Intrinsic Security Logo

Notice to Visitors & Users: This Privacy Policy outlines the general data processing practices, privacy principles, and user security policies of Intrinsic Security (referred to as "Company", "We", "Us", or "Our"). This document serves as an enterprise legal disclosure template. Specific cybersecurity service agreements, managed SOC contracts, and platform licenses may be governed by tailored Data Processing Addendums (DPAs).

No Data Sale

We do not sell, rent, or monetize your personal information or security telemetry to third parties.

AES-256 Encryption

All data at rest and in transit is protected with enterprise cryptographic controls and TLS 1.3.

GDPR & CCPA Rights

Full support for data subject requests including access, rectification, erasure, and data portability.

Strict Confidentiality

Telemetry, threat logs, and vulnerability data are processed strictly for security analysis.

01

Privacy Policy

Welcome to Intrinsic Security ("Intrinsic Security", "Company", "We", "Us", or "Our"). We are committed to protecting your privacy, maintaining data confidentiality, and ensuring robust security across all digital interactions. This Privacy Policy explains how we collect, process, store, disclose, and protect personal data when you visit our website at [Website URL] (https://intrinsic.security), communicate with us, or utilize our cybersecurity consulting, managed security services (Intrinsic Protect, SIEM360, AI Secure), and security platform solutions (Intrinsic Defender, Intrinsic Phorensic, Intrinsic DeepHunt).

By accessing or using our Website and Services, you acknowledge that you have read and understood the terms of this Privacy Policy. If you do not agree with our policies and practices, your choice is not to use our Website or Services.

02

Introduction & Scope

Intrinsic Security operates as a specialized cyber defense firm delivering offensive security, defensive operations, incident response, and security analytics. In delivering these services, we act primarily as a Data Controller for personal data collected directly through our public Website and business operations. Where we process security telemetry or client endpoint data under a master service agreement, we act as a Data Processor in accordance with customer instructions.

This policy applies to information collected:

  • On or through this Website (https://intrinsic.security).
  • In email, text, and other electronic messages between you and Intrinsic Security.
  • Through mobile applications, client portals, or platforms you download from this Website.
  • When you register for iAcademy training modules, webinars, or threat intelligence briefings.
03

Information We Collect

We collect several types of information from and about users of our Website and Services. The information collected depends on your interaction with Intrinsic Security:

Category Examples of Data Collected Primary Purpose
Identity & Contact Data First name, last name, business email address, job title, company name, phone number. Communication, consultation booking, account setup.
Technical & Telemetry Data IP address, browser type, operating system, referrer URL, device identifiers, session timestamps. Security logging, intrusion prevention, performance analysis.
Usage & Interaction Data Pages viewed, time spent on pages, clickstream patterns, resource downloads. Website optimization, UX enhancement.
Security Operations Data Network log metadata, threat indicators (IoCs), file hashes submitted for analysis. Threat hunting, incident response, SIEM telemetry.
04

Information You Provide to Us

The information we collect directly from you when using our Website includes:

  • Contact Forms & Inquiries: Information supplied when filling in forms on our Website (such as booking a security assessment or contacting our threat response desk).
  • Account & Service Registration: Credentials and organization details supplied when registering for client portals or iAcademy courses.
  • Customer Support & Consultations: Records and copies of correspondence if you contact us regarding security advisory or technical support.
  • Surveys & Feedback: Responses to research questionnaires, threat landscape studies, or customer feedback forms.
05

Information Collected Automatically

As you navigate through and interact with our Website, we automatically collect statistical and technical data about your equipment, browsing actions, and patterns using automated data collection technologies:

  • Web Server Log Files: Our web servers automatically log network requests, including client IP address, timestamp, HTTP request headers, User-Agent string, and server response code to protect against denial-of-service (DoS) attacks and malicious probing.
  • Device Telemetry & Fingerprinting: Technical details regarding your hardware architecture, screen resolution, and operating system to optimize page rendering.
  • Cookies and Tracking Pixel Beacon Technology: Small data files stored on your local drive to maintain session state and measure web traffic.
06

How We Use Your Information

We process personal data lawfully, fairly, and transparently. The legal bases under data protection laws (such as EU/UK GDPR Article 6) and primary processing purposes are outlined below:

  • To Fulfill Contractual Obligations: To deliver requested security consulting, platform subscriptions, offensive assessment reports, or training courses.
  • Legitimate Business & Security Interests: To protect our network, detect unauthorized intrusions, conduct threat research, analyze website performance, and defend legal rights.
  • Compliance with Legal Obligations: To adhere to applicable cyber reporting mandates, statutory accounting laws, and lawful law enforcement requests.
  • With Consent: Where you explicitly opt-in to receive cybersecurity advisories, vulnerability bulletins, or marketing communications.
07

Cookies and Similar Technologies

Our Website uses cookies, local storage objects, and similar tracking technologies to differentiate you from other users and provide a seamless browsing experience. We categorize cookies into three tiers:

