Third Party Index

Snapshot 17288

Document
Privacy policy
URL
https://www.contraforce.com/privacy-policy
Fetched
HTTP status
200
Content type
text/html; charset=utf-8
Fetch mode
browser
Size
65293 bytes
SHA-256 (raw)
b72280f2f2ca305375d11c36398687df0d1cfe5d16f896690d90f29c0379bc08
SHA-256 (normalized text)
cc446046dd9012c8f577ee280a8ee4cff47ff0244619ba1a3f420eda16c0cfac

Normalized text

Scripts and page chrome removed; this is what change detection compares.

Privacy Policy
Effective August 17, 2026
Our Commitment to Privacy
ContraForce prioritizes privacy protection. This privacy statement explains our online information practices and your choices regarding data collection and usage. ContraForce reserves amendment rights and maintains current policy versions on its homepage and at information collection points.
Scope of This Statement
This policy applies to contraforce.com, all subpages, amendments, software, and services including free trials and product reviews (collectively “Services”). The statement does not cover third-party websites, products, or services, even if linked from ContraForce’s site. By using the website, users accept these practices.
Information Collection
Types of Personal Information Collected
•Name
•Company
•Title
•Address
•Email Address
•Phone Number
Cookie, Server Log, and Telemetry Information
ContraForce automatically collects certain technical data when you use the Services, including through Microsoft Azure Application Insights. This data may include:
•IP address
•Internet browser type and operating system
•Visit date and time
•Pages visited and user interactions within the Services
•Session identifiers (stored in session storage, not persistent cookies)
•Performance metrics and error diagnostics
•Referring website information
•Search engine and search terms used to reach the Services
This data is used to maintain platform security and reliability, diagnose technical issues, monitor performance, and improve the Services. Azure Application Insights is configured to use session storage rather than persistent cookies for this purpose. Session-based identifiers expire when the browser session ends.
Information Usage
ContraForce uses provided information to deliver requested services, answer emails, process requests, and contact users regarding service follow-ups. The company may contact users about company interest, services, promotions, and events.
You will not be added to any ContraForce email list without your consent — opt-in defaults to OFF. Each newsletter includes an unsubscribe option. Non-identifying aggregate information improves website design and advertising without revealing individual identities.
Lawful Basis for Processing (EEA and UK Users)
For users located in the European Economic Area or United Kingdom, ContraForce processes personal data on the following lawful bases under GDPR Article 6:
•Contract Performance (Article 6(1)(b)) — Processing necessary to deliver the Services you have contracted for, including account management, authentication, and service delivery.
•Legitimate Interests (Article 6(1)(f)) — Processing of operational telemetry data — including via Azure Application Insights — for the purposes of platform security, reliability monitoring, and service improvement. ContraForce has conducted a Legitimate Interests Assessment and determined that these interests are not overridden by your interests or fundamental rights, given the limited nature of the data collected, its strictly operational use, and the reasonable expectation of professional users that a SaaS security platform collects operational telemetry. You have the right to object to processing on this basis by contacting [email protected].
•Legal Obligation (Article 6(1)(c)) — Processing required to comply with applicable law, including responding to lawful requests from regulatory or law enforcement authorities.
•Consent (Article 6(1)(a)) — Where required and not covered by the above bases, ContraForce will seek your explicit consent prior to processing. Where processing is based on consent, you may withdraw it at any time without affecting the lawfulness of processing prior to withdrawal.
Data Retention
ContraForce retains personal data only for as long as necessary to fulfill the purposes for which it was collected, to meet contractual obligations, or to comply with legal requirements.
•Operational Telemetry (App Insights) — Retained for 90 days by default. Data is automatically purged in accordance with the Azure Application Insights retention configuration.
•Account Information — Retained for the duration of the active account and for up to 3 years following account closure for legal, contractual, and audit compliance purposes.
•Email and Communications — Retained for the duration necessary to fulfill the communication purpose and as required by applicable law.
Specific retention schedules are managed by the Chief Privacy Officer and are available upon request by contacting [email protected].
Information Sharing and Disclosure
No Sales or Rentals. ContraForce does not sell or rent personal information to marketers or third parties.
Permitted Sharing
•Trusted third parties integral to website and service operations
•ContraForce partners, payment processors, verification services
•Authorized recipients designated by users
•Hosting providers and co-located databases
•Microsoft Azure (as a data processor for telemetry and infrastructure services)
Legal Disclosures. Information may be disclosed to law enforcement or government officials when legally compelled by subpoena, court order, or legal process. Disclosure occurs when required by law or when reasonably necessary to prevent physical harm or financial loss.
Merger / Acquisition. Personal information may transfer to successors or assigns during organizational changes.
Your Rights (EEA and UK Users)
If you are located in the European Economic Area or United Kingdom, you have the following rights regarding your personal data under applicable data protection law:
•Right of Access (Article 15) — Request a copy of the personal data ContraForce holds about you, along with information about how it is processed.
•Right to Rectification (Article 16) — Request correction of inaccurate or incomplete personal data without undue delay.
•Right to Erasure (Article 17) — Request deletion of your personal data where it is no longer necessary for the purposes for which it was collected, where you have withdrawn consent, or where processing is unlawful.
•Right to Restriction (Article 18) — Request that processing be restricted in certain circumstances, including where you contest the accuracy of data or object to processing.
•Right to Data Portability (Article 20) — Receive personal data you have provided to ContraForce in a structured, commonly used, machine-readable format, and request its transmission to another controller where technically feasible.
•Right to Object (Article 21) — Object to processing of your personal data based on legitimate interests or for direct marketing purposes. Where you object to processing based on legitimate interests, ContraForce will cease processing unless it can demonstrate compelling legitimate grounds.
