Datagrasp, including its subsidiaries and affiliates (“Datagrasp,” “we,” “our,” or “us”), is committed to protecting the privacy, confidentiality, and integrity of personal information. This Privacy Policy explains how we collect, use, disclose, and safeguard personal data when you interact with our websites, platform, and related services (“Services”).
1. Scope
This Policy applies to personal information collected:
- Through Datagrasp websites linking to this Privacy Policy (“Website”);
- Through event registrations or participation at Datagrasp or partner events (“Events”);
- In connection with our hosted software applications, professional services, trainings, and certifications;
- From applicants seeking employment at Datagrasp.
2. Information We Collect
- Information you provide directly: name, company, title, email, phone, billing details, credentials, survey responses, and communications.
- Information from third parties: partner-provided registration data, analytics data, or marketing lists consistent with this Policy.
- Information collected automatically: IP address, browser type, device identifiers, location data, and pages viewed, collected through cookies or similar technologies.
Workspace records and connected sources: information may include control assessments, uploaded evidence, policies, risks, vendor records, AI prompts and responses, tabletop scenarios and session notes, and investigation outcomes. Inventory may include device names, IP and MAC addresses, serial numbers, ownership, assigned users, source observations, and change history. Authorized integrations and imports supply the records needed for the features you enable.
Security monitoring: credential exposure and domain impersonation features process findings, identifiers, technical indicators, and investigation notes. Credential Exposure Monitoring displays sanitized evidence rather than storing exposed plaintext passwords or password hashes in the client workspace.
If your employer or service provider manages your workspace, that organization determines who can access its records. Contact the workspace administrator about access to or correction of organization-controlled information; you may also contact us using the details below.
3. How We Use Information
- Provide, operate, and improve our Website and Services;
- Manage your account and registration for Events;
- Send important updates, security alerts, and administrative messages;
- Enable participation in interactive features and communications;
- Conduct analytics, benchmarking, and product research;
- Send marketing or educational materials in line with your preferences;
- Comply with legal obligations and enforce agreements.
AI-assisted features: relevant prompts and workspace context may be processed by AI service providers to generate requested summaries, recommendations, exercise content, or other outputs. The Master Subscription Agreement describes the terms for AI processing, including the commitment not to use Customer Confidential Information to train publicly available foundation models. Submit only information you are authorized to use, and review generated output before relying on it.
4. How We Share Information
Datagrasp does not sell or rent your personal information. We share information only under controlled conditions:
- With subsidiaries and affiliates for operational purposes described in this Policy;
- With service providers, contractors, and business partners under confidentiality and data-processing agreements, including hosting, payment processing, communications, analytics, and AI services as needed for the features used;
- With authorized workspace users and managed-service providers acting for your organization, and through reports, exports, or Trust Center information your organization chooses to share;
- With event sponsors if you opt in or allow badge scanning at Events;
- In connection with mergers, acquisitions, or asset transfers, under continued data protection obligations;
- To comply with legal obligations or protect rights, property, or safety;
- With your explicit consent.
5. Legal Basis (EEA/UK Visitors)
We collect and process personal data when:
- You have given consent;
- It is necessary to perform a contract with you;
- It is in our legitimate interests and not overridden by your rights;
- We are legally required to do so.
6. International Data Transfers
We store and process data in countries where we operate or have service providers. When transferring data outside the EEA or UK, we implement safeguards such as Standard Contractual Clauses (SCCs) approved by the European Commission and conduct due diligence on recipient entities.
7. Security
We employ administrative, technical, and physical safeguards to protect personal information from unauthorized access, alteration, disclosure, or destruction — including encryption, access controls, monitoring, and incident response aligned with NIST CSF 2.0 and HIPAA standards.
8. Data Retention
We retain personal data only as long as necessary for the purposes outlined in this Policy or as required by law. When no longer needed, we securely delete or anonymize the data.
Archiving an inventory item or marking a monitoring finding Mitigated, Investigated, or Addressed is a workflow action, not a deletion request. Records, source evidence, and review history remain available according to the applicable service and retention arrangements. Contact us about deletion requests and contractual retention requirements.
9. Your Rights
Depending on your jurisdiction, you may have the right to:
- Access, correct, or delete your personal data;
- Restrict or object to processing;
- Request data portability;
- Withdraw consent at any time;
- Opt out of marketing communications.
To exercise your rights, contact us at [email protected].
10. Cookies and Privacy Preferences
Use the website’s cookie controls to accept, reject, or manage non-essential categories. The footer’s Do Not Sell/Share link opens these controls. Necessary storage supports site operation; optional categories cover functional preferences, analytics, and marketing. We use Google Analytics and, when marketing consent is enabled, Mailchimp website scripts, which can contact Mailchimp and Intuit collection services. You can revisit your choices through the footer. Contact [email protected] if a browser privacy signal or saved preference is not being applied as expected.
11. Third-Party Links
Our Website may link to third-party sites. Datagrasp is not responsible for their privacy, content, or security practices. Use such links at your own discretion.
12. Children’s Privacy
Our Services are not directed to individuals under 16 years of age. If we learn that such data has been collected, it will be deleted promptly.
13. Changes to This Policy
We may update this Privacy Policy periodically. Material changes will be communicated via email or our Website. Where a change requires consent under applicable law, we will seek that consent; posting an updated policy does not replace it.
14. Contact
If you have questions or concerns about this Policy, contact us at [email protected] or write to Datagrasp, 8950 SW 74 CT, Suite 2201, Miami, FL 33156, USA.