General Privacy Statement

Effective Date: June 1, 2021

This General Privacy Statement (also referred to as our “Privacy Statement”) explains how Wazuh, Inc. and the https://wazuh.com website, (hereinafter referred to as “Wazuh”, “we”, “our”, “us”, and the “Service”) collect, use, share and otherwise process information that identifies or could be identifiable to you (“personal data”) and that we use to manage our business and our relationships with customers, visitors and event attendees.

Interaction Specific Statements

We supplement this Statement with the following specific statements based on how we interact with you:

Product Privacy Statement. This statement applies to the information we collect and use in connection with customer deployments of our products and services.

Applicant Privacy Statement. This statement applies to the personal data we collect and use in connection with our employment recruiting process.

California Privacy Rights Statement. This statement explains the privacy rights of California residents.

Cookie Statement. This statement explains how we use cookies and similar technologies.

General Privacy Statement: Contents

Scope & Responsibilities
Information We Collect & How We Collect It
How We Use the Information
How We Share the Information
Tracking & Cookies Data
International Data Transfers
Privacy Rights and Choices
Legal Basis for Processing the Information (European Economic Area)
European Union Privacy Rights under GDPR
California Privacy Rights
Security
Links to other Sites
Other Information
How to Contact Us
 

Scope & Responsibilities

This General Privacy Statement explains your rights and choices related to the personal data we collect when:

  • You visit, interact with or use any of our websites, social media pages, marketing or sales communications, or register for our products and services (“Online Properties”); and
  • You visit, interact with or use any of our offices, events, sales, marketing, and other offline activities (“Offline Properties”)(collectively, the “Properties”);

This General Privacy Statement does not cover:

  • Automatic collection from our products and services: This Statement does not cover the information we automatically collect in connection with your use of Wazuh products and services. Please see our Product Privacy Statement for that information.
  • Applicant Information: This Statement does not cover information related to our employment recruiting efforts. Please see our Applicant Privacy Statement for that information.
  • Customer Content: Wazuh products permit customers to ingest or upload and submit content to the product (“Customer Content”). This notice does not cover Customer Content, including any personal data about you that may be contained in Customer Content, because the Customer, rather than Wazuh, controls how Customer Content is processed. Any questions about the processing of Customer Content should be addressed to the Customer directly.
  • Organizational Use: When you use our products or Service on behalf of an organization (e.g., your employer), your use is administered and provisioned by your organization under its policies regarding the use and protection of personal data. If you have questions about how your data is being accessed or used by your organization, please refer to your organization’s privacy policy and direct your inquiries to your organization’s system administrator.

Wazuh determines the purposes and means for the processing (i.e., we are the data controller) of your personal data as described in this Privacy Statement unless expressly specified otherwise.
 

Information We Collect & How We Collect It

Wazuh collects several different types of information for various purposes to provide and improve our Service to you. We will not collect more information than is necessary to provide the Service. We will not collect information, including Personal Data, without notification and consent.

Wazuh collects personal data and other information from you directly, through automated means, and from third parties. More information on each category follows:

From You

We collect personal data when you voluntarily provide it to us (including to our service providers or other parties who collect it on our behalf). For example, we collect personal data when you order, register to use, or request information about Wazuh products and its Service, subscribe to marketing communications, complete surveys, provide such data in product feedback, or sign up for a Wazuh event or webinar. We may also collect personal data from you when you attend one of our events, during phone calls with sales representatives, or when you contact customer support.

Personal, identifiable information may include but is not limited to contact information (such as your name, address, telephone number, or email address), professional information (such as your employer name, address, job title, department, or job role), user IDs, passwords, and contact preferences. We collect the information you choose to provide when completing any “free text” boxes in our forms (for example, for event sign-up, product feedback, or survey requests), and we collect personal data disclosed by you on message boards, chat features, blogs, and other services or platforms to which you can post information and materials (including third-party services and platforms). We may also collect billing and transactional information.

Automatically

We use technology that is integrated into our Online Properties such as cookies, web beacons, and embedded URLs to provide us with automated data collection.

Online Properties

We automatically collect certain information when you use, access, or interact with our Online Properties. This information may include unique identification numbers and other information about the specific device you are using, such as the hardware model, operating system version, web-browser software, your Internet Protocol (IP) address/MAC address/device identifier, device event information (such as crashes, system activity, and hardware settings, browser language, the date and time of your request and referral URL), broad geographic location (e.g., country or city-level location) and other technical data that uniquely identifies your browser. We may also collect information about how the Service is accessed and your device has interacted with our Online Properties, such as the pages of our Service that you visit, the time and date of your visit, the time spent on those pages, unique device identifiers and other diagnostic data or statistical information. To learn more, please read the Wazuh Cookie Statement.

Wazuh Products

Wazuh may automatically collect information in connection with your organization’s deployment of certain products. See our Product Privacy Statement for more information.

