Privacy Policy
Cymulate Ltd. (“Cymulate” or “We”) is committed to maintaining the privacy of its users (“you” or “user”). The following information describes how Cymulate collects and processes information about you when you use our website: www.cymulate.com and/or www.cybersecurityvalidation.com (the “Website”) and Services (as described below).
Our Privacy Policy explains:
- What information we collect and why we collect it.
- How we use that information.
- How we secure your information.
- Your rights with regard to the collection of such information.
By using our Website and Services, you agree to this Privacy Policy.
General
Cymulate provides a SaaS-based breach and attack simulation platform (the “Platform”) which assist the optimization of the security posture of its clients (“Services”). Cymulate’s website provides information on the Platform and Services and enables it users to register to a live demo, request a private demo, start a free-trial, purchase the Platform, become Cymulate’s partner, receive threat alerts, join the e-Cademy, apply for a job, join our blog, and contact us with respect to the Services.
Collecting Information
Please note that the scope of this Privacy Policy is limited only to information collected by Cymulate through your use of its Website and Services. Some information may be automatically collected, and some is collected when you interact with our Website and Services. The type of information that may be automatically collected is non-personal information, which includes your session durations, the content you accessed on the Website and Services, the frequency and scope of your use of the Website and Services and information about your computer and internet connection including the operating system you use and browser type.
Information from which you can be personally identified may also be collected, including but not limited to your name, email address, phone number, country of residence, job title, resume, cover letter, and the location of the computer through which you used the Website or Services (hereinafter: “Personal Information”). Personal Information shall be collected only if received voluntarily from you, including, without limitation, via the following ways:
a. Free-Trial
If you wish to join a free trial of our Platform, we will collect your full name, and your business email address.
b. Private Demo
If you wish to schedule a private demo, we will collect your full name, business email, and your country of residence.
c. Threat Alerts
If you wish to sign up for our threat alerts and get info and remediation guidance on new threats, we will collect your full name, email address, and country and state of residence.
d. Blog
If you wish to subscribe to our blog, we will collect your full name, email address, and your country of residence.
e. Become a Partner
If you wish to become a partner and join our network of partners, we will collect your full name, email address, company name, and your country of residence.
f. Job Application
If you wish to apply for a job at Cymulate, we will collect your full name, email address, phone number, resume/CV, cover letter, LinkedIn profile information, and your associated website.
g. e-Cademy
If you wish to apply for a free course on managing security posture within a company, we will collect your full name, company name, job title, business email address, and your country of residence.
h. Chat
If you wish to contact us via the Website, you will be able to do so via an online chat bot. We will collect the information transmitted via the online chat bot to assure sufficient assistance regarding the Services.
i. Contacting Us
If you wish to contact us for support regarding our Services, Platform, Website, this Privacy Policy or any other matter, we will collect your full name, business email address, country of residence, and the content you submitted to facilitate your inquiry.
Use of Information
We use the Personal Information we collect from you for a range of different business purposes according to different legal bases of processing. We may use or process your Personal Information for the following purposes. One or more purposes may apply simultaneously.
a. Providing the Requested Servicesmation
- We collect your Personal Information such as your full name, and your business email address to provide you with a free trial to explore our Platform.
- We collect your Personal Information such as your full name, business email, and your country of residence, in order to schedule your private demo of the Platform.
- We collect your Personal Information such as your full name, email address, and country and state of residence, in order to provide you with info and remediation guidance on new threats.
- We collect your Personal Information such as your full name, email address, and your country of residence, in order to enable you to subscribe to our blog and staying up to date with the latest cybersecurity news and insights.
- We collect your Personal Information such as your full name, email address, company name, and your country of residence, in order to facilitate your application on becoming a Cymulate’s partner and provide you with additional details on our partner program.
- We collect your Personal Information such as your full name, email address, phone number, resume/CV, cover letter, LinkedIn profile information, and your website, in order to facilitate your job application.
- We collect your Personal Information such as your full name, company name, job title, business email address, and your country of residence, in order to facilitate your application to join the eCademy, and provide you with additional details on the free course we offer.
- We collect your Personal Information such as the information transmitted via the online chat bot to assure sufficient assistance regarding the Services.
