OLIGO PRIVACY POLICY
Last Updated: October 21, 2024
In order to ensure transparency and give you more control over your personal information, this privacy policy (“Privacy Policy”) governs how we, Oligo Cyber Security Ltd. and our affiliates (“Oligo”, “we”, “our” or “us”) use, collect and store personal information that we collect or receive from or about you (“you”) in connection with www.oligosecurity.com (“Website”), and the services provided (the “Services”)..
We greatly respect your privacy, which is why we make every effort to provide a platform that would live up to the highest user privacy standards. Please read this Privacy Policy carefully, so you can fully understand our practices in relation to personal data. Important note: Nothing in this Privacy Policy is intended to limit in any way your statutory rights, including your rights to a remedy or other means of enforcement.
1. WHAT INFORMATION WE COLLECT, WHY WE COLLECT IT, AND HOW IT IS USED
2. HOW WE PROTECT AND RETAIN YOUR PERSONAL INFORMATION
3. HOW WE SHARE YOUR PERSONAL INFORMATION
4. YOUR PRIVACY RIGHTS
5. INTERNATIONAL TRANSFERS OF PERSONAL INFORMATION.
6. USE BY CHILDREN.
7. INTERACTION WITH THIRD PARTY PRODUCTS.
8. ANALYTIC TOOLS/COOKIES
9. SPECIFIC PROVISIONS APPLICABLE UNDER CALIFORNIA PRIVACY LAW
10. CONTACT US.
Oligo’s mission is to provide you with information about our company, products and services. Oligo is providing a security tool, integrating directly into the development tools and workflows of its clients, in order to scan the open source code you might be using when developing your product. Oligo makes it easy for you to detect, monitor, prevent & fix security vulnerabilities in the open source code you might be using.
This Privacy Policy can be updated from time to time and, therefore, we ask you to check back periodically for the latest version of this Privacy Policy. If we implement material changes in the way we use your information, in a manner that is different from that stated at the time of collection, we will notify you by posting a notice on our Website or by other means and take any additional steps as required by applicable law.
- WHAT INFORMATION WE COLLECT, WHY WE COLLECT IT, AND HOW IT IS USED
- We process the following personal information:
- Information provided through the Website. When you use the Website, we collect and process your full name, business email address, job title, phone number and any other personal information that you provide us with.
- Information automatically collected. We may automatically collect certain information through your use of our Website, such as cookies, pixels, tracking technologies and similar identifiers (“Technologies”), your Internet protocol (IP) address, and other device identifiers that are automatically assigned to your device, browser type and language, geo-location information, hardware type, operating system, internet service provider and other information about actions taken through the use of the Services and Website.
- Information from other sources. Oligo may also obtain information about you from other sources, including publicly or commercially available information, and through third-party data platforms, partners and service providers.
- Information you provide to us in person. For example, when you visit one of our exhibition booths or attend one of our events and you provide us with your contact details. We will use this information to answer your enquiries or provide additional information to you.
- Information we collect from online interactions. For example, if you attend a webinar, contact us via social media or otherwise interact with our business, including as a representative of a current / prospective customer, supplier or partner, we track and make a record of those interactions, which may contain your contact details, such as full name, email address, messages and any other information that you decide to provide us with.
- We process information for the following purposes:
- To allow you to make use of our Website. We will use your information to allow you to make full use of our Website, including, (i) if you request a demo, we will use your personal data to process and answer your request for a demo; (ii) to answer your questions and to allow you to communicate with us; (iii) to analyze your use of our Website and to improve our Website; and (iv) to customize your experience.
- For administrative purposes. Oligo may use your information (i) to respond to your questions, comments, and other requests for customer support, or information, including information about potential or future services; (ii) to provide you with the Services; (iii) for internal quality control purposes; (iv) to establish a business relationship; (v) to generally administer the Services; and (vi) to provide you with information about Oligo’s products and Services.
- To market our Website and Services. Oligo may use information to market the Services. Such use includes (i) notifying you about offers and services that may be of interest to you; (ii) developing and marketing new products and services, and to measure interest in Oligo’s products and services; (iii) other purposes disclosed at the time you provide information; (iv) as you otherwise consent;
- Security purposes. Some of the above information will be used for detecting, taking steps to prevent and prosecuting fraud or other illegal activity; to identify and repair errors; to conduct audits; and for security purposes. Information may also be used to comply with applicable laws, with investigations performed by the relevant authorities, law enforcement purposes, and/or to exercise or defend legal claims.
