Corelight Privacy Notice
Last Updated: September 26, 2025
Your privacy is important to us, and so is being transparent about how we collect, use and share information about you. Corelight, Inc. and its affiliates, including Corelight Federal, LLC (“Corelight,” “we”, “us”, or “our”) know that you care about how your data is used and shared. Corelight’s Privacy Notice applies to Personal Data (as defined below) collected through Corelight’s websites, feedback and surveys, the sales and contracting process, and both online, offline, and in-person sales and marketing activities, as further detailed below. We may also choose or be required by law to provide different or additional disclosures relating to the processing of Personal Data about residents of certain countries, regions, or states. Please refer to the Region-Specific Disclosures section below for additional disclosures that may be applicable to you.
“Personal Data” means any data relating to an identified or identifiable individual, including, for example, your first and last name, email address, and phone number.
This Privacy Notice does not address our privacy practices relating to Corelight job applicants, employees and other personnel, nor data that is not subject to applicable data protection laws (such as deidentified or publicly available information in respect of individuals in the US). For job applicants, please refer to our Applicants and Team Members Privacy Notice (UK and EU) or California Job Applicant Privacy Notice (as applicable).
This Privacy Notice is also not a contract and does not create any legal rights or obligations not otherwise provided by law.
About Corelight
Corelight, Inc., is a Delaware corporation headquartered in California. Corelight, Inc. has subsidiaries and affiliated companies (“Corelight Group”) located throughout the world (Corelight, Inc. and the Corelight Group are together referred to as “Corelight” unless specified otherwise.) Please refer to the “About Corelight” section of our website for more information.
Our Role in Processing Personal Data
Data protection laws sometimes differentiate between “controllers” and “processors” of Personal Data. A “controller” determines the purposes and means (the why and how) of processing Personal Data. A “processor,” which is sometimes referred to as a “service provider,” processes Personal Data on behalf of a controller subject to the controller’s instructions.
This Privacy Notice describes our privacy practices where we are acting as the controller of Personal Data. This Privacy Notice does not cover or address how our customers may process Personal Data when they use our services, or how we may process Personal Data on their behalf in accordance with their instructions where we are acting as their processor. As a result, we recommend referring to the privacy notice of the customer with which you have a relationship for information on how they engage processors, like us, to process Personal Data on their behalf. In addition, we are generally not permitted to respond to individual requests relating to Personal Data we process on behalf of our customers, so we recommend directing any requests to the relevant customer.
- What Personal Data We Collect
We may collect Personal Data about you as follows:
Personal Data You Provide to Corelight
You may provide us with certain categories of Personal Data when you:
- Complete and submit forms or chat on our websites.
- Download white papers or other Corelight content.
- Use Online Communication Tools (as defined below).
- Register and/or attend webcasts, seminars, tradeshows, conferences and other events sponsored by Corelight or a partner.
- Subscribe to our newsletters or other Corelight content-related materials.
- Register for courses, training or education.
- Provide us with feedback or contact us by phone, email, online, through social media or otherwise.
- Participate in a survey.
- Purchase Corelight products and/or services.
- Visit our offices.
The categories of personal data we collect include:
- Contact Information, including first and last name, phone number, email address, mailing address, and communication preferences. We use this information primarily to fulfill your request or transaction, to communicate with you directly, and to send you marketing communications in accordance with your preferences.
- Professional Information, including job title, company name, professional background, and the nature of your relationship with us. We use this information primarily to fulfill your request or transaction, to determine how we communicate with you, to administer your account, to provide you with our services, and for customer support purposes.]
- Account Information, including first and last name, email address, phone number, account credentials or one-time passcodes, and the products or services you are interested in, purchased, or have otherwise used. We use this information primarily to administer your account, provide you with our products and services, communicate with you regarding your account and your use of our products and services, and for customer support purposes.]
- Customer Content, including any files, documents, audio, videos, images, data, or communications you choose to input, upload, or transmit to our products and services. We use this content primarily to provide you with our products and services, to facilitate your requests, and to improve our products and services.
- Payment Information, including billing address, and other financial information (such as, routing and account number). Please note that we use third-party payment provider Airbase to process payments made to our vendors. We do not collect or retain any personally identifiable financial information. Any billing or financial information is provided directly by our vendors to Airbase. Airbase’s use of such personal data is governed by their privacy notice. To view Airbase’s privacy policy, please click here.
- Event, Contest, Promotion, and Survey Information, including information provided when you sign up for an event, enter a contest or promotion, complete a survey or submit a testimonial. We use this information primarily to administer and facilitate our products and services, respond to your submission, communicate with you, conduct market research, inform our marketing and advertising activities, improve and grow our business, and facilitate the related event, content, promotion, or survey.
