← Legal Center

ThreatModeler Global Privacy Policy

Last Updated: July, 2026

Global Privacy Policy Last Updated: July, 2026

1. Introduction

This Global Privacy Policy (“Policy”) is issued on behalf of the ThreatModeler group of companies.

When we mention “ThreatModeler”, “we”, “us”, or “our” in this Policy, we are referring to the relevant company within the ThreatModeler group responsible for processing your data. For the purposes of this global policy and the centralized services we provide, ThreatModeler Software, Inc., is the primary Data Controller or Business that determines the purposes and means of processing your personal data.

Our affiliates and subsidiaries (“Affiliates”) are part of our global organization and may access, process, or collect data on our behalf or for their local operational needs, in accordance with the purposes described in this Policy. This is managed through an intra-group data sharing framework.

This Global Privacy Policy (“Policy”) describes how ThreatModeler, acting as a Data Controller or Business, collects, uses, discloses, and otherwise processes your personal data. It also explains the rights you have as a Data Subject or Consumer regarding your personal data.

Please read this Policy carefully. If you do not agree with it, we advise you not to access our websites, use our Services, or interact with any other aspect of our business. For any questions, you can contact our Global Privacy Lead and Privacy Team at privacy@threatmodeler.com.

2. Scope of this Privacy Policy

This Policy applies to the processing of personal data we collect as a Data Controller or Business when you:

  • Visit or interact with our websites, applications, and digital properties where this policy is posted or linked (collectively, our “Websites”).
  • Apply for a job with us.
  • Sign up for and use our free “Community Edition.”
  • Register for, access, and use our online training platform, “ThreatModeler Academy,” including tracking your course progress and issuing certifications.
  • Register for and participate in our other online or in-person events, webinars, training sessions, or contests, including hackathons, raffles, and tournaments.
  • Engage with our communities, such as “Threat Modeling Connect” and participate in ThreatModCon events.
  • Interact with our Customer Support platform to submit inquiries, open tickets, or request technical assistance (whether as a free user or an authorized corporate customer user).
  • Interact with us as an authorized user of our customers’ accounts for our Enterprise Services.
  • Engage with us in a professional context, such as through email, phone, or at industry events.
  • Receive marketing communications from us.

This Policy does not apply to the data that our customers and their users upload, create, or manage within our B2B enterprise SaaS platform (“Customer Data”). In this context, our customer is the Data Controller, and ThreatModeler acts as a Data Processor. Our processing of Customer Data is governed by the service agreement and the Data Processing Addendum (DPA) executed with our customer.

This Policy applies only to the limited personal data we collect about our customers’ authorized users for account administration and service delivery purposes, as detailed in Section 4.

This Policy does not apply to our employees or independent contractors, who are covered by a separate internal privacy notice.

3. How We Collect Your Personal Data

We collect personal data from various sources:

A. Personal Data You Provide Directly to Us:

You provide us with personal data when you create an account, request a demo, register for an event, fill out a form, contact our support, or otherwise communicate directly with us.

B. Personal Data We Collect Automatically:

When you interact with our Websites and Services, we automatically collect technical information using tools like cookies. This includes device information, IP address, and usage data. For detailed information, please refer to our Cookie Policy.

C. Personal Data We Obtain from Third-Party Sources:

We may obtain personal data from other sources to enhance our records and for business development purposes. These sources include:

  • Data Enrichment Providers: B2B data providers who supply us with professional information such as company, job title, and contact details.
  • Publicly Available Sources: Professional networking platforms (e.g., LinkedIn) and public corporate websites.
  • Business & Event Partners: Third parties with whom we co-host events or collaborate on marketing activities.

We only use data from third-party sources that confirm they are legally permitted to share this information with us.

4. Personal Data We Process and Our Lawful Basis

The table below details our data processing activities, the data involved, our legal justification (“Lawful Basis”), and how long we retain the data.