From Third-Party Sources

We may also acquire data from other sources including affiliates in our corporate group, our partners, or others that we use to make our information better or more useful. For example, we may compare the geographic information acquired from commercial sources with the IP address collected by our Automatic Data Collection Tools (see our Cookie Statement) to derive your general geographic area. Information may also be linked via a unique identifier, such as a cookie or account number.
 

How We Use the Information

Depending on the situation, we may use your information for the following purposes:

  • Communications and Transaction Processing. We use your information to communicate with you, respond to your requests, and provide the information you requested. We also use personal data, including financial, credit card, and payment information, to process transactions.
  • Provision, Administer, and Support Your Account. We use your information to provide our products and manage your account. Examples include managing product downloads, updates and fixes, providing support and recommendations, and sending other administrative or account-related communications, including release notes.
  • Manage Your Customer Experience. We use your information to maintain accurate contact and registration data, deliver support, and to offer products, services, and features. We also use your data to deliver personalized communications and create recommendations based on your use of Wazuh products, services, features, and your visits to our websites.
  • Advertising. We use your information to provide personalized advertising to you per your privacy preferences settings and applicable law. We might also share some of your information with marketing service providers and digital marketing networks to present advertisements that might interest you. This may involve the use of Automatic Data Collection Tools. To learn more about how Wazuh uses Automated Data Collection Tools, see our Cookie Statement.
  • Facilitate and Evaluate Use of the Online Properties. We use your information to provide and facilitate your use of the Online Properties (such as facilitating navigation and the login process, preserving information between sessions, and enhancing security), to improve quality, to evaluate page response rates, and personalize and determine content.
  • Business Operations. We use your information to conduct ordinary business operations, e.g., business research and analytics, corporate reporting and management, staff training and quality assurance purposes, and outreach.
  • Security. We use the information to maintain the integrity and security of our websites, products and services, and to prevent and detect security threats, fraud, or other criminal or malicious activity that might compromise your information or the information of other customers or website visitors.
  • Third-Party Social Networks. We may use personal data to interact with you on third-party social networks (subject to that network’s terms of use).
    Conferences and Events. Wazuh and our partners may use your information to communicate with you about our events or our partners’ events. After the event, Wazuh may contact you about the event and related products and services. We may share information about your attendance with your company, and our conference sponsors and partners, where legally permitted to do so. If a partner or conference sponsor directly requests your personal data at their conference booths or presentations, your information will be handled per their privacy practices. We recommend that you review the privacy practices of such partners and sponsors.
  • Education and Training. If you sign up for a Wazuh certification course or training, Wazuh will use your information to facilitate the delivery of such course or training.
  • Research & Innovation. We use your information to develop new products, features, and services using research and development tools and incorporating data analysis activities.
  • Comply with Law. We use your information as required to be compliant with applicable laws, regulations, court orders, government, and law enforcement requests.
  • Other Legitimate Business Purposes: We may use your information when it is necessary for other legitimate purposes, such as protecting Wazuh’s confidential and proprietary information.

 

How We Share the Information

We share your personal data with the following categories of recipients and only with the appropriate contractual obligations in place:

With Wazuh Companies

We may transfer your personal data to other Wazuh entities in the US and worldwide for the purposes outlined in this Privacy Statement. We protect your personal data per this Statement wherever it is processed and take appropriate contractual or other steps to protect it under applicable laws. These steps include implementing the European Commission’s standard contractual clauses and relying on the European Commission’s adequacy decisions about certain countries, as applicable, for data transfers from the EEA to the United States and other countries. We have implemented similar appropriate safeguards with our service providers, partners, and affiliates. Furthermore, our privacy guidelines are communicated to our employees on an annual basis as part of our mandatory training.

With Service Providers

We may employ third-party companies and individuals to facilitate our Service (“Service Providers”), to provide the Service on our behalf, to perform Service-related services, or to assist us in analyzing how our Service is used. We may share your information with third parties, such as vendors, consultants, agents, and other service providers who provide services such as IT and system administration and hosting, credit card processing, research and analytics, marketing, targeted advertising, training and certifications, customer support, and data enrichment for the purposes and according to the legal bases described below. Our service providers are required by contract to safeguard any personal data they receive from us and are prohibited from using the personal data for any purpose other than to perform the services as instructed by Wazuh. These service providers may be located in the US or other global locations.

With Business Partners

We may share your information with our partners, such as distributors and resellers, and to other business partners, to fulfill product and information requests, to effectively deliver unified support, to provide customers and prospective customers with information about Wazuh, and for event purposes. From time to time, Wazuh may engage in joint sales, product promotions, or events with selected business partners. If you purchase or express interest in a jointly-offered product, promotion, service, or event, we may share relevant personal data with those partners. Such partners are responsible for managing their use of the personal data collected in these circumstances, including providing information to you about how they use your personal information. We recommend you review the privacy policies of the relevant partner to find out more about their handling of your personal information.

With Competent Authorities

We may share your personal data when we believe, in good faith, that we must: (i) respond to duly authorized information requests of law enforcement agencies, regulators, courts, and other public authorities, including to meet national security or other law enforcement requirements; (ii) comply with any law, regulation, subpoena, or court order; (iii) investigate and help prevent security threats, fraud or other criminal or malicious activity; (iv) enforce/protect the rights and properties of Wazuh or our affiliates; or (v) protect the rights or personal safety of Wazuh’s and our affiliates’ employees, and third parties on or using Wazuh property when allowed and in line with the requirements of applicable law.

