ThreatMate Privacy Policy
Version: 2.2
Effective Date: August 2026
Previous Version: 2.1 (July 2025)
Contact: privacy@threatmate.com
Document History
| Version | Date | Changes |
|---|---|---|
| 2.2 | Aug 2026 | Updated based on new features; refreshed U.S. state privacy rights coverage and added targeted-advertising opt-out and appeal rights. |
| 2.1 | 2025 | Added US State Privacy Rights section (CCPA/CPRA, VCDPA, CPA, CTDPA, UCPA, Nevada, NY, Texas, and other state laws); expanded PI categories table; added opt-out, sensitive PI, non-discrimination, and Shine the Light disclosures. |
| 2.0 | 2025 | Added EU-U.S. Data Privacy Framework (DPF) and UK Extension compliance section; expanded International Transfers; added recourse and enforcement disclosures; expanded Security, Choice, Access, and Data Integrity sections for all seven DPF Principles. |
| 1.0 | Jan 1, 2025 | Initial publication. |
Introduction
ThreatMate Inc. ("ThreatMate," "we," "us," or "our") is committed to protecting your privacy. This Privacy Policy explains how we collect, use, disclose, and safeguard personal data when you use our SaaS services and visit our website. This policy complies with the General Data Protection Regulation (GDPR), the UK Data Protection Act 2018 and UK GDPR, the California Consumer Privacy Act (CCPA/CPRA), the New York SHIELD Act, Nevada Privacy Law (NRS Chapter 603A), and other applicable privacy laws in the United States, as well as the EU-U.S. Data Privacy Framework (EU-U.S. DPF) and the UK Extension to the EU-U.S. DPF.
Advertising Pixels and Your Privacy Choices
ThreatMate's website uses the Meta (Facebook) Pixel to measure the performance of our marketing campaigns. The pixel may transmit standard event data (such as page views, button clicks, and form submissions) and limited device or browser identifiers to Meta Platforms, Inc.
For visitors that Meta geolocates to California or another covered US state (currently California, Colorado, Connecticut, Florida, Oregon, Texas, Montana, Delaware, Nebraska, New Hampshire, New Jersey, Minnesota, Maryland, and Rhode Island), ThreatMate automatically sends events with Meta's Limited Data Use (LDU) flag. LDU instructs Meta to treat the event as opted-out of cross-context behavioral advertising and custom audiences, while still allowing aggregate measurement.
ThreatMate also honors the Global Privacy Control (GPC) browser signal as a valid opt-out of sale and sharing, as required by the California Attorney General. If your browser sends GPC, LDU is applied to your visit regardless of location.
Any visitor may manually opt out at any time on our Your Privacy Choices page. To exercise other CCPA/CPRA rights, use our Privacy Rights Request form.
EU-U.S. Data Privacy Framework (DPF) Certification
ThreatMate Inc. complies with the EU-U.S. Data Privacy Framework (EU-U.S. DPF) and the UK Extension to the EU-U.S. DPF as set forth by the U.S. Department of Commerce. ThreatMate has certified to the U.S. Department of Commerce that it adheres to the EU-U.S. Data Privacy Framework Principles (EU-U.S. DPF Principles) with regard to the processing of personal data received from the European Union in reliance on the EU-U.S. DPF, and from the United Kingdom in reliance on the UK Extension to the EU-U.S. DPF. If there is any conflict between the terms in this Privacy Policy and the EU-U.S. DPF Principles, the EU-U.S. DPF Principles shall govern.
To learn more about the Data Privacy Framework program and to view ThreatMate's certification, please visit https://www.dataprivacyframework.gov.
ThreatMate is subject to the investigatory and enforcement powers of the Federal Trade Commission (FTC) with respect to its compliance with the EU-U.S. DPF Principles.
Information We Collect
We collect the following categories of personal data:
- Personal identifiers: name, email address, phone number, and mailing address
- Account information: username, account credentials, and profile data
- Billing and payment information: billing name, address, and payment method details
- Usage data: IP addresses, browser type, pages visited, and activity logs
- Device and location information: where permitted by law
- Security monitoring data (processed on behalf of MSP customers as data processor): email addresses, usernames, IP addresses, device identifiers, network access logs, authentication events, and security event logs
DPF Principle 1 — Notice
ThreatMate collects personal data directly from individuals, from its Managed Service Provider (MSP) customers in its capacity as a data processor, and through automated means (usage and activity logs). At or before the time of collection, ThreatMate provides notice of:
- The types of personal data collected
- The purposes for which personal data is collected and used
- The types of third parties to which personal data is disclosed, and the purposes for such disclosures
- The rights and choices available to individuals regarding their personal data
- How to contact ThreatMate with questions or complaints
This Privacy Policy serves as that notice. For personal data received from the EU or UK in reliance on the DPF, individuals are entitled to all rights and protections set out in the DPF Principles.
