Privacy Policy

Effective Date: September 30, 2026

1. Introduction

PrivacyHawk, Inc. (“PrivacyHawk,” “we,” “us,” or “our”) is committed to protecting the privacy and security of personal data. We are transparent about the personal data we collect, the purposes for which we process it, and the rights you have in relation to your data.

Protecting privacy is the reason our company exists — and we start with how we handle your data ourselves.

This Privacy Policy applies to all personal data collected from or about you through your use of our services, including our mobile application (“App”), website, and related services (together, the “Services”).

We operate under the following principles:

  • Data minimization: We collect and store the minimum amount of personal data needed for our Services.
  • Transparency: We are clear about what personal data we hold and how we use it.
  • Privacy by design & by default: Privacy is embedded into our Services from the outset.
  • User control: You have control over the personal data we hold and can exercise your data protection rights at any time.
  • We do not sell personal data for money, and we do not give advertisers or data brokers the personal data you provide to us. Advertising platforms we advertise on use pixels on our websites, which some privacy laws treat as a "sale" or "sharing" of personal information. See Sections 7 and 14(d).

2. Data Controller & EU/UK Representative

For users in the European Economic Area (“EEA”) and the United Kingdom (“UK”), PrivacyHawk, Inc. is the data controller of your personal data.

3. Categories of Personal Data We Collect for PrivacyHawk Consumer

a. Information you provide directly

Note: Information you provide depends on feature usage within the product; not all of the below data is collected for every user.

  • Identification data: Name and email address.
  • Demographic data: Age and city during signup. You may optionally provide address, phone number, and date of birth for identity verification with certain companies.
  • Communication data: Content of messages you send to us (e.g., support, surveys, feedback).
  • Billing data: Minimal billing information if processed via our website (via Stripe). Billing via app stores (Apple/Google) is handled by them directly.
  • Social media data: Information you provide via interactions with our social media pages.
  • Identity protection identifiers: Optional hashed identifiers (e.g., social security number, tax ID) used for dark web scans.

b. Information collected automatically

  • Data broker scan results: Publicly available personal data exposures.
  • Email scan results: Sender domains from emails (not full emails, contacts, or credentials).
  • Log & device data: IP address, browser type, device type, OS, date/time of requests, and how you interact with our Services.
  • Usage data: Features used, actions taken, frequency/duration of activity.
  • Location data: Approximate location derived from IP (not stored).
  • Email open/click data: Via tracking pixels in emails.
  • Emails related to our services: Sender and full text of emails related to opt-out requests that you have sent; used to confirm compliance with the opt-outs and improve the opt-out system as described in Section 5(b); and emails that our automated systems have determined to be security threats, fraud risks, or scams, to be used to notify you and protect you from such threats and improve the protection system.
  • Information from your device’s phone book (contacts list): For those who optionally choose to use RoboHawk, PrivacyHawk’s robocall and spam text blocking service, PrivacyHawk collects your contacts list so that the app always allows calls from people you know. This information may be uploaded to our servers. To keep your contacts safe, they are one-way encoded, which means they are never visible to anyone.
  • Information from your device’s SMS messaging app: If you choose to enable SMS filtering, only messages received from senders not in your device’s phone book are uploaded to our servers for analysis. In those cases, data collection is limited to the sender’s phone number and message body. Your personal information is not included.
  • Website technologies: Information collected by cookies, pixels, and similar technologies on our websites that track how you interact with them (such as clicks  and pages viewed) and cookie and advertising identifiers. See Section 7.

This Section 3 describes our consumer Services. The data accessed by PrivacyHawk Enterprise is described separately in Section 16.

4. Legal Bases for Processing (EU/UK Users)

Under the EU GDPR and UK GDPR, we process your personal data on the following legal bases:

  • Performance of a contract: To provide the Services you request, including opt-out requests, account management, and billing.
  • Legitimate interests: To conduct scans, prevent fraud, secure our systems, improve Services, and respond to enquiries.
  • Consent: For marketing communications and for any non-essential cookies or tracking technologies (see Section 7). You may withdraw consent at any time.

