Privacy Policy
GLOBAL PRIVACY POLICY – WORLDWIDE
Table of Contents
General
Last updated on February 21, 2025.
This Privacy Policy for Kobalt Security Inc. (“Kobalt Security”, “Kobalt.io”, “Kobalt”, “we“, “us“, or “our“) describes how and why we might collect, store, use, and/or share (otherwise defined as “process“) your personal information when you use our services (“Services”) or enter a business relationship with us, such as when you:
- Visit our website at https://kobalt.io, or any other website of ours that links to this Privacy Policy,
- Contact us by email, phone call, videoconference, or engage with us in any other ways,
- Purchase or subscribe to our professional services,
- Apply to work with us (applicants),
- Work with us (employees, contractors, partners).
What is “personal information” ?
The term “personal information” in the context of this Privacy Policy means any information relating to an identified or identifiable natural person (“data subject”), including employee personal information. An identifiable natural person is an individual who can be identified, directly or indirectly. This includes any personal information collected from our website visitors, potential clients, clients, partners, employees, contractors, or any other person contacting us or using our Services.
Questions or concerns ?
Reading this Privacy Policy will help you understand your privacy rights and choices. If you do not agree with our policies and practices, please do not use our Services. If you still have any questions or concerns, please contact our Data Protection Officer.
Consent to use Personal Information
We will seek your consent prior to collection, storage, use, disclosure (“processing”) of your Personal Information, except where the law provides an exemption, and any Personal Information we collect will be limited only to that which is necessary for the purposes initially identified (see next sections that provide details).
Consent may be obtained in various ways, including express consent (signed consent, email or application form, orally, in person) or implied consent (like when you access the terms of service of our website and browse it with cookies allowed).
If you need to provide Personal Information about other individuals (such as your colleagues, employees, clients), you must obtain their consent for these purposes prior to your disclosure to us.
If we intend to use your Personal Information for reasons beyond the original purposes for which we initially collected the data, we will provide you with an additional notice to obtain your consent for this secondary use of your Personal Information. Please note that any secondary use of your Personal Information is generally optional unless we state it is absolutely necessary. In any case, you are not obligated to consent to any such secondary processing.
How do we protect information ?
This applies to confidential and personal information processed by Kobalt.io and/or shared with Kobalt.io’s subprocessors. We apply the same processes and standards whether the personal information is collected from website visitors, when you contact us, when you purchase services from us, apply for a job position, work with us.
All the third-party platforms or services in use at Kobalt.io are vetted prior to processing any information we entrust them with, through service contracts. Kobalt.io’s own collaborators and Kobalt.io’s third-parties (vendors) are contractually required to preserve the security & confidentiality of the data they process on our behalf.
We have a Vendor Risk Management Program in place, which mandates a risk & security assessment of each and every new vendor before approval, and renewal of such risk / security assessment on an at least annual basis.
Data is encrypted in transit and in storage, using industry-standard protocols such as HTTPS/TLS 1.2+ (in-transit) and AES256 (storage).
Strict access controls are in place, with multi-factor authentication enforced everywhere possible. Access is strictly limited to a minimum number of individuals with “need to know”, access rights are granted with “least privilege” wherever possible. Access rights are reviewed on a quarterly basis.
Data is processed in line with policies, business and operational requirements.
Personal data we process when you visit our website
What data do we collect (website) ?
When you visit our website, we need to collect automatically some information for the website’s functionality. Additionally, we collect some information in order to improve the services we offer to you:
- Your Internet Protocol address (IP address)
- Type of browser you use
- Type of operating system you use
- Type of device you use
- Time and duration of your visit
- Pages visited on our websites during your visit
- External links you clicked on our websites
- Entry and exit pages
- Clicks scroll, interactions on website
- Approximate location (city, region, country)
- Language preference
- Age range
- Gender
- Search terms on our website
How do we collect this data (website) ?
We collect this data automatically through the use of cookies, visitor logs, and other tracking technologies used by our website.
What are cookies?
Cookies are text files placed on your computer to collect standard Internet log information and visitor behaviour information. When you visit our website, we may collect information from you automatically through cookies or similar technology.
Why we collect this data and how we use cookies (website) ?
We collect this data and use cookies for the website functionalities such as displaying Kobalt’s story, business offerings, events information, news or blog articles, registration forms for events or webinars, or other such content, and, if you agreed to it through our cookies banner, to collect analytics about how our website is utilised.
