Privacy Policy
Last updated:
Email:
1. About this policy
This privacy policy explains how TriaGuard LTD (“TriaGuard”, “we”, “us” or “our”) collects, uses and discloses personal data about you when you visit our website at www.triaguard.com (the “Website”), interact with us in connection with our products and services, attend our events, or use our automated security alert triage platform (the “Services”).
This policy applies when we act as a controller of personal data. When we provide the Services to our business customers, we generally process personal data on their behalf as a processor. In that case, our processing is governed by the relevant customer’s privacy notices and the data processing agreement we have entered into with that customer; please refer to the relevant customer if you have questions about how their data is handled.
This policy is intended to satisfy our obligations under the United Kingdom General Data Protection Regulation, the Data Protection Act 2018 and other applicable data protection laws (together, “Data Protection Laws”).
2. Who we are and how to contact us
TriaGuard LTD is a company incorporated in England and Wales with company number 17088962 and registered office at 167-169 Great Portland Street, London, England, W1W 5PF. We are the controller of the personal data we collect about you when we are described as the controller in this policy.
If you have any questions or concerns about this policy or the way we handle your personal data, please contact us at info@triaguard.com.
3. The personal data we collect
We collect different categories of personal data depending on how you interact with us. The categories below describe what we collect when we act as a controller.
3.1 Visitors to our Website
Technical data such as IP address, device type, browser type and version, operating system, language preferences and information about how you use the Website.
Cookie and similar tracking data, as described in our Cookie Policy.
Information you submit through Website forms (for example, contact forms or demo requests), such as your name, business email address, telephone number, employer and any message content.
3.2 Prospective customers and business contacts
Identification and contact data such as name, business email address, telephone number, job title and employer.
Communications and meeting notes generated when you contact us, attend a demo or pilot, or otherwise engage with our sales, customer success or support teams.
Marketing data, including your marketing preferences and your engagement with our marketing communications and content.
Limited information from publicly available sources or third-party providers (for example, LinkedIn or business intelligence providers) used to enrich our records and target our outreach.
3.3 Customer administrators and authorised users of the Services
Account data, including your name, business email address, role, and authentication credentials.
Usage and security logs, including login times, IP addresses, the actions you perform in the Services and the configuration changes you make.
Support data, including the content of any tickets, calls or messages you submit to our support team.
3.4 Other interactions
If you apply for a job with us, we will process the personal data set out in our recruitment privacy notice (available on request).
If you attend an event we host, we may process registration data, attendance information and, where relevant, dietary or accessibility requirements.
If you contact us through social media, we may process the public information you make available there.
4. How we use personal data and our legal bases
Under Data Protection Laws, we must have a legal basis to process your personal data. The table below sets out the main purposes for which we process personal data and the legal basis we rely on.
Purpose | Categories of data | Legal basis |
|---|---|---|
Operating, maintaining and securing the Website | Technical data, cookie data | Legitimate interests (running and protecting our Website); where required, your consent (for non-essential cookies) |
Responding to enquiries and providing information you request | Identification and contact data, communications data | Performance of a contract or steps prior to entering into a contract; legitimate interests (responding to communications) |
Pre-sales activities, demos, pilots and account set-up | Identification and contact data, communications data, marketing data | Performance of a contract or steps prior to entering into a contract; legitimate interests (developing our business) |
Providing, maintaining and supporting the Services to our customers and their authorised users | Account data, usage and security logs, support data | Performance of a contract; legitimate interests (operating our business and providing the Services) |
Securing our Website, our Services and our internal systems, and detecting, investigating and preventing security incidents and fraud | Technical data, account data, usage and security logs | Legitimate interests (information security); legal obligation (where required to take security measures) |
Sending marketing communications about products, services and events that may interest you | Identification and contact data, marketing data | Consent (where required); legitimate interests (where we have an existing business relationship and we offer a clear opt-out) |
Operating, improving and developing our products and services, including with anonymised and aggregated data | Limited usage data; data that has been aggregated or anonymised | Legitimate interests (developing and improving our offerings) |
Complying with our legal and regulatory obligations and exercising or defending legal claims | Any of the above as necessary | Legal obligation; legitimate interests (managing our legal affairs) |
Recruitment and HR processes | Information set out in our recruitment notice | Steps prior to entering into an employment contract; legitimate interests; legal obligation |
Where we rely on legitimate interests, we have carried out a balancing assessment to ensure that our interests are not overridden by your rights. You can request information about that assessment by contacting us using the details in section 2.
5. Cookies and similar technologies
Our Website uses cookies and similar technologies. For details of the cookies we use, the purposes for which we use them and how to manage your preferences, please see our Cookie Policy.
6. Marketing
We may send marketing communications by email to business contacts in accordance with applicable law. You can unsubscribe at any time by clicking the “unsubscribe” link in any marketing email or by contacting us at info@triaguard.com. Your unsubscribe request applies to marketing communications only; we may continue to send you service or transactional communications that are necessary for the operation of any ongoing relationship.
7. Sharing personal data
We do not sell your personal data. We may share your personal data with the following categories of recipient, in each case only to the extent necessary for the purposes set out in this policy.
