Last modified: Sept 10, 2019
“Data Processor” means a third party that processes Personal Information on behalf of and pursuant to the instructions of AlienVault.
“Personal Information” means any information relating to an identified individual, or to an individual who can be identified, directly or indirectly, by reference to such information, which may include, an identification number or one or more factors specific to his or her physical, physiological, mental, economic, cultural or social identity. Without limiting the foregoing, Personal Information does not include information that is de-identified or corporate information that relates to an organization but not to an individual, such as a corporate name, corporate address or general corporate phone number.
INFORMATION WE COLLECT FROM OR ABOUT YOU
Personal information you provide to us. We collect Personal Information that you provide to us through our Sites, and in connection with other business dealings we, or our channel sales and business partners, may have with you. Such information may include:
- First and last name
- Company name
- Email address
- IP address
- Login user name and password
- Mailing address
- Telephone number
- Fax number
- Personal preferences regarding products and services
- Information necessary to process a credit card transaction, such as the credit card type, number, and expiration date.
Information we receive from third party sources. Some third parties such as our business partners and service providers provide us with Personal Information about you, such as the following:
- Account information for third party services. If you interact with a third party service when using our Sites, such as if you use a third party service to log-in to our Sites (e.g., Facebook Connect, Google Sign-In, or Twitter OAuth), or if you share content from our Sites through a third party social media service, the third party service will send us information about you, such as information from your public profile, if the third party service and your account settings allow such sharing. The information we receive will depend on the policies and your account settings with the third-party service.
- Information from our advertising partners. We receive information about you from some of our service providers who assist us with marketing or promotional services related to how you interact with our websites, applications, products, services, advertisements, or communications:
- Job Title/Function
- Business Address
- Topics of interest
- Firmographic information (company size by employees or approximate revenue band)
- Role in purchase decisions
Information we automatically collect when you use Open Threat Exchange (OTX). Some Personal Information is automatically collected when you use the OTX Portal and/or the OTX Endpoint Threat Hunter, such as the following:
- Computer name
- External IP
- OS type
- OS version
- Endpoint Scans collect additional data:
- File path
- IP address (source and destination)
- Ports (source and destination)
- Command line of running processes
- Process IDs
- Process working directories
- File hashes of files on your system (SHA-1, SHA-256, MD5)
Website usage information we collect. In addition to Personal Information that you choose to submit to us, whenever you visit or interact with our Sites, we may collect or store information about your interaction with our Sites (“Usage Information”). This Usage Information may include:
- your IP address or any other unique identifier assigned to the device that you use to access our Sites;
- the functionality and characteristics of your device, including type of browser, operating system and hardware, mobile network information, and in some cases location information;
- the URL that referred you to our Sites, if any;
- your activities on our Sites, such as which web pages you visit, what terms you searched within our Sites, and which links within our Sites that you click on; and
- the time of day that you visited our Sites and how long your visit lasted.
We use certain common methods and technologies to collect and store Usage Information about your interaction with our Sites (“Analytic Technologies”). These Analytic Technologies may be downloaded to the personal computer, laptop, tablet, mobile phone, or similar device that you use to access the Sites (“Your Device”). The specific Analytic Technologies that we use are as follows:
- Do Not Track Policy. Your browser may offer you a “Do Not Track” option, which allows you to signal to operators of websites and web applications and services (including behavioral advertising services) that you do not wish such operators to track certain of your online activities over time and across different websites. Our Sites do not support Do Not Track requests at this time.
- Web Beacons. A web beacon, including tracking pixels, is a small graphic image or other web programming code, also known as “1×1 GIF” or “clear GIF.” We may download web beacons to Your Device when you access our Sites or through email messages that we send to you. Web beacons are used to improve your experience on our Sites. Web beacons also help us to understand whether users read email messages and click on the links contained within those messages so that we can deliver relevant content and messages. Our web beacons may collect certain of your contact information (e.g., the email address associated with an email message that contains a web beacon).
