Privacy Notice
Learn how 42 Security collects, uses, shares, and protects your personal information.
Last Updated: February 5, 2026
Introduction
This Privacy Notice explains how 42 Security (“42 Security,” “we,” or “us”) collects, uses, shares, and otherwise processes your personal information (also known as personal data) and information about your choices and privacy rights.
Privacy Notice Applicability
Some data protection laws in various jurisdictions distinguish between a ‘Data Controller’ / ‘Business’ and ‘Data Processors’ / ‘Service Providers’ of personal information. While other jurisdictions may use different terminology, for purposes of this Privacy Notice, a Data Controller / Business decides why and how to process personal information. A Data Processor / Service Provider only processes information on behalf of a Data Controller based on the Data Controller’s instructions.
This Privacy Notice applies when 42 Security is the Data Controller of your personal information (unless a different 42 Security Privacy Notice is displayed when we collect your personal information), collected through:
- Use of the 42 Security websites and applications that link to this Privacy Notice (the “Sites”);
- The usual course of business, such as in connection with our events, sales, and marketing activities (“Corporate Operations”); and
- In certain scenarios in the use of our products and services (the “Service”), as described below.
Where we provide the Service under contract with an organization (for example, your employer), that organization is the Data Controller of the information processed by the Service on their behalf or under their instruction. This Privacy Notice does not apply to the extent that we process personal information in our role as a Data Processor on behalf of such organizations.
We recommend that you read this Privacy Notice in full to ensure that you are informed.
Sites & Corporate Operations
1. Information We Collect About You
Information that we collect from or about you includes information you provide, information we collect automatically, and information we receive from other sources.
1a. Information you provide to us
When you contact us by e-mail or through a contact form on the Sites, we may collect information, such as your name, email address, phone number, postal address, job title, and company name. We may also collect other information that you provide such as your interactions with us, for example, if you request information about our Service, interact with our employees, complete a survey, provide feedback or post comments, register for an event, or take part in marketing activities.
We may keep a record of your communications with us, such as video conference and call recordings, meeting transcripts, voicemail, and other information you share during such communications.
1b. Information we collect automatically
We collect the following information automatically through our Corporate Operations:
- Date and time of the request
- Time zone difference to Greenwich Mean Time (GMT)
- Access status / HTTP status code
- Each transmitted amount of data
- The website from which the request comes
- Browser type
- Operating system and its interface
- Language and version of the browser software
- Information about your computer or device
- Information about your activities within the Sites or Corporate Operations
- City-level geolocation information (in anonymous form)
- Other statistical information relating to your use of the Sites and Corporate Operations
1c. Cookies and Online Identifiers
In addition to the information listed above, we use standard automated data collection tools like cookies (or online identifiers) to collect information about how people use our Sites. When visiting the Sites, you have the option of disabling certain types of cookies through our Cookie Consent pop-up.
Cookies are small pieces of data, stored in text files, that are stored on your computer or other device when websites are loaded in a browser. They are widely used to “remember” you and your preferences, either for a single visit (through a “session cookie”) or for multiple repeat visits (using a “persistent cookie”). They provide a consistent and efficient experience for visitors and perform essential functions such as allowing users to register and remain logged in.
Cookies may be set by the website you are visiting (known as “first party cookies”), or by third parties, for such purposes as serving content or providing advertising or analytics services on the website (“third party cookies”). Both websites and HTML emails may also contain other tracking technologies such as “web beacons” or “pixels.” These are typically small transparent images that provide us with statistics for similar purposes as cookies.
1d. Information we receive from other sources
We may obtain information about you from third party sources, including resellers, distributors, business partners, event sponsors, security and fraud detection services, social media platforms, and publicly available sources. We encourage you to read the terms of use and privacy notices of such third party services before sharing your information with them to understand how your information may be collected and used.
2. How We Use Your Information
We use your personal information to provide, maintain, improve, and update our Sites for our Corporate Operations. Our purposes for the collection of your personal information include:
- To provide, maintain, deliver, and update our Corporate Operations;
- To send you notifications about the Service, including technical notices, updates, security alerts, administrative messages, and invoices;
- For billing, payment, or account management;
- To measure your use and improve Corporate Operations, and to develop new products and services;
- To personalize your experience when using our Sites;
- To generate and analyze statistical information about how our Sites are used in the aggregate;
- To respond to your questions, comments, and requests, including to keep in contact with you regarding the products and services you use;
- To provide you with customer service and support;
- To respond to your responsible disclosure reports;
- To tailor and send you newsletters, emails, and other content to promote our Service;
- For advertising purposes;
- To contact you to conduct surveys and for market research purposes;
- To register and provide you with training and certification programs;
- To investigate security issues, prevent fraud, or combat the illegal, prohibited, or unauthorized uses of our Service;
- For other legitimate interests or lawful business purposes;
- To comply with our obligations under applicable law, legal process, or government regulation; and
- For other purposes, where you have given consent.
3. How We Share Your Information
We may share your personal information with third parties as follows:
- With our affiliates and subsidiaries for the purposes described in this Privacy Notice;
- In connection with a merger, sale, financing, or reorganization of all or part of our business;
- With our service providers who assist us in providing the Service, such as billing, payment card processing, customer support, sales and marketing, and data analysis, subject to confidentiality obligations;
- With our service providers who assist us with detecting and preventing fraud, security threats, or other prohibited, illegal or malicious behavior;
- With business partners, such as resellers, distributors, and/or referral partners;
- With event partners who are working with us to organize or sponsor an event to which you have registered;
- With marketing partners, such as advertising providers;
- Where it has been de-identified;
- When you instruct us to do so;
- Where you have consented to the sharing of your information with third parties;
- When necessary to protect the personal safety, property, or other rights of the public, 42 Security, or our customers;
- When required to protect and defend the rights or property of 42 Security or our customers; or
- When authorized by law or where necessary to comply with a legal process.