If we need to use this information for any other purposes than the ones previously described, we will ask for your renewed consent and will use your information only on receiving your renewed consent and then, only use it for the purpose(s) for which you granted us your renewed consent to use, unless otherwise required by the law.
What types of cookies do we use (website) ?
Kobalt.io website makes use of the following types of cookies:
- Necessary Cookies: Those cookies are required to enable the basic features of this site, such as providing secure log-in or adjusting your consent preferences. These cookies do not store any personally identifiable data.
- Functionality Cookies: Kobalt.io uses these cookies so that we recognize you on our website and remember your previously selected preferences. These could include what language you prefer and location you are in. A mix of first-party and third-party cookies are used. Functional cookies also help perform certain functionalities like sharing the content of the website on social media platforms, collecting feedback, and other third-party features.
- Analytics Cookies: Kobalt.io Analytical cookies are used to understand how visitors interact with the website. These cookies help provide information on metrics such as the number of visitors, bounce rate, traffic source, etc.
- Performance Cookies: Performance cookies are used to understand and analyze the key performance indexes of the website which helps in delivering a better user experience for the visitors.
- Advertising Cookies: Kobalt.io uses these cookies to collect information about your visit to our website, the content you viewed, the links you followed and information about your browser, device, and your IP address. Kobalt.io may sometimes share some limited aspects of this data with third parties for advertising purposes. We may also share online data collected through cookies with our advertising partners. This means that when you visit another website, you may be shown advertising based on your browsing patterns on our website.
We publish our list of cookies and website cookie policy here: https://kobalt.io/cookie-policy
How to manage cookies:
You can reject all non-essential cookies from our website using our cookie banner (geographic differences may apply), or through your browser functionalities. If you select such option, only cookies that are necessary for the website’s functionality will be enabled..
Additionally, you can set your browser not to accept cookies, and you can remove cookies from your browser. Keep in mind that some of our website features may not function as a result of such setting.
Do we share this data (website) ?
We do not transfer your personal information to any third party without seeking your consent first, except in limited circumstances as described below:
- Analytics: We require such third parties to use the personal information we transfer to them only for the purpose for which it was initially transferred, and not to retain it for longer than is required for fulfilling the said purpose.
- Obligations: We may be obligated to disclose your personal information:
- To comply with applicable law, regulation, court order or other legal process;
- To enforce your agreements with us, including this Privacy Policy;
- Or to respond to claims that your use of the Services violates any third-party rights.
How & for how long do we store this data (website) ?
Kobalt.io stores the data collected on our website using vetted third parties, such as our CRM Hubspot or our analytics platform Google Analytics.
Usual retention for such data is five years.
Opting-out of direct marketing communication
Kobalt.io does not send out direct marketing communications to our website visitors, unless such visitors voluntarily register for Kobalt.io’ marketing communications. Opt-out option is available in received marketing communications (for example: email). Users can also contact our Data Privacy Officer here.
Privacy policies of other websites
The Kobalt.io website contains links to other websites that are not operated by us. Our Privacy Policy does not address the privacy policy and other practices of any third parties, including any third party operating any website or service that may be accessible via a link on our website. Kobalt.io has no control over and assumes no responsibility for the content, privacy policies or practices of any third party sites or services.
Personal data we process when you contact us
What data do we collect (when you contact us) ?
If you contact us by email, phone, videoconference, or in-person, we collect the information you provide voluntarily to us. We collect this information to be able to contact you back, answer your requests and questions, or provide service to you. We never share or sell the information you provide to us without your consent. The information you provide voluntarily to us might include:
- Your name,
- The company you work for,
- Your business title/function/role,,
- Your business email address,
- Your business phone number,
- The content of the communication you have with us, such as request, question, comment(s),
- Any other information you might voluntarily provide to us,
- Video and/or audio recording of calls, when consent was provided
How do we collect this data (when you contact us) ?
We collect this data when you voluntarily provide it to us, either by emailing us, calling us, contacting us through an online form, meeting with us virtually through a video call, meeting with us through an in-person meeting or event.
Why do we collect this data (when you contact us) ?
We collect this data to be able to contact you back and to provide service to you.
Do we share this data (when you contact us) ?
Kobalt.io does not share the content of communications and discussions with third parties. We may share topics of interests and questions raised during such conversations with specific third parties in the context of collaborations, referrals, webinars, etc..
Kobalt.io may also share your contact information with some third parties in the context of webinars, events, collaboration opportunities, and marketing campaigns.