- Security-Related Information, including name and contact information of visitors to our events or premises, video recordings of videos on our premises, and electronic login records and access details when a visitor utilizes company technology on our premises. We use this information primarily to protect the security of our premises, employees, and our company.
- Feedback and Support Information, including the contents of custom messages sent through the forms, chat platforms, including our online live chat or automated chat functions, email addresses, or other contact information we make available to customers, as well as recordings of calls with us, where permitted by law (including through the use of automated tools provided by us or our third-party providers). We use this information primarily to investigate and respond to your inquiries, to communicate with you via online chat, email, phone, text message or social media, and to improve our products and services.
Personal Data Collected Automatically
We, and our third-party partners, use data collection tools, such as cookies, pixels, tags and web beacons, to automatically collect the following data when you use our services or otherwise engage with us:
- Technical information including, but not limited to, browser type, operating system, device information, IP address, domain name, referral URL, time zone setting, and/or a time-stamp for your visit.
- Usage information including, but not limited to, geographic location information (such as your country or state), the numbers and frequency of visitors to our site, page views, unique page views, video views, form conversions, and your clickstream behavior (e.g. clicking links to, through and from our website). You can find out more information on how Corelight uses cookies and other automatic data collection tools, and adjust your preferences accordingly, here.
All of the information collected automatically through these tools allows us to improve your customer experience. For example, we may use this information to enhance and personalize your user experience, to monitor and improve our products and services, to offer communications features such as live and automated chat, and to improve the effectiveness of our products, services, offers, advertising, communications and customer service. We may also use this information to: (a) remember information so that you will not have to re-enter it during your visit or the next time you visit the site; (b) provide custom, personalized content and information, including targeted content and advertising; (c) identify you across multiple devices; (d) provide and monitor the effectiveness of our services; (e) monitor aggregate metrics such as total number of visitors, traffic, usage, and demographic patterns on our website; (f) diagnose or fix technology problems; and (g) otherwise to plan for and enhance our products and services.
Personal Data Collected From Third Parties and Other Sources
Corelight works closely with third parties and may receive Personal Data from such third parties. These third-party sources vary based on context but may include:
- data brokers from which we purchase data to supplement the data we collect;
- channel partners who resell or distribute or products and services (including resellers and managed service providers) and whom supply us with data to help establish an account, fulfill orders and offer products and services;
- third-party providers (for example, companies that provide localization, analytics and marketing services in connection with our websites);
- partners with which we offer co-branded services or engage in joint marketing activities;
- your employer or another company for which you work, if you interact with our services in connection with your employment;
- Other customers, such as when a customer provides us with your contact information as a part of a referral;
- Social media platforms you use to interact with us;
- Service providers that perform services on our behalf;
We may also collect personal data about you from other sources, including from publicly available sources, our affiliates or through transactions such as mergers and acquisitions.
- How We Use Personal Data
Corelight uses the Personal Data we collect under this Privacy Notice for two main purposes:
(1) to operate our business and provide the products and services, and
(2) to send communications, including marketing communications.
For example, we may use Personal Data to:
- Administer and provide our websites.
- Customize the content and advertising you see on our websites.
- Respond to your requests and questions.
- Facilitate the relationship we have with you and, where applicable, the company you represent.
- Provide products and services.
- Create and maintain accounts for our users.
- Communicate with you, including about specials, sales offers and new products.
- Request you provide us feedback about our products and services.
- Send notifications regarding our company, products and services and changes to our terms.
- Transact with our customers, suppliers and channel partners and to process orders.
- Register you for and provide you access to events, contests, sweepstakes, and surveys.
- Test, improve, enhance, update, and monitor the products and services, or diagnose or fix technology problems.
- Infer additional information about you from your use of our products and services, such as your interests.
- Create aggregated or de-identified information that cannot reasonably be used to identify you, which information we may use for purposes outside the scope of this Privacy Notice.
- Conduct research and analytics on our user base and our products and services, including to better understand the demographics of our users.
- Help maintain and enhance the safety, security, and integrity of our property, products, services, technology, assets, and business.
- Defend, protect, or enforce our rights or applicable contracts and agreements (including our Terms of Use), as well as to resolve disputes, to carry out our obligations and enforce our rights, and to protect our business interests and the interests and rights of third parties.
- Detect, prevent, investigate, or provide notice of security incidents or other malicious, deceptive, fraudulent, or illegal activity and protect the rights and property of Corelight and others.
- Facilitate business transactions and reorganizations impacting the structure of our business.
