This Privacy Policy applies globally to all visitors and customers of Touchpoint Security, LLC.. We are a US-based company operating worldwide. Depending on where you are located, additional rights and obligations may apply to you, including under the EU General Data Protection Regulation (GDPR), UK GDPR, California Consumer Privacy Act (CCPA/CPRA), Canada's PIPEDA, and other applicable laws. Region-specific supplements are included within this policy. Please read the section that applies to your jurisdiction.
1. Who we are
Touchpoint Security, LLC. ("Touchpoint Security", "we", "us", "our") is a cybersecurity company incorporated in the United States, providing Managed Detection and Response (MDR), Exposure Monitoring, Threat Intelligence, Compliance and GRC services, Cloud Security, Cyber Consultancy, Incident Response, Security Awareness Training, and Phishing Investigation services to organizations globally.
We operate as a fully remote company and serve customers in the United States, European Union, United Kingdom, Canada, and other jurisdictions worldwide.
Registered address: 82 Wendell Ave, Ste 100, Pittsfield, MA 01201, United States
Privacy enquiries: privacy@tp-security.com
Data Protection Officer / EU Representative: dpo@tp-security.com
Security incidents: security@tp-security.com
2. Scope of this policy
This policy covers:
- Visitors to tp-security.com and all subdomains.
- Prospective customers who submit enquiries, request demos, or sign up for communications.
- Customers and their Authorized Users who access our platform and services.
- Partners, resellers, and referral contacts.
It does not cover third-party websites linked from our site, or data processed solely within your environment under a separate Data Processing Agreement (DPA). Our DPA governs the personal data we process on your behalf as a data processor in delivering services such as MDR, Exposure Monitoring, Incident Response, and Phishing Investigations.
3. Data we collect and why
3.1 Website visitors
- IP address, browser type, operating system, referral URL, pages visited, session duration , collected via server logs and analytics tools for security and performance optimization.
- Cookie identifiers , collected as described in our Cookie Policy.
- Form submissions , name, business email, company, job title, and any message content submitted via contact, demo request, or newsletter forms.
3.2 Prospects and marketing contacts
- Identity: full name, job title, company name, LinkedIn profile (where publicly provided).
- Contact: business email address, phone number.
- Engagement: email open and click data, webinar attendance, content downloads.
- Source: how you found us (search, referral, event, partner).
3.3 Customers and Authorized Users
- Account data: username, hashed password, role, MFA status, last login.
- Billing data: company billing address, invoice history, payment reference. Card numbers are handled by our PCI-DSS compliant payment processor , we do not store them.
- Service configuration: integration settings, alert thresholds, notification preferences.
- Support and communication: content of tickets, chat logs, and email correspondence.
3.4 Security service data (processed as data processor on your behalf)
In delivering our core services, we process security telemetry from your environment. This data is processed exclusively for the purposes defined in your service agreement and DPA. It includes:
MDR: Endpoint telemetry, SIEM logs, EDR alerts, network flow data, and security events ingested from your environment for 24/7 threat detection and response.
Exposure Monitoring: External attack surface data including domain assets, open ports, exposed credentials, leaked data, and vulnerability indicators sourced from your environment and open-source intelligence.
Threat Intelligence: Indicators of compromise (IoCs), adversary TTPs (tactics, techniques, procedures), and threat actor profiling correlated against your asset inventory.
Cloud Security (Azure / AWS / GCP): Cloud configuration data, IAM policies, resource inventories, security group rules, and audit logs collected via read-only API access to your cloud environment.
Compliance & GRC / Cloud API Monitoring: Configuration states, audit logs, and compliance posture data mapped against frameworks including SOC 2, ISO 27001, NIST CSF, CIS, PCI-DSS, HIPAA, and DORA.
Cyber Consultancy (vCISO, network security, Infrastructure Security, Information Technology (IT) Security, Operation Technology (OT) security, penetration testing, vulnerability assessments): Network topology data, system inventories, vulnerability scan results, penetration test findings, and IT/OT/ICS asset information as relevant to the engagement scope.