How We Use Your Information
We use personal data to:
- Provide, maintain, and improve our cybersecurity SaaS services
- Process transactions and send billing-related communications
- Respond to inquiries and provide customer support
- Perform security monitoring, vulnerability assessment, and threat intelligence services on behalf of MSP customers (as data processor)
- Analyze usage trends and improve platform performance
- Comply with legal obligations
- Protect our rights, security, and the security of our customers
DPF Principle 2 — Choice
ThreatMate offers individuals the opportunity to opt out of:
- Disclosure of personal data to third parties for purposes other than those for which it was originally collected or subsequently authorized by the individual.
- Use of personal data for a purpose materially different from the purpose for which it was originally collected or subsequently authorized.
For sensitive personal data (including health information, racial or ethnic origin, political opinions, religious or philosophical beliefs, trade union membership, genetic data, biometric data, data concerning a person's sex life or sexual orientation, or financial account information), ThreatMate will obtain affirmative express consent (opt-in) before such data is collected or used for a materially different purpose, or disclosed to a third party.
To exercise your opt-out or opt-in rights, contact us at privacy@threatmate.com or use our Privacy Request Form.
Sharing of Information
We do not sell your personal data. We may share personal data with:
- Service providers and subprocessors under contract who assist with our business operations, subject to appropriate data processing agreements.
- MSP customers in our capacity as data processor, strictly in accordance with their instructions and applicable data processing agreements.
- Government authorities if required by law, court order, or to protect our legal rights or the safety of individuals.
- Successors in the event of a merger, acquisition, or sale of assets, subject to confidentiality commitments.
Mobile information will not be shared with third parties/affiliates for marketing/promotional purposes. All the categories exclude text messaging originator opt-in data and consent; this information will not be shared with any third parties.
DPF Principle 3 — Accountability for Onward Transfer
When ThreatMate transfers personal data received under the DPF to a third party acting as an agent (processor), ThreatMate:
- Transfers such data only for limited and specified purposes consistent with the consent of the individual;
- Ascertains that the third-party agent is obligated to provide at least the same level of privacy protection as required by the DPF Principles;
- Takes reasonable and appropriate steps to ensure the agent processes personal data in a manner consistent with ThreatMate's obligations under the DPF Principles;
- Requires the agent to notify ThreatMate if it determines that it can no longer meet its obligations;
- Upon notice, takes reasonable and appropriate steps to stop and remediate unauthorized processing.
ThreatMate remains liable under the DPF Principles if its agent processes personal data in a manner inconsistent with the DPF Principles, unless ThreatMate proves it is not responsible for the event giving rise to the damage.
DPF Principle 4 — Security
ThreatMate implements appropriate technical, physical, and organizational measures to protect personal data against unauthorized access, disclosure, alteration, or destruction. These measures include, but are not limited to:
- Encryption of data in transit using TLS 1.2 or higher (TLS 1.3 preferred)
- Encryption of data at rest using AES-256
- Role-based access controls and least-privilege principles
- Multi-factor authentication for all system access
- Regular vulnerability assessments and penetration testing
- Continuous security monitoring
- SOC 2 Type II certified security controls
ThreatMate's security measures are aligned with the NIST SP 800-53 Revision 5 Moderate baseline.
DPF Principle 5 — Data Integrity and Purpose Limitation
ThreatMate limits its collection and use of personal data to information that is relevant to the purposes for which it was collected. ThreatMate takes reasonable steps to ensure personal data is reliable, accurate, complete, and current for its intended use.
ThreatMate does not process personal data in a way that is incompatible with the purposes for which it was collected or subsequently authorized by the individual. Personal data is retained only for as long as necessary to fulfill those purposes, unless a longer retention period is required or permitted by law.
Data Retention
We retain personal data for as long as necessary to fulfill the purposes outlined in this policy:
- Customer account and billing data: Duration of the service relationship plus 7 years
- Usage and activity logs: 1 year, unless required for compliance or legal purposes
- Security monitoring data (as processor): Duration of the MSP service agreement plus 90 days, unless otherwise specified in the applicable data processing agreement
- Audit logs: 7 years
Longer retention periods may apply where required by law or to protect legal rights.