- Comply with contractual and legal obligations and requirements,
- Fulfill any other purpose for which you provide your Personal Data, or for which you have otherwise consented.
- How We Disclose Your Personal Data
Corelight may disclose Personal Data collected under this Privacy Notice for the following purposes:
- Corelight Group: we disclose Personal Data to other Corelight corporate affiliates in order to provide, operate and improve our products and services and to offer other Corelight affiliated services to you.
- Your Employer: we may disclose Personal Data to your employer or another company for which you work if you interact with our services in connection with your employment. For example, we may provide information to your employer about your usage of our services in connection with your work for them.
- Other Customers and the General Public: we may disclose Personal Data to other customers and the general public when you use our Online Communication Tools to transmit Personal Data (see the Public Forums section below for more information).
- Ad Networks and Advertising Partners: we work with third-party ad networks and advertising partners to deliver advertising and personalized content on our services, on other websites and services, and across other devices. Subject to your settings, these parties may collect information automatically from your browser or device when you visit our websites and other services using cookies and related technologies. This information is used to provide and inform targeted advertising, as well as to provide advertising-related services such as reporting, attribution, analytics, and market research.
- Service Providers: we contract with third-party service providers who provide assistance with website development, hosting, technical support, backup, infrastructure, payment processing, analysis, and other services, and we disclose Personal Data to these providers to allow them to facilitate their services to us.
- Corelight Partners: Corelight has an extensive network of third-party partners who resell Corelight products and who provide other services and technology based on our products and services. Corelight may disclose Personal Data to our channel partners for purposes of selling and providing Corelight products and services to you.
- Corelight Suppliers: Certain Corelight products incorporate software provided by third-party suppliers. In some cases, Corelight may be required to report on sales of such products incorporating such software to those third-party suppliers, and this reporting may include your Personal Data solely to the extent needed to document such sales.
- Corporate Transactions: we may take part in or be involved with a merger, reorganization, dissolution, corporate reorganization, acquisition of all or portion of our business by or to another company or similar event. We may disclose, transfer, or assign Personal Data to a third party during negotiation of, in connection with, or as an asset in such a business transaction or reorganization. Also, in the unlikely event of our bankruptcy, receivership, or insolvency, your personal data may be disclosed, transferred, or assigned to third parties in connection with the proceedings or disposition of our assets.
- Compelled Disclosure: in response to a request for Personal Data if we reasonably believe disclosure is necessary to comply with any applicable law, regulation, legal process or governmental request, including to meet national security requirements.
- Protection of Corelight and/or Others: we may disclose Personal Data where we reasonably believe that use or disclosure is necessary to protect the rights, property, or safety of Corelight, its customers, users and others.
- With Your Consent or Direction: we may disclose Personal Data to third parties with your consent or direction.
- Your Privacy Choices
Corelight offers you choices regarding the collection, use and sharing of Personal Data. You may also have additional choices regarding your Personal Data depending on your location or residency. Please refer to our Region-Specific Disclosures below for information about additional privacy choices that may be available to you.
Communication Preferences
- Email Communication Preferences: You can stop receiving promotional email communications from us by clicking on the “unsubscribe” link provided in any of our email communications. Please note you cannot opt-out of service-related email communications (such as, account verification, transaction confirmation, or service update emails).
- Phone Communication Preferences: You can stop receiving promotional phone communications from us by informing the caller you no longer wish to receive promotional phone calls from us, following the instructions provided on the call for opting out of promotional phone calls (where available), or replying STOP to any one of our promotional text messages. Please note we may need to continue to communicate with you via phone for certain service-related messages (such as, sending a verification code to your phone via call or text for purposes of verifying the authenticity of a log-in attempt).
- Direct Mailing Preferences: You can stop receiving promotional direct mail communications from us by contacting us at privacy@corelight.com. Please note this opt-out does not affect any mailings that are controlled by third parties that may feature or mention our services.
Automatic Data Collection Preferences
Certain of our services may provide you the ability to adjust your preferences regarding our use of automatic data collection technologies. For example, there is a “Cookie Preferences” manager linked in the footer of our websites that allows you to adjust your preferences regarding certain automatic data collection technologies on the specific website you are visiting for the specific device and browser you are using at that time (which means you will need to change your preferences on each device and browser you use to interact with the specific website you are visiting).
Where a Corelight-specific preference manager or privacy setting is not available, you may be able to utilize third-party tools and features to further restrict our use of automatic data collection technologies. For example, (i) most browsers allow you to change browser settings to limit automatic data collection technologies on websites, (ii) most email providers allow you to prevent the automatic downloading of images in emails that may contain automatic data collection technologies, and (iii) many devices allow you to change your device settings to limit automatic data collection technologies for device applications. Please note that blocking automatic data collection technologies through third-party tools and features may negatively impact your experience using our services, as some features and offerings may not work properly or at all. Depending on the third-party tool or feature you use, you may not be able to block all automatic data collection technologies or you may need to update your preferences on multiple devices or browsers. We do not have any control over these third-party tools and features and are not responsible if they do not function as intended.