5. Purposes of Processing

a. General purposes

We use your personal data to:

  • Identify companies holding your data and assist with deletion and opt-out requests.
  • Verify your identity and contact details.
  • Authenticate your access to the Services.
  • Personalize your experience.
  • Process payments and maintain billing records.
  • Respond to your enquiries.
  • Send administrative notices and updates.
  • Improve our Services and develop new features.
  • Prevent fraud and secure our systems.
  • Comply with legal obligations.

b. Improving opt-out automation

PrivacyHawk operates machine learning systems that improve the accuracy and reliability of its opt-out and deletion automation — for example, recognizing which companies hold your data, identifying the correct opt-out mechanism for a given company, and determining whether a request was honored, refused, or requires follow-up.

We may use the following to develop and improve these systems:

  • Opt-out and deletion correspondence associated with requests made through the Services, including replies from the companies to which those requests were sent.
  • Records of the outcome of requests submitted through the Services, including which companies responded, how they responded, and how long they took.
  • Publicly available information about data brokers and their opt-out processes.

By creating an account and agreeing to our Terms of Service, you agree that we may use data obtained through the Services for these purposes. These systems improve the Services for all users. We do not use this data for advertising.

c. Limited Use of Google user data (consumer Services)

Where you connect a personal Google account to our consumer Services, our use and transfer of information received from Google APIs adheres to the Google API Services User Data Policy, including the Limited Use requirements. These commitments apply to the raw data obtained from the scopes you authorize and to data aggregated, anonymized, or derived from it.

(1) Use. We limit our use of this data to providing or improving the features that are visible and prominent in our user interface: identifying the companies that hold data associated with your account, sending opt-out and deletion requests at your direction, and determining whether those requests were honored, refused, or require follow-up.

(2) Transfers. We do not transfer this data, except:

  1. to provide or improve our appropriate access or user-facing features that are visible and prominent in our user interface, and only with your consent;
  2. for security purposes, such as investigating abuse;
  3. to comply with applicable laws; or
  4. as part of a merger, acquisition, or sale of assets, after obtaining your explicit prior consent.

(3) Prohibited uses. We do not transfer or sell this data to advertising platforms, data brokers, or information resellers. We do not use it for serving ads of any kind, including retargeting, personalized, or interest-based advertising. We do not use it to determine credit-worthiness or for lending purposes.

(4) Human access. We do not allow humans to read this data, unless: you have given us your affirmative agreement to view specific messages, files, or other data, for example to resolve a support request you have raised; it is necessary for security purposes, such as investigating a bug or abuse; it is necessary to comply with applicable law; or the data, including derivations, is aggregated and used for internal operations in accordance with applicable legal requirements.

(5) Improving opt-out automation. By creating an account and agreeing to our Terms of Service, you agree that we may use the opt-out and deletion correspondence associated with requests made through the Services — the requests themselves and the replies received from the companies they were sent to — to improve the accuracy and reliability of the opt-out automation described in Section 5(b), including by developing and improving machine learning models used in the Services. This is an improvement to the user-facing features described in paragraph (1). We do not transfer this data to any third party for model training.

(6) Personnel and successors. We require our employees, agents, contractors, and successors to comply with the Google API Services User Data Policy.

(7) Revoking access. You can withdraw our access to a connected Google account at any time, as described in Section 10.

d. Microsoft user data (consumer Services)

Where you connect a personal Microsoft account to our consumer Services, our use of information received from Microsoft APIs is governed by the Microsoft APIs Terms of Use and by this Policy.

We request only the permissions needed to operate the features you have enabled, and we use the data only for the purposes described in Section 5. We do not transfer or sell this data — including data aggregated, anonymized, or derived from it — to advertising platforms, data brokers, or information resellers, and we do not use it for advertising of any kind, including retargeting, personalized, or interest-based advertising.

By creating an account and agreeing to our Terms of Service, you agree that we may use data obtained from a connected Microsoft account, including opt-out and deletion correspondence, to operate and improve the Services, including by developing and improving machine learning models used in the Services.

You can withdraw our access to a connected Microsoft account at any time, as described in Section 10.

