Outpost24 Privacy Policy

Updated: 27 August,2020 

OUTPOST24 AND YOUR DATA

At Outpost24, we understand the value of data and are committed to protecting your data. Our Privacy Policy (« Privacy Policy ») sets out details about the information that we collect, and how we process, store and share it, both online and offline.

We urge you to read this Privacy Policy so you can understand Outpost24’s use of your information, and our commitment to protecting all data that we receive and how you can be involved in this process. This Privacy Policy should be read alongside the Outpost24 Terms of Use (« Terms »)

1. WHO WE ARE

In this Privacy Policy, the words “our,” “us,” “we,” and “Outpost24” refer to Outpost24 AB, a Swedish limited liability company and our subsidiaries and affiliate entities worldwide. Outpost24 is a leading cyber assessment company focused on enabling its customers to achieve maximum value from their evolving technology investments. By leveraging our full stack security insights to reduce attack surface for any architecture, Outpost24 customers continuously improve their security posture with the least effort. Over 2,000 customers in more than 40 countries around the world trust Outpost24 to assess their devices, networks, applications, cloud and container environments and report compliance status for government, industry sector, or internal regulations.

We collect and use information about our web site visitors (Section 3) and those that interact with our products and services (Sections 4 and 5) in order to manage your relationship with Outpost24 and to better serve you by personalizing your experience and how you connect with us.

2. HOW WE PROCESS AND HANDLE DATA

The information we collect from you depends on the nature of your relationship with us or your interaction with Outpost24’s products, services, websites and marketing events and communications. The information we collect from You (“Your Information”) may include both Personal Information and Other Information, as detailed below.

Personal Information. “Personal Information” follows the definitions under applicable law and includes “Personal Data », such as contact and business information (such as name, title, email address), account information, license information, payment information, information from third parties, social media data and any other unique identifying information.

Other Information. For the purposes of this Privacy Policy, “Other Information” is any information that does not independently reveal your specific identity or does not directly relate to an identifiable individual. Examples include an IP address, browser type, browser language, browsing data, device information, time and date of requests, login activity and cookies. Gathering this information helps us to ensure that our websites and other services work correctly and support our visitor and customer analysis.

Cookies and Similar Technologies. As further described in our cookie policy in Website Terms of Use, cookies are small data files containing information that is sent to us from your computer browser or mobile device. We use cookies and similar technologies (such as web beacons, device identifiers, pixels and ad tags) to recognize you and track your activity across different Outpost24 services and devices. We use cookies to collect information about the way that visitors use Outpost24 Sites (websites, customer and partner portals and product accounts), to support the features and functionality of those Sites, and to personalize your experience when you use them. We use pixel tags and cookies so that we can determine interest in particular topics on our Site and improve the effectiveness of our communications.

You can control cookies and other technologies in your browser settings. You can also disable or block the use of cookies and similar technologies that track your behaviour on the websites of others for third party advertising. In some instances, we may combine Other Information with Personal Information, such as deriving geographical location from your IP address and combining website browsing data about your usage of the Outpost24 services with your name. If we combine Other Information with Personal Information, we will treat the combined information as Personal Information.

You are not required to share the Personal Information that we request. However, if you choose not to share such information, in some cases we might not be able to provide you with the Outpost24 services, allow you to access certain specialized features of the Outpost24 services or be able to effectively respond to any queries you may have.

Outpost24 will never collect more of your Personal Information than is necessary for the intended purpose of processing that information. Some of the uses of Personal Information listed in sections 2, 3 and 4 may not be mandatory and can be controlled by you.

Please see the Your Privacy Rights section below to learn more about how you can control the information Outpost24 processes about you.

3. OUTPOST24 WEBSITES

Outpost24 maintains control of the data provided to, collected by or for, or processed in connection to the Outpost24 Sites, as defined in the Terms. We gather information about visitors to both our password-protected websites and our various publicly accessible websites, including the Outpost24.com website, various Outpost24 blogs, event pages and other websites where this Privacy Policy is posted.

Details of the information we collect through our Sites, and how we process it, are below:

Information you provide to us. We may collect identifiers and Personal Information about you, for example, when you request a free trial or demo or contact us via our Sites, through our websites, online forms, online chat and Email. When you communicate with Outpost24, we will store all communications we receive unless otherwise requested by you. If you are submitting information on behalf of another individual, you are responsible for obtaining appropriate consent, including consent to share and transfer any Personal Information across borders.

