Darktrace Privacy & Data Protection Notice
Darktrace HoldingsLimited (“Darktrace”) is committed to protecting and respecting your privacy.Darktrace collects, uses and keeps information in compliance with the UK DataProtection Act 2018, the Privacy and Electronic Communications (EC Directive)Regulations 2003, the General Data Protection Regulation (Regulation (EU)2016/679) (“GDPR”), the California Consumer Protection Act (CCPA) as amended byThe California Privacy Rights Act (CPRA), the Colorado Privacy Act (CPA), theVirginia Consumer Data Protection Act (CDPA), the Connecticut Data Privacy Act(CTDPA), the Utah Consumer Privacy Act (UCPA) and all relevant regulations.
This Privacy Notice (the “Notice”) is issued on behalf of the Darktrace Group (meaning Darktrace Holdings Limited, its affiliates and its or their subsidiaries) so when we mention “Darktrace”, “we”, “us” or “our” in this Notice, we are referring to the relevant company in the Darktrace Group responsible for processing your personal data.
This Notice aims to give you information on how Darktrace collects and processes your personal data. Please read the following Notice to understand how we collect and use your personal data, for example when you contact us, visit our website (Site),apply for a job, or use our products and services.
Information Darktrace may collect from you
Darktrace may collect and process the following data about you:
- Contact and Identity Data such as your name, email, address and phone number. Phone numbers are used for two factor authentication and support services.
- Recruitment Data such as your Resume or CV, including background check data, to assess your suitability for a role.
- Technical Data including your Internet Protocol (IP) address, login data, operating system and web browser type, browser plug-in types and version, traffic data, location data and other communication data, and the resources that you access.
- Usage Data including how you use our website, products, and services.
- Profile Data including usernames, passwords, and feedback data.
- Marketing and Communications Data including your preferences in receiving marketing from us and your communication preferences.
How Darktrace may collect your personal data
Darktrace may collect your personal data when you:
- Contact us and/or provide feedback.
- Provide contact details (e.g. giving business cards) at a marketing event.
- Request and receive marketing communications.
- Submit a job application: If you are making a job application or inquiry, you may provide us with a copy of your CV or other relevant information. We may use this information for the purpose of considering your application or inquiry. Except when you explicitly request otherwise, we may keep this information on file for future reference.
- Join our Partnership and/or channel scheme.
- An employee of ours gives your contact details as an emergency contact or a referee.
- Purchase our products and services: If you purchase or use our products or services, we may use your personal data for purposes which include but are not limited to:
- Verifying your credentials,
- Carrying out end user compliance checks for export control purposes,
- Processing orders and generating billing information.
Additionally, Darktrace may collect data about you:
- Through our business relationships, contacts and data enrichment services (e.g. Zoominfo, KASPR, Demandbase, etc.) to ensure the personal data that we hold to ensure is accurate and relevant.
How Darktrace may use your personal data
Darktrace may use the personal data held about you in the following circumstances:
- To perform the contract we are about to enter into or have entered into with you, including notification of changes to our products and services.
- Where it is necessary for our legitimate interests (or those of a third party) and your interests and fundamental rightsdo not override those interests.
- Where we need to comply with a legal obligation.
- To provide you with information, products or services that you request from us, or which Darktrace feel may interest you, where you have consented to be contacted for such purposes.
- To allow you to participate in interactive features of our products or service, when you choose to do so.
- To evaluate your suitability and candidacy for employment or other engagement by or with Darktrace.
We have set out below, in a table format, a description of the primary ways we may use your personal data, and which of the lawful basis we rely on to do so. Our lawful basis for collecting and using personal data will depend on the data concerned and the context in which we collect it.
In most circumstances, we collect personal data where it is needed for the performance of a contract with you, where you provide your consent, or where processing the personal data is in our legitimate interests. Your personal data may also be collected and processed to comply with our legal obligations.
Where we have identified Legitimate Interest as our Lawful basis for processing personal data we have also identified what our legitimate interests are where appropriate.
Third Party Links
Our Site may, from time to time, contain links to and from the websites of our partner networks, advertisers and affiliates. If you follow a link to any of these websites, please note that these websites have their own privacy policies and that Darktrace does not accept any responsibility or liability for these policies. Please check these policies before you submit any personal data to these websites.
Selling of Data
We do not sell any data captured as part of your use of Darktrace’s products or services. Our public website uses Google Analytics, which may be considered exchanging data for valuable consideration under CCPA.
If you wish to opt out of Google Analytics, you can use the opt-out browser add-on from Google.
If you are an existing customer, Darktrace will only contact you by electronic means (e-mail or SMS) with information about goods and services similar to those that were the subject of a previous sale to you.
You can ask us to stop sending you marketing or direct sales messages at any time by following the opt-out links on any marketing message sent to you OR by contacting us via email at any time at firstname.lastname@example.org
Where you opt out of receiving these marketing messages, this will not apply to personal data provided to us as a result of a product/service purchase.
We will not sell or rent your data to third parties or share your data with third parties for marketing purposes. We may use third party software to send you information for marketing purposes, but such third parties will not have access to or be able to read your personal information.
If you receive an email which claims to come from us but does not use our domain, or if you are suspicious that an email may not be approved by us, then please send a copy of the email to email@example.com so we can investigate.
