Legal center

Privacy Policy

Clear priorities. Practical protection. A partner accountable for the next step.

How Outfaze collects, uses, shares, retains, and safeguards personal data.

Last updated: August 30, 2026

Overview

At Outfaze (“Outfaze,” “we,” “us,” or “our”), we are committed to protecting your privacy. This Privacy Policy explains how we collect, use, disclose, and safeguard personal data when you visit our website (https://www.outfaze.com) or use our cybersecurity services.

This policy is intended to align with applicable data protection laws, including the General Data Protection Regulation (GDPR), the California Consumer Privacy Act and California Privacy Rights Act (CCPA/CPRA), and other applicable regulations.

1. Who We Are

Outfaze Media Ltd. d/b/a Outfaze provides cybersecurity services to organizations in the markets it serves.

Controller and processor roles

  • For website visitors, marketing interactions, and general inquiries, Outfaze acts as a data controller.
  • For customer data processed as part of our cybersecurity services, Outfaze typically acts as a data processor, processing data on behalf of customers under contractual agreements.
  • If you are located in the European Economic Area (EEA), Outfaze acts as a data controller for website-related data.

2. What Personal Data We Collect

We may collect the following categories of personal data:

  • Identity data: name, job title, and company name.
  • Contact data: email address, phone number, and mailing address.
  • Technical data: IP address, browser type, device type, and usage data.
  • Communication data: support inquiries, chat messages, and email exchanges.
  • Account data: login credentials and account access information, where applicable.
  • Service data: logs, alerts, and monitoring data processed on behalf of customers.

We do not intentionally collect sensitive personal data unless it is required to provide contracted services or comply with legal obligations.

3. How We Collect Personal Data

We collect personal data through:

  • Direct interactions, such as contact forms, service onboarding, and support requests.
  • Automated technologies, such as cookies, analytics tools, and website logs.
  • Third-party sources, such as marketing platforms, partners, and publicly available sources.

Where GDPR applies, we process personal data under the following legal bases:

  • Contractual necessity: to perform services under a contract.
  • Legitimate interests: to secure our systems, improve services, and communicate with clients.
  • Legal obligation: to comply with regulatory requirements.
  • Consent: for specific marketing or optional data-processing activities.

The legal basis depends on the nature of your interaction with us.

5. How We Use Your Data

We use personal data to:

  • Deliver and support cybersecurity services.
  • Detect and respond to cyber threats.
  • Manage accounts and subscriptions.
  • Communicate about services, updates, and events.
  • Conduct analytics and improve performance.
  • Comply with legal and regulatory obligations.
  • Protect against fraud, abuse, and security risks.

We do not sell personal data as defined under the CCPA/CPRA.

6. Cookies and Tracking Technologies

We may use cookies and similar technologies to:

  • Improve website functionality.
  • Analyze site performance.
  • Support marketing initiatives.

You may manage cookies through the controls made available on our website or through your browser settings.

7. Data Sharing and International Transfers

We may share personal data with:

  • Service providers and technology partners.
  • Security vendors and infrastructure providers.
  • Legal and regulatory authorities, where required.
  • Entities involved in a merger, acquisition, financing, or corporate restructuring.

Where data is transferred internationally, including to the United States, we implement appropriate safeguards where required, which may include Standard Contractual Clauses, the UK Addendum, data-processing agreements, or other legally recognized transfer mechanisms.

We maintain a list of subprocessors available upon request.

8. SMS Communications and Data Handling

If you provide your phone number and separately consent to SMS communications, we may send messages related to:

  • Service updates and notifications.
  • Security alerts and incident communications.
  • Appointment confirmations or follow-ups.
  • Other relevant service-related communications.

Message frequency may vary. Message and data rates may apply, depending on your mobile carrier.

Opt-in: By providing your phone number and selecting an SMS consent option, you agree to receive SMS communications from Outfaze.

Opt-out: You may opt out at any time by replying STOP to any message. For assistance, reply HELP or contact us at privacy@outfaze.com.

We use your phone number only for the purposes described above. We do not sell mobile information or share it with third parties or affiliates for marketing or promotional purposes. We may share it with trusted messaging providers solely to deliver SMS services.

Text-message originator opt-in data and consent will not be shared with third parties, except providers used to deliver the requested messaging service or where disclosure is required by law.

9. Data Retention

We retain personal data only for as long as necessary to:

  • Provide services during the contractual term.
  • Comply with legal, tax, and regulatory requirements.
  • Support security monitoring and operational integrity.

Retention periods vary depending on the type of data and the purpose for processing it. Marketing communications data is retained until you opt out or it is no longer needed.

10. Data Security

We use technical and organizational measures appropriate to the nature of the data and the risks involved. Depending on the applicable system and service scope, these measures may include:

  • Encryption in transit and at rest.
  • Role-based access controls.
  • Multi-factor authentication.
  • Security monitoring and endpoint protection.
  • Vulnerability assessments and penetration testing.

No method of transmission or storage is completely secure, and we cannot guarantee absolute security.

11. Your Privacy Rights

For EU and EEA individuals (GDPR)

Subject to applicable law, you may have the right to:

  • Access your personal data.
  • Rectify inaccurate data.
  • Request erasure.
  • Restrict processing.
  • Request data portability.
  • Object to processing.
  • Withdraw consent where applicable.

You may also have the right to lodge a complaint with your local supervisory authority.

For California residents (CCPA/CPRA)

Subject to applicable law, you may have the right to:

  • Know what personal data is collected.
  • Request deletion.
  • Request correction.
  • Opt out of sale or sharing. We do not sell personal data.
  • Not be discriminated against for exercising your rights.

We respond to verified requests within the timeframes required by applicable law. To exercise your rights, contact privacy@outfaze.com.

12. Data Breach Notification

In the event of a personal data breach, we will:

  • Notify affected individuals and relevant authorities as required by law.
  • Take appropriate steps to contain and mitigate the breach.
  • Review the incident to strengthen controls and help prevent recurrence.

13. Automated Decision-Making

We do not engage in automated decision-making that produces legal or similarly significant effects on individuals.

14. Third-Party Websites

Our website may contain links to third-party websites. We are not responsible for their privacy practices. Please review their privacy policies independently.

15. Children's Privacy

Our services are intended for professionals and businesses.

We do not knowingly collect personal data from:

  • Individuals under 16 in the EEA.
  • Individuals under 13 in the United States.

If you believe a child has provided personal data to us, please contact us so we can take appropriate action.

16. Updates to This Policy

We may update this Privacy Policy from time to time. Updates will be reflected by revising the “Last updated” date above. Material changes may be communicated through a website notice or by direct email, where appropriate.

17. Contact Us

For questions about this Privacy Policy or to exercise applicable privacy rights, contact:

Outfaze Media Ltd.
Email: privacy@outfaze.com