Book a Consultation

Legal

Privacy Policy

Last Updated: [Insert Date]

Griffendo, operated by [Insert Legal Entity Name] ("Griffendo," "we," "our," or "us"), respects your privacy. This Privacy Policy explains how we collect, use, disclose, and protect personal information when you visit griffendo.com, interact with our website, submit forms, use our ROI calculator, request pricing, contact us, or otherwise engage with Griffendo online.

This Privacy Policy applies to our website and marketing interactions. If you are a Griffendo customer, the processing of security telemetry, logs, alerts, incident data, customer environments, integrations, or managed security operations data may also be governed by a separate Master Services Agreement, Data Processing Addendum, Statement of Work, or other written agreement.

1. Information We Collect

We may collect the following types of information.

Information you provide directly

You may provide personal information when you:

  • Submit a contact form
  • Request pricing
  • Request an assessment
  • Use the ROI calculator
  • Download content or resources
  • Subscribe to updates
  • Communicate with us by email, phone, or other channels

This may include:

  • First and last name
  • Business email address
  • Company name
  • Job title
  • Phone number
  • Country, region, or location selection
  • Inquiry type
  • Message content
  • Consent preferences
  • Information submitted through the ROI calculator, such as endpoint count, identity count, estimated breach exposure, or related business inputs

Please do not submit sensitive personal information through public website forms unless we specifically request it.

Information collected automatically

When you visit our website, we may automatically collect technical and usage information, including:

  • IP address
  • Browser type
  • Device type
  • Operating system
  • Referring URL
  • Pages visited
  • Time spent on pages
  • Clicks and interactions
  • Date and time of visit
  • Cookie and analytics identifiers
  • General geographic location inferred from IP address

Geolocation and regional routing

Griffendo may use general location information to route visitors to the appropriate regional contact experience, such as United States or EU / Gulf States / India contact pages.

We may infer your country or region from your IP address. If the site requests browser-based geolocation, we will only use it where permitted and where you provide consent through your browser. We do not require precise location data to browse the site.

Customer and service-related data

If you become a Griffendo customer, we may process security-related data in connection with our managed security operations services. This may include logs, alerts, endpoint telemetry, identity events, network events, cloud events, investigation records, support tickets, threat intelligence, and incident response information.

That data is handled according to the applicable customer agreement and is not governed solely by this website Privacy Policy.

2. How We Use Information

We may use personal information to:

  • Respond to inquiries
  • Route your inquiry to the correct regional team
  • Provide pricing information
  • Schedule assessments or demos
  • Generate or improve ROI calculator outputs
  • Provide requested resources
  • Operate and improve the website
  • Analyze website traffic and performance
  • Personalize website content where appropriate
  • Send marketing communications, where permitted
  • Manage preferences and consent
  • Detect, prevent, or investigate fraud, abuse, security incidents, or misuse
  • Maintain records of communications
  • Comply with legal, regulatory, contractual, or security obligations
  • Support business operations, reporting, and analytics

We may also use aggregated or de-identified information that does not reasonably identify you for analytics, benchmarking, product improvement, and business planning.

3. Legal Bases for Processing

Where applicable, we process personal information based on one or more of the following legal bases:

  • Consent, such as when you opt in to marketing communications or accept non-essential cookies.
  • Contract, where processing is necessary to provide requested services or take steps before entering into a contract.
  • Legitimate interests, such as operating our website, responding to business inquiries, improving our services, protecting our systems, and conducting business-to-business marketing where permitted.
  • Legal obligation, where processing is necessary to comply with applicable laws, regulations, legal processes, or enforceable requests.
  • Protection of rights and security, where processing is necessary to protect Griffendo, our customers, website visitors, or others.

4. How We Share Information

We may share personal information with the following categories of recipients.

Service providers

We may share information with vendors and service providers that help us operate our website and business, such as:

  • Website hosting providers
  • Analytics providers
  • CRM and sales tools
  • Email and communications platforms
  • Marketing automation tools
  • Form processing tools
  • Security and fraud prevention tools
  • Cloud infrastructure providers
  • Customer support tools

These providers are authorized to use personal information only as needed to provide services to us, subject to applicable contractual protections.

Business partners and integrations

Where relevant, we may share information with authorized partners, resellers, technology providers, or integration partners to respond to your inquiry, deliver services, or support customer-requested integrations.

Legal and compliance purposes

We may disclose information if we believe it is necessary to:

  • Comply with law or legal process
  • Respond to lawful requests
  • Protect our rights, property, systems, or users
  • Enforce our agreements
  • Investigate fraud, security incidents, or misuse
  • Protect against harm or illegal activity

Business transfers

If Griffendo is involved in a merger, acquisition, financing, reorganization, sale of assets, or similar business transaction, personal information may be transferred as part of that transaction.