DPF Principle 6 — Access
Individuals have the right to access personal data ThreatMate holds about them, subject to limited exceptions under the DPF Principles (e.g., where the burden or expense of providing access would be disproportionate to the risks to the individual's privacy, or where the rights of persons other than the individual would be violated).
To submit an access request, individuals may:
- Use our Privacy Request Form
- Email us at privacy@threatmate.com
- Write to us at: Privacy Officer, ThreatMate Inc., 5005 W Laurel St., Suite 99, Tampa, FL 33607
ThreatMate will respond to access requests within 30 days (or as required by applicable law). Where we are acting as a data processor on behalf of an MSP customer (controller), we will refer the request to that controller within 24 hours.
Your Rights
Depending on your location, you may have the following rights:
- Right to access your personal data
- Right to correct or delete inaccurate or unnecessary data
- Right to restrict or object to processing
- Right to data portability
- Right to opt-out of the sale of personal data (CCPA — note: ThreatMate does not sell personal data)
- Right to lodge a complaint with a supervisory authority (GDPR/UK GDPR)
- Right to opt-out of disclosure to third parties or use for materially different purposes (DPF)
- Right to binding arbitration under the DPF (see Recourse and Enforcement section below)
To exercise your rights, please use our Privacy Request Form or contact us at privacy@threatmate.com.
DPF Principle 7 — Recourse, Enforcement, and Liability
Independent Recourse Mechanisms
In compliance with the EU-U.S. DPF Principles, ThreatMate commits to resolve complaints about your privacy and our collection or use of your personal data. EU, EEA, and UK individuals with inquiries or complaints regarding this Privacy Policy should first contact ThreatMate at:
Privacy Officer — ThreatMate Inc.
5005 W Laurel St., Suite 99, Tampa, FL 33607
Email: privacy@threatmate.com
ThreatMate has further committed to refer unresolved privacy complaints under the DPF Principles to the following independent dispute resolution bodies:
- EU individuals: EU data protection authorities (EU DPAs), available at https://edpb.europa.eu.
- UK individuals: PrivacyTrust DPF Services, a non-profit alternative dispute resolution provider, available at https://www.privacytrust.com/dpf/.
These services are provided at no cost to the individual.
Binding Arbitration
Individuals may invoke binding arbitration for complaints regarding DPF Principles not resolved by other means, as described in Annex I of the EU-U.S. DPF Principles, available at https://www.dataprivacyframework.gov.
FTC Enforcement
ThreatMate's compliance with the EU-U.S. DPF Principles is subject to the investigatory and enforcement powers of the U.S. Federal Trade Commission.
Disclosure to Authorities
ThreatMate may be required to disclose personal data in response to lawful requests by public authorities, including to meet national security or law enforcement requirements.
International Transfers
ThreatMate processes personal data primarily within Google Cloud Platform data centers located in the United States. For personal data transferred from the European Economic Area (EEA) or the United Kingdom to the United States, ThreatMate relies on one or more of the following transfer mechanisms:
- EU-U.S. Data Privacy Framework: For transfers from the EU/EEA in reliance on ThreatMate's DPF certification.
- UK Extension to the EU-U.S. Data Privacy Framework: For transfers from the United Kingdom.
- Standard Contractual Clauses (SCCs): European Commission-approved SCCs where applicable.
- Other appropriate safeguards as permitted under applicable data protection law.
U.S. State Privacy Rights
ThreatMate complies with applicable U.S. state privacy laws, including the California Consumer Privacy Act as amended by the California Privacy Rights Act (CCPA/CPRA), the Virginia Consumer Data Protection Act (VCDPA), the Colorado Privacy Act (CPA), the Connecticut Data Privacy Act (CTDPA), the Utah Consumer Privacy Act (UCPA), the Texas Data Privacy and Security Act (TDPSA), the Oregon Consumer Privacy Act (OCPA), the Montana Consumer Data Privacy Act (MCDPA), the Delaware Personal Data Privacy Act (DPDPA), the Iowa Consumer Data Protection Act (ICDPA), the Nebraska Data Privacy Act (NEDPA), the New Hampshire Data Privacy Act (NHDPA), the Kentucky Consumer Data Protection Act (KCDPA), the New Jersey Data Privacy Act (NJDPA), the Tennessee Information Protection Act (TIPA), the Maryland Online Data Privacy Act (MODPA), the Minnesota Consumer Data Privacy Act (MCDPA), the Rhode Island Data Transparency and Privacy Protection Act (RIDTPPA), the Indiana Consumer Data Protection Act (Indiana CDPA), Nevada Privacy Law (NRS Chapter 603A), the New York SHIELD Act, and other state privacy laws as enacted.