Targeted Advertising Preferences
We engage third parties to help us facilitate targeted advertising designed to show you personalized ads based on predictions of your preferences and interests developed using Personal Data we maintain and Personal Data our third-party partners obtain from your activity over time and across nonaffiliated websites and other services. The data we and our third-party partners use for purposes of facilitating targeted advertising, as well as to provide advertising-related services such as reporting, attribution, analytics, and market research, are primarily collected using a variety of automatic data collection technologies, including cookies, web beacons, pixels, embedded scripts, mobile SDKs, location-identifying technologies and logging technologies.
In addition to taking the steps set forth in the Automatic Data Collection Preferences section above, you may be able to further exercise control over the advertisements that you see by leveraging one or more targeted advertising opt-out programs. For example:
- Device-Specific Opt-Out Programs: Certain devices provide individuals with the option to turn off targeted advertising for the entire device (such as Apple devices through their App Tracking Transparency framework or Android devices through their opt out of ads personalization feature). Please refer to your device manufacturer’s user guides for additional information about implementing any available device-specific targeted advertising opt-outs.
- Digital Advertising Alliance: The Digital Advertising Alliance allows individuals to opt out of receiving online interest-based targeted advertisements from companies that participate in their program. Please follow the instructions at https://optout.aboutads.info/?c=2&lang=EN for browser-based advertising and https://www.youradchoices.com/appchoices for app-based advertising to opt out of targeted advertising carried out by our third-party partners and other third parties that participate in the Digital Advertising Alliance’s self-regulatory program.
- European Interactive Digital Advertising Alliance: The European Interactive Digital Advertising Alliance similarly allows individuals to opt out of receiving online interest-based targeted advertisements from companies that participate in their program. Please follow the instructions at https://www.youronlinechoices.eu to opt out of browser-based targeted advertising carried out by our third-party partners and other third parties that participate in the European Interactive Digital Advertising Alliance’s program.
- Network Advertising Initiative: The Network Advertising Initiative similarly allows individuals to opt out of receiving online interest-based targeted advertisements from companies that participate in their program. Please follow the instructions at https://optout.networkadvertising.org/?c=1 to opt out of browser-based targeted advertising carried out by our third-party partners and other third parties that participate in the Network Advertising Initiative’s self-regulatory program.
- Platform-Specific Opt-Out Programs: Certain third-party platforms provide individuals the option to turn off targeted advertising for the entire platform (such as certain social media platforms). Please refer to your platform provider’s user guides for additional information about implementing any available platform-specific targeted advertising opt-outs.
Please note that when you opt out of receiving interest-based advertisements through one of these programs, this does not mean you will no longer see advertisements from us or on our services. Instead, it means that the online ads you do see from relevant program participants should not be based on your interests. We are not responsible for the effectiveness of, or compliance with, any third parties’ opt-out options or programs or the accuracy of their statements regarding their programs. In addition, program participants may still use automatic data collection technologies to collect information about your use of our services, including for analytics and fraud prevention as well as any other purpose permitted under the applicable advertising industry program.
- Security of Personal Data
Corelight has implemented reasonable physical, technical and organizational measures, including administrative, physical, and technical safeguards, designed to protect the Personal Data we use and process from unauthorized access, use, modification, or disclosure. Please be aware that, despite these controls, no security measures can wholly eliminate security risks associated with the storage and transmission of Personal Data. You are responsible for protecting your usernames and passwords, limiting access to your devices, signing out of websites after your sessions and for any other activity that occurs under your accounts with us. If you have any questions about the security of our websites or feel that the security of any Corelight account you may have has been compromised, please contact us at privacy@corelight.com.
- Retention of Personal Data
We will usually retain the Personal Data we collect about you for no longer than reasonably necessary to fulfil the purposes for which it was collected, and in accordance with our legitimate business interests and applicable law. However, if necessary, we may retain Personal Data for longer periods of time as required under applicable law or as needed to resolve disputes or protect our legal rights.
To determine the appropriate duration of the retention of Personal Data, we consider the amount, nature, and sensitivity of the Personal Data, the potential risk of harm from unauthorized use or disclosure of Personal Data and if we can attain our objectives by other means, as well as our legal, regulatory, tax, accounting, and other applicable obligations.