Processing Activity / Purpose Categories of Personal Data Processed Lawful Basis (under GDPR) Retention Period
Enterprise Service Account Management. To create and manage accounts for our customers’ authorized users, provide support, and ensure service security. Identity & Contact Data: Name, business email, phone.
Professional Data: Company, job title.
Account Data: User ID, credentials.
Usage Data: Platform activity logs.
Performance of a contract with our customer.
Our legitimate interest in service security and administration.
For the duration of the customer’s contract. Data is then blocked for 5 years to address potential legal liabilities before deletion.
Use of Community Edition. To provide access to our free tool, as governed by the Community Edition Terms of Service. Identity & Contact Data: Name, username, email.
Device & Location Data.
Platform & User-Generated Content: User activity, threat models.
Performance of a contract (Community Terms).
Our legitimate interest in product improvement and AI model training, as detailed in the Terms.
For as long as you remain subscribed. Upon unsubscribing, data is blocked for 5 years before deletion.
Threat Modeling Connect Community, Webinars, and ThreatModCon Events. To manage your membership in the community, process event registrations (online and on-site), facilitate event logistics (including dietary or accessibility requirements), issue badges, handle event payments, and manage event recordings/photography. Identity & Contact Data: Name, email, professional details.
Logistical Data: Dietary restrictions (allergies) or accessibility needs (processed only with your explicit consent).
Audiovisual Data: Photography, video, and audio recordings captured during online sessions or on-site events.
Billing Data: Payment details (where applicable for paid tickets).
Performance of a contract (Event terms/ticketing agreement).
Our legitimate interest in capturing promotional media, publishing event recordings, and facilitating networking.
Your explicit Consent for processing health/dietary data and for targeted sponsor data-sharing.
For the duration of your community membership or event cycle. Audiovisual promotional materials may be retained indefinitely in our archives, or until you object/request erasure.
ThreatModeler Academy & Other Training. To provide access to our training platform, as governed by the Academy Terms of Service and Academy Privacy Policy. Identity, Contact & Professional Data.
Learning & Progress Data: Course enrollment, progress, certificates.
Attendance Data (for events).
Image & Voice (for recorded sessions).
Performance of a contract (Academy Terms / event registration).
Your Consent for session recordings.
While your Academy account is active, then blocked for 5 years. For one-off events, data is blocked for 5 years.
Recruitment & Talent Acquisition. To evaluate and process applications for employment. For more details, see our Candidate Privacy Policy. Identity & Contact Data.
Professional & Educational Data: CV/resume, work history, references.
Interview Data: Notes and assessments.
Our legitimate interest in evaluating candidates.
Processing necessary for pre-contractual measures.
For the duration of the application process. If not hired, data is retained for a limited period for legal claims, unless you provide Consent to retain it for future opportunities.
Inquiries, Demos, and Content Requests. To provide you with information you request (via contact forms, chatbot), schedule demos, give pricing quotes, provide resources (ebooks), and offer general support to non-customers. Identity, Contact & Professional Data.
Content of your request: The specific information you are asking for.
Performance of pre-contractual measures at your request (for demos, pricing).
Our legitimate interest in responding to your inquiries and providing support.
For the time necessary to handle your request. Afterward, data is blocked for 5 years to address potential liabilities.
Business Meetings, Sales Demos, and Customer Success Calls. To facilitate, record, and transcribe professional video and audio calls for meeting minutes, accurate customer requirement tracking, internal training, and quality assurance. Identity & Contact Data (Name, email).
Audiovisual Data (Voice recordings, video/image, screen sharing content).
AI-Generated Data (Meeting transcripts, action items, summary notes, and interaction analytics).
Your explicit Consent (provided via our meeting consent screens or verbal confirmation before recording starts).