Transferring personal data
As a global company, we have international sites and users all over the world. When you give us personal data, that data may be used, processed or stored anywhere in the world, including countries outside the European Economic Area (“EEA”). It may also be processed by staff operating outside the EEA, who work for us or for one of our suppliers. Specific to our Products and Services, Darktrace provides a Master Services Agreement (“MSA”) to customers and end users that incorporates the EU Standard Contractual Clauses within its Data Processing Addendum.
Darktrace performs transfer impact assessments (“TIA”) and continually monitors the circumstances surrounding such transfers to ensure that these maintain, in practice, a level of protection that is essentially equivalent to the one guaranteed by the EEA and UK data protection laws.
Darktrace places substantial importance on protecting the confidentiality of personal information and seeks the cooperation of all its suppliers in furthering this goal.
Darktrace will only transfer personal information to a supplier where the supplier has provided assurances that they will provide at least the same level of privacy protection as is required by this Notice. Where Darktrace has knowledge that a supplier is using or sharing personal information in a way that is contrary to this Notice, Darktrace will take reasonable steps to prevent or stop such processing.
Darktrace endeavours to hold all personal data securely in accordance with our internal security procedures and applicable law. We update and test our security on an ongoing basis. Darktrace will do its best to protect your personal data, but Darktrace cannot guarantee the security of your data transmitted to our Site through the internet; any such transmission is at your own risk. Once Darktrace have received your information, Darktrace will maintain appropriate administrative, physical, technical and organizational measures to protect your personal data accessed or processed by Darktrace against unauthorized or unlawful processing or accidental loss, destruction, damage or disclosure.
Disclosure of your information
We may share or disclosure your personal data with the parties set out below:
- Within the Darktrace Group for the fulfilment of the activities described in the table above.
- To third parties to whom we may choose to sell, transfer or merge parts of our business or our assets. Alternatively, we may seek to acquire other businesses or merge with them. If a change happens to our business, then the new owners may use your personal data in the same way as set out in this Notice.
- To our auditors and legal counsel, regarding our business. In some cases, the shared information may contain personal information, but the auditors and legal counsel may only use it for the purpose of providing their professional services, consistent with their obligations of confidentiality.
We will only retain your personal data for as long as reasonably necessary to fulfil the purposes we collected it for, including for the purposes of satisfying any legal, regulatory, tax, accounting or reporting requirements. We may retain your personal data for a longer period in the event of a complaint or if we reasonably believe there is a prospect of litigation in respect to our relationship with you.
To determine the appropriate retention period for personal data, we consider the amount, nature and sensitivity of the personal data, the potential risk of harm from unauthorised use or disclosure of your personal data, the purposes for which we process your personal data and whether we can achieve those purposes through other means, and the applicable legal, regulatory, tax, accounting or other requirements.
Details of retention periods for different aspects of your personal data can be requested via our Data Privacy Officer at the contact details provided below.
Your legal rights
GDPR gives you the right to access information held about you.
If you’re an UK or EU citizen, your right of access can be exercised in accordance with the UK DPA and/or GDPR.
You have the right to request by contacting firstname.lastname@example.org.
· information about how your personal data is processed;
· a copy of your personal data;
· an immediate correction to your personal data.
You can also:
· raise an objection about how your personal data is processed;
· request that your personal data is erased if there is no longer a justification for it;
· ask that the processing of your personal data is restricted in certain circumstances;
· opt out of the use of your personal data for any purposes or a specific purpose, such as the Darktrace Customer Portal.
If you are a resident of a US state that has applicable Data privacy legislation, you have certain rights:
Where Darktrace acts as the Data Controller, i.e. for Direct Sales ad Marketing activity, you can enact the above right by emailing email@example.com. If you are customer employee wishing to enact your legal right, please contact your employer’s privacy team.
Changes to our Privacy & Data Protection Policy
Darktrace reserves the right to amend this Privacy and Data Protection Notice at any time, for any reason, without notice to you, other than the posting of the amended Privacy and Data Protection Notice at this Site. You should check our Site to see the current Privacy and Data Protection Notice that is in effect and any changes that may have been made to it.
This Notice was last amended on 28 September 2023.
How to Contact the Appropriate Authority
Should you wish to report a complaint or if you feel that Darktrace has not addressed your concern in a satisfactory manner you have the right to contact the appropriate authority.
Individuals within the EU and rest of the world have the right to raise a complaint with the supervisory authority in the Member State where they live, where they work, or where the infringement took place.
For UK GDPR (DPA18) you may contact the Information Commissioner’s Office:
Telephone: 0303 123 1113.
For EU GDPR you may contact your local Supervisory Authority. Within the EU Darktrace is Registered with the Irish Data Protection Commission.
Telephone: 01 7650100 / 1800437 737
Data Privacy Officer
Darktrace is headquartered in Cambridge, United Kingdom. Darktrace has appointed an internal Data Protection Officer for you to contact if you have any questions or concerns about Darktrace’s Privacy and Data Protection Notice. The contact information for the Darktrace Data Protection Officer is as follows:
Darktrace Holdings Limited
Maurice Wilkes Building
St John’s Innovation Park