  • Strictly Necessary Cookies: Essential for core website operations, security validation, and session management. These cannot be disabled in our systems.
  • Analytical & Performance Cookies: Aggregate, anonymized cookies that allow us to count visit metrics and traffic sources so we can evaluate site responsiveness.
  • Functional & Preference Cookies: Enable enhanced functionality and personalization, such as remembering your preferred language or region.
Managing Preferences: You can set your browser to refuse all or some browser cookies, or to alert you when cookies are being sent. If you disable or refuse cookies, please note that some parts of this site may become inaccessible or fail to function properly.
08

How We Share Information

We maintain strict data governance protocols. We do not sell, trade, or monetize personal information. We may disclose personal data only under the following limited circumstances:

  • Vetted Subprocessors & Vendors: To trusted third-party service providers (such as cloud hosting infrastructure, encrypted CRM platforms, and transactional email gateways) who assist in operating our Website and delivering services under strict data protection agreements.
  • Corporate Transactions: In the event of a merger, acquisition, restructuring, or asset sale, customer data may be transferred as part of standard due diligence under strict non-disclosure obligations.
  • Legal Compliance & Protection: If required to do so by law, court order, search warrant, or subpoena, or if we believe in good faith that disclosure is necessary to protect the safety, property, or rights of Intrinsic Security, our clients, or the public.
09

Third-Party Services

We utilize trusted third-party service providers for hosting, telemetry analysis, content delivery, and communications. These third parties have access to personal data only to perform specific tasks on our behalf and are contractually obligated not to disclose or use it for any other purpose.

Categories of subprocessors include:

  • Tier-3 Certified Cloud Data Centers (EU & UK regions).
  • Encrypted Customer Relationship Management (CRM) Systems.
  • Privacy-Preserving Web Analytics Services.
  • Distributed Denial-of-Service (DDoS) Mitigation Platforms.
10

Data Retention

We retain personal data only for as long as necessary to fulfill the purposes for which it was collected, including satisfying any legal, accounting, statutory security, or reporting requirements.

  • Web Server & Firewall Security Logs: Retained for a maximum of 12 months for incident analysis and threat hunting, after which logs are securely purged or anonymized.
  • Client Account & Transactional Records: Retained for 7 years post-contract termination to comply with legal, tax, and audit obligations.
  • Inquiry & Consultation Form Data: Retained for 24 months from the last active contact unless requested earlier for deletion.
11

Data Security

As a cybersecurity firm, security is embedded in our foundation. We implement robust technical, physical, and organizational safeguards designed to protect personal data against accidental loss, unauthorized access, alteration, or disclosure:

  • Cryptographic Standards: TLS 1.3 encryption for all data in transit across public networks and AES-256 encryption for data at rest.
  • Access Controls & Authentication: Multi-Factor Authentication (MFA), Role-Based Access Control (RBAC), and Principle of Least Privilege across all internal storage systems.
  • Continuous Audit & Pentesting: Regular internal audits, vulnerability scans, and external penetration testing aligned with ISO/IEC 27001 standards.
12

Your Privacy Rights

Depending on your jurisdiction (such as the European Economic Area, United Kingdom, or California), you possess specific rights regarding your personal data:

  • Right of Access: Request a copy of the personal data we hold about you.
  • Right to Rectification: Request correction of inaccurate or incomplete personal records.
  • Right to Erasure ("Right to be Forgotten"): Request deletion of your personal data where no legal override exists.
  • Right to Data Portability: Request transmission of your data in a structured, machine-readable format.
  • Right to Object & Restrict Processing: Object to processing based on legitimate interests or request processing restrictions.
  • Right to Withdraw Consent: Withdraw consent at any time where processing relies on your consent.

To exercise any of these rights, please submit a Data Subject Request to [Contact Email] (assist@intrinsic.security).

13

International Data Transfers

Intrinsic Security operates internationally. Personal data collected from the European Economic Area (EEA) or UK may be transferred to and processed in countries outside your home jurisdiction. Whenever we transfer personal data internationally, we implement appropriate safeguards, including standard contractual clauses (SCCs) approved by the European Commission or UK International Data Transfer Agreements (IDTA).

14

Children's Privacy

Our Website and Services are directed exclusively to business professionals and individuals aged 16 and older. We do not knowingly solicit or collect personal data from children under the age of 16. If we become aware that we have inadvertently collected personal data from a child under 16, we will take immediate steps to delete such information from our records.

15

Third-Party Links

Our Website may contain links to third-party websites, plugins, or external platforms (such as industry partner sites or LinkedIn). Clicking on those links may allow third parties to collect or share data about you. We do not control these third-party websites and are not responsible for their privacy statements. We encourage you to read the privacy policy of every website you visit.

16

Changes to This Privacy Policy

We reserve the right to modify or update this Privacy Policy at any time to reflect operational changes, legal requirements, or regulatory enhancements. We will notify you of material changes by updating the "Last Updated" date at the top of this page and, where appropriate, providing prominent notice on our Website or via email.

17

Contact Us & Data Protection Officer

If you have any questions, comments, or concerns regarding this Privacy Policy, our data practices, or wish to exercise your data subject rights, please contact our Data Protection Team:

Intrinsic Security Data Protection Office

Phone Support

+974 6629 2690

Physical Office

Office 1, 2nd Floor, Alfardan Centre, Grand Hamad Street, P.O Box-26660, Doha, Qatar

Chat on WhatsApp