Information we collect automatically. We may collect internet or other electronic network activity, geolocation data and draw inferences based on the information collected to personalize your experience with the Sites.

Log data. As with most internet technology services, our servers automatically collect information when you access or use our Sites and record it in log files. This log may include IP address, usage data, browser type, the date and time the Site was accessed, and language preferences cookies (if enabled).

Device Information. Outpost24 collects data about devices accessing the Sites, which may include the type of device, device settings, application IDs, and unique identifiers. Whether we collect any or all of this information will depend on the type of device used and how it has been configured by you.

Location Information. We receive data from you and other third parties that helps us to track an approximate device location. We may use, for example, an IP address detected by your browser or device to determine device location. We may also collect information from devices in accordance with the consent process provided by your device.

Third Parties. We use and permit select third parties to use automatic data collection tools to collect information using website tracking technologies such as cookies, web beacons, embedded URS, pixels, widgets, buttons or other similar technologies. These can be disabled by you. How we use that data. We may use the information collected for the following purposes:

  • To improve the operation of the Sites
  • To engage in research and development of the Sites and Outpost24’s product offerings
  • To conduct ordinary business operations such as sales, marketing, support, education and training
  • To engage in corporate reporting and management
  • To recruit employees for Outpost24
  • To conduct market research
  • To maintain a safe and trusted environment for Outpost24 employees, customers, Site visitors and members of the public
  • To conduct other similar uses pertaining to the Outpost24 Sites.

How we share that data. We may share the information collected for the following purposes:

Sharing with Outpost24 Affiliates. We may share your information with our Outpost24 entities worldwide for the purposes described in this Privacy Policy. As part of our company, our Outpost24 entities are subject to this Privacy Policy, and our internal privacy policies and data protection requirements are regularly communicated to all of our employees as part of our mandatory compliance training.

Sharing with third party service providers. We retain third party service providers (such as web development agency) to manage or support certain aspects of our business. These third party service providers may be located globally and may provide services to us such as website hosting, data analysis, advertising and marketing services, data hosting, live-chat and helpdesk services, providing information technology infrastructure, customer service, email delivery, credit card processing, auditing and other similar services. Our third party service providers are contractually bound to safeguard any Personal Information they receive from us and they are prohibited from using such Personal Information for any purpose other than to perform the services as instructed by Outpost24. Sharing with ad technology providers. We may provide information we collect to ad technology providers so that they may recognize your devices and deliver interest-based content to you.

Engaging in corporate transactions. Circumstances may arise where we may buy or sell assets or businesses as part of a sale, merger or change in control of Outpost24. In such transactions, we may disclose or transfer your information, in accordance with this Privacy Policy, to prospective or actual purchasers or receive your information from sellers. Any entity which buys us or part of our business will have the right to continue to use the information we have collected and stored, but only in the manner set out in this Privacy Policy.

Complying with law / protecting legal rights. We may be required to disclose your information to comply with applicable laws (including laws outside of your country of residence), regulations, court orders, government and law enforcement requests, including national security or other law enforcement requirements. This includes exchanging information with companies and organizations for the purposes of fraud detection.

4. MARKETING ACTIVITIES

Outpost24 maintains control of the data provided to, or collected by or for, or processed in connection with certain marketing activities, such as email communications, webinars, conferences and events. We and our third party service providers may collect information in the following ways:

Details of the information we collect through our marketing activities, and how we process it, are below:

Information you provide to us. In addition to information submitted to Outpost24 through our Sites, for example when you register for a webinar, subscribe to our email newsletter or download content (such as Outpost24 whitepapers), we may also collect information from you offline, such as when you attend our events in person or during phone calls with sales representatives. This may include identifiers and contact information, Personal Information, professional or employment-related information, internet or other electronic network activity information, and any inferences which may be drawn from the above information.

Information we acquire from a third party. To enhance Outpost24’s ability to provide relevant marketing, offers, and services to you, we may receive information about you from third parties, such as public databases, partners, lead generation services, and social media platforms. We also collect information from other sources to help us correct or supplement our records such as customer enrichment services. In each instance we will only accept information from third parties where those third parties can demonstrate they have received all necessary consents to share such information with us.