Our Legitimate Interest in improving our sales processes and training our teams (only where consent is not legally mandated).
Retained for up to 36 months after the recording date. Thereafter, recordings are archived or deleted, unless required for ongoing legal claims or disputes.
Business Development and Strategic Partnerships. To proactively contact professionals, assess business opportunities, and negotiate contractual documents Identity, Contact & Professional Data obtained from public sources (e.g., LinkedIn) or direct contact.
Communication Records.
Signature.
Our legitimate interest in pursuing business opportunities and establishing commercial relationships. For as long as the business relationship or negotiation is active. Afterward, data is blocked for 5 years.
Marketing and Advertising. To send you newsletters and promotions about our products and services. Identity, Contact & Professional Data.
Interaction Data: How you engage with marketing communications.
Inferred Data: Your professional interests.
Consent or Legitimate Interest.
We rely on Consent where required by law.
We rely on our Legitimate Interest for relevant B2B communications where permitted.
Until you opt-out. Upon opt-out, your contact details are moved to a suppression list, retained indefinitely to ensure compliance.
Community Surveys. To gather feedback and improve the user experience of our tools, if you choose to participate. Identity, Contact & Professional Data.
Any other information you choose to provide in the survey.
Your Consent (participation is voluntary). During the time necessary to analyze the survey. Afterward, data will be anonymized or deleted.
Hackathons and Other Contests. To manage your participation in contests, raffles, and tournaments. Identity, Contact & Professional Data. Performance of a contract (through your acceptance of the contest’s legal terms). For the duration of the contest and prize fulfillment. Afterward, data is blocked for 5 years.
Customer Support Services. To triage, troubleshoot, and resolve technical issues submitted through our ticketing system, emails, or live chat, and to maintain support records. Identity & Contact Data: Name, email, phone number.
Account Data: Salesforce support account details.
Support & Diagnostic Data: Live chat transcripts, ticket descriptions, diagnostic attachments (logs, screenshots, or customer-submitted screen recordings), and communication history with our support staff.
Performance of a contract with our customer. Our legitimate interest in resolving technical issues, maintaining platform integrity, and improving our customer service. For the duration of the customer support relationship. Afterward, ticket records and associated personal data are blocked for 5 years to address potential legal or contractual liabilities before deletion.
Interactive Features and Social Media. To engage with our community on third-party forums, blogs, and social media pages. Identity, Contact & Professional Data you make public on those platforms.
Any content you direct at us.
Our legitimate interest in managing our brand presence and engaging with our community. Note: The third-party platform’s privacy policy also applies. Data is retained according to our marketing and business development policies if we import it into our systems.
Data Subject Requests. To manage and fulfill your data protection rights as a data subject. Any personal data necessary to verify your identity and locate your information within our systems. Compliance with a legal obligation (under GDPR, CCPA, etc.). For the time necessary to process the request and for the legal period required to demonstrate compliance (typically 5 years).
Website Analytics & Improvement. To understand how users interact with our Websites and improve functionality. Technical Data: IP address, device/browser.
Usage Data: Pages visited, time on site.
Our legitimate interest in maintaining our digital presence.
Your Consent for non-essential cookies. See our Cookie Policy.
Depends on the specific cookie; refer to our Cookie Policy.
Legal & Security Compliance. To comply with legal obligations and protect our systems and users. All relevant data categories as required by the specific legal or security event. Compliance with a legal obligation.
Our legitimate interest in security and enforcing our legal rights.
As long as required by applicable law or for the duration of the legal process.

