1. Who we are and scope
Trustity ("we," "us," or "our") is a technology company based at 30 Emek Hefer Boulevard, Ashkelon, Israel. This policy applies to trustity.co, trustity.io, trustity.dev, the Trustity Cloud Portal, TAO, VisionX, GenGuard, Vault/PAM, HostGuard IPS, Trustity Axiom, TCP On-Prem, Trustity Authenticator, and related services that link to this policy (collectively, the "Services").
A customer's signed agreement, data processing addendum, product documentation, or in-product notice may provide additional or more specific privacy information. This policy does not govern third-party products or websites that have their own privacy notices.
2. Our role: controller or processor
Trustity acts as a controller when we determine why and how personal data is processed, including website inquiries, account administration, billing, service security, and our own legal and business operations.
For customer content, endpoint telemetry, security events, and other data processed on a customer's instructions to provide the Services, Trustity generally acts as a processor or service provider, and the customer is the controller. In that case, requests concerning the data should normally be directed to the relevant customer; we assist customers as required by contract and applicable law.
3. Data we process
Websites and communications
- Contact details, employer, role, and the content of inquiries.
- Basic request and security data, such as IP address, timestamps, user agent, requested URL, and abuse-prevention events.
- Website analytics and tag-management data collected through Google Tag Manager and Google Analytics, such as pages viewed, approximate location derived from IP address, device/browser type, referral source, and engagement metrics used to understand and improve site performance.
- Conversion and advertising measurement data collected through X (formerly Twitter) conversion tracking, such as page visits, referral from X campaigns, device and browser information, and actions taken on the site after an ad interaction.
- First-party usage and request data used to operate and secure the site, such as pages requested and basic device or browser information in server logs.
- Commercial correspondence and event or demonstration requests.
Accounts and administration
- Name, business email, organization, role, and account identifiers.
- Authentication records, permissions, session information, administrative actions, support tickets, and audit logs.
- Subscription, transaction, and billing contact information.
TAO, GenGuard, HostGuard
- Device and agent identifiers, operating system and software inventory, configuration, health, connectivity, and runtime status.
- GenGuard policy results and technical context for blocked or allowed browser actions. Classification is designed to run in the browser session; we do not treat full pasted content as a general cloud archive unless a customer configuration expressly sends evidence.
- HostGuard failed-logon events, blocked source IPs, host firewall actions, and related usernames or host identifiers reported to the Cloud Portal.
VisionX, Vault/PAM, Axiom
- VisionX detections and customer-configured evidence excerpts. Detection is designed to run on the endpoint; Trustity does not receive a continuous raw video feed.
- Vault/PAM metadata such as secret identifiers, rotation status, and audit events. Designated vault secret content is scoped zero-knowledge as described below.
- Axiom operational metadata for SMB and DNS policy at the edge, such as policy hits, node health, and selected file or domain indicators configured by the customer.
We may also receive data from a customer administrator, authorized reseller, integration provider, identity provider, hosting or security provider, or from public and professional sources in a business-to-business context.
4. Trustity Authenticator
Trustity Authenticator keeps TOTP secrets and generated codes locally in device-protected storage and does not make those secrets available to Trustity. Limited diagnostics, crash data, device information, or feedback may be processed if a user enables or submits them. Any material change to these practices will be reflected in an updated notice.
5. Purposes and legal bases
We process personal data for the following purposes and, where applicable, bases:
- Contract: to create and administer accounts, provide licensed Services, authenticate users, deliver support, process orders, and meet our contractual commitments.
- Legitimate interests: to secure, maintain, troubleshoot, and improve the Services and public websites (including measuring traffic, usage, and advertising effectiveness with analytics and conversion measurement tools); prevent fraud and abuse; manage customer relationships; keep business records; and establish or defend legal claims, balanced against affected individuals' rights.
- Legal obligation: to meet tax, accounting, regulatory, sanctions, law-enforcement, and other binding legal requirements.
- Consent: where required for a specific optional activity. Consent may be withdrawn prospectively at any time.
- Customer instructions: when acting as processor, to perform the customer agreement and documented instructions.
6. Cookies
Our public websites use cookies or similar technologies that are essential to provide requested functionality, maintain security, balance traffic, or preserve necessary session state. Infrastructure providers may also process ordinary server request logs for delivery, reliability, and security.
We use Google Tag Manager (container ID GTM-PLKSR4FS) to load and manage measurement and marketing tags on our public websites. Google Tag Manager itself is a tag-management container; tags it loads may set or read cookies or similar identifiers and process data such as page views, referral sources, device and browser information, and conversion events. Those tags currently include Google Analytics and may include other Google or third-party tags we enable for analytics, advertising measurement, or similar purposes.
