Third Party Index

Snapshot 17947

Document
Trust center
URL
https://trust.patchmypc.com/
Fetched
HTTP status
200
Content type
text/html
Fetch mode
browser
Size
437044 bytes
SHA-256 (raw)
76f294a7a3586bccd81c6b850594f50accf7a769ed773b25e416bd734db74dcb
SHA-256 (normalized text)
0715e6fc07c6a61d289cec99a0fae75d6bb2de10e0f5928e379cebe643c01d4f

Normalized text

Scripts and page chrome removed; this is what change detection compares.

Skip to navigationSkip to main content
Patch My PC
Founded in 2011, we’re a team of 125 dedicated to keeping you more secure online and making application management easy.
Our Trust portal provides access security and privacy related resources, certificates, sub-processor information and documentation.
[email protected]
Privacy PolicyOpens in new tab
Filter by
Compliance
ISO 27001:2022
SOC 2 Type 2
GDPR
Resources
View all
Certifications
EU-US Data Protection Framework Program
Opens in new tab
ISO 27001:2022 - Statement of ApplicabilityOpens in new tab
SOC 2 Type II Report
Security Documentation
2025 External Penetration Test
2025 External Pentest Attestation Letter
Incident Response Plan (IRP)
Business Continuity Plan (BCP)
View 3 more
Data Flow Information
On-Premises Data Flow DiagramOpens in new tab
View 1 more
Questionnaires
CAIQ 2025Opens in new tab
VPAT 2026Opens in new tab
SIGLITE 2025Opens in new tab
HECVAT 2026Opens in new tab
Values and Policies
Our Core Values
Opens in new tab
GDPR
Transfer Impact AssessmentOpens in new tab
Controls
View all
Infrastructure security
Unique production database authentication enforced
Encryption key access restricted
Unique account authentication enforced
View 17 more Infrastructure security controls
Organizational security
Asset disposal procedures utilized
Portable media encrypted
Anti-malware technology utilized
View 8 more Organizational security controls
Product security
Data encryption utilized
Control self-assessments conducted
Penetration testing performed
View 2 more Product security controls
Internal security procedures
Continuity and Disaster Recovery plans established
Continuity and Disaster Recovery plans tested
Cybersecurity insurance maintained
View 34 more Internal security procedures controls
Data and privacy
Data retention procedures established
Customer data deleted upon leaving
Data classification policy established
Data collected
Employee personally identifiable information
Credit card information
Personal health information
Subprocessors
View all
Microsoft
•
Cloud provider
United States & EEA
Purpose: Microsoft is the backbone of our infrastructure, used for e-mail, hosting services in Azure to support our Cloud resources, and more. Depending on the nature of any interaction with Patch My PC team members or a Patch My PC service, some or all of the below information may be processed or stored.
Stored: First name, surname, email address, IP Address. If using our Cloud SaaS solution additional device metadata may be stored depending on the services used; see the data collection matrix for details.
Scope: Every person that is communicating with Patch My PC and every company using a Patch My PC service.
Salesforce
•
Customer Relationship Management
United States
Purpose: Customer relationship management tool. Salesforce is responsible for support case management and tracking of customer communications during the sales cycle. Some customer usage data is re-surfaced here from our usage data stored in Azure. All Salesforce data is stored in and accessed from North America.
Stored: First Name, surname, email address, social media profile IDs/links (if provided)
Scope: Every person that is a customer with Patch My PC.
CloudFlare
•
Cloud Monitoring & WAF
United States
Purpose: Cloudflare serves as a content redistribution tool for our primary website, patchmypc.com, and as a Web Application Firewall (WAF) for our production services. All traffic to these sites is routed through CloudFlare to act as an edge firewall protection.
Stored: IP Address
Scope: Every person that is interacting or communicating with Patch My PC's website or services.
HubSpot
•
Marketing Behavior Analytics
United States
Purpose: Lead management and collection, especially at conferences and events. Also used to ensure delivery of mass communication messages to customers. Tracks engagement across social media platforms.
Stored: First name, surname, email address, Social Media profile IDs/links (if provided)
Scope: Every person that is communicating with Patch My PC for marketing purposes.
