Privacy Policy
Dated May 13th, 2026
Privacy Policy
- Policy Statement
- Scope
- Reason for Policy
- Data PrivacyFramework (DPF) Compliance
- Procedures
- Collection and User of Personal Data
- Disclosure of Personal Data
- Your Choices
- Tracking Technologies and Cookies
- Retention of Your Personal Data
- International Transfers and Onward Transfers
- Security of Personal Data
- Security Measures
- Rights
- U.S State Privacy Rights
- Complaints and Recourse
- Children's Privacy
- Links to Other Websites
- Changes to this Privacy Policy
- Definitions
Policy Statement
Team Cymru, Inc. (“Team Cymru”, “we”, “us”) provides this Privacy Policy to describe how we collect, use, disclose,and otherwise process personal data in connection with our commercial offerings and services.
Scope
This policy applies to the users of Team Cymru's website, services, and business operations.
Reason for Policy
This policyis provided in accordance with the EU-U.S.Data Privacy Framework Principles, including the Notice Principle, and applicable U.S. state privacy laws.
We act as a data controller when we determine the purposes and means of processing personal data in connection with our services, websites, and business operations. In certain cases, we act as a service provider or processor onbehalf of our customers, in which case we process personal data in accordance with contractual obligations.
This Policy describes:
- the categories of personaldata we collect
- the purposes for which we use personal data
- the categories of third parties to whom personal data is disclosed
- the rights available to individuals and how to exercise them
- our commitments under the Data Privacy Framework
Data Privacy Framework (DPF) Compliance
TeamCymru complies with and has certified to the U.S. Department of Commerce that it adheres to the EU-U.S. Data Privacy Framework Principles and the UK Extension to the EU-U.S.Data Privacy Framework with respect to personal data received from the European Union, the United Kingdom, and Gibraltar.
Inaccordance with the DPF Principles, Team Cymru provides notice of:
- the categories of personal data collected
- the purposes of processing
- the types of third parties to whom personal data is disclosed
- the rights available to individuals, including access and choice
- the availability of independent recourse mechanisms
- our liability for onward transfers to third parties
If there is any conflict between the terms in this privacy policy and the EU-U.S. DPF Principles, the principles shall govern. To learn more about the Data Privacy Framework (DPF) program, and to view our certification, please visit https://www. dataprivacyframework.gov/. To view the DPF List, please visit the Data Privacy Framework List here.
Procedures
Collection and User of Personal Data
We collect personal data from the following sources:
- directly from users and customers
- automatically through use of our services (including logs, telemetry, and network data)
- from customers or partners providing data in connection with our services
We collect the following categories of personal data:
- Identifiers: name, email address, account credentials
- Commercial information:billing data, transaction records
- Internet or network activity:IP addresses, device identifiers, usage logs, telemetry data
- Professional information:business contact details
- Authentication data: login records and access metadata
We use personal data for the following purposes:
- to provide, operate, and maintain our services
- to authenticate users and manage accounts
- to detect, analyze, and correlate cybersecurity threats
- to monitor security, prevent fraud, and maintain platform integrity
- to improve and develop our services
- to comply with legal and regulatory obligations
- to market to customers and potential customers
Disclosure of Personal Data
We disclose personal data to the following categories of third parties:
- Service providers and processors that perform services on our behalf
- Customers, where required to deliver our cybersecurity services
- Affiliates within our corporate group
- Legal, regulatory, and law enforcement authorities, where required by law
- Professional advisors (e.g.,auditors, legal counsel)
We require third parties acting as our agents to process personal data only for specified purposes and in accordance with contractual safeguards consistent with the Data Privacy Framework Principles.
Your Choices
Where required by the Data Privacy Framework Principles, individuals have the right to:
- opt out of the disclosure of their personal data to third parties that are not acting as our agents
- opt out of the use of their personal data for purposes that are materially different from those for which it was originally collected
Where we process sensitive personal data, we obtain opt-inconsent where required. To exercise these choices, individuals may contact us at support@cymru.com.
Tracking Technologies and Cookies
We use cookies and similar tracking technologies to track activity on Team Cymru's services and store certain information. Tracking technologies used include beacons, tags, and scripts to collect and track information, all of which help us analyze and improve our service.
Retention of Your Personal Data
We retain personal data for as long as necessary to fulfil the purposes described in this policy, including:
- providing services and maintaining customer relationships
- complying with legal and regulatory obligations
- resolving disputes and enforcing agreements
- maintaining security and preventing fraud
Retention periods are determined based on the nature of the data, the purposes of processing, contractual requirements, and applicable legal obligations.
International Transfers and Onward Transfers
Personal data may be processed in the United States and other jurisdictions where Team Cymru or its service providers operate.
For personal data received under the Data Privacy Framework, Team Cymru complies with the DPF Principles for onward transfers. Where we transfer personal data to third-party agents, we:
- transfer data only for limited and specified purposes
- ensure the recipient is obligated to provide at least the same level of protection as required by the DPF Principles
- take reasonable steps to ensure effective processing consistent with those obligations
TeamCymru remains responsible and liable under the DPF Principles for onward transfers to third-parties.
