Who is responsible
TrustFlare is an early-stage startup. Information about the operating and contracting party, and documents for customer due diligence, are available on request at [email protected] before a paid engagement begins.
For website enquiries and our own business communications, TrustFlare determines why and how the information is used. Contact [email protected] for the identity and contact details of the responsible operator or for any data-protection question.
Information you provide
We use information you submit to handle the request you make. Required fields are marked on each form. You can leave optional fields blank; without a contact address we may be unable to reply.
- Pilot enquiries: name, chosen contact method and contact details, company, team size, message, urgency, language and the page from which you sent the request. We use these to discuss your requirements and, where available, arrange a trial.
- Privacy requests: email, request type, optional name and details, request identifier and handling status. We use these to verify, track and answer your request.
- Security reports: severity, summary, technical details, optional name and email, and a report identifier. We use these to investigate and respond to reported issues.
Technical data and website analytics
When you connect, our hosting and network providers process your IP address and request information to deliver and protect the site. Form records include a salted IP-address hash, browser user agent, approximate country, timestamp and request identifiers. An IP hash is pseudonymous data, not a guarantee of anonymity.
The current public website does not load an analytics tracker. It does not use advertising pixels or cross-site advertising tracking. Security and delivery logs are still processed. See Cookies and browser storage for details.
Why we process data
Where GDPR applies, responding to an enquiry you initiate and preparing a contract rely on steps taken at your request before a contract. Service administration relies on the applicable contract. Security, abuse prevention and handling correspondence rely on legitimate interests; we consider the impact on the people concerned. Handling statutory privacy requests and required records may be necessary to meet legal obligations.
Reading a privacy notice or sending a form is not blanket consent for unrelated processing. If a separate activity requires consent, we will explain it and request consent before that activity starts. You can withdraw such consent without affecting earlier lawful processing.
Data in the TrustFlare service
Customer organizations decide which users and devices to enroll and which access policies to apply. In a hosted deployment, TrustFlare processes service data on their behalf under the agreed instructions and processing terms. In a customer-hosted deployment, the customer operates the core and controls its records; information you separately send to our support team is still covered by this notice.
- Depending on the platform and enabled checks, records can include device and installation identifiers, public keys, operating-system and security facts, OS username, network and browser information, enrollment events and access decisions.
- Face ID, Touch ID and other supported local verification are performed by the device platform. TrustFlare receives a verification result or cryptographic proof, not a face image, fingerprint or biometric template.
- Access decisions may be automated using customer policies and device signals. For a denied sign-in or a concern about the effect of a policy, contact your organization’s administrator for review. The customer must assess the applicable rules for decisions affecting its users.
Who receives information
Infrastructure and communications providers receive information needed to operate the site and handle requests. Our Service providers and subprocessors page describes the current categories and their purposes.
Website submissions are stored in Cloudflare D1. Internal Telegram notifications include pilot-enquiry content and contact details; privacy notifications include the request type, name if provided, email and reference; security notifications include severity, summary and any supplied contact details. Do not put passwords, private keys or unrelated personal information in a form.
We may disclose relevant information where required by law or necessary to establish, exercise or defend legal claims. We do not sell personal information, share it for cross-context behavioral advertising or use enquiries to enroll you in unsolicited marketing campaigns.
Locations and international transfers
Our network and communications providers operate internationally. This public notice does not promise that all information stays in one country or that an EU database setting also confines network traffic, support access and messaging to the EU.
Before a hosted customer deployment, the service arrangement must identify the hosting provider, processing locations and any safeguards required for international transfers. Ask [email protected] for the information relevant to your use. Customer-hosted core storage follows the location and configuration chosen by the customer.
How long information is kept
Retention depends on the purpose and the relevant service arrangement:
- Enquiries and correspondence: while responding to the request and managing any resulting relationship, with further retention only where needed for applicable record-keeping or legal claims.
- Privacy requests: while verifying and resolving the request, and where necessary to retain evidence of how it was handled.
- Security reports and abuse-related records: for investigation, remediation and the continuing need to protect the service or handle a related claim.
- Hosted service records: according to the customer’s instructions and agreed retention, return and deletion terms. Customer-hosted records are managed by the customer.
Your choices and rights
Depending on applicable law, you can request access, correction, deletion, restriction or portability, object to processing, or withdraw consent where consent is used. These rights may have conditions and exceptions. We will explain any refusal and the options available to you.
Use the privacy request form or email [email protected]. The form is a convenient channel, not a condition for exercising your rights. We may ask for proportionate information to verify your identity; please do not send an identity document unless it is needed and we arrange an appropriate channel.
For requests governed by GDPR, we respond without undue delay and within one month. If a permitted extension is necessary because of complexity or the number of requests, we explain the reason within that first month. You can complain to the competent data-protection authority. See Regional privacy rights for further information.
For data controlled by your employer or another customer organization, contact that organization first. If you contact us, we will help identify the appropriate route rather than change customer-controlled records without authority.
Security, audience and updates
See Security for safeguards and reporting channels. No system can guarantee absolute security. The service is intended for organizations and professional use, not for children.
The date above identifies this version. We will update the notice when our processing changes and provide any additional notice or choice required by applicable law.