- Embedded Scripts. An embedded script is a programming code that is designed to collect information about your interactions with our Sites, such as which links within our Sites you click on, which type of browser or device you use (e.g. mobile or desktop version). We use such information to enhance the user experience. This code is downloaded onto Your Device when you access our Sites and is deactivated or deleted when you leave our Sites. Identification of the user does not take place.
HOW WE USE YOUR INFORMATION
Business Use. We use your Personal Information primarily to facilitate our ongoing and proposed business dealings with you (“Business Use”). This includes to: (1) process business transactions with us that you initiate, including without limitation orders of products and services and the creation of user profiles, for example in our AlienVault OTX, USM Anywhere, and USM Central services; (2) establish and maintain customer accounts so that we may provide products or services of ours requested by you or your company; (3) register you as a user of these products or services so that you may access them through our Sites or otherwise; (4) communicate with you about updates, maintenance, outages, or other technical matters concerning these products or services; (5) provide you with training and support regarding usage of these products or services; (6) notify you about changes to any of the policies and procedures for use of these products or services; (7) verify the accuracy of account and technical contact information we have on file for you and your company in relation to these products or services; and (8) respond to questions or inquiries that you or your company may have about our products or services. We also may use your Personal Information as required for us to comply with laws and regulations relating to the products or services that we provide in any of the jurisdictions in which we or our affiliated companies operate, including the United States, and we may use Usage Information internally within AlienVault to help us improve our products or services, or to develop new products or services.
We may also use your Personal Information to personalize the content of the Sites and communications based on your preferences, and to comply with our legal or contractual obligations and to resolve disputes. Additionally, we may use your Personal Information to protect against or deter fraudulent, illegal, or harmful actions and to enforce our MSA or EULA (depending on which service you are using).
Marketing Purposes. With your consent or as otherwise permitted by applicable law, we may use your Personal Information for purposes relating to the marketing of our content, products, and services, or those of our business partners (“Marketing Purposes”). This includes to: (1) send you newsletters, press releases, event announcements, and other similar communications regarding the products or services that we offer; (2) market or promote our products or services to you, including by offering you trial or limited access to certain of our products or services; (3) solicit input from you regarding improvement of our products or services; (4) inform you of third-party offerings that we think you or your company may be interested in which relate to our products or services; (5) send you announcements or requests on behalf of other customers of ours who believe you would benefit from use of our products or services; and (6) other purposes that we disclose to you at the time we obtain your consent.
Referrals. From time to time, we may receive Personal Information about you from third parties who recommend or suggest that we contact you for business purposes. We receive such Personal Information because you have consented towards the third party that they might share your Personal Information. If we use that information to contact you, it will only be to see if you are interested in our products or services, or those of our business partners. We will not use this information for other purposes without your consent. In addition, if you inform us that you are not interested in these products or services, we will stop using the information to contact you.
Data Integrity. You are responsible for the accuracy of all Personal Information that you provide to us. We will use reasonable efforts to maintain the accuracy and integrity of your Personal Information, and to update that information as appropriate. We will take reasonable steps to ensure that the Personal Information we collect from you is relevant to its intended use, and that it is used only in ways that are compatible with the purposes for which it was collected or otherwise authorized by you.
WITH WHOM WE MAY SHARE INFORMATION
Outside of AlienVault. We may share your Personal Information with “Data Processors” as described below, and with other third parties for purposes disclosed to you at the time you provided the information, or as subsequently authorized by you. From time to time, we also may offer you the option of sharing your Personal Information with third parties in order to receive information and/or marketing offers from them or other persons. If you consent to the sharing of your Personal Information for these purposes, it will be subject to the privacy policies and business practices of those third parties. If you later decide that you no longer want us to share Personal Information with such third parties, please contact us as indicated below under the section CHOICE AND UPDATING YOUR INFORMATION AND PREFERENCES (see below). We will process your request in a reasonable period of time. Note, however, that if you no longer wish to receive communications from a third party which has already received your Personal Information from us, you will need to contact that third party directly to inform them of this.