5. Cookies and Tracking Technologies

We use cookies, pixels, tags, scripts, and similar technologies to operate the website, understand usage, improve performance, and support marketing where appropriate consent is given.

Cookie categories

We use the following categories of cookies and tracking technologies:

  • Necessary cookies — required for the website to function and cannot be disabled. These include consent preference storage and session management.
  • Analytics cookies — help us understand how visitors use the website, including traffic patterns, page performance, and interaction data. These are only loaded when analytics consent is granted.
  • Marketing cookies — help Griffendo measure campaign performance and deliver relevant retargeting ads through advertising partners, including Google Ads, LinkedIn, Meta, and Microsoft Advertising. These are only loaded when marketing consent is granted.
  • Functional cookies — support optional features such as user preference storage or enhanced user experience. Only loaded when functional consent is granted.

Consent and preference management

Where required by law, we request consent before loading non-essential cookies. You can manage your cookie preferences at any time using our cookie preference tool, available from the footer of any page.

Griffendo uses Google Consent Mode v2. Non-essential consent signals are set to denied by default and only updated to granted after you make a choice.

We store your consent preference in a first-party browser cookie and localStorage using the key griffendo_cookie_consent_v1. This cookie contains only your preference selection — not your name, email, company, form inputs, or any other personal information.

Global Privacy Control

Where applicable, Griffendo honors the Global Privacy Control (GPC) signal. If your browser or extension sends a GPC signal, Griffendo will automatically treat this as an opt-out of marketing cookies and targeted advertising where required by law.

6. Analytics and Advertising

Analytics tools

When analytics consent is granted, we may use analytics tools including Google Analytics and Google Tag Manager to understand website traffic, visitor behavior, and marketing performance. These tools may collect information such as approximate IP address, device type, browser, pages visited, time on site, and click interactions.

Analytics data is used to improve the website, measure content performance, and understand how visitors navigate to and through Griffendo.com. We do not use analytics tools to build detailed personal profiles for sale.

Advertising and retargeting pixels

When marketing consent is granted, we may load advertising pixels from third-party platforms including Google Ads, LinkedIn, Meta (Facebook/Instagram), and Microsoft Advertising. These pixels may:

  • Record that your browser visited Griffendo.com or specific pages such as the pricing, ROI calculator, or contact pages
  • Allow advertising platforms to show Griffendo ads to visitors who have previously visited the website (retargeting)
  • Measure campaign performance and conversions

Advertising partners may process cookie identifiers, device identifiers, browsing activity on Griffendo.com, and interaction data to support retargeting and measurement.

We do not send your name, email address, phone number, company, form message content, ROI calculator inputs, or security information to advertising platforms through these pixels.

Retargeting pixels are only loaded after marketing consent is granted. No marketing pixel fires before consent.

Retargeting audience management

Retargeting audiences are managed inside advertising platforms such as Google Ads, LinkedIn Campaign Manager, Meta Ads Manager, and Microsoft Advertising — not inside Griffendo's own systems. Griffendo does not maintain or manage retargeting audience lists outside of those advertising platforms.

7. Do Not Sell or Share Personal Information

Griffendo does not sell personal information for money.

However, some uses of advertising pixels and retargeting technologies may be considered a "sale," "sharing," or targeted advertising under applicable privacy laws, including California privacy laws. Where applicable, visitors may opt out of these activities.

How to opt out

  • Use our Cookie Preferences link in the footer to reject marketing cookies at any time.
  • Use the "Do Not Sell or Share My Personal Information" link in the footer to specifically opt out of advertising cookie use.
  • Enable Global Privacy Control in your browser or browser extension, and Griffendo will honor this signal where required by law.

If you opt out, marketing pixels will not load and no retargeting activity will occur from Griffendo.com. You may still see Griffendo ads through other means, such as keyword search, where targeting does not rely on cookie identifiers.

8. Marketing Communications

If you receive marketing communications from us, you may opt out at any time by using the unsubscribe link in the message or by contacting us.

Even if you opt out of marketing communications, we may still send non-marketing messages, such as responses to inquiries, service-related messages, security notices, or transactional communications.

9. Data Retention

We retain personal information for as long as necessary to fulfill the purposes described in this Privacy Policy, unless a longer retention period is required or permitted by law.

Retention periods may depend on:

  • The type of information
  • The reason we collected it
  • The nature of our relationship with you
  • Legal, contractual, tax, audit, or compliance obligations
  • Security and fraud prevention needs
  • Whether you request deletion

Customer security data, logs, alerts, and service-related information are retained according to the applicable customer agreement.