FAQ
View all
Updates
View all
Compliance
Notice of New Sub-Processor: Gong
Published July 8, 2026
At Patch My PC, we are committed to being transparent about the third-party service providers we use to support our business operations. As part of that commitment, we wanted to let you know about an upcoming update to our sub-processor list. This tool is only used as part of the customer relationship process. Data we receive, generate or otherwise use to generate and provide the Patch My PC solution, is not processed by Gong.
Sub-Processor Name: Gong
**Sub-Processor Category: Sales & Customer Relationship Management (CRM) **
Purpose of Processing: Gong is used to support Patch My PC's pre-sales, customer engagement, and CRM processes. The platform helps our teams manage and improve customer interactions, including product demonstrations, sales conversations, and related support activities. Data Processed: Gong may process business contact information and communications associated with prospective and existing customers, such as name, business email address, and meeting and demo participation information.
Data Not Processed: Gong is not used to access, store, or process customer tenant data, endpoint data, device data, or customer content that Patch My PC processes as part of its software services. Its use is limited to supporting sales, customer engagement, and relationship management activities.
Please see our answers to potential additional questions below:
Why use Gong?
Gong helps our team better understand and improve customer interactions related to product demonstrations, sales conversations, and customer engagement activities. The information processed is limited to business contact and interaction data associated with those activities, helping us provide a better customer experience and more effective support throughout the customer journey.
Has Gong undergone security review by Patch My PC?
Yes. Gong completed our vendor review and security assessment process before being added as a sub-processor. You can see Gong’s Trust Center here: https://trust.gong.io/Opens in new tab.
Can I object to the addition of Gong?
We provide customers with 14 days' notice of any additions or changes to our sub-processor list. Prior to Gong’s implementation, customers may object to the addition of Gong or ask additional questions by emailing [email protected]. Furthermore, Gong can be objected on a case by case basis by declining to allow the tool to record calls you join with Patch My PC.
Thank you for your continued trust in Patch My PC.
Compliance
New SOC 2 Type II Report
Published June 1, 2026
Patch My PC is happy to announce that a new SOC 2 Type II report is available and can be found in the Overview Tab or the Resources Tab.
The new report covers an audit period of April 1, 2025 to March 31, 2026.
Compliance
Subprocessors Clarity Update
Published March 23, 2026
For increased clarity, we have implemented some new features in the trust center and provided a short written explanation on the usage of each of our subprocessors.
The new feature allows the usage of tagging, to define what the subprocessors are used for. We have added, internal, cloud, on-prem, website and tagged each of the subprocessors to their appropriate use cases. Our goal with this is to provide clarity when trying to understand which services use which tools.
Tools marked with only the internal tag, are back office tools used for running the business that may process the first and last name of the contract holder or the administrator.
Additionally, a short purpose statement has been added to each subprocessor.
General
New penetration test report available + FAQ updates
Published March 18, 2026
Hello everyone,
Our latest penetration test report, along with an attestation signed by our Director of Security & IT, has been released for customer review. These documents can be found in the Resources tab.
We've also updated our FAQ page. You'll find expanded FAQ categories for easier navigation as well as a new section about the PSADT App Migration AI tool we've added into Patch My PC Cloud.
If there are any questions, please feel free to reach out to [email protected].
Media
View all
Security Deep Dive Catalog Explanation Opens in new tab
We at Patch My PC often get asked how we validate the integrity of the third-party updates included in our catalog. In this video, we will go review the article containing the procedures we take to ensure the quality and integrity of the patches we publish in our third-party software update catalog.
How to Navigate the Patch My PC Trust Center Opens in new tab
This video covers what security documentation and controls can be found on the Trust Center. It also details how to get access to gated resources and who to contact in case further help is needed.
Subprocessor Type
Patch My PC
Founded in 2011, we’re a team of 125 dedicated to keeping you more secure online and making application management easy.
Our Trust portal provides access security and privacy related resources, certificates, sub-processor information and documentation.