Partners. We may also share your contact information with the following partners so that we can better serve you:
- Distributors and resellers. If you are in a location where we primarily sell our products and services through a distributor or reseller, we may pass your contact information on to such distributor or reseller so that they can contact you directly about your interest in AlienVault’s products and services.
- Managed Service Providers. We may share your contact information with third parties that provide an offering or service that runs the AlienVault product for you. If that managed service provider is also an AlienVault reseller or distributor, you may purchase the AlienVault product directly through them.
- Implementation Partners. We may share your contact information with partners who can help you with implementation and integration of AlienVault into your environment.
- Training Delivery Partners. We may share your contact information with partners that we work with to deliver training for AlienVault products in certain locations, so that such partner can facilitate the delivery of the training directly to you.
Site Hosting. Our Sites and the servers on which they are hosted are operated in various countries around the world in which we conduct our business. Thus, your Personal Information associated with our Sites may be transferred to and/or processed in a country other than that from which it was collected. The data protection laws in those countries may differ from those of the country in which you are located. The servers may be operated by third party hosted service providers.
Links to Other Websites and Applications. The Sites may contain various links to, as well as plug-ins or widgets from, social media and other third-party websites or applications, which may provide additional information, goods, services, and/or promotions. These third-party websites or applications are owned and operated independently of AlienVault, and may have their own separate privacy and data collection practices. We are not responsible for the privacy practices of any third party; therefore, you should review their privacy policies and practices prior to interacting with their websites or applications, using any of their tools, or sharing any of your Personal Information with them.
Community Forums. Our Sites may offer message boards, chat rooms, blogs, and other public areas, as well as the Open Threat Exchange (OTX) Portal (“Community Forums”) where you can interact with our employees, other customers, post images, data, requests, questions, comments, suggestions, or other content, including your Personal Information (“User Submissions”). To participate in Community Forums, you may be asked to select a user name and password and/or provide us with your email-address, and to agree to the terms of participation for those Community Forums. We use this information to identify you and to contact you, if needed, for the provision of those Community Forums. You are able to change your email preferences or discontinue your participation in the Community Forums at any time. Your password and your email-address will not be visible to other users or shared with third parties. You should be aware that any User Submissions you post to a Community Forum, as well as your user name, may be viewed by other members of that forum. If you choose to voluntarily post User Submissions to a Community Forum, be aware that such information is viewable by anyone else on that Community Forum. Think carefully before you post and use caution before disclosing any Personal Information in a Community Forum. We are not responsible for the accuracy, use, or misuse of any User Submission that you disclose or receive through a Community Forum. We might also delete User Submissions without further notice if they include harmful or inappropriate content (e.g., pornographic material, content encouraging vandalism, crime, terrorism, racism, violence, or cruelty), or infringe any third party’s rights or applicable law.
Promotions. We may offer various promotions (“Promotions”) through the Sites or elsewhere that may require registration with your Personal Information. If you choose to enter or otherwise participate in a Promotion, your Personal Information may be disclosed to third parties in connection with administration of the Promotion, such as in connection with winner selection, prize fulfillment, and as otherwise required by law. By entering into a Promotion, you are agreeing to the official rules that govern that Promotion, which may contain specific requirements of you, including, except where prohibited by law, allowing the sponsor and/or other parties to use your name, voice, and/or likeness in advertising or marketing materials. These rules will be displayed to you during the registration process, and you will be asked for your consent to the respective data processing at that time.
CHOICE AND UPDATING YOUR INFORMATION AND PREFERENCES
We reserve the right to take reasonable steps to authenticate the identity of any individual seeking access to Personal Information. We may provide web pages or other mechanisms on our Sites through which you can update subscription preferences. You can also contact us to update your Personal Information or change your preferences. Our contact information for these purposes is by email at [email protected]. If you receive a marketing communication from us by email, you may also opt out of receiving future email marketing communications by following the opt-out instructions provided in that email. Please note that we reserve the right to send you certain communications relating to transactions you initiate, your customer account, your use of our Sites, or other business matters, and that these communications may be unaffected if you choose to opt-out from marketing communications.