- We collect your Personal Information such as your full name, business email address, country of residence, and the content you submitted to facilitate your inquiry when you choose to contact us via the designated form.
- Such collection of information will enable us to provide you with technical and professional assistance, with regard to the Website and Services you are provided with or wish to be provided with.
We process the Personal Information where it is necessary for the adequate performance of the contract regarding the requested Services.
b. Improvement and Development of the Services
- We collect Personal Information to improve and develop our Services and understand feedback on Cymulate’s Website and Services to help provide more information on the use of our Services quickly and easily.
- We collect Personal Information for ongoing review and improvement of the information provided on our Website to ensure it is user friendly.
- We collect Personal Information to improve the management and administration of our business and maintain compliancy with our internal policies and procedures.
- We conduct surveys and research, test features in development, and analyze the information we have to evaluate and improve our Website and Services, develop new features, and conduct audits and troubleshooting activities.
- We process this information in light of our legitimate interest in improving the Website and Services to allow our users to have the best experience.
c. Maintain a Safe and Secure Environment We may use your information to detect and prevent fraud, abuse and security incidents in the following ways;
- Verify and authenticate your identity and prevent unauthorized or illegal activity;
- Enhance the safety and security of our Website and Services;
- Conduct security investigations and risk assessments;
- Prevent or take action against activities that are, or may be, in breach of our terms of service or applicable law.
We process this information in light of our legitimate interest in improving our Website and Services by enabling our users to browse in a secure environment.
d. Personalize Content, Advertising and Marketing
- If you have used Cymulate’s Services in the past, we have a legitimate business interest for matching the data we collect with other data we had already collected.
- This enables us to understand your needs and interests, optimize the content we send you and make it more suitable and relevant to your needs.
- This also enables us to improve your experience on the Website and Services by providing you with personalized content, recommendations, and features.
We process this information in light of our legitimate interest to personalize your experience on the Website and Services and customize our content.
Disclosure of Information and Transfer of Data
Except as otherwise provided in this Privacy Policy, we reasonably attempt to ensure that we never intentionally disclose any of your Personal Information, to any third party without having received your permission, except as provided for herein or otherwise as permitted or required under law.
In order to perform our contractual and other legal responsibilities or purposes, we may, from time to time, need to share your Personal Information with third parties.
We will share your Personal Information without limitation with:
a. AWS marketplace, when you choose to buy one of the available packages we offer, all in accordance with AWS marketplace privacy policy and terms of use.
b. BrightTalk, when you choose to register to a webinar presented by one of our experts, all in accordance with BrightTalk’s privacy policy and terms of use.
c. Cisoexecnet, when you choose to join one of the roundtables we host, all in accordance with Cisoexecnet’s privacy policy and terms of use.
d. LinkedIn, when you choose to apply to one of our open job positions with your LinkedIn profile, all in accordance with LinkedIn’s privacy policy and terms of use.
We may as well share your Personal Information with our affiliates, subsidiaries or any third party service providers and individuals to facilitate our Services or any portion thereof, such as marketing, data management or maintenance services. We may also share your information with analytics service providers for analytics services. Such analytics service providers set their own cookies or other identifiers on your computer, through which they can collect information about your usage of our Website and Services. This helps us compile aggregated statistics about the effectiveness of our Website and Services.
The above mentioned third parties may be located in countries other than your own, and we may send them information we receive. When such third party service providers process your Personal Information on our behalf, we will assure that they comply with obligations similar to those which are set forth in this Privacy Policy. We will also assure that they will abide by our data privacy and security requirements, and will be allowed to use the Personal Information solely for the purposes we set. We will transfer your Personal Information while using appropriate and suitable safeguards, while using a variety of legal mechanisms, including contracts, to ensure your rights and protections travel with your data.
We may also transfer your information, including Personal Information, in connection with a corporate merger, consolidation, the sale of related assets or corporate division or other fundamental corporate changes. Furthermore, information about you may also be released in order to comply with any valid legal obligation or inquiry or process such as a search warrant, subpoena, statute or court order. We will also release specific information in special cases, such as if you use the Website or Services to perform an unlawful act or omission or take any act or omission that may damage Cymulate, its property and goodwill, or if there is an attempted breach of the security of the Website or Services or a physical or property threat to you or others. With respect to our data protection practices, you have the right to file a complaint to any relevant supervisory data protection authority.