10. Security

We use reasonable administrative, technical, and organizational measures to protect personal information. These measures are designed to help protect against unauthorized access, disclosure, alteration, and destruction.

No website, network, system, or method of transmission is completely secure. We cannot guarantee absolute security.

11. International Data Transfers

Griffendo may process and store information in the United States and other countries where we, our service providers, partners, or infrastructure providers operate.

If personal information is transferred across borders, we use appropriate safeguards where required by applicable law. These may include contractual safeguards, data processing agreements, standard contractual clauses, or other lawful transfer mechanisms.

12. Your Privacy Rights

Depending on where you live, you may have rights regarding your personal information. These rights may include the right to:

  • Request access to personal information
  • Request correction of inaccurate information
  • Request deletion of personal information
  • Request a copy of personal information
  • Object to or restrict certain processing
  • Withdraw consent where processing is based on consent
  • Opt out of marketing communications
  • Opt out of sale, sharing, targeted advertising, or certain profiling where applicable
  • Lodge a complaint with a data protection authority or regulator

To exercise your rights, contact us at:

Email: privacy@griffendo.com

Mail: [Insert Company Address]

We may need to verify your identity before processing your request.

13. California Privacy Notice

If you are a California resident, you may have additional rights under California privacy laws, where applicable.

In the past 12 months, we may have collected the following categories of personal information:

  • Identifiers, such as name, email address, phone number, and IP address
  • Commercial information, such as pricing requests, service inquiries, and downloaded resources
  • Internet or network activity, such as pages viewed, clicks, browser information, and device information
  • Geolocation data, such as approximate location inferred from IP address or region selection
  • Professional information, such as company, job title, and business contact details
  • Inferences, such as interest in Griffendo services based on site interactions

We collect this information from you directly, automatically through the website, and from service providers or business partners.

We use this information for the purposes described in this Privacy Policy, including responding to inquiries, operating the website, providing services, analytics, marketing, security, and compliance.

We may disclose personal information to service providers, business partners, analytics providers, marketing tools, security providers, and legal or compliance recipients as described above.

California residents may have the right to:

  • Know what personal information we collect, use, disclose, sell, or share
  • Access personal information
  • Delete personal information
  • Correct inaccurate personal information
  • Opt out of sale or sharing
  • Limit certain uses of sensitive personal information, where applicable
  • Not be discriminated against for exercising privacy rights

To submit a request, contact privacy@griffendo.com.

14. India Privacy Notice

If you are located in India, you may have rights under applicable Indian data protection laws. These may include rights to access information about processing, request correction or erasure, withdraw consent where processing is based on consent, and raise grievances.

To submit a request or grievance, contact:

Email: privacy@griffendo.com

Grievance Contact: [Insert Grievance Officer / Contact Name if required]

15. EU / UK / EEA Privacy Notice

If you are located in the European Union, United Kingdom, or European Economic Area, you may have additional rights under applicable data protection laws.

For website and marketing interactions, Griffendo acts as a controller of the personal information it collects directly from visitors and prospects.

For customer security data processed as part of Griffendo managed security services, Griffendo may act as a processor or service provider, depending on the applicable customer agreement.

You may have the right to access, correct, delete, restrict, object to, or receive a copy of your personal information. You may also withdraw consent where processing is based on consent.

You may contact us at privacy@griffendo.com.

You may also have the right to lodge a complaint with your local data protection authority.

16. Children's Privacy

Our website and services are intended for business users and are not directed to children. We do not knowingly collect personal information from children under 13 or the applicable age of consent in your jurisdiction.

If you believe a child has provided personal information to us, please contact us so we can take appropriate action.

17. Third-Party Links

Our website may contain links to third-party websites, platforms, resources, or services. We are not responsible for the privacy practices of those third parties. We encourage you to review their privacy policies before providing personal information.

18. Changes to This Privacy Policy

We may update this Privacy Policy from time to time. If we make material changes, we will update the "Last Updated" date and may provide additional notice where required.

Your continued use of the website after an updated Privacy Policy is posted means that you acknowledge the updated policy.

19. Contact Us

For privacy questions, requests, or concerns, contact us at:

Griffendo

[Insert Legal Entity Name]

[Insert Company Address]

Email: privacy@griffendo.com

Website: https://griffendo.com

Before Publishing

Replace all placeholder text: [Insert Date], [Insert Legal Entity Name], [Insert Company Address], and [Insert Grievance Officer / Contact Name if required] before making this page public.