[email protected]
Privacy PolicyOpens in new tab
Filter by
Compliance
ISO 27001:2022
SOC 2 Type 2
GDPR
Resources
View all
Certifications
EU-US Data Protection Framework Program
Opens in new tab
ISO 27001:2022 - Statement of ApplicabilityOpens in new tab
SOC 2 Type II Report
Security Documentation
2025 External Penetration Test
2025 External Pentest Attestation Letter
Incident Response Plan (IRP)
Business Continuity Plan (BCP)
View 3 more
Data Flow Information
On-Premises Data Flow DiagramOpens in new tab
View 1 more
Questionnaires
CAIQ 2025Opens in new tab
VPAT 2026Opens in new tab
SIGLITE 2025Opens in new tab
HECVAT 2026Opens in new tab
Values and Policies
Our Core Values
Opens in new tab
GDPR
Transfer Impact AssessmentOpens in new tab
Controls
View all
Infrastructure security
Unique production database authentication enforced
Encryption key access restricted
Unique account authentication enforced
View 17 more Infrastructure security controls
Organizational security
Asset disposal procedures utilized
Portable media encrypted
Anti-malware technology utilized
View 8 more Organizational security controls
Product security
Data encryption utilized
Control self-assessments conducted
Penetration testing performed
View 2 more Product security controls
Internal security procedures
Continuity and Disaster Recovery plans established
Continuity and Disaster Recovery plans tested
Cybersecurity insurance maintained
View 34 more Internal security procedures controls
Data and privacy
Data retention procedures established
Customer data deleted upon leaving
Data classification policy established
Data collected
Employee personally identifiable information
Credit card information
Personal health information
Subprocessors
View all
Microsoft
•
Cloud provider
United States & EEA
Purpose: Microsoft is the backbone of our infrastructure, used for e-mail, hosting services in Azure to support our Cloud resources, and more. Depending on the nature of any interaction with Patch My PC team members or a Patch My PC service, some or all of the below information may be processed or stored.
Stored: First name, surname, email address, IP Address. If using our Cloud SaaS solution additional device metadata may be stored depending on the services used; see the data collection matrix for details.
Scope: Every person that is communicating with Patch My PC and every company using a Patch My PC service.
Salesforce
•
Customer Relationship Management
United States
Purpose: Customer relationship management tool. Salesforce is responsible for support case management and tracking of customer communications during the sales cycle. Some customer usage data is re-surfaced here from our usage data stored in Azure. All Salesforce data is stored in and accessed from North America.
Stored: First Name, surname, email address, social media profile IDs/links (if provided)
Scope: Every person that is a customer with Patch My PC.
CloudFlare
•
Cloud Monitoring & WAF
United States
Purpose: Cloudflare serves as a content redistribution tool for our primary website, patchmypc.com, and as a Web Application Firewall (WAF) for our production services. All traffic to these sites is routed through CloudFlare to act as an edge firewall protection.
Stored: IP Address
Scope: Every person that is interacting or communicating with Patch My PC's website or services.
HubSpot
•
Marketing Behavior Analytics
United States
Purpose: Lead management and collection, especially at conferences and events. Also used to ensure delivery of mass communication messages to customers. Tracks engagement across social media platforms.
Stored: First name, surname, email address, Social Media profile IDs/links (if provided)
Scope: Every person that is communicating with Patch My PC for marketing purposes.
FAQ
View all
Updates
View all
Compliance
Notice of New Sub-Processor: Gong
Published July 8, 2026
At Patch My PC, we are committed to being transparent about the third-party service providers we use to support our business operations. As part of that commitment, we wanted to let you know about an upcoming update to our sub-processor list. This tool is only used as part of the customer relationship process. Data we receive, generate or otherwise use to generate and provide the Patch My PC solution, is not processed by Gong.
Sub-Processor Name: Gong
**Sub-Processor Category: Sales & Customer Relationship Management (CRM) **
Purpose of Processing: Gong is used to support Patch My PC's pre-sales, customer engagement, and CRM processes. The platform helps our teams manage and improve customer interactions, including product demonstrations, sales conversations, and related support activities. Data Processed: Gong may process business contact information and communications associated with prospective and existing customers, such as name, business email address, and meeting and demo participation information.
Data Not Processed: Gong is not used to access, store, or process customer tenant data, endpoint data, device data, or customer content that Patch My PC processes as part of its software services. Its use is limited to supporting sales, customer engagement, and relationship management activities.
Please see our answers to potential additional questions below:
Why use Gong?
Gong helps our team better understand and improve customer interactions related to product demonstrations, sales conversations, and customer engagement activities. The information processed is limited to business contact and interaction data associated with those activities, helping us provide a better customer experience and more effective support throughout the customer journey.
