Closing the ITDR Gap: The Okta Breach Revisited
RevealSecurity logo

PRIVACY POLICY

    Add a header to begin generating the table of contents

    RevealSecurity Ltd, including our subsidiaries and affiliates (“RevealSecurity” or “we“) respect the privacy rights of our website users and are strongly committed to protecting them. It is important to us that you kindly carefully read this Privacy Policy.

    WHEN YOU USE THE WEBSITE, YOU ARE CONSENTING TO THE PRACTICES SET FORTH IN THIS PRIVACY POLICY.

    This Privacy Policy describes how we collect, store, use and disclose the following types of personal information. For purposes of this Privacy Policy, “personal information” means information that can be used to personally identify you, such as your name, address, telephone number, e-mail address, contact preferences, and similar information.

    You are not legally required to provide us with any personal information and may do so (or avoid doing so) at your own free will. However, if you do not provide some of the personal information requested, we may not be able to proceed with the activity for which the personal information is being requested. If you do not wish to provide us with your personal information, or to have it processed by us or by any of the entities described in this Privacy Policy, please avoid any interaction with us or any use of our services.

    1. Collection of Personal Information

    We may collect personal information that you voluntarily provide on our website (the “website”). The information may include your name, phone number, e-mail address, job title, company, and any other information you disclose to us.

    With respect to job offers advertised on the website, the information may also include your job position, address, resume, LinkedIn profile URL, cover letter, and any other information you disclose to us in this respect.

    In addition, when you visit the website, we may automatically collect, record and store information. Said information may include your IP address, cookie information, the pages that you have visited, the links that you have entered into from any pages of the website, length of visit, browser type and version, operating system and website navigation paths. Please read more in section 9 regarding cookies.

    2. How We Use Personal Information

    We may use your personal information and other information we collect in various ways including in connection with the following:
    To communicate with you, to verify your identity, to provide our services and to provide you with customer care, assistance and technical support services;

    To carry out our legal, regulatory and contractual obligations and enforce our rights arising from any contracts entered into between you and RevealSecurity;

    To examine personal data you have provided regarding an advertisement for a position in our company, so that we might consider offering you a job in this context;

    To further improve our website, services offerings, and other interactions, and to improve your user experience;

    To provide you with information by various means, including e-mail, to inform you about products and services that may be of interest to you, to send you promotional information and to manage and deliver advertisements for our products and services more effectively.

    To support and enhance our data security measures, including for the purposes of preventing and mitigating the risks of fraud, error or any illegal or prohibited activity.

    We use your IP address, inter alia, to help diagnose problems with our server and to administer the website. Your IP address is also used, inter alia, to help identify you and to gather broad demographic information about you. Your IP address may also be used to assist in the detection of fraud and we may pass this information to the applicable authority.

    Combating fraud, crime and as otherwise required or permitted by law;
    For any other purpose with your consent or as permitted by applicable law.

    We may share your personal information as described in this Privacy Policy with our service providers and suppliers to the extent necessary to carry out all the said purposes and uses. Third-party service providers and suppliers receiving personal information are authorized to use your personal information only for the purpose it was originally intended for, or as required or permitted by law.

    We may share non-personal information (e.g., anonymous, aggregated data) without restriction.

    3. Data Retention

    We retain your personal data for as long as it is reasonably necessary to provide our services; to maintain and expand our relationship and provide you with our services and offerings; to comply with our legal and contractual obligations; or to protect ourselves from any potential disputes (e.g., as required by laws applicable to log-keeping, records and bookkeeping, and in order to have proof and evidence concerning our relationship, should any legal issues arise following your discontinuance of use), all in accordance with applicable laws and regulations, and where applicable.

    Please note that except as required by applicable law or our specific agreements with you, we will not be obligated to retain your personal information for any particular period, and we are free to securely delete it or restrict access to it for any reason and at any time, with or without notice to you.

    4. Sharing of Personal Information

    RevealSecurity may engage selected third-party companies and individuals to perform services complementary to our own. Such Service Providers include hosting and server co-location services, data management SaaS services (like HubSpot), data analytics services, marketing and advertising services, data and cyber security services, fraud detection and prevention services, billing and payment processing services, web analytics, e-mail and SMS distribution and monitoring services, performance measurement, data optimization services, support and customer relation management systems, and our business, legal, financial and compliance advisors (collectively, “Service Providers“). These Service Providers may have access to your personal data, depending on each of their specific roles and purposes in facilitating, supporting and enhancing our services, and may only use it for such purposes.

    RevealSecurity may share your personal information with its affiliates (including affiliated websites under ownership or control shared by RevealSecurity) and service provider.

    RevealSecurity may share with other third parties’ information about website users, such as the fact that you use our website or other websites, and that you use the services provided on our website or other websites, but only anonymously and in aggregated form.

    RevealSecurity may also disclose your personal and other information to third parties if it believes in good faith that such disclosure is necessary: (a) to comply with the law or in response to a subpoena, court order, government request, or other legal process; (b) to produce relevant documents or information in connection with litigation, arbitration, mediation, adjudication, government or internal investigation, or other legal or administrative proceedings; (c) to protect the interests, rights, safety, or property of RevealSecurity or of others; (d) to enforce any terms of use of our website; (e) to provide you and other users of our website with the services or products requested by you or by other users, and to perform other activities related to such services and products, including billing and collection; (f) to provide you with special offers or promotions that may be of interest to your; or (g) to properly operate RevealSecurity’s system.