6. Sharing of Personal Data

We share your personal data only as necessary and with safeguards in place:

  • Service providers: For payment processing, hosting, analytics (including A/B testing), customer support, and security.
  • Recipients of deletion and opt-out requests: As described below.
  • Legal compliance: Where required to comply with legal obligations or respond to lawful requests.
  • Business transfers: In connection with mergers, acquisitions, or similar transactions.
  • With your consent: Where you explicitly agree to sharing.
  • Advertising platforms: When you visit our websites, advertising platforms we advertise on collect information through their pixels and cookies to measure our ads and to show our ads to people who have visited our websites. See Sections 7 and 14(d).

We do not sell or share the personal data you provide to us, such as your account details, the information you submit for data broker removal, or data from connected email accounts.

Deletion and opt-out requests

Exercising your privacy rights necessarily involves giving the recipient enough information to locate your record. The Services offer two separate mechanisms, which handle your information differently.

Data broker removal

This mechanism does not use or require access to any email account. We submit the request directly to the data broker on your behalf, using the identifying information you have provided in your PrivacyHawk profile — typically name, email address, postal address, and date of birth — which is the information the broker needs to locate and suppress your record. We then re-check the broker’s site to confirm the record has been removed.

Digital footprint opt-outs

Where you connect an email account, we identify the companies holding data associated with that account — generally companies with which you have a direct relationship — and you can direct that opt-out or deletion requests be sent to them. Those requests are sent from your own mailbox, through the connection you authorized. Each request contains the minimum information the recipient needs to identify your record, typically your name and email address — information the recipient already holds, since holding it is the reason the request is being sent. We do not transmit these requests ourselves and do not disclose additional, unnecessary information to these recipients. Responses are delivered to your own mailbox, where we read them in order to determine whether a request was honored, refused, or requires follow-up.

7. Cookies & Similar Technologies

We use cookies, pixels, and similar technologies on our websites in these categories:

Necessary: Required for the website to work, including security and remembering your cookie choices. These are always on.

Analytics: Clicks and pages viewed so we can see how the website is used. A/B testing tools may show visitors different versions of a page and measure which one works better. These providers process this data on our behalf.

Advertising: Advertising platforms we advertise on, such as Google and Meta, place pixels and cookies on our websites to measure whether our ads lead to visits or sign-ups and to show our ads to people who have visited our websites. These platforms receive information such as pages viewed, actions taken, device and advertising identifiers, and IP address. We do not show ads in our Services.

The current list of cookies and providers is available from the cookie settings button on our website.

Your choices: In the EU, UK, and other regions that require consent, non-necessary cookies stay off unless you accept them. In the United States, these technologies run by default. You can opt out of advertising cookies using "Your Privacy Choices" in our website footer, or by enabling Global Privacy Control (GPC) in your browser. You can change your choices anytime using the cookie settings button at the bottom left of the page. Choices apply only to the browser and device you use.

8. International Transfers

We store and process personal data in the United States.

Where we transfer personal data from the EEA/UK to the US, we implement safeguards such as Standard Contractual Clauses (SCCs) under the EU GDPR and the International Data Transfer Addendum (IDTA) under the UK GDPR. Copies of these safeguards are available on request.

9. Data Retention

We retain personal data only for as long as necessary to fulfil the purposes outlined in this Policy and comply with legal obligations.

Retention of data processed through PrivacyHawk Enterprise is governed by Section 16.9, which sets specific deletion periods.

10. Your Rights (Global)

All users, regardless of location, have the right to:

  • Access your personal data.
  • Rectify inaccurate data.
  • Erase your personal data (“right to be forgotten”).
  • Restrict processing.
  • Data portability.
  • Object to processing based on legitimate interests.
  • Withdraw consent at any time.

You can exercise your deletion right via the App or by emailing support@privacyhawk.com. All other rights can be exercised by emailing support@privacyhawk.com. We may request proof of identity before responding.

Revoking access to a connected email account

If you have connected a Google or Microsoft email account to the Services, you can withdraw our access at any time, directly with that provider and without contacting us:

You can also disconnect an account from within the App. Revoking access stops all further collection from that account immediately. To also delete data already collected, email support@privacyhawk.com or use the deletion option in the App — revoking access alone does not delete data we already hold.

