privacy

Privacy Notice

COMMITMENT WITH INTERNATIONAL PRIVACY REGULATIONS


CipherTechs, Inc complies with the EU-U.S. Privacy Shield Framework and Swiss-U.S. Privacy Shield Framework as set forth by the U.S. Department of Commerce regarding the collection, use, and retention of personal information transferred from the European Union and Switzerland to the United States.  CipherTechs, Inc has certified to the U.S. Department of Commerce that it adheres to the Privacy Shield Principles.  If there is any conflict between the terms in this privacy policy and the Privacy Shield Principles, the Privacy Shield Principles shall govern.  To learn more about the Privacy Shield program, and to view our certification, please visit https://www.privacyshield.gov/.

Our Privacy Notice was last reviewed or updated in August 2022.

This Privacy Notice describes CipherTechs policies and procedures on the collection, use and disclosure of Your information when You use a CipherTechs services and tells You about Your privacy rights and how the law protects You.

Our services do not require Your Personal data to obtain the best services possible for your organization. When needed, you agree to the collection and use of information in accordance with this Privacy Notice.

Definitions

For the purposes of this Privacy Notice:


Collecting and Using Your Personal Data

CipherTechs Services

CipherTechs services collects information from client organizations corporate environments to perform cyber security assessments, audits, testing, and security event monitoring. CipherTechs is a Data Processor, but not a data controller. No CipherTechs services requires personal information from client corporate environments in any of our services.


Personal Data

While using Our Service, We may ask You to provide Us with certain business information, which may qualify as personal information, that can be used to contact or identify You. Personally identifiable information may include, but is not limited to:


Usage Data

Usage Data is collected automatically when using the Service. Usage Data may include information such as Your Device's Internet Protocol address (e.g., IP address), browser type, browser version, the pages of our Service that You visit, the time and date of Your visit, the time spent on those pages, unique device identifiers and other diagnostic data, which may be a standard part of system and application logs.


Tracking Technologies and Cookies

We do not use Cookies or tracking technologies to track the activity on Our Service and store certain information. When You access the Service, We do not collect any personal, IP, or location information for CipherTechs processing. There is a third-party ZoomInfo that collects information for email campaigns.


Use of Your Personal Data

The Company may use Personal Data for the following purposes:

We do not sell or share Your personal information in the course of your organization’s Service.


Retention of Your Personal Data

The Company will retain Your Personal Data only for as long as is necessary for the purposes set out in this Privacy Notice. We will retain and use Your Personal Data to the extent necessary to comply with our legal obligations (for example, if we are required to retain your data to comply with applicable laws), resolve disputes, and enforce our legal agreements and policies.

The Company will also retain Usage Data for internal analysis purposes. Usage Data is generally retained for a shorter period of time, except when this data is used to strengthen the security or to improve the functionality of Our Service, or We are legally obligated to retain this data for longer time periods.


Transfer of Your Personal Data

Your information is processed at the Company's operating offices and in any other places where the parties involved in the processing are located. It means that this information may be transferred to — and maintained on — computers located outside of Your state, province, country, region or other governmental jurisdiction where the data protection laws may differ than those from Your jurisdiction.

Your consent to this Privacy Notice followed by Your submission of such information represents Your agreement to that transfer.

The Company will take all steps reasonably necessary to ensure that Your data is treated securely and in accordance with this Privacy Notice and no transfer of Your Personal Data will take place to an organization or another country or region unless there are adequate controls in place including the security of Your data and other personal information.


ACCOUNTABILITY FOR ONWARD TRANSFER

In the event we transfer Personal Data covered by this Privacy Shield Statement to a third party acting as a controller, we will do so consistent with any notice provided to Data Subjects, any consent they have given, and only if the third party has given us contractual assurances that it will (i) process the Personal Data for limited and specified purposes consistent with any consent provided by the Data Subjects, (ii) provide at least the same level of protection as is required by the Privacy Shield Principles and notify us if it makes a determination that it cannot do so; and (iii) cease processing of the Personal Data or take other reasonable and appropriate steps to remediate if it makes such a determination. If CipherTechs has knowledge that a third party acting as a controller is processing Personal Data covered by this Privacy Shield Statement in a way that is contrary to the Privacy Shield Principles, CipherTechs will take reasonable steps to prevent or stop such processing.

CipherTechs maintains liability insurance and will take lawful action toward any third-party organization which may take part in onward transfer of its employees personal information.