Marketing Communication:
Kobalt.io might occasionally, with your prior consent, send information to you about services of ours or our partner companies that we think you might like. For this purpose, we might share your contact information, for example your email address, with some of our partners listed below:
- A-LIGN
- Circle Innovation
- Sophos
- KnowBe4
- Prescient Assurance
- Vanta
If you have agreed to receive marketing communications, you may always opt out at a later date. You have the right at any time to stop Kobalt.io from contacting you for marketing purposes or sharing your data to the Kobalt.io partners. If you no longer wish to be contacted for marketing purposes, please contact us here.
How & for how long do we store this data (when you contact us) ?
We may retain the information we process about your communication with us for up to five years in our systems, or longer if you purchase services from us, or if a regulatory requirement mandates it.
Personal data we process when you purchase our Services
What data do we collect (using our Services) ?
When you purchase our Services, we need to collect some information in order to contact you, to provide you the service purchased, and to process your payment information.
The information we collect for this purpose will include, at least:
- Your name,
- Your title, role and/or function at your company,
- Your business email address,
- Your business phone number (if available),
- Your business payment information,
- Names / titles / roles / functions of major stakeholders involved in the execution of the contractual engagement.
How do we collect this data? (using our Services)
We collect this data when you voluntarily provide it to us either by emailing us, calling us, contacting us through an online form, meeting with us virtually through a video call, meeting with us through an in-person meeting or event.
Why do we collect this data (using our Services) ?
The data we collect supports the sales, operations, and support processes and activities (stakeholder details in contracts, tools, documents, communications), and also promotional materials. We also share some information with our business partners, either to support the services we provide to you, or to promote new services that we think would be beneficial to your business.
Do we share this data (using our Services) ?
List of core 3rd parties that support all our processes:
- Fathom Call – recording & notes taking (as applicable)
- Google – Emails/Calendar/Calls
- Hubspot – CRM
- Slack – Instant communication (as applicable)
Additional 3rd parties for Sales support:
- A-LIGN – Audit partner (as applicable)
- Circle Innovations –Partnerships (as applicable
- NRCC / IRAP – Partnerships (as applicable)
- Prescient Assurance – Audit partner (as applicable)
- RBC – Partnerships (as applicable)
- Vanta – GRC platform ( as applicable)
- Websec – Pentest partner (as applicable)
- Zoom – Calls (as applicable)
Additional 3rd parties for Service Delivery:
- Atlassian Documentation management
- Sophos – EDR (as applicable)
- KnowBe4 – Training (as applicable)
- Monday – Project Management
- SumoLogic – SOC (as applicable)
- Zendesk – Client support
We may share this data with other select third parties involved in the sales or delivery process, on a case by case basis, with your prior approval.-
How and for how long do we store this data (using our Services) ?
We store this data in our approved systems, for at least the duration of the services delivered, and generally up to five years after termination of the services. Some of your information, related to financial transactions, may be retained for up to seven years, for regulatory purposes.
Personal data we process when you apply to work with us
What data do we collect ? (job applicants) ?
If you apply to work at Kobalt.io, we collect the information you provide to us in order to process your application. We might collect additional information to evaluate your candidature later in the process, with your consent. The information we collect to process and evaluate your candidature may include:
- The resume or CV you provide to us
- Your full legal name
- Your email address
- Your phone number
- Your location
- Your employment history (part of the resume)
- (later on in the hiring process) The references you provide to us (names and contact information)
- (when applicant has signed offer letter and has started working for Kobalt.io) Information necessary to perform a background check (identification pieces, home address history, [manual identity verification using national or local photo ID proof, facial print biometrics, criminal record check, credit check)
- Video and audio recording(s) of your interview(s) with us
- Transcript and AI-generated notes derived from the video and audio recording(s) of your interview(s) with us
How do we collect this data (job applicants) ?
The personal information is voluntarily disclosed by the applicant when applying for a job offer on our applicant tracking system(s).
Do we share this data (job applicants) ?
Kobalt.io does not resell its hiring information to third parties.
However we do share it with select and vetted third parties to manage this information. Those third parties are SaaS platforms with whom we have a contractual relationship, including security and confidentiality provisions:
- BambooHR – HRIS & Applicant tracking
- Deel – HRIS & Applicant tracking
- Certn – Background verification
- Google – Document management
- Slack – Instant communication between personnel involved in the recruitment process.
How & for how long do we store this data (job applicants) ?