Where an organization has authorized PrivacyHawk Enterprise, an administrator may revoke access as described in subsection 16.9.

11. Marketing Communications

We may send you marketing emails if you have opted in or if permitted by law. You can unsubscribe at any time via the link in each email.

12. Security

We use highly secure, industry best practices to protect personal data and take security extremely seriously. No system is completely secure, but we work hard to minimize risks.

13. Children’s Data

Our Services are intended for adults. You must be at least 18 years of age to create an account or use the Services, as set out in our Terms of Service. Our Services are not directed at children, and we do not knowingly collect personal data from anyone under 18. If we learn that we have collected personal data from a person under 18, we will delete it.

14. U.S. State Privacy Rights (Including California Residents)

Certain U.S. states — including California, Colorado, Connecticut, Utah, and Virginia — provide their residents with specific rights regarding their personal information. If you are a resident of one of these states, this section explains those rights and how to exercise them.

a. Categories of personal information we collect

The categories of personal information we collect are described in Section 3 and may include:

  • Identifiers (e.g., name, email address)
  • Personal information described in Cal. Civ. Code §1798.80(e) (e.g., phone number, billing information)
  • Internet or other electronic network activity information (e.g., usage data, device data)
  • Geolocation data (approximate location)
  • Inferences drawn from other information to create a profile

b. Purposes of collection

We collect personal information for the purposes described in Section 5.

c. Categories of third parties to whom we disclose personal information

We disclose personal information to the categories of recipients described in Section 6: service providers, recipients of opt-out and deletion requests, and advertising networks (see Section 14(d)).

d. Sale and sharing of personal information

We do not sell personal information for money. We do not sell or share the personal information you provide to us, such as your account details, the information you submit for data broker removal, or data from connected email accounts, with advertisers, data brokers, or other third parties.

When you visit our websites, advertising platforms we advertise on collect information through their pixels and cookies to measure our advertising and to show our ads to people who have visited our websites. Under the California Consumer Privacy Act and similar state laws, this may be considered a "sale" of personal information, "sharing" for cross-context behavioural advertising, or "targeted advertising." In the preceding 12 months, the categories of personal information disclosed this way were identifiers (such as cookie IDs, advertising IDs, and IP address) and internet or other electronic network activity information (such as pages viewed and actions taken on our websites), and they were disclosed to advertising networks.

We do not knowingly sell or share the personal information of consumers under 18 years of age.

To opt out, click "Your Privacy Choices" in our website footer, or enable Global Privacy Control in your browser. We treat a GPC signal as a valid opt-out request for that browser and confirm on our website when it has been honoured.

e. Sensitive personal information

We do not use or disclose sensitive personal information for any purpose other than those permitted by applicable state privacy laws, including the CPRA.

f. Your state privacy rights

Depending on your state of residence, you may have the right to:

  • Know the categories and/or specific pieces of personal information we have collected about you.
  • Access and obtain a copy of your personal information.
  • Request correction of inaccurate personal information.
  • Request deletion of your personal information.
  • Restrict or limit the use of sensitive personal information (if applicable).
  • Opt out of the sale or sharing of personal information, or of targeted advertising.
  • Appeal a decision we make regarding your privacy rights request.

We will not discriminate against you for exercising any of your state privacy rights.

g. How to exercise your rights

You can make a privacy rights request by:

  • Emailing support@privacyhawk.com
  • Submitting a request via the App
  • Using the "Your Privacy Choices" link in our website footer, or enabling Global Privacy Control in your browser, for opt-outs of sale, sharing, or targeted advertising.

We will verify your identity before processing your request, which may include requesting additional information from you or your authorized agent.

This section reflects our practices for the 12 months preceding the Effective Date of this Privacy Policy and will be updated annually as required by applicable state laws.

15. Changes to This Policy

We may update this Policy from time to time. Changes will be posted with a new “Effective Date.”

16. PrivacyHawk Enterprise and Workplace Services

PrivacyHawk offers business customers up to three distinct services. They involve different data, different roles, and different consent. This section identifies which is which, and which parts of this Policy apply to each.