Categories of Personal Information Collected
The following table describes the categories of personal information ThreatMate collects, the purposes for collection, and whether each category is sold or shared. ThreatMate does not sell or share any personal information.
| Category | Examples | Collected? | Sold/Shared? |
|---|---|---|---|
| Identifiers | Name, email, phone, IP address, account username | Yes | No |
| Commercial information | Billing details, payment method, transaction history | Yes | No |
| Internet/network activity | Pages visited, browser type, activity logs, usage data | Yes | No |
| Geolocation data | Approximate location derived from IP address | Yes (limited) | No |
| Professional/employment info | Job title, company name (MSP customer contacts) | Yes | No |
| Security and technical data | Device identifiers, authentication logs, network configs (as processor for MSP customers) | Yes | No |
| Inferences | Service usage patterns for platform improvement | Yes | No |
| Sensitive personal information | Financial account details (billing only); no other sensitive categories collected | Limited | No |
Sale and Sharing of Personal Information
ThreatMate does NOT sell personal information as defined under the CCPA/CPRA or any other applicable state law. ThreatMate does NOT share personal information for cross-context behavioral advertising.
Sensitive Personal Information
ThreatMate collects limited sensitive personal information (billing payment details only) solely for the purpose of processing transactions. ThreatMate does not use sensitive personal information for any purpose beyond what is necessary to provide the services. You have the right to direct ThreatMate to limit its use of sensitive personal information to purposes necessary to provide the services.
Your State Privacy Rights
Depending on your state of residence, you may have some or all of the following rights:
- Right to Know / Access: Request disclosure of the categories and specific pieces of personal information ThreatMate has collected about you.
- Right to Delete: Request deletion of personal information ThreatMate has collected about you, subject to certain exceptions.
- Right to Correct: Request correction of inaccurate personal information.
- Right to Data Portability: Receive a copy of your personal information in a portable format.
- Right to Opt-Out of Sale/Sharing: Opt out of the sale or sharing of your personal information. (Note: ThreatMate does not sell or share personal information.)
- Right to Opt-Out of Targeted Advertising: Opt out of the processing of your personal information for targeted advertising. ThreatMate does not use personal information for targeted advertising, and honors the Global Privacy Control (GPC) signal as a valid opt-out.
- Right to Appeal: Appeal ThreatMate's decision regarding a privacy rights request. To appeal, reply to our decision email or write to privacy@threatmate.com with "Privacy Appeal" in the subject line. We will respond to appeals within 60 days.
- Right to Limit Use of Sensitive PI: Direct ThreatMate to limit its use of sensitive personal information.
- Right to Non-Discrimination: Not receive discriminatory treatment for exercising your privacy rights.
- Right to Opt-Out of Profiling: Opt out of processing for the purposes of profiling in furtherance of decisions that produce legal or similarly significant effects.
These rights apply to residents of California, Virginia, Colorado, Connecticut, Utah, Texas, Oregon, Montana, Delaware, Iowa, Nebraska, New Hampshire, Kentucky, New Jersey, Tennessee, Maryland, Minnesota, Rhode Island, Indiana, and other states with enacted privacy laws. Specific rights vary by state.
How to Submit a Privacy Rights Request
To submit a verifiable consumer request or exercise any of the rights listed above:
- Privacy Request Form: Submit a request
- Email: privacy@threatmate.com (include "Privacy Rights Request" in the subject line)
- Mail: Privacy Officer, ThreatMate Inc., 5005 W Laurel St., Suite 99, Tampa, FL 33607
ThreatMate will acknowledge your request within 10 business days and respond within 45 days. If additional time is needed, ThreatMate will notify you and may extend the response period by an additional 45 days (California) or as permitted by applicable law.
ThreatMate will verify your identity before processing your request. Verification may include confirming the email address associated with your account. Authorized Agents: California residents may designate an authorized agent to submit requests on their behalf. Authorized agents must provide written authorization from the consumer and may be required to verify their own identity.
Non-Discrimination
ThreatMate will not discriminate against you for exercising any of your privacy rights. We will not deny you goods or services, charge you different prices, or provide a different level of quality because you exercised your rights under applicable state privacy laws.