How we use that data. We may use information that is collected through our marketing activities in the same way we use information collected through our Sites, as well as for the following purposes:

  • To verify your identity if required (for example, for payment of a product license)
  • To tailor marketing to your interests, or to recommend products and services that may be of interest to you
  • To contact you with business, marketing and sales communications that you have agreed to receive such as newsletters, announcements, and special offers
  • To contact you to notify you of upcoming events that you have registered for (via email, text message or other communication channel where you have agreed to receive notifications)
  • To update and improve Outpost24 services and product offerings
  • To engage in corporate reporting and management
  • To conduct market research
  • To conduct other similar uses pertaining to the Outpost24’s Marketing Activities

How we share that data. We may share information that is collected through our marketing activities in the same way we share information collected through our Sites, as well as for the following purposes:

Communicating with you regarding an Outpost24 Event. We or our partners may communicate with you about events hosted or co-sponsored by Outpost24 or one or more of our partners. These communications may include information about the event’s content, logistics, payment, updates, or requests for additional information related to your event registration. After the event, Outpost24 may contact you about the event and our related products and services and may share information about your attendance with other third parties. Outpost24 may also share your information with designated event sponsors or partners who may then send you communications related to your event attendance.

5. OUR CUSTOMER RELATIONSHIPS

Outpost24 provides direct training and technical support through our existing customer relationships, as well as educational and marketing services to certain partners and prospective customers through secure, password-protected portals. In these relationships, where the data is still controlled by you (the customer, partner, prospective customer), Outpost24 is a processor. Outpost24 collects, processes and stores information throughout these processes, as follows:

What data we collect and how we collect it. Information customers and certain users provide directly through password protected portals. We collect data as registration details from you when an account is set up. We will collect anonymous aggregated data that you share with Outpost24 in the product, as based on your organization’s configuration of the Outpost24 product. We also collect data through customer and product support portals when a helpdesk ticket is submitted. As part of the product support process, customers must consent to the processing and transfer by our support team of the data they submit, including any of the customer’s end user data they may submit in the support process. This may include identifiers and contact information, Personal Information, professional or employment-related information, internet or other electronic network activity information, commercial information and any inferences drawn from the above information. Information collected automatically. We may automatically collect information through our services in the same way we automatically collect information through our Sites.

Anonymized, aggregated data. In addition to the information you provide to us and which we collect automatically, Outpost24 also collects anonymous and aggregated information about how Outpost24’s services are used, to better design and operate our Sites. As part of our operations we might also anonymize or pseudonymize your information for regulatory compliance, market analysis and other Outpost24 business purposes.

How we use that data. Outpost24 collects and uses customer information as necessary for the adequate performance of the contract between you as a customer and Outpost24, and in accordance with any instructions received and the applicable contract terms. We use customer, partner and prospective customer information collected through our password-protected portals in a number of ways.

Using account generated data. Outpost24 will use account generated data in furtherance of our legitimate interests in operating the Outpost24 Sites. We may use information that is collected through our customer relationships in the same way we use information collected through our Sites and Marketing Activities, as well as for the following purposes:

  • To verify your identity if required (for example, for security reasons to gain access to an account)
  • To prevent fraudulent activities, such as fraudulent purchases
  • To monitor use of the product to ensure compliance with Outpost24’s Terms of Use
  • To provide customer support services, problem solution support and enhancing your customer experience – we use the data (which can include communications with Outpost24 employees through our Customer Success team) to investigate, respond to and resolve complaints and service issues
  • To monitor license compliance
  • To provide transaction support, including fulfillment of purchased licenses and to communicate with you about those requests
  • To provide notification of bug fixes and security patches
  • To personalize service offerings and advertise to you any products which may be relevant and of interest
  • To review and respond to queries or feedback that you may provide to us · To monitor calls for training and providing support purposes
  • To conduct other similar uses pertaining to our relationships with Outpost24’s customers.

We do not share information that is collected through our customer relationships in any way with external third parties.

6. PROCESSING YOUR PERSONAL INFORMATION

We will only collect and process your Personal Information in the ways described in this Privacy Policy when we have a legal basis and a legitimate purpose to do so. In accordance with applicable laws, Outpost24 relies on the following reasons for processing Personal Information: Consent (where you have freely given and explicit consent). We process certain Personal Information based on the consent you provided when you submitted your information. Where we rely on your consent, you have the right to withdraw or decline your consent at any time by opting out as in section 9.

Contract (where processing is necessary for the performance of a contract with you, i.e. to deliver the Outpost24 product or services you or your organization have purchased). When information is processed under contract, you are able to terminate the contract within notice period and request that information be returned to you and/or deleted.