(1) Tenant Exposure Scan. An organization’s Google Workspace or Microsoft 365 administrator installs and authorizes PrivacyHawk for the organization’s tenant. PrivacyHawk identifies the third-party companies and services that hold data associated with the organization’s employee work email addresses, and reports them to the administrator. This is the core PrivacyHawk Enterprise product. Subsections 16.2 through 16.10 govern it.

(2) Employee Privacy Accounts (optional). Some organizations elect to provide their employees with individual PrivacyHawk accounts covering the employee’s own personal and work data — including data broker removal, deletion and opt-out requests, breach and dark web monitoring, mobile protection, and identity protection benefits. This applies only where an organization has purchased and offered this benefit and the employee has individually enrolled. If your employer has not offered you a PrivacyHawk account, nothing in this subsection applies to you. Where an employee does enroll, the account is the employee’s own, and Sections 3 through 15 of this Policy apply to it in the same way they apply to any consumer user. Subsection 16.11 describes the additional limits that apply because the account was provided through an employer.

(3) Business relationship data. Separately from (1) and (2), PrivacyHawk collects information for its own business purposes from the individuals who buy, administer, and support the product. Subsection 16.12 describes this.

16.2 Roles and responsibilities

For the Tenant Exposure Scan, the organization is the data controller (or “business”) and PrivacyHawk acts as its processor (or “service provider”), processing tenant data on the organization’s instructions as set out in our Terms of Service, which the organization accepts when it subscribes to the Services. Individual rights described in Section 10 with respect to Tenant Exposure Scan data are exercised through the organization’s administrator.

For Employee Privacy Accounts, the enrolled employee is the user and PrivacyHawk’s role is the same as it is for any consumer user of the Services. The employer is not a party to the employee’s account and does not control it.

For business relationship data described in subsection 16.12, PrivacyHawk is the controller.

16.3 Tenant Exposure Scan — permissions requested, data retrieved, and data retained

The permissions an administrator grants are broader than the data PrivacyHawk actually retrieves, and the data PrivacyHawk retrieves is broader than the data PrivacyHawk retains. We describe all three below so there is no ambiguity about what the grant technically permits.

Google Workspace. We request the following OAuth scopes and no others.

Gmail message metadata (https://www.googleapis.com/auth/gmail.metadata)

  • What the permission technically allows: read access to Gmail message metadata, including message headers (sender, recipients, subject line, date), labels, thread and message identifiers, and history records. It does not permit access to message bodies or attachments.
  • What PrivacyHawk retrieves: the domain portion of the sender address, and the message date.
  • What PrivacyHawk retains: the third-party domain, and the date it was first and most recently observed.

Directory read-only (https://www.googleapis.com/auth/admin.directory.user.readonly)

  • What the permission technically allows: read-only access to the organization’s user directory, including user profiles, primary email addresses, aliases, organizational unit, job title, manager, and account status.
  • What PrivacyHawk retrieves: the account identifiers necessary to enumerate the accounts covered by the organization’s license and to run the scan.
  • What PrivacyHawk retains: nothing beyond what is necessary to administer the organization’s license.

We do not request or receive access to Google Drive, Google Calendar, Google Contacts, Google Chat, Google Meet, or any other Google service.

Microsoft 365. Our Microsoft integration operates on the same principle. We request Mail.ReadBasic.All and User.Read.All, and no others. As with Gmail, the mail permission technically permits retrieval of basic message properties including sender, recipients, subject line, and date — but not message bodies, previews, or attachments — and the directory permission technically permits retrieval of user profile fields. PrivacyHawk retrieves and retains the same narrow set described above: third-party sender domains and the dates observed.

What is never retrieved. Under no circumstances does the Tenant Exposure Scan retrieve or retain message bodies, attachments, subject lines, recipient lists, individual sender addresses, calendar or file contents, device contacts, SMS messages, government identifiers, or location data.

What administrators can see. An administrator’s dashboard shows the third-party companies and services identified across the tenant, and the dates observed. It does not show messages, subject lines, individual sender addresses, or any other personal information from any employee’s mailbox.