Incident Response: Forensic artefacts, memory captures, disk images, malware samples, timeline reconstructions, and communications relating to the incident, retained only for the duration of the engagement plus agreed archive period.
Security Awareness Training: Employee names, email addresses, training completion status, quiz scores, and phishing simulation click/report rates, processed under your direction as controller.
Phishing Investigations: Email headers, URLs, attachment metadata, sender reputation data, and threat actor infrastructure indicators relating to reported phishing incidents.
3.5 Data from third parties
- Threat intelligence feeds: licensed data from commercial and open-source threat intelligence providers (e.g. IP reputation, malware hashes, domain categorisation) used to enrich detections.
- Business data providers: company and contact data from providers such as Apollo, LinkedIn Sales Navigator, or ZoomInfo used for prospecting, subject to those providers' terms and applicable law.
- Partner referrals: name, company, and contact details shared by referring partners.
4. Legal bases for processing
4.1 All jurisdictions, general principles
We process personal data only where we have a lawful basis. The bases we rely on, mapped to applicable law:
4.2 EU and UK customers (GDPR / UK GDPR)
- Article 6(1)(b) Contractual necessity: to perform our service agreement with you (platform access, service delivery, billing, support).
- Article 6(1)(f) Legitimate interests: security monitoring of our own systems, fraud prevention, improving our services through anonymized analytics, and outbound B2B marketing to business contacts, subject to your right to object.
- Article 6(1)(c) Legal obligation: financial record retention (e.g. US federal and state tax law, EU VAT Directive where applicable).
- Article 6(1)(a) Consent: marketing communications and non-essential cookies. You may withdraw consent at any time.
Where security event data processed during MDR or Incident Response reveals information about criminal offences or special category data, we rely on applicable derogations under Article 9(2) and, for UK processing, Schedule 1 of the DPA 2018.
4.3 California residents (CCPA / CPRA)
We do not sell personal information. We do not share personal information for cross-context behavioral advertising without opt-out rights being available. California residents have the following rights under the CCPA/CPRA:
- Right to know: categories and specific pieces of personal information collected, the purposes, and third parties with whom it is shared.
- Right to delete: request deletion of personal information, subject to legal exceptions.
- Right to correct: request correction of inaccurate personal information.
- Right to opt out of sale/sharing: we do not sell or share PI for advertising. If this changes, we will provide an opt-out mechanism.
- Right to limit use of sensitive personal information: we do not use sensitive PI for purposes beyond those permitted under CPRA.
- Right to non-discrimination: we will not discriminate against you for exercising your rights.
To exercise these rights, contact privacy@tp-security.com or use the "Do Not Sell or Share My Personal Information" link in our website footer.
4.4 Canadian customers (PIPEDA / Law 25)
We collect, use, and disclose personal information with consent or as otherwise permitted by PIPEDA and applicable provincial law. You have the right to access and correct your personal information and to withdraw consent subject to legal and contractual restrictions. Quebec residents have additional rights under Law 25 (Bill 64), including the right to data portability and the right to be forgotten.
4.5 Other jurisdictions
We respect applicable data protection laws in all jurisdictions in which we operate. Where required by local law, including Brazil (LGPD), Australia (Privacy Act 1988), Singapore (PDPA), and other , we comply with applicable obligations for lawful processing, individual rights, and cross-border data transfer. Contact privacy@tp-security.com for jurisdiction-specific information.
5. How we use your data
- Providing, operating, and supporting the services described in your agreement.
- Creating and managing accounts and platform access for Authorized Users.
- Processing billing, invoicing, and payment.
- Sending service notifications, security alerts, incident reports, and platform updates (contractual basis, cannot be opted out without terminating the service).
- Sending marketing emails, newsletters, and event invitations where you have opted in or where we have a legitimate interest in B2B outreach, always with an opt-out mechanism.