Once retention of the Personal Data is no longer reasonably necessary for the purposes outlined above, we will either delete or deidentify the Personal Data or, if that is not possible (for example, because Personal Data has been stored in backup archives), we will securely store the Personal Data and isolate it from further active processing until deletion or deidentification is possible.
- Links to Third Party Websites
Corelight may provide links to other third-party websites and services that are outside our control and not covered by Corelight’s Privacy Notice. Corelight is not responsible for the privacy practices or the content of such websites. We encourage you to review the privacy notices on any website you visit whether linked to or not.
- Public Forums
Corelight offers individuals the opportunity to interact and publish content via discussion forums, community groups, blogs, and other means on our websites (“Online Communication Tools”). If you use such Online Communication Tools, any information that you disclose becomes publicly available, and could be used to contact you, to send you unsolicited messages, or for purposes neither Corelight nor you have control over. Your use of certain Online Communication Tools may be subject to additional terms and conditions. Corelight is not responsible for the Personal Data or any other information you choose to submit or publish via these Online Communication Tools.
- Children’s Personal Data
Corelight does not knowingly collect Personal Data from individuals under the age of thirteen (13) or the applicable age of consent in your country. If you believe that Corelight may have collected Personal Data from someone under the applicable age of consent, please contact Corelight’s Privacy Team at privacy@corelight.com.
- Region-Specific Disclosures
We may choose or be required by law to provide different or additional disclosures relating to the processing of Personal Data about residents of certain countries, regions or states. Please refer below for disclosures that may be applicable to you:
- European Economic Area, United Kingdom or Switzerland: If you are located in the European Economic Area (Member States of the European Union together with Iceland, Norway, and Liechtenstein), the United Kingdom, or Switzerland, please click here for additional European-specific privacy disclosures, including a description of the Personal Data rights made available to individuals located in those jurisdictions under applicable law.
- California, United States: If you are a resident of the State of California in the United States, please click here for additional California-specific privacy disclosures, including a description of the Personal Data rights made available to California residents.
- Updates
Corelight may update this Privacy Notice from time to time. If we make changes to this Privacy Notice, we will post the updated version, which will be effective as of the updated revision date. If there are material changes to our Privacy Notice or in how Corelight will use Personal Data, we may provide notification by other means prior to such changes taking effect, for example, by posting a notice on our website or sending you a notification.
- Contacting Us
Questions regarding our Privacy Notice and Corelight’s privacy practices can be directed to Corelight’s Privacy Team by emailing privacy@corelight.com.
Additional California Privacy Disclosures
These disclosures supplement the information contained in our Privacy Notice by providing additional information about our Personal Data processing practices relating to individual residents of the State of California in the United States. For a detailed description of how we collect, use, disclose, and otherwise process Personal Data, please read our Privacy Notice.
- Personal Data Collection and Use
As described in more detail in the What Personal Data We Collect section of our Privacy Notice, we collect the following categories of Personal Data:
- Identifiers, including full name, email address, IP address, and account username and password.
- Customer Records, including mailing address and account information.
- Commercial Information, including the product or services you are interested in, purchased, or have otherwise used.
- Internet / Network Information, including log data and analytics data.
- Geolocation Data, including general geographic location.
- Sensory Information, including, where permitted by law, recordings of phone calls between us and individuals, and audio, image and video recordings of visitors to our offices or events.
- Profession/Employment Information, including employer / company name or the name you are doing business as, contact information, job title or description, professional background, and the nature of your relationship with us.
- Sensitive Personal Data, including account credentials or one-time passcodes.
- Other Personal Data, including communication preference, entries to events, sweepstakes, contests and promotions, comments and content submitted through our Online Communication Tools or in response to surveys and any other inquiries, requests, or comments an individuals chooses to send us.
- Inferences, including our predictions about interests and preferences based on other Personal Data we have collected.
- We use this Personal Data for the purposes set forth in the How We Use Personal Data section of our Privacy Notice.
- Personal Data Disclosures, Sales and Targeted Advertising
As described in the How We Disclose Your Personal Data section of our Privacy Notice, we may disclose all of the Personal Data identified above to third parties for business purposes. The categories of third parties to whom we disclose personal data for these purposes include our affiliates, businesses you represent, other customers and the general public, ad networks and advertising partners, service providers, business partners and suppliers, and certain other third parties where you have provided consent, we are engaging in a business transaction or reorganization, or we are addressing our legal obligations and rights
As is common practice among companies that operate online, we allow certain third-party providers to use cookies and related technologies to collect technical and usage data about individuals directly through our website for purposes of analyzing and optimizing our services, delivering ads, providing content and ads that are more relevant, measuring statistics and the success of ad campaigns, and detecting and reporting fraud. Some of these practices would constitute the sale of Personal Data or the use of Personal Data for the purpose of displaying advertisements that are selected based on Personal Data obtained or inferred over time from an individual’s activities across businesses or distinctly-branded websites, applications, or other services (otherwise known as “targeted advertising” or “cross-context behavioral advertising”) if they were carried out without your consent or direction.