16.4 How we use Tenant Exposure Scan data

We use it solely to identify which third-party companies and services hold data associated with the organization’s work email addresses, to produce the exposure inventory and risk reporting in the administrator dashboard, and to monitor for new exposures over time. We do not use it for any other purpose.

16.5 Limited Use of Google Workspace data

PrivacyHawk’s use and transfer of information received from Google APIs adheres to the Google API Services User Data Policy and the Google Workspace user data and developer policy, including the Limited Use requirements. The commitments below apply to Google Workspace data and to any data derived from it.

(a) Use. We limit our use of Google Workspace data to providing or improving the appropriate use case and the features that are visible and prominent in the PrivacyHawk Enterprise user interface.

(b) Transfers. We do not transfer Google Workspace data, except:

  1. to provide or improve our appropriate use case or user-facing features that are visible and prominent in the requesting application’s user interface, and only with the user’s consent;
  2. for security purposes, such as investigating abuse;
  3. to comply with applicable laws or regulations; or
  4. as part of a merger, acquisition, or sale of assets, after obtaining explicit prior consent from the user.

We do not sell Google Workspace data, transfer it to advertising platforms, data brokers, or information resellers, use it to serve or target advertising of any kind, or use it to determine credit-worthiness or for lending purposes.

(c) Artificial intelligence and machine learning. Data obtained from a Google Workspace tenant is never used to train, create, or improve any artificial intelligence or machine learning model.

This prohibition is absolute and applies to the raw data obtained from Google Workspace scopes and to everything derived from it, including aggregated, anonymized, and de-identified derivations. Google Workspace data is not used to create, train, improve, evaluate, fine-tune, or benchmark any foundational, frontier, generalized, industry-specific, organization-specific, or other non-personalized model. It is not incorporated into any training corpus. It is not stored in conjunction with any such model. It is not transferred to any third party for any of those purposes. The only exception Google’s Limited Use requirements permit — a model personalized to a specific user for the appropriate use case or user-facing feature — is not one PrivacyHawk currently relies on for Workspace data.

PrivacyHawk does operate machine learning systems that improve its opt-out automation over time, as described in Section 5(b). Those systems are trained on data obtained from sources other than Google Workspace tenants. Google Workspace data does not enter them.

Processing Google Workspace data through an AI system at the time a scan runs — that is, inference, where the data is evaluated by a model but does not alter the model — is distinct from training and is permitted. Where we use a third-party AI provider for such processing, we do so under contractual terms that prohibit the provider from retaining the data or using it to train its own models.

(d) Human access. We do not allow humans to read Google Workspace data, unless:

  1. we have obtained and documented the affected user’s explicit consent or affirmative agreement to view specific data — for example, where a user contacts us for support and agrees that we may examine specific data in order to resolve their issue;
  2. a tenant owner or authorized representative of the tenant owner authorizes it for performance of the services, for example, for PrivacyHawk’s managed Shadow Digital Footprint services where PrivacyHawk’s internal team assists with making data deletion and other opt out requests to clean up the organization’s shadow digital footprint; this authorization is always provided by agreeing to PrivacyHawk’s Enterprise Terms of Service;
  3. the data, including derivations, is aggregated and anonymized and used for internal operations in accordance with applicable legal requirements;
  4. it is necessary for security purposes, such as investigating a bug or abuse; or
  5. it is necessary to comply with applicable laws or regulations.

PrivacyHawk personnel do not have access to the contents of any employee’s mailbox. Access to the third-party domain data produced by a scan is restricted, under a least-privilege access control policy, to the specific authorized engineering and support personnel who require it for the purposes listed above, and such access is logged.

(e) Personnel and successors. We require our employees, agents, contractors, and successors to comply with the Google API Services User Data Policy and the Google Workspace user data and developer policy.

(f) Precedence. The commitments in this subsection 16.5 govern Google Workspace data notwithstanding anything to the contrary in our Terms of Service, including any general license to use customer data for research, product improvement, artificial intelligence model training, or machine learning. That general license does not extend to Google Workspace data or to data derived from it. Subsection 16.6 sets out which of these commitments apply to Microsoft 365 tenant data.