Legitimate interests of Outpost24 or any third parties. Legitimate interests include enabling us to conduct internal business services, such as audits, mergers and acquisitions, reporting, and improving our products and services. Personal Information will only be processed on these grounds when doing so does not outweigh your rights.

Compliance with laws. If we ask you to provide Personal Information to comply with a legal requirement or to perform a contract with you, we will make this clear at the relevant time and advise you whether the provision of your Personal Information is mandatory or not (as well as the possible consequences if you do not provide your information).

7. HOW WE KEEP YOUR INFORMATION SECURE

We have implemented and maintain technical, administrative and physical security measures designed to protect Your Information from unauthorized access, disclosure, misuse, alteration, accidental loss or destruction. To demonstrate our commitment to protecting Your Information.

We regularly review our security procedures to maintain the confidentiality, integrity, availability and resilience of all data both online and offline. These security procedures and measures vary based on the sensitivity of the information that we collect, process and store and the current state of technology but include firewalls, data encryption, physical access controls and information access authorization controls. We take steps to regularly monitor our systems for vulnerabilities and to ensure that we only share information with those who need to know it.

However, no website or internet transmission is completely secure. While we strive to protect your data, we cannot guarantee that unauthorized access, hacking, data loss or a data breach will never occur, and we cannot warrant the security of any information that you provide to us. You are responsible for securing and maintaining the privacy of any password(s) and account registration information uses with Outpost24 and verifying that the information we maintain about you is accurate and current.

We require that our third party service providers and partners agree to keep the information we share with them confidential and to use the information only to perform their obligations in the agreements we have in place with them. Outpost24 has implemented internal policies to ensure that such parties are required under contract to maintain privacy and security protections which are at least as consistent with our own policies and practices.

8. STORAGE AND RETENTION OF YOUR INFORMATION

Outpost24 is a global company and your information is stored within EEA/EU and the locations of the servers of the companies we hire to provide services to us based on contractual requirements. We will retain your Personal Information for the length of time needed to fulfill the purposes outlined in this Privacy Policy unless a longer retention period is required or permitted by law, or unless the information is deleted pursuant to the exercise of your rights. We may also retain cached or archived copies of information provided to us. The deletion of your Personal Information and other use of our Sites may result in the deletion and/or de-identification of Other Information that is retained by us.

9. YOUR PRIVACY RIGHTS

We provide you the ability to exercise certain controls and choices regarding our collection, use and sharing of your information. Your choices. In accordance with applicable law, you may be entitled to exercise your rights to rectify and choices as follows:

Account settings. You may update your profile, your account and any related information at any time to ensure that information is up-to-date or delete inaccuracies.

Devices and browsers. Some of our mobile services use your device’s location information. You can adjust the setting of your mobile device at any time to control whether your device communicates this location information.

Communications from Outpost24. We may use your information to communicate with you by email, including sending you transactional, or marketing emails. Outpost24 enables you to opt out of marketing communications. Some common such as communications related to product download, sales transactions, software updates and other support-related information, patches and fixes, security alerts, events for which you have registered, disclosures to comply with legal requirements, and (where permitted by law) quality assurance surveys. Such transactional emails are not subject to general opt-out. You can tell us to stop sending you marketing emails by clicking the unsubscribe link at the bottom of every Outpost24’s marketing emails to update your preferences. If you have any issues unsubscribing, you may contact us directly on marketing@outpost24.com

Cookies. Some web browsers (including mobile web browsers) provide settings that allow you to control or reject cookies or to alert you when a cookie is placed on your computer, tablet or mobile device. Although you are not required to accept cookies, if you block or reject them, you may not have access to all features or functionalities available through our services.

10. UPDATES AND HOW TO CONTACT US

Updates to this privacy statement. From time to time, we may change this Privacy Policy to accommodate new technologies, industry practices, regulatory requirements or to reflect any changes in how we process information. Any changes to this Privacy Policy will be effective when we post the revised Privacy Policy on this website. The Effective Date at the top of this Privacy Policy states when this Privacy Policy came into effect and serves as notice of any updates. Your use of the Outpost24 Site or Content provided following these changes means you accept the revised Privacy Policy.

Contact us. If you believe your Personal Information has been used in a way that is not consistent with this Privacy Policy or your specified preferences, or if you have further questions related to this Privacy Policy or Outpost24’s Privacy Shield certification, we encourage you to please contact our Legal Team at the address below or by emailing: legal@outpost24.com

Written inquiries may be addressed to our General Counsel at:

Outpost24 AB
Blekingegatan 1,
371 57 Karlskrona
Sweden