Privacy Policy
Dated May 13th, 2026
Privacy Policy
- Policy Statement
- Scope
- Reason for Policy
- Data PrivacyFramework (DPF) Compliance
- Procedures
- Collection and User of Personal Data
- Disclosure of Personal Data
- Your Choices
- Tracking Technologies and Cookies
- Retention of Your Personal Data
- International Transfers and Onward Transfers
- Security of Personal Data
- Security Measures
- Rights
- U.S State Privacy Rights
- Complaints and Recourse
- Children's Privacy
- Links to Other Websites
- Changes to this Privacy Policy
- Definitions
Policy Statement
Team Cymru, Inc. (“Team Cymru”, “we”, “us”) providesthis Privacy Policy to describehow we collect, use, disclose,and otherwise process personal data in connection with our commercialofferings and services.
Scope
This policyapplies to the users of Team Cymru's website, services, and business operations.
Reason for Policy
This policyis provided in accordance with the EU-U.S.Data Privacy Framework Principles, including the Notice Principle, and applicable U.S. stateprivacy laws.
We act as a data controller when we determinethe purposes and means of processing personaldata in connection with our services, websites, and businessoperations. In certain cases, we act as a service provider or processor onbehalf of our customers, in which case we process personal data in accordancewith contractual obligations.
ThisPolicy describes:
- the categories of personaldata we collect
- the purposes for which we usepersonal data
- the categories of thirdparties to whom personal data is disclosed
- the rights available toindividuals and how to exercise them
- our commitments under theData Privacy Framework
Data Privacy Framework (DPF) Compliance
TeamCymru complies with and has certified to the U.S. Department of Commerce thatit adheres to the EU-U.S. Data Privacy Framework Principles and the UK Extension to the EU-U.S.Data Privacy Frameworkwith respect to personal data received from the European Union, theUnited Kingdom, and Gibraltar.
Inaccordance with the DPF Principles, Team Cymru provides notice of:
- the categories of personaldata collected
- the purposes of processing
- the types of third parties towhom personal data is disclosed
- the rights available toindividuals, including access and choice
- the availability ofindependent recourse mechanisms
- our liability for onwardtransfers to third parties
If there is any conflict betweenthe terms in this privacypolicy and the EU-U.S. DPF Principles, the principles shall govern.To learn more about the Data Privacy Framework (DPF) program, and to view ourcertification, please visit https://www. dataprivacyframework.gov/.To view the DPF List, please visit the Data PrivacyFramework List here.
Procedures
Collection and User of Personal Data
We collect personal data from the following sources:
- directly from users and customers
- automatically through use ofour services (including logs, telemetry, and network data)
- from customers or partners providingdata in connection with our services
We collect the following categories of personal data:
- Identifiers: name, email address, account credentials
- Commercial information:billing data, transaction records
- Internet or network activity:IP addresses, device identifiers, usage logs, telemetry data
- Professional information:business contact details
- Authentication data: login records and access metadata
We use personal data for the following purposes:
- to provide, operate, andmaintain our services
- to authenticate users andmanage accounts
- to detect, analyze, andcorrelate cybersecurity threats
- to monitor security, preventfraud, and maintain platform integrity
- to improve and develop our services
- to comply with legal andregulatory obligations
- to market to customers andpotential customers
Disclosure of Personal Data
We disclosepersonal data to the following categories of third parties:
- Service providers andprocessors that perform services on our behalf
- Customers, where required todeliver our cybersecurity services
- Affiliates within ourcorporate group
- Legal, regulatory, and lawenforcement authorities, where required by law
- Professional advisors (e.g.,auditors, legal counsel)
We require third parties acting as our agents to process personaldata only for specified purposesand in accordance withcontractual safeguards consistent with the Data Privacy Framework Principles.
Your Choices
Where requiredby the Data Privacy Framework Principles, individuals have the right to:
- opt out of the disclosure oftheir personal data to third parties that are not acting as our agents
- opt out of the use of their personaldata for purposesthat are materially different from those for which it was originallycollected
Where we process sensitive personal data, we obtain opt-inconsent where required. To exercise these choices,individuals may contact us at support@cymru.com.
Tracking Technologies and Cookies
We use cookiesand similar trackingtechnologies to track activity on Team Cymru'sservices and store certain information. Tracking technologies used include beacons,tags, and scriptsto collect and track information, all of which help us analyzeand improve our service.
Retention of Your Personal Data
We retainpersonal data for as long as necessary to fulfil the purposes described in thispolicy, including:
- providing services andmaintaining customer relationships
- complying with legal andregulatory obligations
- resolving disputes andenforcing agreements
- maintaining security andpreventing fraud
Retention periodsare determined basedon the nature of the data, the purposes of processing, contractual requirements, and applicable legal obligations.
International Transfers and Onward Transfers
Personal data may be processed in the United States and other jurisdictions where Team Cymru or its service providers operate.
For personaldata received under the Data Privacy Framework, Team Cymru complieswith the DPF Principles for onwardtransfers. Where we transfer personal data to third-party agents, we:
- transfer data only forlimited and specified purposes
- ensure the recipient isobligated to provide at least the same level of protection as required by theDPF Principles
- take reasonable steps toensure effective processing consistent with those obligations
TeamCymru remains responsible and liable under the DPF Principles for onwardtransfers to third-parties.