16.6 Microsoft 365 tenant data

We apply the following commitments from subsection 16.5 to data obtained from a Microsoft 365 tenant and to data derived from it: the same limits on use (16.5(a)), the same limits on transfer (16.5(b)), the same restrictions on human access (16.5(d)), and the same retention and deletion commitments in subsection 16.9.

By subscribing to PrivacyHawk Enterprise and agreeing to our Terms of Service, a customer organization agrees that we may use Microsoft 365 tenant data, and data derived from it, to operate, secure, and improve the Services, including by developing and improving the machine learning models used to deliver privacy and security functionality. We do not use this data for advertising and do not transfer it to third parties for model training.

16.7 Scope of the restrictions in this section

The commitments in subsections 16.5 and 16.6 attach to data by its source, not by the identity of the person it concerns. They apply to data obtained from a Google Workspace or Microsoft 365 tenant through an administrator’s authorization, and to data derived from it, and they continue to apply after that data has been aggregated, anonymized, or transferred. Subsection 16.6 identifies which of these commitments apply to Microsoft 365 tenant data.

They do not govern data PrivacyHawk obtains from other sources — including personal email accounts an individual connects to the consumer Services, and information obtained from public records or data brokers. Our handling of that data is governed by Sections 3 through 15. Data obtained from a personal Google account connected to the consumer Services is separately subject to the Limited Use commitments in Section 5(c), and data from a personal Microsoft account to Section 5(d).

16.8 Sharing

We never sell the limited data we get from the Tenant Exposure Scan.

We share it with the subprocessors necessary to operate the service — cloud hosting, security, and support infrastructure — under contractual confidentiality and security obligations, and only for the purposes described in subsection 16.4. A current list of subprocessors is available on request.

Tenant Exposure Scan data is not disclosed to anyone else other than for data deletion and opt out purpose. PrivacyHawk uses Tenant Exposure Scan data limited to email address and website of the company to which the user is sending the opt-out request to send deletion or opt-out requests (upon request of the account owner or authorized representative).

Where an individual has an Employee Privacy Account (subsection 16.11), deletion and opt-out requests made through that account are handled as described in Section 6.

16.9 Storage, retention, and deletion

Tenant data is processed and stored in Google Cloud Platform data centers in the United States, encrypted in transit and at rest.

An administrator may revoke PrivacyHawk’s access at any time from the Google Workspace Admin console or the Microsoft 365 admin center, and may request deletion at any time by emailing support@privacyhawk.com.

Within 30 days of revocation, deletion request, or termination of the organization’s subscription, we delete: all Google Workspace and Microsoft 365 data; all data derived from it, including third-party domain records, exposure inventories, and risk scores; and any cached copies. Operational logs that reference tenant data are deleted within 30 days. Backups and disaster recovery snapshots are purged on their ordinary rotation cycle, which does not exceed 30 days, after which no copy remains.

We may retain aggregated and anonymized statistics derived from tenant data for product improvement and internal operations, in accordance with subsection 16.5(d)(2). Such statistics do not identify, and cannot reasonably be used to identify, any organization or individual. Statistics derived from Google Workspace data are not used to train or improve any artificial intelligence or machine learning model.

Deletion under this subsection does not require us to reverse improvements already made to the Services or to models trained on Microsoft 365 tenant data in accordance with subsection 16.6, from which an individual organization’s data cannot be separately extracted.

16.10 Notice and consent

Before any data is accessed, the person granting access is shown Google’s or Microsoft’s own hosted consent screen, which identifies PrivacyHawk and itemizes each permission being requested. PrivacyHawk displays its disclosure of what data will be accessed, how it will be used, and how it will be shared in the product itself, immediately before that consent screen is presented. That disclosure is not located only in this Policy or in our Terms of Service. No data is collected before affirmative consent is given.

An administrator’s authorization covers the organization’s tenant. It does not, by itself, authorize PrivacyHawk to act on behalf of any individual employee. Where PrivacyHawk performs an action that requires an individual’s own authorization — including exercising an individual’s personal privacy rights as an authorized agent — that authorization comes from the individual, through their own enrollment and consent, and not from the administrator.

Where the product performs an action on a user’s behalf, the user confirms that action.

