Effective Date: March 15, 2024

To view our privacy policy prior to March 15, 2024, click here.

Welcome to our website. This Privacy Statement describes the types of information that Conceal, Inc. or its subsidiaries or affiliates (“Conceal,” “we” or “us”) collects from and about our customers and their corporate representatives (our “Customers”) on our website, www.conceal.io or (collectively, the “Site”). Our Site and the services we provide are aimed at companies and their representatives and not at individual consumers or households.

Your privacy is important to us. This Privacy Statement is for informational purposes and sets forth our policy with respect to the collection, use and disclosure of business information that we collect when engaging with prospective and existing Customers and their representatives (the “Customer Representatives” and from Customers’ employees or others who are authorized to use a Customer issued device where the Conceal product is installed (the “Device Users”) when we provide our services. By using the Site, or engaging us to provide our services, you agree to the data collection, use, disclosure and storage practices described in this Privacy Statement.

Conceal’s mission is to stop ransomware and credential theft for companies of all sizes by developing innovative solutions that provide social engineering protection in any browser ensuring data protection and employee productivity. Conceal collects identifiable information from and about Customer Representatives and employees or others who are authorized to use a Customer issued device (the “Customer Data”). When Conceal collects and uses Customer Data on behalf of its Customers in order to provide our services, Conceal is generally a processor, or “service provider” and not a controller, of that Customer Data.

Conceal does not receive consumer household information from its Customers, nor does it sell or share Customer Representative information with third parties (excluding subprocessors).

By accessing or using the Site, you consent to the information collection, disclosure and use practices described in this Privacy Statement. Certain features or services referenced in this Privacy Statement may not be offered on the Site at all times. Please also review our Terms of Service, which governs your use of the Site, and which is accessible at https://conceal.io/terms-of-service/.

Your Rights

If you are a Device User who is a resident of California, click here for additional information about our privacy practices.

Device Users from the United States, including those in Colorado, Connecticut, Virginia, and Utah, have the right to:

  • Confirm whether we process their personal information.
  • Access and delete certain personal information.
  • Data portability.
  • Opt-out of personal data processing for targeted advertising and sales
  • Correct inaccuracies in their personal information, taking into account the information’s nature processing purpose.
  • Opt-out of profiling in furtherance of decisions that produce legal or similarly significant

If you would like to exercise your rights, please contact us by email at [email protected] or phone at 706-481-2642 and provide us with your contact information. If you are a Customer Representative or Device User, you will need to contact the Customer with whom you have a relationship, who may be your employer, to exercise your rights.

If you are a Device User and would like to opt-out of Conceal processing your information on behalf of a Customer, which may include sharing your information with our subprocessors, please contact our Customer directly in order to exercise your privacy rights.

We will only use personal information provided in a verifiable opt-out request to verify the requestor’s identity or authority to make the request. Only you, or someone legally authorized to act on your behalf, may make a verifiable consumer opt-out request related to your personal information. You may also make a verifiable consumer request on behalf of your minor child.

You do not need to create an account with us to exercise your opt-out rights. We will only use and retain personal information provided in an opt-out request to review and comply with the request.

Information Collection

We collect information from Customer Representatives when they choose to provide it to us.  This may include when they create an account with us, sign up for our email lists, use our services, or otherwise contact us.

We collect personal information about Customer Representatives in a range of forms, including business information such as name, address, email address, telephone number, mobile telephone number, when they choose to provide it to us as a current or prospective Customer. Personal information means information about an individual from which that person can be identified and does not include anonymous personal information where the identity has been removed. This may include when Customer Representatives contact us with inquiries or otherwise contact us, or when we provide Device Users with access to the Site. We do not collect consumer or household personal information directly from individual consumers.

If Customers make purchases through the Site, they may provide certain payment information, such as payment card or other financial account information, and billing address. A third-party payment processor collects and processes that information directly from our Customers in order to process payments on our behalf; we do not collect or retain your payment information.

Device User Notice

As a Customer Representative, if you have device access on behalf of one of our Customers, you are considered an “Device User” under the Customer’s contract with us. We collect Device Users’ personal information on behalf of our Customers and our Customers decides how the information is collected and used, including what is shared with us for our use. Your device activities are subject to our privacy statement and terms of use, as well as the contract with our Customer. If you have questions about the collection and use of your information on a Site as part of services we provide to a Customer, please contact the Customer, who may be your employer.