- Threat detection, incident response, and security monitoring within your environment, as directed by you under our DPA.
- Conducting phishing simulations and security awareness training as configured and directed by you.
- Producing anonymized, aggregated threat intelligence and industry benchmarks that do not identify any individual or organisation.
- Improving the accuracy of our detection models using anonymized security telemetry, only with appropriate contractual authorization.
- Complying with legal obligations including tax, financial reporting, and lawful government requests.
- Protecting the security, integrity, and availability of our platform and services.
6. How we share your data
We do not sell personal information. We share data only as follows:
- Service providers acting as subprocessors: cloud infrastructure (AWS / Azure / GCP / IONOS), email delivery (Brevo), CRM, payment processing, analytics, and security tooling, each under a Data Processing Agreement with equivalent protections.
- Threat intelligence networks: anonymized or pseudonymized IoCs and threat indicators may be contributed to collective intelligence sharing platforms (e.g. ISACs) to improve industry-wide defenses. No personal or organizational data is shared without your consent.
- Professional advisors: lawyers, accountants, insurers, and auditors bound by confidentiality.
- Legal and regulatory disclosure: where required by US federal or state law, court order, or regulatory authority. We will notify you where legally permitted before disclosing.
- Business transfers: in the event of a merger, acquisition, or asset sale, data may be transferred to a successor entity subject to equivalent protections and notice to affected parties.
- With your consent or at your direction: any other sharing will require your explicit authorization.
7. International data transfers
Touchpoint Security, LLC is headquartered in the United States. As a globally operating company, some personal data such as account, billing, and contact information may be transferred to, stored in, and processed in the United States and other countries where our service providers operate.
However, all dedicated MDR platform instances are hosted within the customer's local region. Security telemetry, event data, logs, and other data ingested from your environment for threat detection and response purposes is never transferred across borders. It is collected, processed, and stored within the region where your MDR instance is deployed. This is a deliberate architectural commitment to data residency and sovereignty.
We ensure appropriate safeguards are in place for any international transfers that do occur, including:
- EU Standard Contractual Clauses (SCCs), European Commission Decision 2021/914, for transfers of EU personal data to third countries.
- UK International Data Transfer Agreements (IDTAs), for transfers of UK personal data.
- EU-US Data Privacy Framework (DPF), where applicable and where we maintain certification.
- Binding Corporate Rules or adequacy decisions where available.
A list of countries where we and our subprocessors operate, together with the applicable transfer mechanisms, is available in our DPA Subprocessor List at tp-security.com/legal/subprocessors or on request.
8. Data retention
- Customer account data: duration of the service agreement plus 7 years for financial and contractual records (US federal tax and accounting requirements; EU/UK VAT records where applicable).
- Security event and telemetry data (MDR, Exposure Monitoring, Cloud Security): as specified in your Service Agreement, typically 12 months hot storage and up to 13 months total retention. Extended retention up to 24 months is available for customers with specific compliance requirements (PCI-DSS, HIPAA, NIST 800-53). Data is made available for export for 30 days following contract termination, after which it is securely deleted.
- Incident Response and forensic data: retained for the duration of the engagement plus 12 months, or longer where litigation hold applies.
- Security event and telemetry data (MDR, Exposure Monitoring, Cloud Security): as specified in your Service Agreement, typically 12 months hot storage and up to 13 months total retention. Extended retention up to 24 months is available for customers with specific compliance requirements (PCI-DSS, HIPAA, NIST 800-53). Data is made available for export for 30 days following contract termination, after which it is securely deleted.
- Penetration test and vulnerability assessment reports: Delivered to you at engagement close. Our working copies are retained for 12 months to support any remediation queries, then securely destroyed. Final signed reports are retained for the duration of any applicable legal hold or regulatory requirement, up to 3 years maximum.