5. How We Share and Disclose Your Personal Data

Our commitment is to limit data sharing to what is necessary for our operations and to do so with the utmost respect for your privacy. We do not “sell” your personal data for monetary consideration. However, as defined by laws like the CCPA/CPRA, we may “share” it with third parties for cross-context behavioral advertising.

We may disclose or share your personal data with the following categories of third parties under specific circumstances and with appropriate safeguards in place:

5.1. ThreatModeler Group Affiliates

We disclose personal data within our corporate group of Affiliates for internal administrative and business purposes, operational delivery, consolidated customer support, and shared marketing or sales activities, in accordance with Recital 48 of the GDPR. Because corporate group members are treated as separate legal entities, this data sharing is strictly governed by our Intra-Group Data Sharing and Transfer Agreement (IGDTA). This agreement legally establishes the respective roles and responsibilities of each entity (whether acting as independent controllers, joint controllers, or data processors). It incorporates the EU Standard Contractual Clauses (SCCs) to secure cross-border transfers and mandates strict technical and organizational security measures, ensuring a consistent and high level of data protection throughout our global organization. Access to shared databases (such as CRM and customer support platforms) is strictly restricted based on the principle of least privilege.

5.2. Service Providers and Sub-processors

We engage trusted third-party vendors who act as our data processors to perform services on our behalf. These providers are contractually bound to protect your data under strict Data Processing Addenda (DPAs) and are prohibited from using it for any purpose other than as instructed by us. This includes:

  • Cloud and IT Infrastructure: Cloud hosting providers that store our data, run our platforms, and ensure high availability (e.g., Amazon Web Services, Microsoft Azure, Google Cloud).
  • Business and Sales Platforms: Customer Relationship Management (CRM) systems that help us manage our customer and prospect relationships (e.g., Salesforce).
  • Marketing, Analytics, and User Experience Platforms: Tools for marketing automation (e.g., HubSpot), website and platform analytics (e.g., Google Analytics), and user experience analysis.
  • Communication, Collaboration, and Support Tools: Platforms for email delivery, internal communication, engineering collaboration, and customer support ticket management (e.g., Slack, Jira).
  • E-Learning, Training, and Certification Platforms: Third-party LMS platforms and digital credential services that host our training materials, track student progress, and issue professional certifications (e.g., LearnWorlds, Accredible).
  • Payment Processors: Where applicable, secure third-party services that process payments for our paid services. We do not store your full payment card details.
  • Recruitment and Talent Management Platforms: Applicant Tracking Systems (ATS) and candidate evaluation tools that help us manage the recruitment process.
  • Security, Auditing, and IT Operations Vendors: Cybersecurity tools, backup services, and external auditors who assist us in maintaining our systems’ security, monitoring operations, and maintaining our ISO 27001 certification.
  • Other Corporate and Business Operations Vendors: We may also share personal data with other trusted third-party service providers, contractors, and partners who assist us with our day-to-day business operations, financial, administrative, or legal functions, or who provide specialized technical services necessary to support, maintain, and deliver our Websites and Services. Any such sharing is always subject to strict confidentiality obligations and compliant data processing agreements.

5.3. Event Sponsors and Exhibitors

When you register for or attend an on-site or virtual event (such as ThreatModCon), we may offer you the opportunity to share your contact information with our event sponsors and exhibitors (for example, by allowing your attendee badge to be scanned at their booth, or opting into sponsor sessions). We will only share this data with your explicit consent or through your active, voluntary participation. You have the right to object to or withdraw your consent for such sharing at any time.

5.4. Advertising Partners

We may share data collected via cookies and similar technologies with third-party advertising networks to deliver personalized advertisements to you (“cross-context behavioral advertising”). You have full control over this and can opt-out at any time via our Cookie Settings.

5.5. Professional Advisors

In the course of our business operations, we may share personal data with our professional advisors—including legal counsel, financial auditors, tax advisors, and insurers—who are bound by strict statutory or contractual confidentiality obligations.

5.6. In Connection with a Business Transaction

We may disclose, share, or transfer your personal data as a business asset in connection with, or during the active negotiation of, any prospective or actual corporate business transaction. This includes, without limitation, any merger, acquisition, financing, due diligence process, joint venture, corporate reorganization, divestiture, sale of all or a portion of company assets, dissolution, or in the event of an insolvency, bankruptcy, or receivership.

Any prospective buyers, investors, or transaction partners who receive access to your data during the negotiation phase will be bound by strict non-disclosure and confidentiality agreements. In the event that a transaction is completed, the acquiring entity or successor will be legally bound to respect and uphold your personal data in accordance with the commitments made in this Privacy Policy, unless you are subsequently notified of any changes.

5.7. Law Enforcement and Public Authorities

In exceptional circumstances, we may be required to disclose your personal data to comply with a subpoena, court order, regulatory investigation, or other lawful requests from public and government authorities. We also reserve the right to disclose your information when we believe in good faith that disclosure is necessary to protect our legal rights, property, or safety, or the safety of our users, employees, or the public, and to prevent, detect, or address fraud, security vulnerabilities, or technical issues.

6. International Data Transfers

As a global company, your personal data will be processed in the United States and other countries where our Affiliates and service providers operate, including Spain, India and the UK. We are committed to ensuring that all cross-border data transfers comply with applicable data protection laws and that your data is protected with an equivalent level of security wherever it is processed.