On behalf of our Customers, we collect information from and about Device Users including , including your first name, last name, email address, user name, device identifiers (including employee name), internet activity information such as website URLs and domains, IP addresses and other metadata from websites, characteristics of websites and browsing activity, and general geographic location or any other information required to collect while using the services that we provide to a Customer. We may only be able to change how we share personal information of Customer Representatives in accordance with our agreement with our Customers or our Customer’s instructions. We expect our Customers to notify Device Users about the types of information we collect on our Customers’ behalf.

This Site is not intended to collect personal health information or other sensitive information about Customer Representatives or Device Users. Any such information should remain with the Customer and should be shared and used only in accordance with our contracts with our Customers and the Customer’s privacy and other policies and procedures.

If a Customer Representative provides us with the name of their company, we may use the name of the company (but not other information) on a list of current or former customers for promotional purposes.

We do not intentionally collect personally identifiable information from visitors to the Site. If you use a third party service to link to us or communicate with us (such as a social network or third party video chat), we may receive certain information about you from the third party based on your registration and privacy settings on those third party services.

Information Collected From Other Sources

We may obtain Customer Representative information from other sources, including from websites and social networks that individuals use to connect with our Customers. This information may include purchase or browsing history, anonymous identifier, demographic information, interests, and publicly-observed data, such as from social media and online activity that we may review or analyze for our internal customer acquisition or support purposes or in order to provide a service to our Customers.

Information Obtained from Third Parties

If we receive Customer Data about you from or on behalf of our Customers, we will only use that information for the specific reason for which it was provided to us.

Information We Automatically Collect and cookie policy

As is true of most web sites, we automatically gather information about your computer such as your IP address, browser type, referring/exit pages, and operating system. For information about what we collect from Device Users, please see “Device User Information” above.

We and our third party service providers, including advertisers, analytics, and third party content providers, may automatically collect certain information from you as a Site visitor or Customer Representative whenever you access or interact with the Site. This information may include, among other information:

  • the browser and operating system you are using
  • the URL or advertisement that referred you to the Site
  • the search terms you entered into a search engine that led you to the Site
  • areas within the Site that you visited, and
  • other information commonly shared when browsers communicate with websites.

When service providers receive this information, they are not permitted to use the information collected on our behalf except to help use conduct and improve our business.

We may use cookies, web beacons, pixel tags, log files, or other technologies to automatically collect certain information when you use our Site or interact with our emails and online or mobile advertisements.

For example, we may automatically collect certain non-personal information from you such as your mobile device identifier or MAC address, browser type, operating system, device model, software version, Internet Protocol (“IP”) address, mobile or ISP carrier information, and the domain name from which you accessed the Site. Some mobile service providers may also provide us or our third party service providers with information regarding the physical location of the device used to access the Site. If such information is linked to your Personal Information, we will treat it as Personal Information under this Privacy Statement.

We also may collect information about your use of the Site including the date and time you access the Site, the areas or pages of the Site that you visit, the amount of time you spend using the Site, the number of times you return, whether you open forward or click-through emails and ads, and other usage data so that we can understand the statistical use trends of our Site in order to make improvements. This information may be stored and used with your personal information attached to it.

We may also use third-party tools or services, such as Google Analytics, to assist us with analyzing and improving the Site. These service providers are not permitted to use the information collected on our behalf except to help use conduct and improve our business.

In addition, we may use a variety of other technologies that collect similar information for security and fraud detection purposes and we may use third parties to perform these services on our behalf.

Tracking Options, EEA/UK/Switzerland and California Do Not Track Disclosures. 

We strive to provide you with choices regarding the personal information you provide to us.

You may adjust your browser or operating system settings to limit this tracking or to decline cookies, but by doing so, you may not be able to use certain features on the Site or take full advantage of all of our offerings. Check the “Help” menu of your browser or operating system to learn how to adjust your tracking settings or cookie preferences. To learn more about the use of cookies or other technologies to deliver more relevant advertising and your choices about not having this information used by certain Service Providers (defined below), please click here.  On your mobile device, you can adjust your privacy and advertising settings to limit your tracking for advertising or control whether you receive more relevant advertising.  Note that our systems may not recognize Do Not Track headers or requests from some or all browsers.