Since Corelight only engages in these activities where you turn on automatic data collection technologies, we do not treat these activities as the “sale” of Personal Data or “sharing” of Personal Data under California law. You may, however, turn these automatic data collection technologies back OFF (if you choose to turn them ON in the first place) by clicking on the “Cookie Preferences” link in the footer of the website and adjusting your toggles accordingly.
We do not otherwise sell Personal Data or share Personal Data for purposes of targeted advertising, including sensitive Personal Data. Nor do we use sensitive Personal Data for the purpose of inferring characteristics about an individual in a manner that would require our offering of the right to limit the use of such information.
- Deidentified Information
We may at times receive, or process Personal Data to create, deidentified information that can no longer reasonably be used to infer information about, or otherwise be linked to, a particular individual or household. Where we maintain deidentified information, we will maintain and use the information in deidentified form and not attempt to reidentify the information except as required or permitted by law.
- Your Additional U.S. Privacy Choices
Subject to certain legal limitations and exceptions, you may be able to exercise some or all of the following rights:
- Right to Know: The right to confirm whether we are processing Personal Data about you and to obtain certain personalized details about the Personal Data we have collected about you, including:
- The categories of Personal Data collected;
- The categories of sources of the Personal Data;
- The purposes for which the Personal Data were collected;
- The categories of Personal Data disclosed to third parties (if any), and the categories of recipients to whom this Personal Data were disclosed;
- The categories of Personal Data shared for targeted advertising purposes (if any), and the categories of recipients to whom the Personal Data were disclosed for these purposes; and
- The categories of Personal Data sold (if any) and the categories of third parties to whom the Personal Data were sold.
- Right to Access & Portability: The right to obtain access to the Personal Data we have collected about you and, where required by law, the right to obtain a copy of the Personal Data in a portable and, to the extent technically feasible, readily usable format that allows you to transmit the data to another entity without hindrance.
- Right to Correction: The right to correct inaccuracies in your Personal Data, taking into account the nature of the Personal Data and the purposes of the processing of the Personal Data.
- Right to Deletion: The right to have us delete Personal Data we maintain about you. If you are a resident of the State of California under the age of 18, you may also request and obtain removal of user-generated content you have posted on our platform (though please note that such a request does not ensure complete or comprehensive removal of all user-generated content, particularly where user-generated content has been republished or reposted by another user or third party).
You may also have the right to not receive retaliatory or discriminatory treatment in connection with a request to exercise the above rights. However, the exercise of the rights described above may result in a different price, rate or quality level of product or service where that difference is reasonably related to the impact the right has on our relationship or is otherwise permitted by law.
Submitting Privacy Rights Requests
Please submit a request specifying the right you wish to exercise by:
- Completing our online form found here; or
- Calling our toll-free U.S. telephone number: (888) 547-9497.
Before processing your request to exercise certain rights (including the Right to Know, Access & Portability, Correction, and Deletion), we will need to verify your identity and confirm you are a resident of California. In order to verify your identity, we will generally either require the successful authentication of your account, or the matching of sufficient information you provide us to the information we maintain about you in our systems.
In certain circumstances, we may decline or limit your request, particularly where we are unable to verify your identity or locate your information in our systems, or where you are not a resident of California.
Submitting Authorized Agent Requests
In certain circumstances, you are permitted to use an authorized agent to submit requests on your behalf through the designated methods set forth above where we can verify the authorized agent’s authority to act on your behalf. To verify the authorized agent’s authority, we generally require evidence of either (i) a valid power of attorney or (ii) a signed letter containing your name and contact information, the name and contact information of the authorized agent, and a statement of authorization for the request. Depending on the evidence provided, we may still need to separately reach out to you to confirm the authorized agent has permission to act on your behalf and to verify your identity in connection with the request.
Additional European Economic Area, United Kingdom, and Switzerland Privacy Disclosures
These disclosures supplement the information contained in our Privacy Notice by providing additional information about our Personal Data processing practices relating to individuals who access our services or otherwise interact with us from the European Economic Area (“EEA”), United Kingdom ("UK"), and Switzerland. For a detailed description of how we collect, use, disclose, and otherwise process Personal Data, please read our Privacy Notice.