Has Gong undergone security review by Patch My PC?
Yes. Gong completed our vendor review and security assessment process before being added as a sub-processor. You can see Gong’s Trust Center here: https://trust.gong.io/Opens in new tab.
Can I object to the addition of Gong?
We provide customers with 14 days' notice of any additions or changes to our sub-processor list. Prior to Gong’s implementation, customers may object to the addition of Gong or ask additional questions by emailing [email protected]. Furthermore, Gong can be objected on a case by case basis by declining to allow the tool to record calls you join with Patch My PC.
Thank you for your continued trust in Patch My PC.
Compliance
New SOC 2 Type II Report
Published June 1, 2026
Patch My PC is happy to announce that a new SOC 2 Type II report is available and can be found in the Overview Tab or the Resources Tab.
The new report covers an audit period of April 1, 2025 to March 31, 2026.
Compliance
Subprocessors Clarity Update
Published March 23, 2026
For increased clarity, we have implemented some new features in the trust center and provided a short written explanation on the usage of each of our subprocessors.
The new feature allows the usage of tagging, to define what the subprocessors are used for. We have added, internal, cloud, on-prem, website and tagged each of the subprocessors to their appropriate use cases. Our goal with this is to provide clarity when trying to understand which services use which tools.
Tools marked with only the internal tag, are back office tools used for running the business that may process the first and last name of the contract holder or the administrator.
Additionally, a short purpose statement has been added to each subprocessor.
General
New penetration test report available + FAQ updates
Published March 18, 2026
Hello everyone,
Our latest penetration test report, along with an attestation signed by our Director of Security & IT, has been released for customer review. These documents can be found in the Resources tab.
We've also updated our FAQ page. You'll find expanded FAQ categories for easier navigation as well as a new section about the PSADT App Migration AI tool we've added into Patch My PC Cloud.
If there are any questions, please feel free to reach out to [email protected].
Media
View all
Security Deep Dive Catalog Explanation Opens in new tab
We at Patch My PC often get asked how we validate the integrity of the third-party updates included in our catalog. In this video, we will go review the article containing the procedures we take to ensure the quality and integrity of the patches we publish in our third-party software update catalog.
How to Navigate the Patch My PC Trust Center Opens in new tab
This video covers what security documentation and controls can be found on the Trust Center. It also details how to get access to gated resources and who to contact in case further help is needed.
Read more about Notice of New Sub-Processor: Gong
Patch My PC
Founded in 2011, we’re a team of 125 dedicated to keeping you more secure online and making application management easy.
Our Trust portal provides access security and privacy related resources, certificates, sub-processor information and documentation.
[email protected]
Privacy PolicyOpens in new tab
Filter by
Compliance
ISO 27001:2022
SOC 2 Type 2
GDPR
Resources
View all
Certifications
EU-US Data Protection Framework Program
Opens in new tab
ISO 27001:2022 - Statement of ApplicabilityOpens in new tab
SOC 2 Type II Report
Security Documentation
2025 External Penetration Test
2025 External Pentest Attestation Letter
Incident Response Plan (IRP)
Business Continuity Plan (BCP)
View 3 more
Data Flow Information
On-Premises Data Flow DiagramOpens in new tab
View 1 more
Questionnaires
CAIQ 2025Opens in new tab
VPAT 2026Opens in new tab
SIGLITE 2025Opens in new tab
HECVAT 2026Opens in new tab
Values and Policies
Our Core Values
Opens in new tab
GDPR
Transfer Impact AssessmentOpens in new tab
Controls
View all
Infrastructure security
Unique production database authentication enforced
Encryption key access restricted
Unique account authentication enforced
View 17 more Infrastructure security controls
Organizational security
Asset disposal procedures utilized
Portable media encrypted
Anti-malware technology utilized
View 8 more Organizational security controls
Product security
Data encryption utilized
Control self-assessments conducted
Penetration testing performed
View 2 more Product security controls
Internal security procedures
Continuity and Disaster Recovery plans established
Continuity and Disaster Recovery plans tested
Cybersecurity insurance maintained
View 34 more Internal security procedures controls
Data and privacy
Data retention procedures established
Customer data deleted upon leaving
Data classification policy established
Data collected
Employee personally identifiable information
Credit card information
Personal health information
Subprocessors
View all
Microsoft
•
Cloud provider
United States & EEA
Purpose: Microsoft is the backbone of our infrastructure, used for e-mail, hosting services in Azure to support our Cloud resources, and more. Depending on the nature of any interaction with Patch My PC team members or a Patch My PC service, some or all of the below information may be processed or stored.