For personal data transferred from jurisdictions with specific transfer restrictions—such as the European Economic Area (EEA), the United Kingdom, and Switzerland—to countries without an adequacy decision, we rely on the following legally-recognized transfer mechanisms:

  • Intra-group Data Sharing Agreement: All transfers of personal data between our ThreatModeler Group Affiliates are governed by a comprehensive internal agreement (the Intra-Group Data Sharing Agreement) that incorporates the European Commission’s Standard Contractual Clauses (SCCs) and the UK International Data Transfer Addendum to ensure that your data is protected uniformly and securely across our global organization.
  • Standard Contractual Clauses (SCCs): For transfers of personal data to third-party service providers and sub-processors located in countries without an adequacy decision, we execute the approved Standard Contractual Clauses (supplemented by the UK International Data Transfer Addendum or Swiss equivalents where applicable) to contractually guarantee the protection and confidentiality of your data.
  • Adequacy Decisions: Where applicable, we may transfer data to third-party service providers located in countries that have been formally deemed by the European Commission, the UK Government, or the Swiss Federal Council to provide an adequate level of data protection.

We supplement these transfer mechanisms with appropriate technical, administrative, and organizational safeguards (including conducting Transfer Impact Assessments where required) to ensure that your personal data receives a level of protection equivalent to that of your home jurisdiction.

7. Data Security

We take the security of your data seriously. We have implemented appropriate technical and organizational measures designed to protect your personal data from accidental or unlawful destruction, loss, alteration, or unauthorized access. These measures include data encryption, access controls, regular security audits, and secure software development practices.

8. Your Privacy Rights and How to Exercise Them

We are committed to honoring your data protection rights, which may vary depending on your jurisdiction. Subject to certain legal exceptions and depending on where you reside, you may have the right to:

  • Access and Know: Request a copy of the personal data we hold about you and receive information on how we collect, use, and share it.
  • Correct (Rectify): Ask us to correct or update any inaccurate or incomplete personal data.
  • Delete (Erase): Request the deletion of your personal data, subject to our legal obligations and other regulatory retention exceptions.
  • Object and Opt-Out:
    • Object to our processing of your personal data based on our legitimate interests.
    • Opt-out of direct marketing communications at any time, without needing to provide a reason.
    • Direct us not to “share” or “sell” your personal information for cross-context behavioral advertising (pursuant to CCPA/CPRA).
  • Withdraw Consent: Where our processing of your personal data is based on your explicit consent (such as for non-essential cookies, event recordings, or certain marketing activities), you have the right to withdraw your consent at any time. The withdrawal of consent will not affect the lawfulness of processing based on consent before its withdrawal.
  • Restrict Processing: Ask us to temporarily limit or restrict the processing of your personal data in certain circumstances.
  • Data Portability: Receive a copy of your personal data in a structured, commonly used, and machine-readable format, or request that we transfer it to another controller where technically feasible.

How to Exercise Your Rights

You or your legally authorized agent can submit a request to exercise these rights by emailing us at privacy@threatmodeler.com.

For your protection, we will need to verify your identity before fulfilling your request. This may involve asking you to confirm information we already have on file. We will respond to your request within the timeframes required by applicable law and will not discriminate or retaliate against you for exercising your rights.

Right to Lodge a Complaint

You have the right to lodge a complaint with a competent data protection or supervisory authority if you have concerns about how we process your personal data. Key competent authorities include:

  • Spain: The Spanish Data Protection Agency (AEPD) or your local data protection authority.
  • United Kingdom: The Information Commissioner’s Office (ICO).
  • United States: The California Privacy Protection Agency (CPPA) and the Federal Trade Commission (FTC).

9. Updates to this Privacy Policy

We may modify or update this Privacy Policy from time to time to reflect changes in our services, our operational practices, or applicable laws. We will post the revised Policy on this page and update the “Last Updated” date at the top. For material changes, we will use commercially reasonable efforts to provide a more prominent notice (such as sending an email notification or posting a banner on our Website). Your continued interaction with us after such changes become effective constitutes your acknowledgment of the updated Privacy Policy.

10. Contact Us

If you have any questions about this Privacy Policy or our data practices, please contact our Data Protection Officer at:

Email: privacy@threatmodeler.com

Postal Address:

ThreatModeler Software, Inc.
Attn: Legal & Privacy Department
1 Evertrust Plaza, Suite 802,
Jersey City, NJ 07302, USA