You may adjust your browser or operating system settings to limit this tracking or to decline cookies, but by doing so, you may not be able to use certain features on the Site or take full advantage of all of our offerings. Check the “Help” menu of your browser or operating system to learn how to adjust your tracking settings or cookie preferences. To learn more about the use of cookies or other technologies to deliver more relevant advertising and your choices about not having this information used by certain Service Providers (defined below), please click here.

On your mobile device, you can adjust your privacy and advertising settings to limit your tracking for advertising or control whether you receive more relevant advertising. Note that our systems may not recognize Do Not Track headers or requests from some or all browsers.

Information Use

We may use the information we collect from and about Customer Representatives or Device Users on our Site to:

  • Assess the needs of your business to determine suitable products;
  • Send you requested product or service information;
  • Respond to customer service requests;
  • Send you a newsletter and marketing communications;
  • Respond to your questions and concerns;
  • Improve the content and functionality of our Website  and marketing efforts;
  • Conduct research and analysis;
  • Display content based upon your interests;
  • Comply with applicable laws, including to respond to requests from public and government authorities;
  • Enforce this Privacy Statement;
  • Protect our rights, privacy, safety or property, and/or that of you or others.
  • Develop new programs, products or services
  • Protect the security or integrity of the Services and our business; and
  • As described to you at the point of data collection or in our Agreement with our Customer.

Conceal uses Device User information that cannot be associated with an identifiable individual (“Pseudonymized Information”) in order to improve our products and services, including the machine learning tools and algorithms that support our products and services, and consequently improve the tools that help our Customers.

Information Sharing

We may share Customer Representative or Device User information with our vendors in order to provide our services to our Customers. We may also share certain Customer Data that we receive from our Customers with our Service Providers or subprocessors, such as Amazon Web Services, in order to provide our services to our Customers.

We may contract with our service providers to perform functions related to the Site and services we provide to our Customers. These service providers will have access to only that Customer Data needed to perform their business functions, but may not use or share that information for other purposes. These companies are authorized to use your personal information only as necessary to provide these services to us and/or to support the services we provide to our Customers.

We do not sell Customer Data or Device User data.

We may share the information we collect from and about Customer Representatives and Device Users:

  • with third parties that we believe may provide promotional materials, and goods and services that may be of interest to you;
  • with our Service Providers, if the disclosure will enable them to perform a business, professional or technical support function for us, including as part of our agreement with our Customers;
  • as necessary if we believe that there has been a violation of this Privacy Statement, our Terms of Use, of our rights or the rights of any third party;
  • when we believe in good faith that disclosure is necessary to protect our rights, protect your safety or the safety of others, investigate fraud, or respond to a government request;
  • to respond to judicial process or provide information to law enforcement or regulatory agencies or in connection with an investigation on matters related to public safety, national security or law enforcement, as permitted by law, or otherwise as required by law; and
  • as described to you at the point of collection or in our Agreement with a Customer.

If we are involved in a merger, acquisition, or sale of all or a portion of its assets, you will be notified via email and/or a prominent notice on our Web site of any change in ownership or uses of your personal information, as well as any choices you may have regarding your personal information.

Combination of Information

We may combine the information we receive from and about you, including information you provide to us and information we automatically collect through our Site, as well as information collected offline or from third party sources to help us tailor our communications to you and to improve our services.

We may sell or purchase assets during the normal course of our business. If another entity acquires us or any of our assets, information we have collected about Customer Representatives and Customer Data may be transferred to such entity. In addition, if any bankruptcy or reorganization proceeding is brought by or against us, such information may be considered an asset of ours and may be sold or transferred to third parties. Should such a sale or transfer occur, we will use reasonable efforts to try to require that the transferee use personal information provided through the Site in a manner that is consistent with this Privacy Statement.

If you are a Customer Representative or Device User and you do not want us to share or process your personal information as set forth in this Privacy Statement, please contact the Customer with whom you have a relationship, who may be your employer.

Visitors from the EEA,UK or Switzerland

If you are a resident of the EEA, UK or Switzerland, we are a data controller when we collect Customer Representative information and a processor when we collect Device User information.

