or retaliation as prohibited by applicable State Privacy Laws.

15.2.7. Right to Limit Use of Sensitive Personal Information. Where we collect Sensitive Personal Information (as defined under applicable State Privacy Laws), you may have the right to limit our use and disclosure of such information to purposes that are reasonably necessary and expected to provide the requested services. We do not use or disclose Sensitive Personal Information for purposes that you have a right to limit under applicable State Privacy Laws.

15.2.8. Right to Opt-Out of Profiling. Under certain State Privacy Laws, you may have the right to opt out of profiling in furtherance of decisions that produce legal or similarly significant effects concerning you.

15.2.9. Right to Appeal. If we deny your privacy request, in whole or in part, you may have the right to appeal our decision. To submit an appeal, please contact us at my.privacy@guard.io with the subject line “Privacy Rights Appeal.” We will respond to your appeal within the timeframe required by applicable State Privacy Laws (generally 45–60 days). If your appeal is denied, we will provide you with instructions on how to contact your state attorney general to submit a complaint.

15.3. Opt-Out Preference Signals and California Shine the Light. We honor opt-out preference signals that comply with the Global Privacy Control specs (“GPC”). When we detect a GPC signal from your browser, we will treat it as a valid request to opt out of the sale and sharing of Personal Information associated with that browser and device. You do not need to take any additional action beyond enabling the GPC signal. We do not respond to other “Do Not Track” browser signals. In addition, California Civil Code Section 1798.83, often called “Shine the Light”, permits California residents with an established business relationship to request information about disclosures of Personal Information to third parties for direct marketing purposes. To make such a request, please contact us at my.privacy@guard.io. We respond to one request per customer per year.

15.4. How to Exercise Your Rights.

15.4.1. Right to Information/Know, Access, Correction, and Deletion. You can exercise any of these rights by submitting a request through our dedicated email here: my.privacy@guard.io.

15.4.2. Right to Opt-Out of Tracking for Targeted Advertising Purposes. You can submit requests to opt-out of tracking for targeted advertising purposes by my.privacy@guard.io. Your request to opt-out will apply only to the browser and the device from which you submit the request.

15.4.3. Authorized Agent. You may designate an authorized agent to submit a privacy request on your behalf. To do so, you must provide the authorized agent with written permission signed by you, and we may require you to verify your identity directly with us and confirm that you have authorized the agent to act on your behalf.

15.5. Verification of Identity. If we receive any request from you, we will use a two-step process for online requests where you must first clearly submit the request and then separately confirm it. We will use other appropriate measures to verify requests received from you. If you are a California consumer submitting a request, you must provide sufficient information to identify yourself, such as name, e-mail address, home or work address, or other such information that is on record with us so that we can match such information to the Personal Information that we maintain. Do not provide social security numbers, driver’s license numbers, account numbers, credit or debit card numbers, medical information or health information with requests. If your request is unclear or submitted through means other than described above, we will give you specific directions on how to submit the request or remedy any deficiencies. If we cannot verify your identity, we may deny the request.

15.6. Response Timing and Format. We will respond to a verifiable consumer request within forty-five (45) calendar days of its receipt. If we require more time (up to an additional 45 days), we will inform you of the reason and extension period in writing. We will deliver our written response by e-mail. For California residents, disclosures we provide may only cover the 12-month period preceding the request’s receipt. The response we provide will also explain the reasons we cannot comply with a request, if applicable.

15.7. Personal Information that we Collect, Use and Disclose. The following describes our Personal Information practices by reference to the categories in the “Information We collect and How we Use it” section above and the categories described in the CCPA (Cal. Civ. Code Section 1798.140(v)) and describes our practices currently and during the 12 months preceding the effective date of this Privacy Policy. Information you voluntarily provide to us, may contain other categories of personal information not described below. Note that:

15.7.1. We do not “sell” Personal Information as defined by the CCPA and applicable State Privacy Laws, and have not sold Personal Information in the preceding 12 months.

15.7.2. To the extent that some of our data transfers are deemed as “sharing” pursuant to the CCPA, e.g. sharing online identifiers in order to present you with advertisements of the Solution on other websites and services, the following categories are relevant: pixel data that identifies user for presenting ads of the Solution on other websites or services.

15.7.3. We do not use or disclose Sensitive Personal Information for purposes that residents have a right to limit under the CCPA or applicable State Privacy Laws.

(A) Identifiers — Name, email address, phone number, Internet Protocol address, address, cookie identifiers.