Your Rights
You have the right at any time to request to access or modify your information. To exercise these options, please contact us at [email protected].
In some jurisdictions, in particular those located within the European Union (the “EU”) or within the European Economic Area (the “EEA”), you may be afforded specific rights regarding your Personal Information. Subject to such eligibility, you may have the following rights to:
- Request a rectification of your Personal Information where the information we hold about you is incorrect or incomplete.
- Object to the processing of your Personal Information for direct marketing purposes.
- Object to the processing of your Personal Information where our legal basis for that processing is that such processing is necessary for our legitimate interests.
- Object to an automated decision-making (including profiling) in certain circumstances.
- Request the erasure of your Personal Information in certain circumstances, such as where processing is no longer necessary for the purpose it was originally collected for, and there is no compelling reason for us to continue to process or store it;
- Receive your Personal Information, or ask us to transfer it to another organization that you have provided to us, which we process by automated means, where our processing is either based on your consent or is necessary for the performance of a contract with you.
Generally, with regard to information collected on our Website and Services, Cymulate is a “Data Controller”. Therefore, if you wish to exercise the above mentioned rights, please contact us, and we will make our best efforts to fulfill your request.
With respect to our Platform, Cymulate is considered a “Data Processor”, so in such case, if you wish to exercise the above mentioned rights, please contact the applicable “Data Controller” who we provide our Services to.
If you wish to file a request regarding any of the above, you may contact us at: [email protected].
Cookies
We may use “cookies” and/or other technologies or files (collectively, “cookies”) to identify how visitors make use of our Website and Services. This aggregated tracking information may be used to help us improve and enhance the Website and Services experience for all of our users. In addition, cookies are used for adjusting the Website and Services to your personal preferences, as well as personalizing advertisement that are suitable to your interests and needs. Cookies contain information such as the pages you visited, the length of time you stayed on the Website and Services, the location from which you accessed the Website and Services and more. If you would prefer not to have cookies stored on your computer, you may modify your browser settings to reject most cookies, or manually remove cookies that have been placed on your computer. However, by rejecting the cookies, you may be unable to fully access the offerings on this Website and Services. To find out more about cookies, visit www.allaboutcookies.org, or our Cookie Policy https://cymulate.com/cookie-policy/.
Opt In or Opt Out
You are always in control of your data, and if you choose to receive information from us, or others, you can change your mind later. If, at any time, you would like to stop receiving such information or opt out of a feature, you may notify us by writing to [email protected]. You should be aware, however, that it is not always possible to completely remove or modify information in our databases and servers, although we will always make reasonable efforts to do so upon your request.
Links to Other Websites
This Website may provide links to other websites. Please be aware that these other websites are not covered by our Privacy Policy. This Privacy Policy does not cover the information practices exercised by other providers of products or services, advertisers or other websites, companies or individuals, which are not owned or controlled by Cymulate. We suggest that when linking to another website, you always read that website’s privacy policy before volunteering any personally identifiable information.
Data Security
We deploy industry standard measures to ensure the security, confidentiality, integrity and availability of the Personal Information we process. We maintain physical, technical and administrative safeguards, and test and update these periodically. We endeavor to restrict access to Personal Information on a ‘need to know’ basis for the provision of the Website and Services to you. No such measures are perfect or impenetrable. In the event of a security breach, we will take all reasonable action to minimize any harm. Although we will do our best to protect Personal Information, we cannot guarantee the security of data transmitted to our Website and transmission is at the users own risk.
Data Retention
Generally, Cymulate does not retain information longer than necessary to provide its Services and for its reasonable business and lawful needs. If you withdraw your consent to us processing your Personal Information, we will erase your Personal Information from our systems, unless the Personal Information is required for Cymulate to establish, exercise or defend against legal claims or it is necessary for the performance of the requested Services.
Representation for data subjects in the EU
We value your privacy and your rights as a data subject and have therefore appointed Prighter Group with its local partners as our privacy representative and your point of contact.
Prighter gives you an easy way to exercise your privacy-related rights (e.g. requests to access or erase personal data). If you want to contact us via our representative Prighter or make use of your data subject rights, please visit the following website https://prighter.com/q/19173190507.