Our legal basis for collecting and using your personal data or information is to do so with your consent, as provided to us by our Customers; in performance of a contract with our Customers or where the collection and use is in our legitimate interests and not overridden by your data protection interests or fundamental rights and freedoms. In some cases, we may also have a legal obligation to collect the personal information in question. If you are a Customer Representative, you may contact our Customers at any time to withdraw your consent to our collection and use of your personal data and to exercise the following rights to:

  • Access your personal data or information;
  • Delete, or request deletion of, your personal data or information;
  • Object to or restrict processing of your personal information;
  • Request portability of your personal information;
  • Complain to your local data protection authority at any time;
  • Object to automated decision making; and
  • Update your personal data or information.

Withdrawing your consent will not affect the lawfulness of any processing we conducted prior to your withdrawal, nor will it affect processing of your personal information conducted in reliance on lawful processing grounds other than consent.

You have the right at any time to withdraw your consent to our collection and use of your personal data and to exercise the following rights. If we are the data controller, you can contact us to exercise these rights. If we are the data processor, you must contact the controller to exercise these rights:

  • Access your personal data or information;
  • Delete, or request deletion of, your personal data or information;
  • Object to or restrict processing of your personal information;
  • Request portability of your personal information;
  • Complain to your local data protection authority at any time;
  • Object to automated decision making; and
  • Update your personal data or information

To withdraw consent or exercise these rights, please contact our Privacy Office at [email protected].

Withdrawing your consent will not affect the lawfulness of any processing we conducted prior to your withdrawal, nor will it affect processing of your personal information conducted in reliance on lawful processing grounds other than consent.

If we ask you to provide personal data to us to comply with a legal requirement or enter into a contract, we will inform you of this and let you know whether providing us with your personal data is required and if not, the consequences of not sharing your personal data with us.

Similarly, if we collect and use your personal information in reliance on our or a third party’s legitimate interests and those interests are not already listed above (see “Information Use” section), we will let you know what those legitimate interests are.

Legal Requirements

We may disclose Customer Representative or Device User information if required to do so by law or in the good faith belief that such action is necessary to (i) comply with a legal obligation, (ii) protect and defend the rights or property of Company, (iii) act in urgent circumstances to protect the personal safety of users of the Site or the public, or (iv) protect against legal liability.

Children

Protecting children’s privacy is important to us. We do not direct the Site to, nor do we knowingly collect any personal information from, children under the age of 18.

Links to Other Websites

This Privacy Statement applies only to the Site. The Site may contain links to third-party sites or applications, including social media sites, which may have privacy policies that differ from our own. We are not responsible for the practices of such sites or applications. The links to third-party sites from the Site does not imply that we endorse or have reviewed the third-party sites.

Data Security

The security of your personal information is important to us. We have taken certain physical, administrative, and technical steps to safeguard the information we collect from and about You. While we make every effort to help ensure the integrity and security of our network and systems, the transmission of information via the internet is not completely secure. E-mail sent to or from the Site may not be secure. Although we do our best to protect your personal information, we cannot guarantee the security of your personal information transmitted to our Site. Any transmission of personal information is at your own risk. We are not responsible for circumvention of any privacy settings or security measures contained on the Site.

Data Storage and Retention

Your personal information is stored on our Service Providers’ servers in the United States. You understand and agree that we may collect, use, disclose, and otherwise process the information you provide as described in this Privacy Statement even if you are from an area outside the United States. Your personal information may be disclosed in response to inquiries or requests from government authorities or to respond to judicial process in the United States. We will retain your personal information for as long as it is needed to provide you with use of the Site, or to fulfill any legal or contractual obligations we may have.

Changes to Our Privacy Statement

We reserve the right to revise this Privacy Statement at any time. When we do, we will post the changes on the Site. If we change the Privacy Statement in a material way, we will provide appropriate notice to you. Your continued use of the Site after any changes or revisions to this Privacy Statement shall indicate your agreement with the terms of such revised Privacy Statement.

Please also feel free to contact us [email protected] if you have any questions about our Privacy Statement or the information practices of the Site.

CALIFORNIA RESIDENTS – YOUR CALIFORNIA PRIVACY RIGHTS

In California, when Conceal collects and uses Customer Data or Device User data on behalf of its Customers in order to provide our services, Conceal is generally a “service provider” that processes that Customer Data on behalf of its corporate Customers.