We store this data in the SaaS platforms we use for managing job applicants information. The default retention period is five years. See the details of security & privacy controls in place in the section “How do protect this data
Information used to make a decision about you:
Unless you instruct us to delete it, Kobalt.io will retain any personal information about an individual that was used to make a decision that directly affects the individual for at least one year after using it, so that the individual has a reasonable opportunity to obtain access to it. After this period, Kobalt.io will securely destroy any personal information about an individual as soon as it is no longer necessary to fulfil the identified purposes or any other legal or business purposes.
Personal data we process when you work with us
What data do we collect (employees & partners) ?
If you enter an employment, contractor, or partnership agreement with us, we might collect the following information for the purpose of establishing, carrying out, managing, or terminating your contractual relationship with Kobalt.io, or by obtaining your prior consent. The personal information we collect to perform this contract may include:
- Your full legal name
- Your personal email address
- Your phone number
- Your home address
- Your Internet Protocol address (IP address)
- Your Social Insurance Number (SIN, for employee payroll only, potentially for the group retirement plan)
- Your bank account information (for payroll and payment deposits)
- Information about the computer you work with, such as serial number, MAC address, username, etc (due to our Bring Your Own Device (BYOD) security policy)
- A list of the installed applications on your computer (BYOD)
- Any information we have already collected during the hiring process (see section 4)
- Video and audio recording(s) of recorded meetings you participate to
- Transcript and AI-generated notes derived from the video and audio recording(s) of the recorded meetings you participate to
How do we collect this data (employees & partners) ?
Personal information is collected through the candidate recruitment process, the employee onboarding process, contractor onboarding process, and various operational activities involving documentation, calls and transcripts.
Additional technical information, considered personal information based on the context, is collected through the compliance monitoring process for BYOD devices.
Why do we collect this data (employees & partners) ?
We collect and retain information for the purpose of establishing, carrying out, managing, or terminating your contractual relationship with Kobalt.io. We also collect and retain information in order to perform our contract with you and to fulfil our legal obligations.
Finally, we collect and retain some information to fulfill our compliance requirements.
Do we share this data (employees & partners) ?
We share this data with some of our approved subprocessors used to operationally manage such information. Those third parties are SaaS platforms with whom we have a contractual relationship, including security and confidentiality provisions. Employees’ information is shared with the third-parties described in the sections “Do we share this data (job applicants)” and “Do we share this data (using our Services)”.
How & for how long do we store this data (employees & partners) ?
We store this data in the SaaS platforms we use for managing employees and partners information. The default retention period is the duration of the contractual engagement plus up to seven years (depending on the type of information, since some tax/financial reporting may require up to seven years retention).
The legal bases we rely on to process your data
Consent
We may process your information if you have given us permission (consent) to use your personal information for a specific purpose. We will request your consent again to use your personal information for any different purpose from the one previously described. You have the right to withdraw your consent at any time.
Performance of a contract
We may process your personal information when we believe it is necessary to fulfil our contractual obligations to you, including providing our Services or at your request prior to entering into a contract with you.
Legitimate interests
We may process your information when we believe it is reasonably necessary to achieve our legitimate business interests and those interests do not outweigh your interests and fundamental rights and freedoms.
For example, we may process your personal information for some of the purposes described below:
- Direct Marketing (Existing Customers): Sending marketing communications about similar products or services to existing business customers, where there’s a pre-existing relationship and a reasonable expectation of receiving such communications;
- Direct Marketing (Prospecting – Carefully Considered): Reaching out to business contacts at companies that are a clear fit for Kobalt.io’s products/services, based on their role and the company’s industry;
- Maintaining Customer Relationships: Processing contact information to manage accounts, provide support, and communicate about ongoing contracts;
- Improving Products and Services: Analyzing anonymized or aggregated data to understand customer usage patterns and identify areas for improvement;
- Fraud Prevention: Processing data to detect and prevent fraudulent activities (i.e. IP address, login activity);
- Network and Information Security: Processing data to protect your systems and data from cyberattacks (i.e. Kobalt.io’s Managed Threat Detection and Managed Endpoint Protection Program clients);
- Internal Administrative Purposes: Processing data for internal administrative tasks, such as accounting and auditing.
Legal obligations
We may process your information where we believe it is necessary for compliance with our legal obligations, such as to cooperate with a law enforcement body or regulatory agency, exercise or defend our legal rights, or disclose your information as evidence in litigation in which we are involved.
Vital interests
We may process your information where we believe it is necessary to protect your vital interests or the vital interests of a third party, such as situations involving potential threats to the safety of any person.
Your privacy rights
Kobalt.io values your privacy rights and we want to make sure you are fully informed of all of your data protection rights. We will reply to each request related to your privacy rights within a 30 days time frame. For some especially complex requests, we might ask for a time extension in order to fulfil such request thoroughly, when permitted by law.
