- ABOUT CYMULATE
2. You do not have to provide your personal information to us, but if you do not provide certain information we will only be able to provide limited products and services to you. Where you refuse to provide mandatory company information, we will not be able to provide you with our security assessment services.
- THE PERSONAL INFORMATION THAT WE COLLECT
2. We may collect personal data directly from you when you use our Platforms, contact us by telephone, by email or in person such as conventions, meetings etc. (see “Information Collected Using the Platforms”).
3. We may also collect personal information from third parties who you have authorised to provide your personal information to us (e.g., Cymulate partner’s, IT operators etc.).
4. We will combine the information that we collect automatically from you with any other information that we collect directly from you or about you.
5. We also collect and store certain personal information as set out below.
- INFORMATION COLLECTED USING THE PLATFORMS
1. When you register an account with us we collect – title, first name, surname, your organization name, phone number, email address, country of residence and address, preferred language, organization address and organization phone number, physical address and IP address.
- HOW WE USE PERSONAL INFORMATION?
1. We use the information provided in the following ways:
2. To fulfil our agreement with you and/or dealing with your security assessments, including processing your assessments, sending you your assessment results or other details relating to your assessments account, or contacting you if there is a problem with your assessments (for example by sending you a service message to inform you when your assessment has not been completed);
3. Personalisation of the service you receive, for example being aware of previous assessments experiences or preferences, and tailoring the way we provide our products or services to you based on your preferences and profile;
4. Interaction with you at different touch points throughout your membership (for example we may inform you that regarding new vulnerabilities and immediate threats to assess yourself);
5. To register you with our Platforms and administer our Platforms’ products or services where you have registered to receive these. You can unsubscribe from these Platforms products or services at any time (contact Cymulate Support);
6. To administer any contest, competition, prize draw or your acceptance of any other promotional offer you may enter, and notify winners, as more fully set out in the applicable terms and conditions;
7. To personalise the look and feel of our Platforms and our communications with you, so as to align with preferences you may have told us about or which we have inferred from your use of our Platforms, market research and, (where you have agreed to this) via social media and networks;
8. To answer any queries which you may send to us by email or other forms of communication, and we may keep a record of these contacts including call recordings (to the extent permitted by applicable law);
9. In order to conduct customer satisfaction surveys and improve the products and services we offer or create new products and services;
10. To meet our legal compliance obligations or for accounting or audit purposes, including the prevention of fraud for online payments and use of loyalty schemes;
11. For legal purposes, such as to respond to a valid legal subpoena or regulatory order;
12. For direct marketing purposes, as set out in detail below in the section “How do we use your personal information for marketing purposes?”; and
13. As you may authorise or consent to additionally from time to time.
- WHAT SENSITIVE PERSONAL DATA MAY WE REQUIRE OR HOLD?
1. Sensitive personal data includes data about an individual’s health and religion and other categories of personal data which are closely protected. We do not generally collect this information from you. In regards to the data we are collecting about you, see section 4 “Information Collected Using the Platforms”.
2. You agree that you have voluntarily provided that information to us and that you consent for us to use that information to provide you with these products or services.
- HOW DO WE USE YOUR PERSONAL INFORMATION FOR MARKETING PURPOSES?
1. Where you have indicated, you would like to receive updates from us:
2. We may send marketing information to you to tell you about developments in the products and services available through our Platforms and those of our carefully selected partners (provided that we will communicate these to you in conjunction with our own marketing);
3. Where we are able to determine or you have indicated to us that you would like to receive it, other entities such as Cymulate’s partners and/or other third parties may also send you marketing or updates relating to their products or services; and
4. We will use your personal preferences which you have told us about, which we have derived from Cookies and/or which we have inferred from your service usage (see Aggregate data, data analytics and social media functionality below) or market research. We will use this information to tailor the advertising and communications that you receive to be those of the most relevance and interest to you.
5. You can also unsubscribe from receiving certain electronic messages (see “Withdrawing your consent” below).
- LAWFUL BASIS
1. The lawful basis for collecting and using most of your personal data for Cymulate’s services is that it is necessary for the performance of the relevant services which you contractually enter into (see: “How we use your personal information?”). Failure to provide mandatory data fields will mean that we will not be able to provide you with the relevant services.
2. The lawful basis for sending marketing communications regarding Cymulate’s services to you, is that you have given your clear consent for your personal data to be used for that specific purpose. (see: “How do we use your personal information for marketing purposes”)
3. If you have used Cymulate’s services in the past, we have a legitimate business interest for matching the data we collect with other data we had already collected, to personalize the content we send you, to make it more suitable and relevant to your needs. (see: “How we use your personal information?”)
- TO WHOM DO WE DISCLOSE YOUR PERSONAL INFORMATION?
1. We may disclose information about you as follows:
2. Except as otherwise provided in this policy, we reasonably attempt to ensure that we never intentionally disclose any of your Personal Information, to any third party without having received your permission, except as provided for herein or otherwise as permitted or required under law. We may use third party companies and individuals or employees to facilitate services or any portion thereof, such as marketing, data management, or maintenance services and technical support.