•Right to Withdraw Consent — Where processing is based on consent, withdraw it at any time without affecting the lawfulness of prior processing.
To exercise any of these rights, contact [email protected]. ContraForce will respond within 30 days of receipt. There is no charge for exercising your rights unless requests are manifestly unfounded or excessive.
You also have the right to lodge a complaint with your local data protection supervisory authority. For UK users, this is the Information Commissioner’s Office (ICO) at ico.org.uk. For EEA users, this is the supervisory authority in the EU member state where you are habitually resident, where you work, or where the alleged infringement occurred.
Choice and Opt-Out
Users can decline personal information provision (which may limit service access) or opt-out of email communications via unsubscribe links. Browser settings can be modified to limit session storage, though this may disable certain website features.
EEA and UK users may additionally exercise their right to object to legitimate-interests processing as described in the Your Rights section above.
Data Security Commitment
We have put in place appropriate physical, electronic, and managerial procedures to safeguard and secure the information we collect online. The Chief Privacy Officer manages confidentiality, integrity, and availability of personal information with accompanying policies, procedures, and technical controls.
Children's Privacy
ContraForce does not knowingly collect information from those under 18 and has no website content targeting minors. Inadvertently collected child information is deleted immediately.
Online Forums
Chat rooms, forums, message boards, and news groups are public venues where disclosed information becomes public. ContraForce does not request confidential information through these channels.
Third-Party Vendor Advertising
Third parties, including Google, display ContraForce advertisements across the internet using cookies based on prior website visits. Users can opt-out through Google’s advertising opt-out page.
International Data Transfers
EU-U.S. Data Privacy Framework
ContraForce complies with the EU-U.S. Data Privacy Framework (EU-U.S. DPF) and the UK Extension to the EU-U.S. DPF as set forth by the U.S. Department of Commerce. ContraForce has certified to the U.S. Department of Commerce that it adheres to the EU-U.S. Data Privacy Framework Principles with regard to the processing of personal data received from the European Union in reliance on the EU-U.S. DPF, and from the United Kingdom in reliance on the UK Extension to the EU-U.S. DPF. If there is any conflict between the terms in this privacy policy and the EU-U.S. DPF Principles, the Principles shall govern. To learn more about the Data Privacy Framework (DPF) program, and to view our certification, please visit Data Privacy Framework.
Onward Transfer Liability
ContraForce is responsible for the processing of personal data it receives, under the DPF, and subsequently transfers to a third party acting as an agent on its behalf. ContraForce complies with the DPF Principles for all onward transfers of personal data from the EU and UK including the onward transfer liability provisions.
Regulatory Jurisdiction and Lawful Access
The Federal Trade Commission has jurisdiction over ContraForce’s compliance with the EU-U.S. DPF and the UK Extension to the EU-U.S. DPF. In certain situations, ContraForce may be required to disclose personal data in response to lawful requests by public authorities, including to meet national security or law enforcement requirements.
Canadian Recognition
The EU Commission recognizes Canada’s Personal Information Protection and Electronic Documents Act (PIPEDA) as providing adequate protection for EU personal data transfers.
Dispute Resolution
EU and UK individuals with inquiries or complaints regarding our handling of personal data received in reliance on the EU-U.S. DPF and the UK Extension to the EU-U.S. DPF should first contact ContraForce at [email protected] and give us the opportunity to resolve your complaint. We will respond to your complaint promptly.
In compliance with the EU-U.S. DPF and the UK Extension to the EU-U.S. DPF, ContraForce Group, Inc. commits to cooperate and comply respectively with the advice of the panel established by the EU data protection authorities (DPAs) and the UK Information Commissioner’s Office (ICO) with regard to unresolved complaints concerning our handling of personal data other than human resources data received in reliance on the EU-U.S. DPF and the UK Extension to the EU-U.S. DPF. These dispute resolution services are provided at no cost to you.
In compliance with the UK Extension to the EU-U.S. DPF, ContraForce Group, Inc. commits to cooperate and comply with the advice of the UK Information Commissioner’s Office (ICO) with regard to unresolved complaints concerning our handling of human resources data received in reliance on the UK Extension to the EU-U.S. DPF in the context of the employment relationship.
For complaints regarding DPF compliance not resolved by any of the other DPF mechanisms, you have the possibility, under certain conditions, to invoke binding arbitration. Further information can be found on the official Data Privacy Framework website.
Privacy Principles
•Accountability — A Chief Privacy Officer (CPO) manages documented roles and responsibilities for personally identifiable information handling.
•Identifying Purposes — Personal information processed aligns with legitimately defined purposes.
•Consent — Plain language privacy notices precede participation. All consent modifications and withdrawals are CPO-managed via [email protected].
•Limiting Collection — Collection restricted to minimum necessary information for service provision to clients, human resource operations, and legal compliance.
•Limiting Use, Disclosure, and Retention — Information is used, disclosed, or retained only for stated collection purposes and necessary durations. Additional uses require client notification and explicit documented consent.
•Accuracy — ContraForce ensures retained information is accurate, complete, and current for proper service and operations.
•Safeguards — The CPO manages confidentiality, integrity, and availability of personal information with accompanying policies, procedures, and technical controls.
•Openness — Privacy practices are summarized in this public website privacy statement.
•Individual Access — Personal information access requests are addressed via CPO email contact.
•Challenging Compliance — Procedures address inquiries, concerns, and complaints regarding personal information handling. The CPO shall respond within a reasonable amount of time.
Contact Information
Primary Contact: [email protected]
Privacy Contact: [email protected]
Nominated European Representative (GDPR Article 27):
[email protected]
Headquarters
5 Cowboys Way, Suite 300
Frisco, TX 75034
London Office
124 Wigmore Street
London W1U 3RY