California residents have the following rights in connection with their personal information, including business contact information:

  • The right to know:
  • the categories of personal information we’ve collected and the categories of sources from which we got the information;
  • the business purposes for sharing personal information; and
  • the categories of third parties with whom we’ve shared personal information;
  • The right to access the specific pieces of personal information we’ve collected;
  • The right to delete your information;
  • The right to opt-out of automated decision-making and the sale or sharing of your information.
  • The right to correct information;
  • The right to limit use and disclosure of sensitive information.

California residents also have the right to not be discriminated against if they choose to exercise their privacy rights.

If you are Customer Representative or Device User who is a California resident and would like to opt-out of Conceal processing your information as a service provider on behalf of a Customer, which may include sharing your information with our Service Providers or subprocessors, please contact our Customer with whom you have a relationship, who may be your employer, in order to exercise your privacy rights.

As a service provider, we have collected the following categories of consumer personal information on behalf of our Customers within the last twelve (12) months.

Sensitive personal information is a subtype of personal information consisting of specific information categories. While we collect information that falls within the sensitive personal information categories listed in the table below, the CCPA does not treat this information as sensitive because we do not collect or use it to infer characteristics about a person.

Category

 

Examples

 

Collected from our Customers to provide a service to them

 

Sold or Shared?Retention Period
A. Identifiers.A real name, alias, postal address, unique personal identifier, online identifier, Internet Protocol address, email address, account name, Social Security number, driver’s license number, passport number, or other similar identifiers.YESShared with our subprocessorsIn accordance with our  Customers’ instructions
B. Personal information categories listed in

the California Customer Records statute

(Cal. Civ. Code § 1798.80(e)).

A name, signature, Social Security number, physical characteristics or description, address, telephone number, passport number, driver’s license or state identification card number, insurance policy number, education,

employment, employment history, bank account number, credit card number, debit card number, or any other financial information, medical information, or health insurance information. Some personal information included in this category may overlap with other categories.

YES, but only a name, signature, address and telephone number.Shared with our subprocessorsIn accordance with our  Customers’ instructions
C. Protected classification characteristics

under California or federal law.

Age (40 years or older), race, color, ancestry, national origin, citizenship, religion or creed, marital status, medical condition, physical or mental disability, sex (including gender, gender identity, gender expression, pregnancy or childbirth and related medical conditions), sexual orientation, veteran or military status, genetic information (including familial genetic information).NO

 

D. Commercial information.Records of personal property, products or services purchased, obtained, or considered, or other purchasing or consuming histories or tendencies.YESShared with our subprocessorsIn accordance with our  Customers’ instructions
E. Biometric information.Genetic, physiological, behavioral, and biological characteristics, or activity patterns used to extract a template or other identifier or identifying information, such as, fingerprints, faceprints, and voiceprints, iris or retina scans, keystroke, gait, or other physical

patterns, and sleep, health, or exercise data.

NO
F. Internet or other similar network activity.Browsing history, search history, information on a consumer’s interaction with a website, application, or advertisement.YESShared with our subprocessorsIn accordance with our  Customers’ instructions
G. Geolocation data.Physical location or movements.YESShared with our subprocessorsIn accordance with our  Customers’ instructions
H. Sensory data.Audio, electronic, visual, thermal, olfactory, or similar information.NO
I. Professional or employment-related

information.

Current or past job history or performance evaluations.NO
J. Non-public education information (per the Family Educational Rights and Privacy Act (20 U.S.C. Section 1232g, 34 C.F.R. Part 99)).Education records directly related to a student maintained by an educational institution or party acting on its behalf, such as grades, transcripts, class lists, student schedules, student identification codes, student financial information, or student disciplinary records.NO
K. Inferences drawn from other personal

information.

Profile reflecting a person’s preferences, characteristics,

psychological trends, predispositions, behavior, attitudes,

intelligence, abilities, and aptitudes.

NO
Sensitive Personal Information CategoryGovernment identifiers (social security, driver’s license, state identification card, or passport number)NO
Complete account access credentials (user names, account numbers, or card numbers combined with required access/security code or password)NO
Precise geolocationYESShared with our subprocessorsIn accordance with our  Customers’ instructions
Racial or ethnic originNO
Religious or philosophical beliefsNO
Union membershipNO
Genetic dataNO
Mail, email, or text messages contents not directed to usNO
Unique identifying biometric informationNO
Health, sex life, or sexual orientation informationNO