Stored: First name, surname, email address, IP Address. If using our Cloud SaaS solution additional device metadata may be stored depending on the services used; see the data collection matrix for details.
Scope: Every person that is communicating with Patch My PC and every company using a Patch My PC service.
Salesforce
•
Customer Relationship Management
United States
Purpose: Customer relationship management tool. Salesforce is responsible for support case management and tracking of customer communications during the sales cycle. Some customer usage data is re-surfaced here from our usage data stored in Azure. All Salesforce data is stored in and accessed from North America.
Stored: First Name, surname, email address, social media profile IDs/links (if provided)
Scope: Every person that is a customer with Patch My PC.
CloudFlare
•
Cloud Monitoring & WAF
United States
Purpose: Cloudflare serves as a content redistribution tool for our primary website, patchmypc.com, and as a Web Application Firewall (WAF) for our production services. All traffic to these sites is routed through CloudFlare to act as an edge firewall protection.
Stored: IP Address
Scope: Every person that is interacting or communicating with Patch My PC's website or services.
HubSpot
•
Marketing Behavior Analytics
United States
Purpose: Lead management and collection, especially at conferences and events. Also used to ensure delivery of mass communication messages to customers. Tracks engagement across social media platforms.
Stored: First name, surname, email address, Social Media profile IDs/links (if provided)
Scope: Every person that is communicating with Patch My PC for marketing purposes.
FAQ
View all
Updates
View all
Compliance
Notice of New Sub-Processor: Gong
Published July 8, 2026
At Patch My PC, we are committed to being transparent about the third-party service providers we use to support our business operations. As part of that commitment, we wanted to let you know about an upcoming update to our sub-processor list. This tool is only used as part of the customer relationship process. Data we receive, generate or otherwise use to generate and provide the Patch My PC solution, is not processed by Gong.
Sub-Processor Name: Gong
**Sub-Processor Category: Sales & Customer Relationship Management (CRM) **
Purpose of Processing: Gong is used to support Patch My PC's pre-sales, customer engagement, and CRM processes. The platform helps our teams manage and improve customer interactions, including product demonstrations, sales conversations, and related support activities. Data Processed: Gong may process business contact information and communications associated with prospective and existing customers, such as name, business email address, and meeting and demo participation information.
Data Not Processed: Gong is not used to access, store, or process customer tenant data, endpoint data, device data, or customer content that Patch My PC processes as part of its software services. Its use is limited to supporting sales, customer engagement, and relationship management activities.
Please see our answers to potential additional questions below:
Why use Gong?
Gong helps our team better understand and improve customer interactions related to product demonstrations, sales conversations, and customer engagement activities. The information processed is limited to business contact and interaction data associated with those activities, helping us provide a better customer experience and more effective support throughout the customer journey.
Has Gong undergone security review by Patch My PC?
Yes. Gong completed our vendor review and security assessment process before being added as a sub-processor. You can see Gong’s Trust Center here: https://trust.gong.io/Opens in new tab.
Can I object to the addition of Gong?
We provide customers with 14 days' notice of any additions or changes to our sub-processor list. Prior to Gong’s implementation, customers may object to the addition of Gong or ask additional questions by emailing [email protected]. Furthermore, Gong can be objected on a case by case basis by declining to allow the tool to record calls you join with Patch My PC.
Thank you for your continued trust in Patch My PC.
Compliance
New SOC 2 Type II Report
Published June 1, 2026
Patch My PC is happy to announce that a new SOC 2 Type II report is available and can be found in the Overview Tab or the Resources Tab.
The new report covers an audit period of April 1, 2025 to March 31, 2026.
Compliance
Subprocessors Clarity Update
Published March 23, 2026
For increased clarity, we have implemented some new features in the trust center and provided a short written explanation on the usage of each of our subprocessors.
