This Privacy Policy explains how 1Defender, Inc. (“1Defender,” “we”) handles personal information in connection with the 1Defender enterprise security platform, our websites, and related services (the “Platform”). Because we process security data on our customers’ behalf, this Policy works together with our Data Processing Addendum (“DPA”).
01 Two roles: controller and processor
We handle two categories of data, with different responsibilities:
- Data we control. Information about our business customers and their personnel, website visitors, and prospects — account, contact, and billing details. Here we act as a controller, and this Policy governs.
- Data we process for you. Security telemetry, logs, configurations, identity data, and findings drawn from your Connected Systems. Here we act as a processor on your instructions, governed by the DPA and your agreement with us. If you are an individual whose data appears in a customer’s environment, contact that customer (the controller) to exercise your rights.
The rest of this Policy concerns data we control.
02 Information we collect
- Account and contact information — name, business email, phone, company, job title, and credentials you provide when you register, request a demo, or correspond with us.
- Billing and wallet information — plan, balance, and transaction history; card processing is handled by our payment processor and we do not store full card numbers.
- Usage and device information — log data such as IP address, browser and device type, pages viewed, and actions within the Platform.
- Communications — your support requests, sales conversations, and survey responses.
- Connected Systems metadata — high-level configuration and account identifiers needed to maintain integrations; the security telemetry itself is processor data under Section 1.
We do not run advertising trackers or sell personal information.
03 How we use information
To provide, maintain, and secure the Platform; authenticate users and prevent fraud or abuse; process billing; respond to inquiries and provide support; send service and, where permitted, marketing messages (which you can opt out of); analyze and improve our products; and comply with legal obligations.
04 Legal bases (EEA / UK)
Where the GDPR or UK GDPR applies, we rely on performance of a contract, our legitimate interests (to secure, operate, and improve our services and for business-to-business marketing, balanced against your rights), consent where required, and legal obligation.
06 International transfers
We may transfer data to countries other than yours. Where required, we use appropriate safeguards such as the EU Standard Contractual Clauses and the UK Addendum.
07 Data retention
We retain controlled data for as long as needed to provide the Platform and for legitimate business and legal purposes, then delete or anonymize it. Processor data is retained per the DPA.
08 Security
We protect personal information with administrative, technical, and organizational measures appropriate to the risk — including encryption in transit and at rest, least-privilege access controls, tenant isolation, and continuous monitoring. No method of transmission or storage is completely secure, and we cannot guarantee absolute security. To report a vulnerability or a security concern, contact security@1defender.ai.
09 Your rights
Depending on where you live, you may have rights to access, correct, delete, port, restrict, or object to processing, and to withdraw consent. California residents have CCPA/CPRA rights, including to know, delete, correct, and opt out of “sale” or “sharing” (we do neither), without discrimination. EEA and UK residents have GDPR rights, including to lodge a complaint with a supervisory authority. To exercise rights, contact privacy@1defender.ai. We will verify your request and respond within the timeframes the law requires; if your data is processor data (Section 1), we will refer you to the relevant customer.
10 Cookies and tracking
Our public marketing site does not run advertising or third-party analytics trackers, and does not build advertising or behavioral profiles. It loads web fonts from a third-party provider (Google Fonts) to render the site. The signed-in Platform uses strictly necessary cookies and similar local storage to keep you authenticated, remember your interface preferences (such as light or dark theme), and secure your session. Where local law requires consent for non-essential cookies, we will request it before setting them.
11 Children
The Platform is a business product not directed to children, and we do not knowingly collect personal information from children under 16.
12 Changes to this Policy
We may update this Policy. Material changes take effect when posted, with additional notice where required. The “Last updated” date reflects the latest revision.
13 · Contact us
1Defender, Inc.
Privacy questions and requests: privacy@1defender.ai · support@1defender.ai
On request we will provide our current registered mailing address for formal or legal correspondence.