Nevada Opt-Out
Nevada residents may opt out of the sale of personal information under Nevada Revised Statutes Chapter 603A. ThreatMate does not sell personal information. To confirm or submit a Nevada opt-out request, contact us at privacy@threatmate.com.
California "Shine the Light" Disclosure
California Civil Code Section 1798.83 ("Shine the Light") permits California residents to request a list of third parties to whom ThreatMate has disclosed personal information for direct marketing purposes during the preceding calendar year. ThreatMate does not disclose personal information to third parties for their own direct marketing purposes. To make a Shine the Light inquiry, contact privacy@threatmate.com.
Notice to MSP End-Users
If you are an employee or end-user of an organization that uses ThreatMate's services through a Managed Service Provider, ThreatMate processes your personal data as a data processor on behalf of that MSP or their customer (the data controller). To exercise your privacy rights with respect to that data, please contact the MSP or their customer directly. ThreatMate will assist the controller in responding to your request as required by applicable law.
ThreatMate Discovery Browser Extension
ThreatMate Discovery is deployed by IT service providers on organization-managed devices to inventory the AI and SaaS applications in use.
What the extension collects
When a browser visits an application on ThreatMate's curated tool list (for example, an AI assistant such as ChatGPT), the extension records the tool's name, the day, a daily visit count, and daily active minutes (time the tool's tab was focused while the user was active). These daily totals, together with the extension version and an organization identifier configured by the IT service provider, are reported through the ThreatMate agent installed on the device to ThreatMate's service, where they are visible to the device's organization and its IT service provider.
What the extension does not collect
- Browsing history (pages not on the tool list are never examined, stored, or transmitted)
- Page content, prompts, conversations, or keystrokes
- Full URLs, page titles, or search terms
- Files or their contents
- Browser credentials or identity
Individual visit timestamps do not leave the browser — only daily totals are transmitted.
Transparency
The extension's options page shows the signed-in user everything it has recorded on that device.
Use and retention
Data is used solely to provide software-usage visibility and security governance to the device's organization. It is not sold, not used for advertising, and not shared beyond the organization, its IT service provider, and ThreatMate acting as their processor. The extension retains at most 30 days of local totals; server-side retention follows the organization's ThreatMate agreement.
Contact
For questions about the Discovery extension, contact privacy@threatmate.com.
SMS/Text Messaging Terms & Conditions
By opting in to ThreatMate's SMS/text messaging program, you consent to receive text messages from ThreatMate Inc. ("ThreatMate") at the mobile number you provide. The following terms apply to our SMS communications:
- Brand Name: ThreatMate Inc.
- Types of Messages: You may receive text messages related to account notifications, security alerts, multi-factor authentication codes, service updates, and customer support communications.
- Message Frequency: Message frequency varies. You may receive up to 5 messages per week depending on your account activity and security events.
- Message and Data Rates: Message and data rates may apply. Please consult your mobile carrier's plan for details.
- Help: For help, text HELP to any message you receive from ThreatMate, or contact our support team at support@threatmate.com or call (813) 896-4672. Support hours: 9:00 AM – 5:00 PM EST, Monday through Friday.
- Opt-Out: You may opt out of receiving text messages at any time by replying STOP to any message you receive from ThreatMate. After opting out, you will receive a one-time confirmation message and will no longer receive SMS messages from ThreatMate unless you re-subscribe.
- Privacy: Your privacy is important to us. Please review this Privacy Policy for information on how we collect, use, and protect your data.
Mobile information will not be shared with third parties/affiliates for marketing/promotional purposes. All the categories exclude text messaging originator opt-in data and consent; this information will not be shared with any third parties.
Children's Privacy
Our services are not intended for children under the age of 16. We do not knowingly collect personal data from children without verifiable parental consent.
Changes to This Policy
We may update this policy from time to time. We will notify you of material changes through our website or via the contact information on file. The effective date at the top of this policy indicates when it was last revised.
Contact Us
If you have questions about this policy or our privacy practices, please contact:
Privacy Officer
ThreatMate Inc.
5005 W Laurel St., Suite 99
Tampa, FL 33607
Email: privacy@threatmate.com
Website: https://www.threatmate.com/legal/privacy
Support: support@threatmate.com | (813) 896-4672
Support Hours: 9:00 AM – 5:00 PM EST
© 2026 ThreatMate Inc. | privacy@threatmate.com