The new feature allows the usage of tagging, to define what the subprocessors are used for. We have added, internal, cloud, on-prem, website and tagged each of the subprocessors to their appropriate use cases. Our goal with this is to provide clarity when trying to understand which services use which tools.
Tools marked with only the internal tag, are back office tools used for running the business that may process the first and last name of the contract holder or the administrator.
Additionally, a short purpose statement has been added to each subprocessor.
General
New penetration test report available + FAQ updates
Published March 18, 2026
Hello everyone,
Our latest penetration test report, along with an attestation signed by our Director of Security & IT, has been released for customer review. These documents can be found in the Resources tab.
We've also updated our FAQ page. You'll find expanded FAQ categories for easier navigation as well as a new section about the PSADT App Migration AI tool we've added into Patch My PC Cloud.
If there are any questions, please feel free to reach out to [email protected].
Media
View all
Security Deep Dive Catalog Explanation Opens in new tab
We at Patch My PC often get asked how we validate the integrity of the third-party updates included in our catalog. In this video, we will go review the article containing the procedures we take to ensure the quality and integrity of the patches we publish in our third-party software update catalog.
How to Navigate the Patch My PC Trust Center Opens in new tab
This video covers what security documentation and controls can be found on the Trust Center. It also details how to get access to gated resources and who to contact in case further help is needed.
Read more about Subprocessors Clarity Update
Patch My PC
Founded in 2011, we’re a team of 125 dedicated to keeping you more secure online and making application management easy.
Our Trust portal provides access security and privacy related resources, certificates, sub-processor information and documentation.
[email protected]
Privacy PolicyOpens in new tab
Filter by
Compliance
ISO 27001:2022
SOC 2 Type 2
GDPR
Resources
View all
Certifications
EU-US Data Protection Framework Program
Opens in new tab
ISO 27001:2022 - Statement of ApplicabilityOpens in new tab
SOC 2 Type II Report
Security Documentation
2025 External Penetration Test
2025 External Pentest Attestation Letter
Incident Response Plan (IRP)
Business Continuity Plan (BCP)
View 3 more
Data Flow Information
On-Premises Data Flow DiagramOpens in new tab
View 1 more
Questionnaires
CAIQ 2025Opens in new tab
VPAT 2026Opens in new tab
SIGLITE 2025Opens in new tab
HECVAT 2026Opens in new tab
Values and Policies
Our Core Values
Opens in new tab
GDPR
Transfer Impact AssessmentOpens in new tab
Controls
View all
Infrastructure security
Unique production database authentication enforced
Encryption key access restricted
Unique account authentication enforced
View 17 more Infrastructure security controls
Organizational security
Asset disposal procedures utilized
Portable media encrypted
Anti-malware technology utilized
View 8 more Organizational security controls
Product security
Data encryption utilized
Control self-assessments conducted
Penetration testing performed
View 2 more Product security controls
Internal security procedures
Continuity and Disaster Recovery plans established
Continuity and Disaster Recovery plans tested
Cybersecurity insurance maintained
View 34 more Internal security procedures controls
Data and privacy
Data retention procedures established
Customer data deleted upon leaving
Data classification policy established
Data collected
Employee personally identifiable information
Credit card information
Personal health information
Subprocessors
View all
Microsoft
•
Cloud provider
United States & EEA
Purpose: Microsoft is the backbone of our infrastructure, used for e-mail, hosting services in Azure to support our Cloud resources, and more. Depending on the nature of any interaction with Patch My PC team members or a Patch My PC service, some or all of the below information may be processed or stored.
Stored: First name, surname, email address, IP Address. If using our Cloud SaaS solution additional device metadata may be stored depending on the services used; see the data collection matrix for details.
Scope: Every person that is communicating with Patch My PC and every company using a Patch My PC service.
Salesforce
•
Customer Relationship Management
United States
Purpose: Customer relationship management tool. Salesforce is responsible for support case management and tracking of customer communications during the sales cycle. Some customer usage data is re-surfaced here from our usage data stored in Azure. All Salesforce data is stored in and accessed from North America.
Stored: First Name, surname, email address, social media profile IDs/links (if provided)
Scope: Every person that is a customer with Patch My PC.
CloudFlare
•
Cloud Monitoring & WAF
United States
Purpose: Cloudflare serves as a content redistribution tool for our primary website, patchmypc.com, and as a Web Application Firewall (WAF) for our production services. All traffic to these sites is routed through CloudFlare to act as an edge firewall protection.