Service
We provide the Service to our customers and users (collectively, “Customers”) under an agreement with them and solely for their benefit and the benefit of personnel authorized to use the Service (“Authorized User”). As part of its normal functioning, the Service collects personal information contained in security assessment data, user information including user names, roles, email, group assignments, and configurations; and personal data contained within activity logs, audit logs, and administrator reports (“Service Information”).
42 Security processes personal information only as provided in our agreements with the relevant Customer. Customers may choose to enable integrations or exchange personal data from the Service with third-party platforms. Customer use of third-party platforms and how such providers use personal data is governed by the terms of use and privacy notices of such third-party platforms.
Notice to Users
Our Service is intended to be used by Customers. Where the Service is made available to you through a Customer (e.g., your employer), the Customer is the administrator of the Service and responsible for the accounts and/or services over which it has control. We are not responsible for the privacy or security practices of a Customer, which may be different from this Privacy Notice. Please contact the applicable Customer or refer to your organization’s policies for more information.
International Transfers
42 Security may transfer your personal information to countries other than your country of residence. Wherever we process your personal information, we take appropriate steps to ensure it is protected in accordance with this Privacy Notice and applicable data protection laws, including the General Data Protection Regulation (GDPR).
These safeguards include implementing the European Commission’s Standard Contractual Clauses for transfers of personal information from the European Economic Area or Switzerland between us and our business partners and service providers, and equivalent measures for transfers of personal information from the United Kingdom.
Your Choices and Rights
We offer you choices regarding the collection, use, and sharing of your personal information and we will respect the choices you make in accordance with applicable law. You may choose (opt-out) whether your personal information is (i) disclosed with a third party or (ii) to be used for a purpose that is materially different from the purpose(s) for which it was originally collected or subsequently authorized.
You may indicate your choice by clicking through the appropriate dialogue box to opt out or by emailing us at privacy@42security.io. Please note that if you decide not to provide us with certain personal information, you may not be able to access certain features of the 42 Security websites and applications or use our Service.
European Economic Area, UK, and Switzerland
If you are located in the European Economic Area (EEA), United Kingdom (UK), or Switzerland, you have certain rights under applicable data protection laws, including the right to:
- Access your personal data and receive a copy of it;
- Rectify inaccurate personal data;
- Request the erasure of your personal data;
- Restrict the processing of your personal data;
- Data portability;
- Object to processing of your personal data;
- Withdraw consent at any time (where processing is based on consent);
- Lodge a complaint with a supervisory authority.
To exercise these rights, please contact us at privacy@42security.io.
Opt Out of Marketing
We may periodically send you marketing communications that promote our products and services consistent with your choices. You may opt out of receiving such communications by following the unsubscribe instructions in the communication you receive. Please note that we may still send you important service-related communications regarding our products or services, such as communications about your subscription or account, service announcements, or security information.
Data Retention
We retain the personal information described in this Privacy Notice for as long as needed to fulfill the purposes for which it was collected. We may retain your personal information as needed to provide you with our Service, as may be required by law (for example to comply with applicable legal tax or accounting requirements), as necessary for other legitimate business or commercial purposes described in this Privacy Notice (for example, to resolve disputes or enforce our agreements), or as otherwise communicated to you.
We consider the following criteria when we are making decisions on how long we will retain your personal information:
- Whether the personal information is necessary to operate or provide our Service;
- How long we need to retain the personal information to comply with our legal obligations and any audit requirements;
- Our legitimate interests or legal purposes, such as improving our Service, developing new products or services, fraud prevention, record-keeping, promoting safety, security and integrity, or enforcing our legal rights; and
- Whether the personal information is typically deleted based on specific schedules, such as marketing information.
When the purpose for which your personal information was collected no longer exists and there is no business or legal reason to retain your personal information, 42 Security will securely delete your data.
Children’s Data
The Sites, Service, and our Corporate Operations are not directed to children under 18 years of age, and 42 Security does not knowingly collect personal information from children under 18. If we learn that we have collected any personal information from children under 18, we will promptly take steps to delete such information. If you are aware that a child has submitted such information, please contact us using the details provided below.
Artificial Intelligence Tools
42 Security’s commitment to transparency and responsible data handling extends to the use of Artificial Intelligence Tools (AI Tools) within our Sites, Service, and Corporate Operations. Our AI Tools may process personal information to enhance user experience, provide personalized recommendations, and improve our overall service delivery.
Any data processed by our AI Tools is treated with the utmost confidentiality, and we strictly adhere to data protection regulations. We do not make decisions based solely on automated processing, including profiling, that produce legal effects concerning you or similarly significantly affect you. When we use AI Tools at 42 Security, we do so in accordance with applicable laws.
Changes to Privacy Notice
42 Security may change this Privacy Notice from time to time. We will post any changes on this page and, if we make material changes, provide a more prominent notice (for example, by adding a statement to the website landing page, providing notice through the Service, or by emailing you). You can see the date on which the latest version of this Privacy Notice was posted above.
How To Contact Us
Please contact us at privacy@42security.io if you have any questions about our privacy practices or this Privacy Notice.
You can also write to us at:
42 Security Spain
If you interact with 42 Security through or on behalf of a Customer, then your personal information may also be subject to the applicable Customer’s privacy practices and you should direct any questions to that organization.
© 2026 42 Security