If your request cannot be honoured – in part of fully – for example because it is in conflict with other legal obligations, such as financial mandatory data retention periods or privacy rights of other individuals, we will inform you of the reason we cannot fulfil your request.
If you would like to exercise any of these rights, please contact Kobalt.io’s Data Protection Officer here.
Every person we collect personal information about is entitled to the following:
The right to access (to know)
You have the right to contact Kobalt.io to request a copy of your personal data or to know which information we have about you.
The right to rectification (to correct)
You have the right to contact Kobalt.io to request that we correct any information you believe is inaccurate. You also have the right to request Kobalt.io to complete the information you believe is incomplete.
The right to erasure (to delete)
You have the right to contact Kobalt.io to request that we erase your personal data, under certain conditions.
The right to restrict processing
You have the right to request that Kobalt.io restrict the processing of your personal data, under certain conditions.
The right to object to processing
You have the right to object to Kobalt.io’s processing of your personal data, under certain conditions.
The right to data portability
You have the right to request that Kobalt.io transfers the data that we have collected to another company, or directly to you, under certain conditions.
Personal information of minors
We do not knowingly solicit data from or market to children under 19 years of age . By using our Services, or by engaging with us in any other way, you represent that you are at least 19 years of age or that you are the parent or guardian of such a minor and consent to such minor dependent’s use of our services. If we learn that personal information from individuals less than 19 years of age has been collected, we will take reasonable measures to promptly delete such data from our records and any third party software where it might have been stored. If you become aware of any data we may have collected from children under age 19, please contact us here.
Mergers, Acquisitions, and Other Business Transfers
In the event that Kobalt Security Inc. is involved in a merger, acquisition, restructuring, bankruptcy, or other sale or transfer of all or a portion of its assets, your information may be transferred as part of that transaction. We will make reasonable efforts to notify you via email and/or a prominent notice on our website of any such change in ownership or control of your personal information previously collected, as well as any choices you may have regarding your personal information.
The acquiring or successor entity will be bound by the terms of this Privacy Policy, or a privacy policy that is at least as protective of your personal information as this Privacy Policy, unless and until such time as the acquiring or successor entity provides you notice of changes to its privacy policy and gives you the opportunity to opt-out.
If the acquiring entity makes material changes to this Privacy Policy, we will provide notice as required by applicable laws.
Notwithstanding the foregoing, in the event of a merger or acquisition, we may disclose information to the other party or parties involved in the transaction as reasonably necessary to facilitate the transaction. This may include, but is not limited to, due diligence purposes. We will seek to limit such disclosure to the minimum necessary information and will require the other party or parties to maintain the confidentiality of any disclosed information.
How to contact us
If you have any questions about Kobalt.io’s Privacy Policy, the data we hold on you, or you would like to exercise one of your data protection rights, please do not hesitate to contact us.
EU / EEA reporting link
Our EU Representative:
Under Article 27 of the GDPR, we have appointed an EU Representative to act as our data protection agent. Our nominated EU Representative is :
| Instant EU GDPR Representative Ltd. Adam Brogden [email protected] Tel +35315549700 | INSTANT EU GDPR REPRESENTATIVE LTD Office 2, 12A Lower Main Street, Lucan Co. Dublin K78 X5P8 Ireland |
|---|---|
UK reporting link
Our UK Representative:
Under Article 27 of the UK Data Privacy Act, we have appointed a UK Representative to act as our data protection agent. Our nominated UK Representative is:
| GDPR Local Ltd. Adam Brogden [email protected] Tel +44 1772 217800 | GDPR Local Ltd. 1st Floor Front Suite 27-29 North Street, Brighton England |
|---|---|
How to contact the appropriate authority
Should you wish to report a complaint, or if you feel that Kobalt.io has not addressed your concern in a satisfactory manner, you have the right to submit a complaint to a data protection authority about our collection and use of your Personal Information.
- Contact details for the various EU/EEA members’ Data Protection Authorities are kept up-to-date on the European Commission website
- Kobalt.io’s local Data Protection Authority, which for British Columbia, Canada is the Office of the Information and Privacy Commissioner:
- Website: https://www.oipc.bc.ca
- Email: [email protected]
- Phone number: +1 (250) 387-5629
Changes to our Privacy Policy
Kobalt.io keeps its Privacy Policy under regular review and places any updates on this web page. Please make sure to review our Privacy Policy regularly for the latest version.