  • Purpose: Providing, maintaining, and improving the Solution; billing customers; cybersecurity monitoring and threat detection; personalizing your experience; placing ads of our services on other websites; complying with legal obligations.
  • Disclosed to: See Section 6 (Information Sharing) above.
  • Sources: From you or platform sign-in (e.g. Google or Apple) and completing or correcting data from third party service providers.
  • Sold or shared? Shared for cross-context behavioral advertising of our Solution.

(B) California Personal Record Statute — Name, address, phone number, payment card and billing information.

  • Purpose: Providing, maintaining, and improving the Solution; billing customers; cybersecurity monitoring and threat detection; personalizing your experience; complying with legal obligations.
  • Disclosed to: See Section 6 (Information Sharing) above.
  • Sources: From you and completing or correcting data from third party service providers.
  • Sold or shared? Not sold or shared.

(F) Internet or network information — Browsing history, search history, realtime browsing data, DNS traffic metadata, browser extensions and security settings, information regarding your interaction with websites and advertisements, cookies.

  • Purpose: Providing and improving the Solution; cybersecurity monitoring including browsing, DNS, and extension analysis; detecting online threats, risks and vulnerabilities; cookies used for placing ads of our services; complying with legal obligations.
  • Disclosed to: See Section 6 (Information Sharing) above.
  • Sources: From your use of the Solution and data imported from your browser. Browsing data and state. Other demographics also from ad service providers for presenting you with ads of the Solution on other websites and services. We do not use browsing data for placing ads.
  • Sold or shared? Shared for cross-context behavioral advertising of the Solution.

(G) Geolocation — General location derived from IP address.

  • Purpose: Providing, maintaining, and improving the Solution; cybersecurity monitoring and threat detection; personalizing your experience; placing ads of our services on other websites; complying with legal obligations.
  • Disclosed to: See Section 6 (Information Sharing) above.
  • Sources: From your device.
  • Sold or shared? Not sold or shared.

(K) Inferences drawn from any of the information above — Preferences and personalization of the Solution based on the information above.

  • Purpose: Providing, maintaining, and improving the Solution; cybersecurity monitoring and threat detection; personalizing your experience; placing ads of our services on other websites; complying with legal obligations.
  • Disclosed to: See Section 6 (Information Sharing) above.
  • Sources: By us or using analytics service providers.
  • Sold or shared? Not sold or shared.

(C) Protected Classification Characteristics. Not Collected.

  • Purpose, disclosed to, sources, sold or shared: N/A

(D) Commercial Information — Subscription and payment history; records of services purchased.

  • Purpose: To provide and maintain the Solution; billing and account management.
  • Disclosed to: Payment processors, cloud service providers.
  • Sources: From you and payment service providers.
  • Sold or shared? Not sold or shared.

(E) Biometric Information. Not Collected.

  • Purpose, disclosed to, sources, sold or shared: N/A

(H) Sensory Data — Voice recordings from AI Voice Agent interactions.

  • Purpose: To provide support and AI Agent communications regarding use of the Solution and quality assurance, and security. See Section 1.10 above.
  • Disclosed to: Third-party AI voice and transcription service providers.
  • Sources: From you, via AI Voice Agent phone interactions.
  • Sold or shared? Not sold or shared.

(I) Professional or Employment-Related Information. Not Collected.

  • Purpose, disclosed to, sources, sold or shared: N/A

(J) Non-Public Education Information. Not Collected.

  • Purpose, disclosed to, sources, sold or shared: N/A

(L) Sensitive Personal Information. We do not intentionally process any Sensitive Personal Information. However, such information may be inadvertently processed as part of processing cloud (Drive and G-mail) data, SMS content, social media public data, online browsing data or compromised data you ask us to retrieve.

  • Purpose: To provide cybersecurity monitoring and breach detection services. See Sections 1.6 and 1.8 above.
  • Disclosed to: Cloud and cybersecurity service providers.
  • Sources: From you, from your cloud service provider, from your SMS provider and compromised data sources.
  • Sold or shared? Not sold or shared.

Any category included in your browsing data, social media public data, cloud data (Drive and Gmail), SMS contents, compromised credential scan results, and AI Voice Agent interactions.

  • Purpose: Providing, maintaining, and improving the Solution; cybersecurity monitoring and threat detection; personalizing your experience; placing ads of our services on other websites; complying with legal obligations.
  • Disclosed to: See Section 6 (Information Sharing) above.
  • Sources: From you and your use of the Solution; from your cloud service provider; from your SMS provider; from compromised and leaked data sources; and via AI Voice Agent phone interactions.
  • Sold or shared? Not sold or shared.

Last Date Updated: September 1, 2026.