In accordance with our routine record keeping and applicable law, we may delete certain records that contain your Personal Information. We are under no obligation to store such information indefinitely, and we disclaim any liability arising out of, or related to, the destruction of that information. In addition, you should be aware that it is not always possible to completely remove or delete all of your information from our databases without some residual data because of backups and other reasons. Also, if you have posted any User Submissions to a Community Forum, these communications cannot generally be removed.
Under California Civil Code Sections 1798.83-1798.84, California residents are entitled to contact us to prevent disclosure of Personal Information to third parties for such third parties’ direct marketing purposes; in order to submit such a request, please contact us at [email protected].
We will take reasonable precautions to protect your Personal Information in our possession from loss, misuse, and unauthorized access, disclosure, alteration or destruction. We will make reasonable efforts to keep your Personal Information reliable for its intended use, accurate, current and complete. As necessary, we will take additional precautions regarding the security of particularly sensitive information, such as credit card information. While we strive to secure your Personal Information, we cannot warrant or guarantee that this information will be protected under all circumstances, including those beyond our reasonable control.
The Sites are intended for business use. We do not knowingly collect or solicit Personal Information from anyone under the age of 16. If you are under 16, please do not attempt to register for the Sites or send any Personal Information about yourself to us. If we learn that we have collected Personal Information from a child under age 16, we will delete that information as quickly as possible. If you believe that a child under 16 may have provided us Personal Information, please contact us at [email protected].
EUROPEAN DATA SUBJECTS: PRIVACY SHIELD AND EU GENERAL DATA PROTECTION REGULATION (GDPR)
You have the right to exercise choice (opt-out) from our disclosure of Personal Data to a third party. (Please see the section on WITH WHOM WE MAY SHARE INFORMATION above for details of such disclosures.) If consent has been given, you also have the right to opt out of the use of your EU Personal Data for direct marketing purposes. To exercise these rights, please send us an email at [email protected] or follow the instructions in any direct marketing message you may have received (e.g., click the provided opt-out link in the email message).
Please contact us as specified below if you have any questions, need access to your EU Personal Data, or otherwise need assistance. We remain responsible for our collection, use, and disclosure of EU Personal Data in accordance with the Privacy Shield. We also are responsible for third party agents that are processing such data on our behalf, unless we prove that we are not responsible for the event giving rise to the damage. In certain situations, we may be required to disclose EU Personal Data in response to lawful requests by public authorities, including meeting national security or law enforcement requirements.
If you are an EU data subject with an unresolved complaint or dispute arising under the requirements of the Privacy Shield, we agree to refer your complaint under the Privacy Shield to an independent dispute resolution mechanism. That independent dispute resolution mechanism is the International Centre for Dispute Resolution, the international division of the U.S.-based American Arbitration Association. For more information and to file a complaint, you may contact the International Centre for Dispute Resolution by phone at +1.212.484.4181, or by visiting the website http://go.adr.org/privacyshield.html. We are also subject to the investigatory and enforcement powers of the Federal Trade Commission with respect to the Privacy Shield. In addition, under certain conditions, more fully described on the Privacy Shield website at https://www.privacyshield.gov/article?id=How-to-Submit-a-Complaint, EU data subjects may invoke binding arbitration before the Privacy Shield Panel jointly created by the U.S. Department of Commerce and the European Commission.
Please contact us at [email protected] if you have any questions, wish to exercise your rights of access, or to request the correction, amendment, removal, and/or limitation of the use and disclosure of your EU Personal Data or seek other assistance as described above.
GDPR. For this GDPR section, we use the terms “Personal Data” and “processing” as they are defined in the GDPR, but “Personal Data” means information that can be used to individually identify a person, and “processing” generally covers actions that can be performed in connection with data such as collection, use, storage and disclosure. AlienVault is the controller of your Personal Data processed in connection with the Sites. Note that we may also process Personal Data of our customers’ end users or employees in connection with our provision of services to customers, in which case we are the processor of Personal Data. If we are the processor of your Personal Data (i.e., not the controller), please contact the controller party in the first instance to address your rights with respect to such data.