- Controller Details and Privacy Contacts
EEA, UK, and Swiss Controller
Corelight, Inc., a company duly incorporated and organised under the laws of the United States, having its registered address at 548 Market Street PMB 77799, San Francisco, CA 94104, is the “controller” responsible for the processing of Personal Data in connection with our EEA, UK, and Swiss services and operations as described in this Privacy Notice. This means Corelight, Inc., determines and is responsible for how your Personal Data is used. You may contact Corelight, Inc., by sending an email to privacy@corelight.com.
Additional Questions or Complaints
If you have a concern about our processing of Personal Data, you have the right to lodge a complaint with the Data Protection Authority where you reside, where you work, or where an alleged violation of the law has occurred. Contact details for applicable Data Protection Authorities can be found using the links below:
- European Economic Area: https://edpb.europa.eu/about-edpb/board/members_en
- United Kingdom: https://ico.org.uk/global/contact-us/
- Switzerland: https://www.edoeb.admin.ch/edoeb/en/home/the-fdpic/contact.html
We would, however, appreciate the chance to handle your concerns directly prior to a complaint being filed, so please contact us directly at privacy@corelight.com if you have any concerns.
- Purposes and Legal Basis for Processing Personal Data
When we process your Personal Data, we will do so in reliance on the following lawful bases:
How we use Personal Data | Categories of Personal Data used | Lawful basis |
---|---|---|
Communicate with you, such as sending service-related notifications regarding our company, products and services and changes to our terms. | Contact information, professional information. | Performance of a contract with you or, if our services are provided under a contract with someone else, our legitimate interests, namely managing our relationship under that contract. |
Send you marketing communications, such as information about specials, sales offers and new products, and asking you to provide feedback about our products and services. | Contact information, professional information, account information. Privacy preferences. |
Our legitimate interests, namely promoting our products and services, or, where required under applicable law, your consent. Legal obligation. |
Respond to your requests and questions. | Contact information, professional information, account information, customer content, feedback and support information (if you are the customer) | Performance of a contract with you or, if our services are provided under a contract with someone else or we do not have a contract in place, our legitimate interests, namely managing our relationship under that contract and communicating with prospective customers. |
Facilitate the relationship we have with you and, where applicable, the company you represent. | Contact information, professional information, account information, payment information (if you are the customer), feedback and support information (if you are the customer). | Performance of a contract with you or, if our services are provided under a contract with someone else, our legitimate interests, namely managing our relationship under that contract. |
To provide you with products and services in accordance with our agreement with you (if you are the customer) | Contact information, professional information, account information, customer content, payment information, feedback and support information, technical information, usage information. | Performance of a contract with you. |
To administer events, contests, sweepstakes and surveys. | Event, contest, promotion and survey information. | Performance of a contract with you (namely the relevant event, contest or sweepstake terms); otherwise, our legitimate interests, namely conducting market research and identifying ways in which we can improve our products. |
To customize the content and advertising you see on our websites, and to conduct interest-based advertising on other websites. | Technical information, usage information. | Your consent. |
To conduct research and analytics. | Technical information, usage information. Survey information, feedback and support information. |
Your consent. Our legitimate interests, namely identifying ways in which we can improve our products and services. |
To test, improve, enhance, update, and monitor the products and services, or diagnose or fix technology problems. | Technical information, usage information. Survey information, feedback and support information. |
Your consent. Our legitimate interests, namely identifying ways in which we can improve our products and services. |
To protect the security and integrity of our systems and facilities, including protecting our systems from and investigating malicious or unauthorized activity. | Technical information, usage information. | Our legitimate interests, namely protecting the security and integrity of our systems. |
To protect our property, enforce our rights and resolve disputes. | Security-related information, contact information, professional information, account information, customer content. | Our legitimate interests, namely protecting and enforcing our rights. |
To facilitate business transactions and reorganizations impacting the structure of our business. | All of the information listed above. | Our legitimate interests, namely facilitating business transactions and reorganizations. |
We will inform you at the point that we collect Personal Data from you if the provision of certain Personal Data is mandatory or optional for receipt of our products and services. If you choose not to provide us with Personal Data marked as required, we may not be able to provide you with a service or product you request.
- Automated Decision-Making and Profiling
We do not conduct automated processing of Personal Data, including profiling, for the purposes of making decisions about you.
- Automated Decision-Making and Profiling
We operate and engage third-party partners and providers in various jurisdictions. Therefore, we and our third-party providers may transfer Personal Data to, or store, access, or process Personal Data in, a country other than the one in which it was collected, including, but not limited to, the United States. The country to which Personal Data is transferred may not provide the same level of protection for Personal Data as the country from which it was transferred.