Stored: IP Address
Scope: Every person that is interacting or communicating with Patch My PC's website or services.
HubSpot
•
Marketing Behavior Analytics
United States
Purpose: Lead management and collection, especially at conferences and events. Also used to ensure delivery of mass communication messages to customers. Tracks engagement across social media platforms.
Stored: First name, surname, email address, Social Media profile IDs/links (if provided)
Scope: Every person that is communicating with Patch My PC for marketing purposes.
FAQ
View all
Updates
View all
Compliance
Notice of New Sub-Processor: Gong
Published July 8, 2026
At Patch My PC, we are committed to being transparent about the third-party service providers we use to support our business operations. As part of that commitment, we wanted to let you know about an upcoming update to our sub-processor list. This tool is only used as part of the customer relationship process. Data we receive, generate or otherwise use to generate and provide the Patch My PC solution, is not processed by Gong.
Sub-Processor Name: Gong
**Sub-Processor Category: Sales & Customer Relationship Management (CRM) **
Purpose of Processing: Gong is used to support Patch My PC's pre-sales, customer engagement, and CRM processes. The platform helps our teams manage and improve customer interactions, including product demonstrations, sales conversations, and related support activities. Data Processed: Gong may process business contact information and communications associated with prospective and existing customers, such as name, business email address, and meeting and demo participation information.
Data Not Processed: Gong is not used to access, store, or process customer tenant data, endpoint data, device data, or customer content that Patch My PC processes as part of its software services. Its use is limited to supporting sales, customer engagement, and relationship management activities.
Please see our answers to potential additional questions below:
Why use Gong?
Gong helps our team better understand and improve customer interactions related to product demonstrations, sales conversations, and customer engagement activities. The information processed is limited to business contact and interaction data associated with those activities, helping us provide a better customer experience and more effective support throughout the customer journey.
Has Gong undergone security review by Patch My PC?
Yes. Gong completed our vendor review and security assessment process before being added as a sub-processor. You can see Gong’s Trust Center here: https://trust.gong.io/Opens in new tab.
Can I object to the addition of Gong?
We provide customers with 14 days' notice of any additions or changes to our sub-processor list. Prior to Gong’s implementation, customers may object to the addition of Gong or ask additional questions by emailing [email protected]. Furthermore, Gong can be objected on a case by case basis by declining to allow the tool to record calls you join with Patch My PC.
Thank you for your continued trust in Patch My PC.
Compliance
New SOC 2 Type II Report
Published June 1, 2026
Patch My PC is happy to announce that a new SOC 2 Type II report is available and can be found in the Overview Tab or the Resources Tab.
The new report covers an audit period of April 1, 2025 to March 31, 2026.
Compliance
Subprocessors Clarity Update
Published March 23, 2026
For increased clarity, we have implemented some new features in the trust center and provided a short written explanation on the usage of each of our subprocessors.
The new feature allows the usage of tagging, to define what the subprocessors are used for. We have added, internal, cloud, on-prem, website and tagged each of the subprocessors to their appropriate use cases. Our goal with this is to provide clarity when trying to understand which services use which tools.
Tools marked with only the internal tag, are back office tools used for running the business that may process the first and last name of the contract holder or the administrator.
Additionally, a short purpose statement has been added to each subprocessor.
General
New penetration test report available + FAQ updates
Published March 18, 2026
Hello everyone,
Our latest penetration test report, along with an attestation signed by our Director of Security & IT, has been released for customer review. These documents can be found in the Resources tab.
We've also updated our FAQ page. You'll find expanded FAQ categories for easier navigation as well as a new section about the PSADT App Migration AI tool we've added into Patch My PC Cloud.
If there are any questions, please feel free to reach out to [email protected].
Media
View all
Security Deep Dive Catalog Explanation Opens in new tab
We at Patch My PC often get asked how we validate the integrity of the third-party updates included in our catalog. In this video, we will go review the article containing the procedures we take to ensure the quality and integrity of the patches we publish in our third-party software update catalog.
How to Navigate the Patch My PC Trust Center Opens in new tab
This video covers what security documentation and controls can be found on the Trust Center. It also details how to get access to gated resources and who to contact in case further help is needed.