    RevealSecurity may share personal data internally within our group of affiliates, for the purposes described in this Privacy Policy. In addition, in the event that RevealSecurity is sold, or transferrs some of its assets to another party, including in case RevealSecurity organizes its activities or the website’s activities in another framework, and also in case it changes its legal structure, your personal information could be one of the transferred assets. If your personal information is transferred, use of your personal information will remain subject to this Privacy Policy. Your personal information may also be passed on to a successor in interest in the event of a liquidation of RevealSecurity.

    5. Data Subject Rights

    Individuals have rights concerning their personal data according to any applicable law, including the Israeli Privacy Protection Law 1981, EU General Data Protection Regulation (GDPR), or the California Consumer Privacy Act (CCPA). such rights include the right to request access, rectification or expunction of your personal data held by RevealSecurity, to restrict or object to such personal data’s processing (each to the extent available to you under the laws which apply to you). If you are a GDPR-protected individual, you also have the right to lodge a complaint with an EU supervisory authority. If you wish to exercise any of these rights, please contact us by e-mail at: privacy@reveal.security

    Please note that such rights are not absolute. There are instances where applicable law or regulatory requirements allow or require us to refuse your request. In the event that we cannot accommodate your request, we will inform you of the reasons why, subject to any legal or regulatory restrictions.

    Please also note that we may require additional information, including certain personal data, in order to authenticate and process your request. Such additional information may be then retained by us for legal purposes (e.g., as proof of the identity of the person submitting the request). We may redact from the data which we will make available to you, any personal data related to others.

    6. Communications

    RevealSecurity engages in service and promotional communications, through e-mail, phone, SMS and notifications.

    RevealSecurity may contact you with important information regarding our services. For example, we may send you notifications (through any of the means available to us) of changes or updates to our services, billing issues, payment issues, etc.

    RevealSecurity may also notify you about new features, additional offerings, events, special opportunities or any other information we think you will find valuable. We may provide such notices through any of the contact means available to us (e.g., SMS, phone, mobile or e-mail), through the Services, or through our marketing campaigns on any other sites or platforms.

    If you do not wish to receive promotional communications, you may notify RevealSecurity by sending an e-mail to: privacy@reveal.security.

    7. Location of Storage and Process of Database

    RevealSecurity may store and process personal information in cloud-based central databases at third-party providers’ location in Europe, United States and other countries. With respect to a GDPR-protected individual – any transfer of your data outside the European Economic Area shall only take place with appropriate safeguards in place, such as contractual terms in compliance with applicable data protection laws and regulations

    8. Links to Third Party Websites

    RevealSecurity may provide links to third-party websites, including social networking websites. Because we do not control third-party websites and are not responsible for any information you may provide while accessing such sites, we encourage you to read the privacy policies of those websites before providing any information to such websites

    9. Cookies

    Use of Cookies – a “cookie” is a small piece of information sent by a Web server to store in a Web browser so that it can later be read back from that browser. We may use cookies to store some personal preferences for your future visits. Cookies allow us to recognize you more quickly; therefore, your time spent on our site can be more personalized and productive. You’ll find that cookies are an industry standard and are used at most major web sites, in much the same way we use them here at our Site.

    RevealSecurity may collect and/or log your Internet Protocol address, internet domain name, the web browser and operating system used to access RevealSecurity’s website or other interactions), the files/pages visited, the time spent in each file/page, and the time and date of each visit or clickstream data.

    RevealSecurity may collect this information automatically as you browse via the use of log files and web beacons to analyze trends in the aggregate and administer the RevealSecurity Websites and Service Offerings. RevealSecurity and its partners use cookies or similar technologies to analyze trends, administer the website, track users’ movements around the website, and to gather demographic information about our user base as a whole.

    We may also use cookies and other electronic tools placed by a third-party service provider to measure the effectiveness of our advertising and other information and help us understand what product information is of most interest to our customers and what kinds of advertising offers our customers like to see.

    You can control the use of cookies at the individual browser level, but if you choose to disable cookies, it may limit your use of certain features or functions on our website or service.

    10. Security of Your Personal Information

    RevealSecurity has implemented administrative, technical, and physical measures designed to protect your personal information from accidental loss and from unauthorized access, disclosure, use, alteration, or destruction. However, no electronic data transmission or storage of information can be guaranteed to be 100% private and secure, and you understand that RevealSecurity does not ensure or warrant the privacy or security of any information we collect from or about you, and that you use the RevealSecurity websites and provide us with information at your own risk. Please also be careful to avoid “phishing” scams, where someone may send you an email that looks like it is from RevealSecurity asking for your personal information. RevealSecurity will never request your personal information through e-mail. If you have any questions about the security of your personal information, you can contact us at set forth below.

    11. Modifications to this Privacy Policy

    RevealSecurity reserves the right to change this Privacy Policy at any time by posting revisions on this page. Such changes become effective when posted. If we make material changes to this Privacy Policy, we will notify you either by prominently posting a notice of such changes prior to implementing the changes, or by directly sending you a notification. We encourage you to review this Privacy Policy frequently to be informed of how RevealSecurity is collecting, using, retaining, protecting, disclosing, and transferring your information.

    12. Contact

    If you need further assistance, or if you have any comments or questions regarding our Privacy Policy, or if you have any concerns regarding your personal data held with us, or if you wish to make a complaint about how your personal data is being processed by us, you can contact our Data Protection Officer via: E-mail address: privacy@reveal.security

    Address: 5 HaKhilazon St, Ramat Gan, Israel. 5252269

    Effective Date: 01 July, 2023