For Corporate Transactions

We may share your information where, whether for strategic or other business reasons, Wazuh decides to sell, buy, merge, or otherwise reorganize its businesses. In such transactions, we may disclose or transfer your personal data to prospective or actual purchasers, or receive your personal data from sellers. Our practice is to seek appropriate protection for your personal data in these types of transactions.
 

Tracking & Cookies Data

We use cookies and similar tracking technologies to track the activity on our Service and hold certain information.

Cookies are files with a small amount of data that may include an anonymous unique identifier. Cookies are sent to your browser from a website and stored on your device. Tracking technologies also used are beacons, tags, and scripts to collect and track information and to improve and analyze our Service.

You can instruct your browser to refuse all cookies or to indicate when a cookie is being sent. However, if you do not accept cookies, you may not be able to use some portions of our Service. You can learn more about how to manage cookies in the Browser Cookies Guides.

For more information about how we use cookies, see our Cookie Statement.
 

International Data Transfers

Your information, including Personal Data, will be transferred to — and maintained on — computers located outside of your state, province, country, or other governmental jurisdiction where the data protection laws may differ from those from your jurisdiction.

If you choose to provide information to us, please note that we transfer the data, including Personal Data, to the United States or the EU and process it there.

Your consent to this Statement followed by your submission of such information represents your agreement to that transfer.

Wazuh will take all steps reasonably necessary to ensure that your data is treated securely and in accordance with this Statement and no transfer of your Personal Data will take place to an organization or a country unless there are adequate controls in place including the security of your data and other personal information.
 

Privacy Rights and Choices

Upon your request, we will: (1) inform you of what personal information we have on file for you; (2) update or correct the personal information that we have on file for you; and/or (3) erase personal information that you have provided us, or that we have collected.

To exercise your rights, email us at privacy@wazuh.com. Please, identify yourself and specify your request. We use commercially reasonable efforts to delete your personal data as required, but retain records necessary to comply with a governmental authority or applicable federal, state, or local law. Where legally permitted, we may decline to process requests that are unreasonably repetitive or systematic, require disproportionate technical effort, or jeopardize the privacy of others (for instance, requests concerning information stored on backup tapes).

If you are an EEA resident, you also have the right to complain to a data protection authority about our collection and use of your Personal Data. For more information, please contact your local data protection authority.

Subscription Communications and General Communications

You have the option of subscribing to communications from us. Wazuh subscription communications include email newsletters, software updates, and maintenance notifications that may be expressly requested by you or which you consented to receive.

After you consent to such communications, you may opt out of receiving them by following the instructions in the email.
 

Legal Basis for Processing the Information (European Economic Area)

We only use your information in a lawful, transparent, and fair manner. Depending on the specific personal data concerned and the factual context, we rely on the following legal bases:

  • As necessary to prepare and enter into a contract;
  • Consistent with specific revocable consents;
  • As necessary to comply with our legal obligations;
  • To protect your vital interests or those of others; and
  • As necessary for our (or others’) legitimate interests, including our interests, unless those interests are overridden by your interests or fundamental rights and freedoms, which require protection of personal data.

 

European Union Privacy Rights under GDPR

If you are an EU person and would like to exercise your GDPR privacy rights, such as your right to access, amendment, correction, or erasure of Personal Data, please email us at privacy@wazuh.com.
 

California Privacy Rights

If you are a resident of the State of California and would like to opt out from the disclosure of your personal information to any third party, see our California Privacy Rights Statement for information and other required disclosures, or email us at privacy@wazuh.com.
 

Security

Wazuh is committed to protecting the security of personal data. We use appropriate technical and organizational measures to protect personal data from unauthorized access, use, or disclosure. Despite these measures, Wazuh cannot eliminate security risks associated with personal data, and mistakes and security breaches may happen. We retain the data only as required or permitted by law, and while the data continues to have a legitimate business purpose. Please, contact us with security questions at privacy@wazuh.com.
 

Links to other Sites

Our Service may contain links to other sites that are not operated by us. If you click on a third-party link, you will be directed to that third party’s site. We strongly advise you to review the Privacy Policy of every site you visit.

We have no control over and assume no responsibility for the content, privacy policies, or practices of any third-party sites or services.
 

Other Information

Data Retention. We retain information collected in connection with the Properties for so long as necessary to fulfill the purposes outlined in this Statement or where we have an ongoing legitimate business need to do so.

Changes to this Privacy Statement. This General Privacy Statement is subject to occasional revision. We will provide notice of any material changes if and where required by applicable data protection laws.

The date of the most recent update to this General Privacy Statement can be found by checking the “effective” date displayed at the top of this Statement.
 

How to Contact Us

If you have any questions or concerns regarding this Statement, you may contact us via email at privacy@wazuh.com.