We use Google Analytics (measurement ID G-DY71C8SE0P) to understand how visitors use our public websites, including pages viewed, approximate geographic region, device and browser information, and referral sources. Google may set or read cookies or similar identifiers and process data on our behalf for this purpose under Google's terms and privacy practices.
We use X (formerly Twitter) conversion tracking (pixel ID recqj) to measure whether visitors from X advertising complete actions on our public websites, such as page views, demo requests, and form submissions. X may set or read cookies or similar identifiers and process data on our behalf under X's terms and privacy practices.
We do not sell personal data for behavioral advertising. Where applicable law requires consent for non-essential cookies or similar technologies, we will provide the required controls. You can also limit analytics and conversion measurement through browser settings or the opt-out tools offered by Google, X, or your device or browser provider.
7. Sharing and subprocessors
We do not sell personal data. We disclose it only as needed to provide and protect the Services, operate our business, follow customer instructions, complete a corporate transaction, or comply with law. Recipients may include affiliated personnel, professional advisers, a successor in a merger or acquisition, competent authorities, and subprocessors in categories such as:
- Cloud hosting, storage, content delivery, and infrastructure providers;
- Identity, authentication, email, communications, and customer-support providers;
- Security monitoring, incident response, error diagnostics, and service operations;
- Website analytics and tag-management providers, including Google Tag Manager and Google Analytics;
- Advertising and conversion measurement providers, including X (formerly Twitter);
- Transactional email and SMS delivery providers used for product notifications where configured;
- Billing, payment, accounting, and business administration providers.
Subprocessors are authorized only for defined services and are subject to contractual confidentiality, security, and data-protection obligations appropriate to their role. Enterprise customers may receive more specific subprocessor information under their agreement.
8. International transfers
Trustity is based in Israel, and personal data may be processed in Israel and in countries where our customers, personnel, or service providers operate. The European Commission currently recognizes Israel as providing an adequate level of protection, so a transfer from the EEA to Israel does not by itself require Standard Contractual Clauses. Onward transfers to providers in other countries use recognized mechanisms where required, such as an adequacy decision, the European Commission's Standard Contractual Clauses, or another lawful basis, together with supplementary measures where appropriate.
9. Retention
Retention varies by the type of data, customer contract, product configuration, legal requirements, security needs, and the customer's deletion instructions. We retain account and commercial records while the relationship is active and afterward as reasonably necessary for legal, tax, audit, fraud-prevention, and dispute purposes. Customer data, event history, evidence, and operational logs are retained according to the applicable agreement and configured service settings. Backup copies may remain for a limited lifecycle before secure overwrite. We delete or de-identify data when it is no longer reasonably required, subject to legal holds and technical limitations.
10. Security and scoped zero-knowledge vault
We maintain administrative, technical, and organizational measures designed to protect personal data, including access controls, authentication, encryption where appropriate, logging, environment separation, vulnerability management, and incident-response procedures. No system is completely secure, and we cannot guarantee absolute security.
Certain designated Vault data is protected using a scoped zero-knowledge design under which supported secret content is encrypted so Trustity does not hold the material required to decrypt that content in ordinary operation. This statement applies only to supported Vault content and does not extend to account data, identifiers, access and rotation metadata, audit events, configuration, or other operational information needed to provide and secure the feature.
11. Your privacy rights
Subject to the Israeli Privacy Protection Law, 5741-1981 and other applicable law, you may have rights to review personal data held about you and request correction or deletion where it is inaccurate, incomplete, unclear, or unlawfully processed. Where the GDPR or UK GDPR applies, rights may also include access, rectification, erasure, restriction, objection, portability, withdrawal of consent, and a complaint to a competent supervisory authority. These rights may be limited by law.
Send a request to legal@trustity.co. We may verify your identity and authority before acting. If Trustity processes the data for a customer, we may refer the request to that customer or ask you to contact it directly.
12. Automated actions
In its controller role, Trustity does not make solely automated employment, credit, or similarly significant legal decisions about individuals. Customer-configured security controls may perform automated technical actions under the customer's instructions, such as blocking a paste, locking a workstation, or blocking an IP address. Those actions are the customer's deployment choices.
13. Children
The Services are designed for organizations and professionals, not children. We do not knowingly solicit or collect personal data directly from children under 16. If you believe a child has provided personal data to us without appropriate authorization, contact us so we can investigate and take appropriate action.
14. Changes to this policy
We may update this policy to reflect changes in our Services, practices, or legal obligations. We will post the revised policy with a new effective date and, where required or appropriate, provide additional notice through the Services, by email, or through the relevant customer. Earlier versions may be requested from us.
15. Contact
Trustity30 Emek Hefer Boulevard, Ashkelon, Israel
legal@trustity.co