Members of our group, including affiliates and subsidiaries, that need access to deliver our products and services.
Service providers and processors that help us run our business and the Services. This includes our cloud hosting and security infrastructure provider Microsoft Azure (Microsoft Corporation and Microsoft Ireland Operations Limited), our large language model provider Anthropic, PBC, and other technology, communications, payment, recruiting, professional services and analytics providers.
Professional advisers, including lawyers, accountants, auditors and insurers, where reasonably necessary.
Law enforcement, regulators, courts and other public authorities, where required by law or where reasonably necessary to enforce our rights or protect our property and safety.
Actual or prospective acquirers, investors and their advisers in connection with any actual or proposed merger, acquisition, sale of assets, financing or similar transaction, subject to appropriate confidentiality obligations.
All processors who handle personal data on our behalf are bound by written agreements requiring them to comply with Data Protection Laws and to protect your personal data.
8. International transfers
Some of our service providers (for example, Anthropic in the United States and certain support and engineering functions of Microsoft Azure) are located, or process personal data, outside the United Kingdom. Where we transfer personal data to a country that is not the subject of UK adequacy regulations, we put in place an appropriate safeguard, such as the International Data Transfer Agreement (IDTA) or the EU Standard Contractual Clauses supplemented by the UK International Data Transfer Addendum, together with any additional measures required to ensure that your personal data benefits from a level of protection essentially equivalent to that guaranteed within the United Kingdom.
You can request a copy of the safeguards we have in place by contacting us at info@triaguard.com.
9. How long we keep your personal data
We retain personal data for no longer than is necessary for the purposes for which it was collected, taking into account our legal obligations, our contractual commitments and any legitimate operational needs. The table below summarises our typical retention periods.
Category | Retention period |
|---|---|
Website analytics and cookie data | As set out in our Cookie Policy. |
Sales and marketing contact data | For the duration of our active business relationship and for up to 3 years after the last meaningful interaction, unless you ask us to delete it earlier. |
Customer account and Service usage data | For the duration of the relevant subscription and for up to 12 months after termination, except where a longer retention period is required by law or to defend legal claims. |
Support tickets and communications | For up to 12 months after closure of the ticket. |
Financial and tax records | For at least 6 years to comply with UK accounting and tax laws. |
Legal claims | For the duration of the limitation period applicable to the relevant claim. |
After the applicable retention period expires, we will securely delete or anonymise the relevant personal data.
10. How we keep your personal data secure
We have implemented appropriate technical and organisational measures designed to protect personal data against unauthorised or unlawful processing and accidental loss, destruction or damage. These measures include access controls, encryption of data in transit and at rest, network segmentation, vulnerability management and regular security testing, security training for personnel, and incident response procedures.
Although we work hard to protect personal data, no method of transmission over the internet or electronic storage is fully secure. If you have reason to believe that your personal data is at risk, please contact us immediately.
11. Your rights
Depending on the circumstances, you have the following rights under Data Protection Laws.
Right of access: you can ask us for a copy of the personal data we hold about you and certain related information.
Right to rectification: you can ask us to correct inaccurate or incomplete personal data.
Right to erasure: you can ask us to delete your personal data in certain circumstances.
Right to restrict processing: you can ask us to restrict the processing of your personal data in certain circumstances.
Right to data portability: where we process your personal data on the basis of consent or contract by automated means, you can ask us to provide your data in a structured, commonly used and machine-readable format and to transmit it to another controller.
Right to object: you can object to the processing of your personal data where we rely on legitimate interests, including for direct marketing purposes.
Right to withdraw consent: where we rely on your consent to process your personal data, you can withdraw that consent at any time. Withdrawal does not affect the lawfulness of processing carried out before withdrawal.
Rights in relation to automated decision-making: we do not make decisions about you based solely on automated processing that produce legal or similarly significant effects in relation to our customer-facing relationships. If this changes, we will update this policy and provide additional information.
You can exercise these rights by contacting us at info@triaguard.com. We may need to verify your identity before responding. We will respond within the time periods required by Data Protection Laws (typically within one month, which may be extended in complex cases).
If you are unhappy with the way we handle your personal data, you have the right to lodge a complaint with the UK Information Commissioner’s Office (ICO) at www.ico.org.uk or by calling 0303 123 1113. We would, however, appreciate the opportunity to address your concerns first, so please contact us before approaching the ICO.
12. Children
Our Website and Services are not directed at children under 16 and we do not knowingly collect personal data about them. If you believe a child has provided us with personal data, please contact us using the details in section 2 and we will take appropriate steps to delete it.
13. Third-party links
Our Website may contain links to third-party websites, services and applications. This policy does not apply to those third parties, and we are not responsible for their privacy practices. We encourage you to read the privacy policies of any third party before providing personal data to them.
14. Changes to this policy
We may update this policy from time to time. The “Last updated” date at the top of the policy indicates when it was last revised. If we make material changes, we will notify you, for example by posting a prominent notice on our Website or by emailing you. We encourage you to review this policy regularly.
15. Contact us
If you have any questions about this policy or how we handle your personal data, please contact us at:
TriaGuard LTD
167-169 Great Portland Street, London, England, W1W 5PF
Email: info@triaguard.com