- De-identified and aggregated information use. In certain cases, we may or will anonymize or de-identify your Information and further use it for internal and external purposes, including, without limitation, to analyze and improve Oligo’s products and services (including through the use of artificial intelligence) and for research purposes. We may use this anonymous or de-identified information and/or disclose it to third parties without restrictions (for example, in order to improve our services and enhance your experience with them and/or to develop new product features and improve existing offerings).
- Cookies and similar technologies. We, as well as third parties that provide content, advertising, or other functionality on the Website, and Services, may use cookies, pixel tags, local storage, and other technologies (“Technologies”) to automatically collect information through the Services. We use Technologies that are essentially small data files placed on your device that allow us to record certain pieces of information whenever you visit or interact with the Services. If you would like to opt out of the Technologies we employ on the Services, you may do so by blocking, deleting, or disabling them as your browser or device permits.
- The lawful bases we rely on for processing personal information are (if and when applicable):
- The data subject has given consent to the processing of his or her personal data;
- Processing is necessary for the performance of a contract to which the data subject is party or in order to take steps at the request of the data subject prior to entering into a contract;
- processing is necessary for compliance with a legal obligation to which the controller is subject; and/or
- Processing is necessary for the purposes of the legitimate interest.
- HOW WE PROTECT AND RETAIN YOUR PERSONAL INFORMATION
- Security. We have implemented and maintain reasonable technical, organizational and security measures designed to protect your information. However, please note that we cannot guarantee that the information will not be compromised as a result of unauthorized penetration to our servers. As the security of information depends in part on the security of the computer, device or network you use to communicate with us and the security you use to protect your user IDs and passwords, please make sure to take appropriate measures to protect this information.
- Retention of your information. Your information will be stored until we delete our records, and we proactively delete it, or if you send a valid deletion request. Please note that in some circumstances we may store your information for longer periods of time, for example (i) where we are required to do so in accordance with legal, regulatory, tax or accounting requirements, or (ii) for us to have an accurate record of your dealings with us in the event of any complaints or challenges, and/or (iii) if we reasonably believe there is a prospect of litigation relating to your information or dealings.
- HOW WE SHARE YOUR PERSONAL INFORMATION
We share your information as follows:
- The information Oligo gathers is shared with our partners and other third parties.
- We may also share information with our affiliated companies about you.
- We may use third party service providers to process your information for the purposes outlined above, including, without limitation:
3.3.1 With cloud service providers for hosting purposes;
3.3.2 With websites and web content creation platforms in order to help us manage our Website;
3.3.3 With email providers, marketing, CRM, other similar tool providers;
3.3.4 With analytic companies, in order to help us understand and analyze information we collect in accordance with this policy; and
3.3.5 With Vitally, a customer success platform, for the purpose of tracking customer interactions, engagement, and success metrics. for managing customer relationships and improving your experience. - To the extent necessary, with regulators, courts, banks or competent authorities, to comply with applicable laws, regulations and rules (including, without limitation, federal, state or local laws), and requests of law enforcement, regulatory and other governmental agencies or if required to do so by court order, as well as for internal compliance procedures and to protect the safety, security, and integrity of Oligo, our Services, customers, employees, property, and the public.
- If, in the future, we sell or transfer, or we consider selling or transferring, some or all of our business, shares or assets to a third party, we will disclose your information to such third party (whether actual or potential) in connection with the foregoing events (including, without limitation, our current or potential investors). In the event that we are acquired by, or merged with, a third party entity, or in the event of bankruptcy or a comparable event, we reserve the right to transfer, disclose or assign your information in connection with the foregoing events.
- Where you have otherwise provided your consent to us for sharing or transferring your information.
- YOUR PRIVACY RIGHTS
- The following rights (which may onlybe subject to certain exemptions or derogations) shall apply to certain individuals (some of which apply to individuals protected by specific laws):
- i. You have the right to withdraw consent to the processing, where consent is the basis of processing.
- ii. You have the right to access the personal information that we hold and request further details about how we process it, under certain conditions.
- iii. You have the right to demand rectification of inaccurate personal information about you. We will promptly correct any information found to be incorrect.
- iv. You have the right to object to unlawful data processing under certain conditions.
- v. You have the right to the erasure of past data about you (your “right to be forgotten”) under certain conditions.
- vi. You have the right to demand that we restrict the processing of your personal information, under certain conditions, if you believe we have exceeded the legitimate basis for processing, the processing is no longer necessary, or if you believe your personal information is inaccurate.
- vii. You have the right to data portability of personal information concerning you that you provided us in a structured, commonly used, and machine-readable format, subject to certain conditions.