California Online Privacy Protection Act
CalOPPA requires commercial websites and online services to post a privacy policy. The law’s reach stretches well beyond California to require any person or company in the United States (and conceivably the world) that operates websites collecting Personally Identifiable Information from California consumers, to post a conspicuous privacy policy on its website stating exactly the information being collected and those individuals or companies with whom it is being shared. See more at: http://consumercal.org/california-online-privacy-protection-act-caloppa/#sthash.0FdRbT51.dpuf.
According to CalOPPA, we agree to the following:
- Once this Privacy Policy is created, we will add a link to it on the first significant page after entering our Website.
- Our Privacy Policy link includes the word ‘Privacy’ and can easily be found on the Website.
- You can request to change your Personal Information by emailing us.
California Privacy Rights
The California Consumer Privacy Act of 2018 (“CCPA”) permits users who are California residents to request to exercise certain rights. If you are a California resident, the CCPA grants you the right to request certain information about our practices with respect to your Personal Information. In particular, you can request to receive information on the following:
- The categories and specific pieces of your Personal Information that we have collected.
- The categories of sources from which we collected your Personal Information.
- The business or commercial purposes for which we collected your Personal Information.
- The categories of third parties with which we shared your Personal Information.
You can be rest assured that we do not sell your Personal Information. If you choose to exercise your rights, we will not charge you different prices or provide different quality of our Services, unless those differences are related to your provision of your Personal Information.
Please note that you must verify your identity and request before further action is taken. As a part of this process, government identification may be required. Moreover, you may designate an authorized agent to make a request on your behalf.
We endeavor to respond to a verifiable consumer request within 45 days of its receipt. If we require more time (up to 90 days), we will inform you of the reason and extension period in writing. Any disclosures we provide, will only cover the 12 month period preceding your verifiable request’s receipt. If, for some reason, we cannot reply within such time frame, our response will include an explanation for our inability to comply. If you wish to exercise your CCPA rights, please contact us at: [email protected].
We will not discriminate against you for exercising any of your CCPA rights. Unless permitted by the CCPA, we will not:
- Deny you goods or services.
- Charge you different prices or rates for goods or services, including through granting discounts or other benefits, or imposing penalties.
- Provide you with a different level or quality of goods or services.
- Suggest that you may receive a different price or rate for goods or services or a different level or quality of goods or services.
CAN SPAM Act
The CAN-SPAM Act is a Federal US law that sets the rules for commercial email, establishes requirements for commercial messages, gives recipients the right to have emails stopped from being sent to them, and spells out tough penalties for violations.
To be in accordance with CAN SPAM, we agree to the following:
- Not use false or misleading subjects or email addresses.
- Identify the commercial message sent to you as an advertisement when required.
- Include the physical address of our business or site headquarters.
- Monitor third-party email marketing services for compliance, if one is used.
- Honor opt-out/unsubscribe requests quickly.
- Allow users to unsubscribe by using the link at the bottom of each email.
If at any time you would like to unsubscribe from receiving future emails, you can email us at [email protected] and we will promptly remove you from ALL correspondence.
Children’s Privacy
The Website and Services are not intended for children under the age of 16. We do not, knowingly or intentionally, collect information about children who are under 16 years of age.
IF YOU ARE UNDER THE AGE OF 16 YOU MAY NOT USE THE WEBSITE AND SERVICES, UNLESS PARENTAL CONSENT IS PROVIDED ACCORDINGLY
Questions Regarding Our Privacy Policy
If you have any questions regarding this Privacy Policy or the practices described above, you are always welcome to contact us at [email protected].
Revisions and Modifications to our Privacy Policy
We reserve the right to revise, amend, or modify this Privacy Policy at any time. When changing the policy, we will update this posting accordingly. Please review this Privacy Policy often so that you will remain updated regarding our current policies.
Governing Law and Jurisdiction
This Privacy Policy will be governed and interpreted pursuant to the laws of the State of Israel without giving effect to its choice of law rules. You expressly agree that the exclusive jurisdiction for any claim or action arising out of or relating to this Privacy Policy shall be to the competent courts in Tel Aviv, Israel, to the exclusion of any other jurisdiction.
This page was updated on April 2022.