Security of Personal Data
Team Cymru implements administrative, technical, and organizational measures designed to protect personal data against unauthorized access, disclosure, alteration, and destruction. These measures are aligned with ISO/IEC 27001 and include encryption, access controls, monitoring, and incident response processes.
Security Measures
Team Cymru maintains ISO/IEC 27001-aligned controls, including encryption, multi-factor authentication (MFA), network segmentation, monitoring, incident response, and secure software development life cycle(SSDLC) processes. Team Cymru’s breach notification and response actions coincide with Team Cymru's own Incident Response Policy, as well as applicable laws and customer agreements. In the event of a security incident involving personal data, Team Cymru will respond and provide notifications, where required, in accordance with applicable law and customer agreements.
Team Cymru shall maintain administrative, physical, and technical safeguards to ensure the integrity, confidentiality, and security of client data. These safeguards shall be appropriate to the nature of the services and the volume of data processed and are specifically designed to prevent security incidents, protect against reasonably foreseeable threats, as well as maintain compliance with relevant data protection regulations.
Rights
In compliance with the EU-U.S.DPF and the UK Extensionto the EU-U.S. DPF, Team Cymru commits to resolve DPF Principles-related complaints about our collection and use of your personal information.
- Access: Individuals have the right to access their personal data and to limit its use and disclosure.
- Inquiries: Individuals may contact Team Cymru at support@cymru.com with any inquiries or complaints about its own privacy practices or compliance with the Data Privacy Framework Principles. Team Cymru will respond to an individual’s complaint within no more than 45 days of receiving that complaint.
- Enforcement: The Federal Trade Commission has jurisdiction over Team Cymru’s compliance with the EU-U.S.DPF and the UK Extension to the EU-U.S. DPF.
- Arbitration: Under certain conditions, more fully described on the Data Privacy Framework website, you may invoke binding arbitration when other dispute resolution procedures have been exhausted.
- Data Correction: Individuals may contact support@cymru.com regarding whether and how they can access and correct their Personal Information.
U.S State Privacy Rights
Residents of California, Colorado, Connecticut, Virginia, and Utah may have the following rights, subject to applicable law:
- the right to access personal data
- the right to correctin accurate personal data
- the right to delete personal data
- the right to obtain a copy of personal data (data portability)
- the right to opt out of the sale of personal data, sharing for targeted advertising, or profiling in furtherance of decisions that produce legal or similarly significant effects
To exercise these rights, individuals may contact us at support@cymru.com
We will verify requests and respond in accordance with applicable law. Individuals may designate an authorized agent to submit requests on their behalf where permitted.
Where required, individuals may appeal our decision by contacting us using the same details.
Complaints and Recourse
In compliance with the EU-U.S.Data Privacy Framework and the UK Extension, Team Cymru commits to resolve complaints about our collection and use of personal data.
Individuals may contact us at support@cymru.com. We will respond within 45 days.
If a complaint cannot be resolved directly, Team Cymru has designated JAMS as an independent dispute resolution provider. This service is provided at no cost to the individual. More information is available at https://www.jamsadr.com/dpf-dispute-resolution.
Team Cymru is subject to the investigatory and enforcement powers of the U.S.Federal Trade Commission.
Undercertain conditions, individuals may invoke binding arbitration as described in AnnexI of the Data Privacy Framework
Children's Privacy
Our Service is not intended for, nor directly addresses anyone under the age of 16. We do not knowingly collect personally identifiable information from anyone under the age of 16. If You are a parent or guardian and You are aware that Your child has provided Us with Personal Data, please contact Us. If We become aware that We have collected Personal Data from anyone under the age of 16 without verification of parental consent, We take steps to permanently remove that information.
If We need to rely on consent as a legal basis for processing Your information and Your countryrequires consent from a parent, We may require Your parent's consent before We collect and use that information.
California residents under 16 years of age may have additional rights regarding the collection and sale of their personal information. Please see YourState Privacy Rights for more information.
Links to Other Websites
Our Service may contain links to other websites that are not operated by Us. If You click on a third-party link, You will be directed to that third party's site. We strongly advise You to review the Privacy Policy of every site You visit.
We have no control over and assume no responsibility for the content, privacy policies or practices of any third-party sites or services.
Changes to this Privacy Policy
We may update Our Privacy Policy from time to time.
You are advised to review this Privacy Policy periodically for any changes. Changes to this Privacy Policy are effective when they are posted on this page.
Definitions
- Account: A unique account created to access our Services or parts of our Services
- Commercial Offerings: Those products and services listed within Team Cymru’s ISO27001 ISMS Scope document
- Cookies: Small files that are placed on a computer, mobile device, or any other device by a website, containing details of your browsing history on that website among its many uses
- DPF Principles: The collective set of principles (Notice, Choice, Accountability for Onward Transfer, etc.) defined by the Data Privacy Framework
- Personal Data: information that identifies, relates to, describes, or can reasonably be linked to an identified or identifiable individual.
- Services: Team Cymru's commercial offering websites
- Service Provider/Processor: an entity that processes personal data on behalf of Team Cymru for business purposes
- Sell/Share: as defined under applicable U.S state privacy law