- viii. The personal information we collect is not used for automated decision-making and profiling, except for automated processes in the context of marketing. As stated above, you can opt out of direct marketing by Oligo by contacting Oligo directly or by following the instructions through the unsubscribe options in our email messages.
- You can exercise your rights by contacting us at info@oligosecurity.io. You may use an authorized agent to submit a request on your behalf if you provide the authorized agent with written permission signed by you. To protect your privacy, we may take steps to verify your identity before fulfilling your request. Subject to legal and other permissible considerations, we will make every reasonable effort to honor your request promptly in accordance with applicable law or inform you if we need further information in order to fulfil your request. When processing your request, we may ask you for additional information to confirm or verify your identity and for security purposes, before processing and/or honoring your request. We reserve the right to charge a fee where permitted by law, for instance if your request is manifestly unfounded or excessive. In the event that your request would adversely affect the rights and freedoms of others (for example, would impact the duty of confidentiality we owe to others) or if we are legally entitled to deal with your request in a different way than requested, we will address your request to the maximum extent possible, all in accordance with applicable law.
- Deleting your account: Should you ever decide to delete your account, you may do so by emailing info@oligosecurity.io. If you terminate your account, any association between your account and personal data we store will no longer be accessible through your account. However, given the nature of sharing on certain services, any public activity on your account prior to deletion will remain stored on our servers and will remain accessible to the public.
- Marketing emails – opt-out: You may choose not to receive marketing email of this type by sending a single email with the subject “BLOCK” to info@oligosecurity.io Please note that the email must come from the email account you wish to block OR if you receive an unwanted email from us, you can use the unsubscribe link found at the bottom of the email to opt out of receiving future emails, and we will process your request within a reasonable time after receipt. If you terminate your account, any association between your account and personal information we store will no longer be accessible through your account.
- INTERNATIONAL TRANSFERS OF PERSONAL INFORMATION.
- We store the Personal Data with the following storing companies: AWS - EU.
- In order to run our business and provide our Website, and Services to you, we transfer Personal Data to certain countries around the world, including to our affiliates and service providers, many of whom are located outside of your jurisdiction. Therefore, your Personal Data may be processed in countries with privacy laws that are different from privacy laws in your country. Whenever we make such transfers, we will use commercially reasonable efforts to implement an appropriate level of protection to your Personal Data by implementing at least one of the following safeguards:
- making sure the destination country has been deemed to provide an adequate level of protection for Personal Data; and/or
- by executing implement data onward transfer instruments such as data processing and protection agreements.
- USE BY CHILDREN.
We do not offer our products or services for use by children and, therefore, we do not knowingly collect information from, and/or about children under the age of 18. If you are under the age of 18, do not provide any information to us without the involvement of a parent or a guardian. In the event that we become aware that you provide information in violation of applicable privacy laws, we reserve the right to delete it. If you believe that we might have any such information, please contact us at info@oligosecurity.io - INTERACTION WITH THIRD PARTY PRODUCTS.
We enable you to interact with third party websites, mobile software applications and products or services that are not owned, or controlled, by us (each, a “Third Party Service”). We are not responsible for the privacy practices or the content of such Third Party Services. Please be aware that Third Party Services can collect information from you. Accordingly, we encourage you to read the terms and conditions and privacy policies of each Third Party Service. - ANALYTIC TOOLS/COOKIES
- • Google Analytics. The Website uses a tool called “Google Analytics” to collect information about use of the Website. Google Analytics collects information such as how often users visit this Website, what pages they visit when they do so, and what other websites they used prior to coming to this Website. We use the information we get from Google Analytics to maintain and improve the Website and our products. We do not combine the information collected through the use of Google Analytics with information we collect. Google’s ability to use and share information collected by Google Analytics about your visits to this Website is restricted by the Google Analytics Terms of Service, available at https://marketingplatform.google.com/about/analytics/terms/us/, and the Google Privacy Policy, available at http://www.google.com/policies/privacy/. You may learn more about how Google collects and processes data specifically in connection with Google Analytics at http://www.google.com/policies/privacy/partners/. You may prevent your data from being used by Google Analytics by downloading and installing the Google Analytics Opt-out Browser Add-on, available at https://tools.google.com/dlpage/gaoptout/.