- Security Awareness Training records: Employee completion status and phishing simulation results are retained for 12 months by default. Extended retention beyond 12 months is available where required for audit or compliance purposes (SOC 2, ISO 27001, HIPAA).
- Marketing contact data: Retained while your consent or legitimate interest applies. On unsubscribe, your details are suppressed rather than deleted to ensure we honor your opt-out on any future contact attempts. Suppressed records are reviewed annually and deleted where no active customer or legal relationship exists.
- Website logs and analytics: Raw server and access logs are retained for 90 days. Aggregated, anonymized analytics data is retained for 13 months, aligned with Google Analytics 4 default retention and standard web analytics practice.
After retention periods expire, data is securely deleted or anonymized using industry-standard methods.
9. Your rights
Depending on your jurisdiction, you may have some or all the following rights:
- Access: obtain a copy of the personal data we hold about you.
- Rectification / correction: request that inaccurate or incomplete data be corrected.
- Erasure / deletion: request deletion of your data where no overriding legal basis exists for its retention.
- Restriction: request that we limit processing in certain circumstances.
- Portability: receive your data in a structured, machine-readable format (GDPR / UK GDPR / CPRA).
- Objection: object to processing based on legitimate interests, including direct marketing.
- Withdraw consent: where processing is consent-based, withdraw at any time without affecting prior processing.
- Automated decisions: we do not make solely automated decisions with legal or significant effects.
To exercise any right, email privacy@tp-security.com. We will respond within 30 days (GDPR / UK GDPR), 45 days (CCPA/CPRA), or within the timeframe required by your applicable law. We may verify your identity before actioning requests.
You also have the right to lodge a complaint with your applicable supervisory authority:
- EU: your national Data Protection Authority (DPA).
- UK: the Information Commissioner's Office (ICO) at ico.org.uk.
- USA: the FTC or your state Attorney General.
- Canada: The Office of the Privacy Commissioner at priv.gc.ca.
10. Security
As a cybersecurity company, security is foundational to everything we do. Our technical and organizational measures include:
- Encryption of all data in transit (TLS 1.3) and at rest (AES-256).
- Role-based access control (RBAC) with least-privilege enforcement.
- Multi-factor authentication (MFA) required for all platform and infrastructure access.
- Continuous security monitoring of our own environment using our MDR platform.
- Regular internal and third-party penetration testing and vulnerability assessments.
- SOC 2 Type 1 in progress, SOC 2 Type 2 audit in progress, ISO27001 in progress.
- Incident response plan with defined MTTD, MTTR, and breach notification procedures.
- Employee security awareness training, background checks and right to work.
- Vendor security assessments for all subprocessors with access to personal data.
In the event of a personal data breach, we will notify affected parties and applicable regulators within the timeframes required by law (72 hours under GDPR/UK GDPR; as required under applicable US state breach notification laws).
11. Cookies and tracking technologies
We use cookies and similar technologies as described in our Cookie Policy at tp-security.com/cookie-policy, which is incorporated into this Privacy Policy. Our consent management platform allows you to control non-essential cookies at any time.
12. Children's data
Our services are directed at business organizations and professionals aged 18 and over. We do not knowingly collect personal data from individuals under 18. If you believe we have inadvertently done so, contact privacy@tp-security.com and we will delete it promptly.
13. Changes to this policy
We may update this Privacy Policy to reflect changes in our services, legal requirements, or data practices. Where changes are material, we will notify you by email and/or prominent notice on our website at least 30 days before the change takes effect. The "Last reviewed" date at the top reflects the most recent revision. Continued use of our services after the effective date constitutes acceptance.
14. Contact us
For privacy enquiries, data subject requests, or to reach our Data Protection Officer:
Touchpoint Security, LLC.
82 Wendell Ave, Ste 100, Pittsfield, MA 01201, United States
Privacy: privacy@tp-security.com
DPO / EU Representative: dpo@tp-security.com
Legal: legal@tp-security.com
Security incidents: security@tp-security.com