We may transfer Personal Data about you to recipients outside of the EEA, UK, and Switzerland, and when we do so we rely on appropriate or suitable safeguards recognized under applicable law, including adequacy decisions, standard contractual clauses, and the EU-US Data Privacy Framework. If you would like more information on the specific safeguards we use (and obtain a copy of such safeguards, where applicable), please contact us at privacy@corelight.com.
Adequacy Decisions
We may transfer Personal Data about you to recipients in countries or sectors that the relevant regulatory authority have deemed to adequately safeguard Personal Data.
Standard Contractual Clauses
We may enter into agreements with recipients that incorporate standard contractual clauses approved under the EU GDPR, UK GDPR or Swiss Federal Act on Data Protection when transferring Personal Data to a recipient in a third country that has not been deemed to adequately safeguard Personal Data.
EU-U.S. Data Privacy Framework
The EU-U.S. Data Privacy Framework was designed by the U.S. Department of Commerce and the European Commission to ensure adequate protection for Personal Data transferred to a company participating in the EU-U.S. Data Privacy Framework. If we transfer any Personal Data about you from the EEA, UK or Switzerland to a third party in the USA that is participating in the EU-U.S. Data Privacy Framework, UK Extension to the EU-U.S. Data Privacy Framework or Swiss-U.S. Data Privacy Framework (as applicable) we may rely on their participation in the Framework to ensure adequate protection for Personal Data so transferred.
- Your Additional EEA, UK, and Swiss Privacy Choices
Subject to certain limitations at law, you may be able to exercise the following rights:
- Right to Access: The right to obtain confirmation of whether we are processing Personal Data about you, access to and a copy of the Personal Data we are processing about you, and information relating to its processing, including:
- The categories of Personal Data being processed;
- The purposes of the processing;
- The categories of the sources of the Personal Data;
- The categories of recipients to whom the Personal Data have been or will be disclosed;
- The envisaged period for which the Personal Data will be stored, or the criteria used to determine that period;
- Any automated decision-making or profiling performed in connection with your Personal Data; and
- The safeguards relied upon for the transfer of Personal Data to any third country.
- Right of Portability: The right to obtain a copy of the Personal Data we have collected about you in a structured, commonly used, and machine-readable format, and the right to transmit that Personal Data to another controller without hindrance.
- Right to Rectification: The right to correct or update any Personal Data about you that is inaccurate or incomplete.
- Right to Restriction of Processing: The right to require us to limit the purposes for which we process your Personal Data if the continued processing of the Personal Data in this way is not justified, such as where the accuracy of the Personal Data is contested by you.
Right to Object to Processing: The right to object to any processing based on our legitimate interests where there are grounds relating to your particular situation. There may be compelling reasons for continuing to process your Personal Data, and we will assess and inform you if that is the case. You can object to marketing activities for any reason.
- Right to Withdraw Consent: The right to withdraw your previously provided consent to our processing of your Personal Data. Please note withdrawing your consent will not affect the lawfulness of our use of your Personal Data before your consent was withdrawn, nor our processing of Personal Data pursuant to a different lawful basis for processing.
- Right to Erasure: The right to have us erase your Personal Data if the continued processing of that Personal Data is not otherwise justified.
Please note that if the exercise of these rights limits our ability to process Personal Data, we may not be able to provide our services to you, or otherwise engage with you in the same manner.
Submitting Privacy Rights Requests
Please submit a request specifying the right you wish to exercise by sending a request to privacy@corelight.com.
Before processing your request to exercise certain rights (taking into account the confidential nature of any Personal Data we maintain), we will need to verify your identity and confirm you are accessing our services or otherwise interacting with us from the EEA, UK, or Switzerland. In order to verify your identity, we will generally either require the successful authentication of your account, or the matching of sufficient information you provide us to the information we maintain about you in our systems.
In certain circumstances, we may decline or limit your request, particularly where we are unable to verify your identity as needed to protect your Personal Data or locate your information in our systems, or where you are not accessing our services or otherwise interacting with us from the EEA, UK, or Switzerland.
Cookies
If you access our websites or services from the EEA, UK or Switzerland, other than cookies and similar technologies that are strictly necessary to operate all or part of the website or service, we will only place these technologies on your device and use them to collect and use data with your consent.
You can withdraw your consent to the use of these data collection technologies by clicking the “Cookie Settings” link in the footer of the website and adjust your preferences accordingly. Please note this preferences tool is website, device, and browser specific, so you will need to change your preferences on each device and browser you use to interact with the specific website you are visiting. In addition, you may follow the other steps set forth in the Automatic Data Collection Preferences section of the Your Privacy Choices section of our Privacy Notice to further exercise control over automatic data collection technologies.