16.11 Employee Privacy Accounts

This subsection applies only where an organization has purchased Employee Privacy Accounts and offered them to its employees, and the individual employee has enrolled. If your employer has not offered you a PrivacyHawk account, this subsection does not apply to you.

Where an employee enrolls:

  • The account is the employee’s own. Sections 3 through 15 of this Policy apply to it in full, including the descriptions of data collected, purposes, retention, and individual rights.
  • The employee — not the employer, and not PrivacyHawk acting on the employer’s instruction — designates PrivacyHawk as their authorized agent for privacy rights requests, on the terms described in our Terms of Service.
  • Deletion and opt-out requests are handled as described in Section 6.
  • The employer’s administrator has no visibility into the employee’s account. Administrators cannot see the employee’s messages, subject lines, senders, recipients, personal email content, data broker records, breach or dark web monitoring results, or any other personal information associated with the account. Administrator reporting is limited to the tenant-level information described in subsection 16.3.
  • An employee may decline to enroll, and may close the account at any time, without the employer being informed of the reason.

16.12 Information PrivacyHawk collects as controller

Independently of the data processed on an organization’s behalf, PrivacyHawk collects and determines the purposes for the following:

  • Administrator and contact information: name, business email address, job title, phone number, and organization, for the individuals who evaluate, purchase, administer, or are billed for the Services.
  • Billing and transaction records: billing contact details, purchase and invoice history, and payment records. Card details are handled by our payment processor and are not stored by us.
  • Support records: the content of support tickets, correspondence, and any information voluntarily provided in the course of a support interaction.
  • Website and marketing data: the data described in Sections 3(b) and 7 for visitors to our website, including log data, usage data, and cookie data, subject to the consent requirements described in Section 7.
  • Security and audit logs: authentication events, administrative actions within the product, access logs, and similar records generated by our systems, which we retain for security, fraud prevention, and compliance purposes.

We process this information as a controller for the purposes described in Section 5, and it is subject to Sections 4 through 15 of this Policy. It is not customer-controlled tenant data and is not subject to the Limited Use restrictions in subsection 16.5, because it is not obtained from Google Workspace or Microsoft 365 APIs.

16.13 Permitted use and worker monitoring

PrivacyHawk Enterprise is provided exclusively for privacy protection and cybersecurity purposes: identifying and reducing third-party exposure of organizational and employee data.

PrivacyHawk Enterprise is not a workforce monitoring, productivity measurement, or employee evaluation tool. It does not measure or report on employee productivity, communications volume, working hours, message content, or performance. Exposure findings and risk scores reflect the behavior of third-party companies that hold data, not the conduct or competence of any employee.

Prohibited uses. As a condition of using the Services, the customer organization agrees not to use PrivacyHawk Enterprise output — including exposure inventories, risk scores, and any derived metric — as a factor in any decision regarding hiring, compensation, promotion, demotion, reassignment, scheduling, training, discipline, or termination, or in any other employment decision affecting an individual worker. The customer organization further agrees not to use the output to single out, rank, or profile individual employees for adverse treatment.

Customer responsibilities. The customer organization is responsible for determining the lawful basis for processing its workers’ data, for providing its workers with any notice required by applicable law regarding the scanning of company accounts, for conducting any data protection impact assessment, legitimate interests assessment, or worker consultation required in its jurisdiction, and for honoring worker rights requests relating to tenant data. PrivacyHawk will provide reasonable assistance with such requests.

16.14 Security

PrivacyHawk Enterprise is operated in accordance with the security practices described in Section 12. PrivacyHawk has completed a SOC 2 audit; a copy of the report is available to prospective and current enterprise customers under NDA. Applications accessing Google restricted scopes are subject to the Cloud Application Security Assessment (CASA) and, where applicable, periodic third-party security assessment.

16.15 Contact

Administrators and enterprise customers may contact us regarding PrivacyHawk Enterprise data practices, access, or deletion at support@privacyhawk.com. Employees with questions about an Employee Privacy Account may use the same address, and may also exercise the rights described in Section 10 directly.

17. Contact Us

PrivacyHawk, Inc.
Email: support@privacyhawk.com
EU/UK Representative: support@privacyhawk.com

‍

‍