Disclosure of Your Personal Data

CipherTechs Disclosures

CipherTechs does not collect personal customer or consumer information. CipherTechs has controls in place to ensure business information is protected with controls and performs regular reviews and security testing of the CipherTechs global network environment. Any information collected is used for Human Capital or business processing to protect CipherTechs and customer business information. At a minimum, CipherTechs performs an annual risk assessment and assessments against General Data Protection Regulation (GDPR), Personal Information Protection and Electronic Documents Act (PIPEDA), California Consumer Privacy Act (CCPA), 201 CMR 17.00: Standards for the Protection of Personal Information of Massachusetts Residents (MA 201) requirements, and other residency locations of CipherTechs staff members and maintains a set of security and privacy controls that is reviewed and updated according to industry threats to CipherTechs’ business.

CipherTechs works with human resource related organizations to process employee data related to benefit packages and background checks.

With a formal request, CipherTechs' employees have the right to view personal identifiable information CipherTechs may store at all times working with Human Resources and the Chief Technology Officer (CTO).

Employees may opt out of personal identifiable information (i) to be disclosed to a third party or (ii) to be used for a purpose that is materially different from the purpose(s) for which it was originally collected or subsequently authorized by the individuals. Our employees are provided with clear, conspicuous, and readily available mechanisms to exercise choice.

CipherTechs only requires individuals to disclose information related to processing of payroll and benefits, as well as running background checks prior to employment.


CipherTechs, as a private organization, adheres to all investigatory and enforcement powers required of it by law, including the Federal Trade Commission (FTC).

CipherTechs employees may, under certain conditions, invoke binding arbitration, if they feel as though their personal identifiable information has been released without prior approval or cause.

CipherTechs will disclose personal information in response to lawful requests by public authorities, including to meet national security or law enforcement requirements only as required by law.

Business Transactions

If the Company is involved in a merger, acquisition or asset sale, Your Personal Data may be transferred. We will provide notice before Your Personal Data is transferred and becomes subject to a different Privacy Notice.

Law enforcement

Under certain circumstances, the Company may be required to disclose Your Personal Data if required to do so by law or in response to valid requests by public authorities (e.g. a court or a government agency).

Other legal requirements

The Company may disclose Your Personal Data in the good faith belief that such action is necessary to:


Security of Your Personal Data

The security of Your Personal Data is important to Us but remember that no method of transmission over the Internet, or method of electronic storage is 100% secure. While We strive to use commercially acceptable means to protect Your Personal Data, We cannot guarantee its absolute security.


Legal Basis for Processing Personal Data under this Privacy Notice

We may process Personal Data under the following conditions:

In any case, the Company will gladly help to clarify the specific legal basis that applies to the processing, and in particular whether the provision of Personal Data is a statutory or contractual requirement, or a requirement necessary to enter into a contract.


Your Rights under this Privacy Notice

The Company undertakes to respect the confidentiality of Your Personal Data and to guarantee You can exercise Your rights.

You have the right under this Privacy Notice, and by law, to:


Exercising of Your Data Protection Rights

You may exercise Your rights of access, rectification, cancellation and opposition by contacting Us. Please note that we may ask You to verify Your identity before responding to such requests. If You make a request, We will try our best to respond to You as soon as possible.

You have the right to complain to a Data Protection Authority about Our collection and use of Your Personal Data. For more information, if You are in the European Economic Area (EEA), please contact Your local data protection authority in the EEA.


Links to Other Websites

Our Service may contain links to other websites that are not operated by Us. If You click on a third-party link, You will be directed to that third party's site. We strongly advise You to review the Privacy Notice of every site You visit.

We have no control over and assume no responsibility for the content, privacy policies or practices of any third party sites or services.


Changes to this Privacy Notice

We may update Our Privacy Notice from time to time. We will notify You of any changes by posting the new Privacy Notice on this page.

We will let You know via email and/or a prominent notice on Our Service, prior to the change becoming effective and update the "Last updated" date at the top of this Privacy Notice.

You are advised to review this Privacy Notice periodically for any changes. Changes to this Privacy Notice are effective when they are posted on this page.

Contact Us

In compliance with the Privacy Shield Principles, CipherTechs, Inc commits to resolve complaints about our collection or use of your personal information. EU and Swiss individuals with inquiries or complaints regarding our Privacy Shield policy should first contact CipherTechs, Inc at support@ciphertechs.com.

CipherTechs, Inc has further committed to cooperate with the panel established by the EU data protection authorities (DPAs) and the Swiss Federal Data Protection and Information Commissioner (FDPIC) with regard to unresolved Privacy Shield complaints concerning human resources data transferred from the EU and Switzerland in the context of the employment relationship.