3. We may disclose information to other entities within the Cymulate entity and partners for fulfilment of the purposes listed above;
4. We may also disclose your personal information as permitted or required by law. For example, we will disclose personal information to those governmental bodies who have authority to obtain it, in order to comply with a warrant or subpoena issued by a court of competent jurisdiction, and to comply with record production requirements;
6. To anyone to whom we transfer or may transfer our rights and duties under our agreement with you;
- WORKING WITH OTHER SERVICE PROVIDERS AND CYMULATE’S PARTNER COMPANIES
2. These service providers and partner companies may be located in your country, countries in the European Economic Area, the Americas or elsewhere in the world. Different privacy laws may apply in these countries See further detail in our “Transfer of Your Personal Information” section below.
- YOUR RIGHTS
If you are located within the European Union (the “EU”) or within the European Economic Area (the “EEA”), you are afforded specific rights regarding your personal information. Subject to eligibility, users in the EU or in the EEA have the following rights to;
- Request a rectification of your Personal Information where the information we hold about you is incorrect or incomplete,
- Object to the processing of your personal data for direct marketing purposes.
- Object to the processing of your Personal Data where our legal basis for that processing is that such processing is necessary for our legitimate interests.
- Object to an automated decision making (including profiling) in certain circumstances.
- Request the erasure of your Personal Data in certain circumstances, such as where processing is no longer necessary for the purpose it was originally collected for, and there is no compelling reason for us to continue to process or store it;
- Receive your Personal Information, or ask us to transfer it to another organization that you have provided to us which we process by automated means, where our processing is either based on your consent or is necessary for the performance of a contract with you.
If you wish to file a request regarding any of the above you may contact us at [email protected]
- WITHDRAWING YOUR CONSENT
1. You do not have to provide us with your personal information. However, if you choose not to provide certain personal information we request and/or require or consent to its use and disclosure, you will still be able to visit our Platforms but you may be unable to access certain options, products or services, and in some cases, we may not be able to provide you with complete scope of work.
2. All marketing communications we send to you will provide you with a way to withdraw your consent to future marketing. If you no longer wish to receive promotional materials you may opt-out of receiving these communications by contacting Cymulate Support or changing your account settings, this will remove you from Cymulate’s marketing lists.
3. Be aware that if you unsubscribe completely from our marketing communications we may be unable to notify you of tailored offers to meet your needs.
4. Please note that if you unsubscribe from marketing communications you will still receive operational and service messages from us regarding your account use and responses to your enquiries made to us, and that we may hold your details on a suppression list so we don’t send you marketing communications in the future.
1. We will take reasonable appropriate steps to protect the personal information you share with us. We have implemented technology and security features to safeguard the privacy of your personal information. We invest significant resources to protect your personal information, from loss, misuse, unauthorised access, modification or disclosure. However, no internet-based site can be 100% secure and we cannot be held responsible for unauthorised or unintended access that is beyond our control.
- AGGREGATE DATA, DATA ANALYTICS AND SOCIAL MEDIA FUNCTIONALITY
1. We may aggregate personal information and remove any identifying elements in order to analyse patterns and improve our marketing and promotional efforts, to analyse Platforms use, to improve our content and product offerings, and to customize our Platforms’ content, layout, products and services, and we may appoint third parties to do this on our behalf, as set out above.
2. We gather certain usage information like the number and frequency of visitors to our Platforms. This information may include which webpage you just came from, which webpage you next go to, what browser you are using, your device and your IP address. We only use such data in the aggregate. This collective data helps us to determine how much our customers use parts of our Platforms, and do research on our users’ interests, and behavior to better understand and serve you.
3. If you use buttons on our Platforms linked to social media or similar sites (for example “Like” and/or “Share” buttons), content from our Platforms may be sent back to that other website or service and, depending on your privacy settings, may be privately or publicly visible (for example to friends, followers or generally to anyone who has access to your profile page).
- COOKIES AND OTHER TRACKING TECHNOLOGIES
2. See also our section on Aggregate data, data analytics and social media functionality above.
- CORRECTION/UPDATING OF PERSONAL INFORMATION
1. If your Personal Identifiable Information changes or is inaccurate, or if you no longer desire our service, we will provide a way to correct, update or suppress your personal information provided to us. If you are concerned that any of the information we hold about you is incorrect please contact us. These rights are without prejudice to any legal rights you may have in applicable laws, including your right to object to certain processing of data.
- ACCESS TO YOUR PERSONAL INFORMATION
1. You may have the right to receive a copy of personal information we keep about you, including the sources of the data, the purposes and methods of processing, any electronic decision-making and the entities with whom we share your data. We will endeavor to provide the information you require within a reasonable time. There may be a small monetary charge for some requests, depending on the information requested, to the extent permitted by applicable law.
- TRANSFER OF YOUR PERSONAL INFORMATION
2. In the event your personal information is transferred to a foreign jurisdiction, it may be subject to the laws of that jurisdiction and we may be required to disclose it to the courts, law enforcement or governmental authorities in those jurisdictions but we will only do so where required by applicable laws.
- TECHNICAL RELATED QUERIES
1. If you experience any technical problems during your interaction with this web site, please contact Cymulate Support.
- GOVERNING LAW AND JURISDICTION
- CHILDREN’S PRIVACY
1. The Service is not intended for children under the age of 16. We do not knowingly or intentionally collect information about children who are under 16 years of age.
IF YOU ARE UNDER THE AGE OF 16 YOU MAY NOT USE THE SERVICE IN ANY WAY.