- • Facebook Pixels and SDKs. We use Facebook pixels or SDKs, which are tools that provide help to website owners and publishers, developers, advertisers, business partners (and their customers) and others integrate, use and exchange information with Facebook, as such the collection and use of information for ad targeting and retargeting. Please note that third parties, including Facebook, use cookies, web beacons, and other storage technologies to collect or receive information from our website and elsewhere on the internet and use that information to provide measurement services and target ads. Facebook’s ability to use this information is governed by the Facebook Business Tools Terms, available at: https://www.facebook.com/legal/technology_terms/. You can prevent your data from being used by Facebook Pixels and SDKs by exercising your choice through these mechanisms: http://www.aboutads.info/ choices or http://www.youronlinechoices.eu/.
- • Hotjar. We use Hotjar in order to better understand our users’ needs and to optimize this service and experience. Hotjar is a technology service that helps us better understand our users’ experience (e.g. how much time they spend on which pages, which links they choose to click, what users do and don’t like, etc.) and this enables us to build and maintain our service with user feedback. Hotjar uses cookies and other technologies to collect data on our users’ behavior and their devices. This includes a device's IP address (processed during your session and stored in a de-identified form), device screen size, device type (unique device identifiers), browser information, geographic location (country only), and the preferred language used to display our website. Hotjar stores this information on our behalf in a pseudonymized user profile. Hotjar is contractually forbidden to sell any of the data collected on our behalf. For further details, please see the ‘about Hotjar’ section of Hotjar’s support site.
- • Google Signals. The Website uses a tool called “Google Signals” to collect information about use of the Website. When we activate Google Signals, some existing Google Analytics features are updated to also include aggregated data from Google users who have turned on “Ads Personalization” (Ads Personalization available at https://support.google.com/ads/answer/2662856/). Audiences that we create in Google Analytics and publish to Google Ads and other Google Marketing Platform advertising products can serve ads in cross device-eligible remarketing campaigns to Google users who have turned on Ads Personalization. Google Analytics collects additional information about users who have turned on Ads Personalization, base across device types and on aggregated data from users who have turned on Ads Personalization. The data is user based rather than session based. The Cross Device reports include only aggregated data. No data for individual users is ever exposed. You can modify your interests, choose whether your Personal Data is used to make ads more relevant to you, and turn on or off certain advertising services in the Ads Personalization link above.
- • Linkedin Pixel. We use LinkedIn pixels and Insight Tags, which are tools that allow us to send data to LinkedIn and its affiliates about actions that people take on our platform, in order to use LinkedIn's tool to assess the performance and effectiveness of our campaigns and to optimize our campaigns. The LinkedIn Insight Tag enables the collection of data regarding members’ visits to our platform, including IP address, device and browser characteristics, and timestamp. LinkedIn's ability to use and share your information is governed LinkedIn's Ads Agreement, available here: https://www.linkedin.com/legal/sas-terms. You can opt-out of having your data used by LinkedIn through this link: https://www.linkedin.com/psettings/guest-controls/retargeting-opt-out, or through these standard opt-out websites: www.networkadvertising.org/choices or www.aboutads.info/choices.
- • Hubspot. We use Hubspot for the purpose of optimizing our social media marketing, to better manage our content, and to help us optimize our Platform. For more information about Hubspot's privacy practices, please see their privacy policy available here: https://legal.hubspot.com/privacy-policy.
- • Through our Services we may allow third party advertising partners to set technologies and other tracking tools to collect information regarding your activities and your device (e.g., your IP address, mobile identifiers, page(s) visited, location, time of day). We may also combine and share such information and other information (such as demographic information and past purchase history) with third party advertising partners. These advertising partners may use this information (and similar information collected from other websites) for purposes of delivering targeted advertisements to you when you visit third party websites within their networks. This practice is commonly referred to as “interest-based advertising” or “online behavioral advertising”. We may allow access to other data collected by the services to share information that may be useful, relevant, valuable or otherwise of interest to you.
- • We reserve the right to remove or add new analytic tools, cookies, pixels and other tracking technologies.
- SPECIFIC PROVISIONS APPLICABLE UNDER CALIFORNIA PRIVACY LAW
- California Privacy Rights: California Civil Code Section 1798.83 permits our customers who are California residents to request certain information regarding our disclosure of information to third parties for their direct marketing purposes. To make such a request, please send an email to info@oligosecurity.io. Please note that we are only required to respond to one request per customer each year.
- Our California Do Not Track Notice: Do Not Track (“DNT”) is a privacy preference that users can set in certain web browsers. Please note that we do not respond to or honor DNT signals or similar mechanisms transmitted by web browsers.
- CONTACT US.
If you have any questions, concerns or complaints regarding our compliance with this notice and the data protection laws, or if you wish to exercise your rights, we encourage you to first contact us at info@oligosecurity.io.