This Privacy Policy applies to ThreatBook, a company incorporated in Singapore (“we”, “us”, “our”), and governs the collection, use, storage, disclosure, and protection of Personal Data in connection with our Threat Intelligence (ATI) platform, threat intelligence services, website, console, API, and mobile application (APP) (collectively, the “Services”).
1. Definitions
1.1 Personal Data: Any data about an identified or identifiable individual, as defined under Personal Data Protection Act (PDPA), including name, email, phone, job title, company, IP address, login details, billing information, and usage data.
1.2 Processing: Any operation performed on Personal Data, including collection, recording, storage, use, disclosure, and destruction.
1.3 User / You: Any individual or organization that accesses or uses the Services.
1.4 Services: Attack surface intelligence, threat data, vulnerability information, sandbox analysis, reporting, monitoring, API, mobile application (APP), and related platform features.
2. Personal Data We Collect
2.1 Account and contact data: Name, email address, company name, login credentials.
2.2 Usage and technical data: IP address, device type, browser, log data, API call records, service access patterns, configuration settings.
2.3 Mobile app specific data: device identifier (IDFA/IDFV/Android ID), device model, operating system version, APP crash logs, push notification status, and APP usage session data.
2.4 Support and communication data: Information provided in support tickets, feedback, inquiries, and correspondence.
2.5 Other data: Any information you voluntarily upload or input into the Services.
2.6 System permissions for APP
We may request the following mobile system permissions to provide corresponding functions:
You may disable permissions at any time in system settings, which may only affect related functions but not basic use of the APP.
3. Purposes of Collection and Use
We collect and use Personal Data only for reasonable, specified, and lawful purposes, including:
3.1 To create, verify, and manage your account.
3.2 To provide, operate, maintain, and improve the Services.
3.3 To process subscriptions, payments, and billing.
3.4 To respond to support requests, inquiries, and feedback.
3.5 To send service announcements, updates, and security alerts.
3.6 To ensure security, detect fraud, abuse, unauthorized access, and violations of our User Agreement and AUP.
3.7 To comply with legal obligations, resolve disputes, and enforce agreements.
3.8 To conduct data analytics and product development (on anonymized or aggregated data).
4. Disclosure of Personal Data
We may disclose Personal Data only as permitted under this Policy and applicable law:
4.1 To our affiliates, employees, and contractors who need access to perform Services.
4.2 To third-party service providers (cloud hosting, payment processing, customer support, IT services) bound by confidentiality and data protection obligations.
4.3 To legal authorities, regulators, or courts when required by law, subpoena, or official request.
4.4 In connection with a corporate transaction such as merger, acquisition, or sale of assets.
4.5 With your explicit consent or at your direction.
We do not sell, rent, or lease Personal Data to third parties for commercial purposes without your consent.
5. Data Security
5.1 We implement reasonable technical and organizational safeguards to protect Personal Data against unauthorized access, use, disclosure, alteration, or destruction.
5.2 Access to Personal Data is limited to authorized personnel on a need-to-know basis.
5.3 We maintain security incident response procedures to address data breaches in compliance with PDPA.
5.4 Despite our efforts, no electronic storage or transmission is fully secure; we cannot guarantee absolute security.
6. Data Retention
6.1 We retain Personal Data only for as long as necessary to fulfill the purposes for which it was collected or as required by law.
6.2 Upon termination of your account or subscription, we will delete or anonymize your Personal Data except where retention is required for legal, regulatory, tax, or audit purposes.
7. Cross-Border Transfers
7.1 Personal Data may be transferred, stored, or processed outside Singapore.
7.2 We ensure such transfers comply with PDPA, including through appropriate safeguards such as written agreements, standard contractual clauses, or consent.
8. Your Rights Under PDPA
You may request to:
8.1 Access or correct your Personal Data.
8.2 Withdraw consent to the collection, use, or disclosure of your Personal Data (where applicable).
8.3 Delete your Personal Data, where legally permissible.
8.4 Limit or restrict Processing of your Personal Data.
We may verify your identity before fulfilling requests and may decline requests as permitted by law.
9. Cookies and Similar Tracking Technologies (APP and Web)
9.1 We may use cookies, log files, and similar tools to improve user experience, analyze usage, and manage security.
9.2 You may adjust browser settings to refuse cookies; however, some features of the Services may not function properly.
9.3 On the APP, we may use similar identifiers (such as IDFA, Android ID) for statistical analysis, service optimization and security monitoring. You can reset or disable advertising identifiers in your device system settings.
10. Third-Party Links
The Services may contain links to third-party websites or services. We are not responsible for the privacy practices or content of such third parties.
11. Changes to This Policy
11.1 We may update this Policy periodically. Material changes will be posted on our website with a revised effective date.
11.2 Your continued use of the Services including the APP after the update constitutes acceptance of the revised Policy.
12. Contact Information
For questions, complaints, or requests regarding this Privacy Policy or Personal Data, please contact: contactus@threatbook.io