Security of Personal Data
Team Cymru implements administrative, technical, and organizational measuresdesigned to protectpersonal data against unauthorized access,disclosure, alteration, and destruction. Thesemeasures are alignedwith ISO/IEC 27001and include encryption,access controls, monitoring, and incident response processes.
Security Measures
TeamCymru maintains ISO/IEC 27001-aligned controls, including encryption,multi-factor authentication (MFA), network segmentation, monitoring, incident response, and secure softwaredevelopment life cycle(SSDLC) processes. Team Cymru’s breach notification and response actions coincide with Team Cymru's ownIncident Response Policy, as well as applicable laws and customer agreements.In the event of a security incident involving personal data, Team Cymru willrespond and provide notifications, where required, in accordance withapplicable law and customer agreements.
TeamCymru shall maintain administrative, physical, and technical safeguards toensure the integrity, confidentiality, and security of client data. These safeguards shall be appropriate to the nature of the services and the volume of data processedand are specifically designed to prevent security incidents, protect againstreasonably foreseeable threats, as well as maintain compliance with relevantdata protection regulations.
Rights
In compliance with the EU-U.S.DPF and the UK Extensionto the EU-U.S. DPF, Team Cymru commitsto resolve DPF Principles-related complaints aboutour collection and use of your personal information.
- Access: Individuals have the right to access their personal data and to limitits use and disclosure.
- Inquiries: Individuals may contact Team Cymru at support@cymru.com with any inquiries or complaints aboutits own privacy practicesor compliance with the Data Privacy FrameworkPrinciples. Team Cymru will respondto an individual’s complaintwithin no more than 45 days of receiving that complaint.
- Enforcement: The FederalTrade Commission has jurisdiction over Team Cymru’scompliance with the EU-U.S.DPF and the UK Extension to the EU-U.S. DPF.
- Arbitration: Under certainconditions, more fullydescribed on the DataPrivacy Framework website, you may invoke binding arbitration when otherdispute resolution procedures have been exhausted.
- Data Correction: Individuals may contact support@cymru.com regarding whether and how they can accessand correct their Personal Information.
U.S State Privacy Rights
Residents of California, Colorado, Connecticut, Virginia, and Utah mayhave the following rights, subject to applicable law:
- the right to access personal data
- the right to correctinaccurate personal data
- the right to delete personal data
- the right to obtain a copy ofpersonal data (data portability)
- the right to opt out of the sale of personaldata, sharing for targeted advertising, or profiling in furtherance of decisions that produce legal orsimilarly significant effects
Toexercise these rights, individuals may contact us at support@cymru.com
We will verify requestsand respond in accordance with applicable law. Individuals may designate an authorized agent tosubmit requests on their behalf where permitted.
Whererequired, individuals may appeal our decision by contacting us using the same details.
Complaints and Recourse
In compliance with the EU-U.S.Data Privacy Frameworkand the UK Extension, Team Cymru commitsto resolve complaints about our collection and use ofpersonal data.
Individualsmay contact us at support@cymru.com. We willrespond within 45 days.
Ifa complaint cannot be resolved directly, Team Cymru has designated JAMS as anindependent dispute resolution provider. This serviceis provided at no cost to the individual. More information is available at https://www.jamsadr.com
TeamCymru is subject to the investigatory and enforcement powers of the U.S.Federal Trade Commission.
Undercertain conditions, individuals may invoke bindingarbitration as described in AnnexI of the Data Privacy Framework
Children's Privacy
OurService is not intended for, nor directly addresses anyone under the age of 16.We do not knowingly collect personally identifiable information from anyone under the age of 16. If You are a parent or guardianand You are aware that Your child has provided Us with Personal Data,please contact Us. If We become aware that We have collected Personal Data fromanyone under the age of 16 withoutverification of parentalconsent, We take steps to permanently remove that information.
If We need to rely on consent as a legal basis for processing Your information and Your countryrequires consent from aparent, We may require Your parent's consent before We collect and use thatinformation.
California residentsunder 16 years of age may have additional rights regarding the collection and sale of their personal information. Please see YourState Privacy Rights for more information.
Links to Other Websites
Our Servicemay contain links to other websites that are not operated by Us. If You click on a third-party link, You will bedirected to that third party's site. We strongly advise You to review thePrivacy Policy of every site You visit.
We have no controlover and assume no responsibility for the content,privacy policies or practices of any third-party sites or services.
Changes to this Privacy Policy
We may updateOur Privacy Policy from time to time.
You are advised to review this Privacy Policy periodically for any changes.Changes to this Privacy Policy are effectivewhen they are posted on this page.
Definitions
- Account: A unique accountcreated to access our Services or parts of our Services
- Commercial Offerings: Thoseproducts and services listed within Team Cymru’s ISO27001 ISMS Scope document
- Cookies: Small files that are placed on a computer, mobile device, or any other device by a website,containing details of your browsing history on that website among itsmany uses
- DPF Principles: The collective set of principles (Notice, Choice, Accountability for Onward Transfer, etc.) defined by the Data Privacy Framework
- Personal Data:information that identifies, relates to, describes, or can reasonably be linked to an identified or identifiable individual.
- Services: Team Cymru'scommercial offering websites
- Service Provider/Processor: an entity thatprocesses personal data on behalf of Team Cymru for business purposes
- Sell/Share: as defined underapplicable U.S state privacy law