We collect information in a few different ways: directly from you, automatically as you use the Service, and from trusted third parties that help us operate and secure it. The categories below describe what we collect and where it comes from.
You share this information when you create an account, configure the platform, or contact our team.
As you navigate and use the Service, certain technical information is collected by default.
We may also receive information from identity providers and single sign-on services you connect, from security and IAM tools you integrate, and from publicly or commercially available sources. We combine this with the information above to keep your account secure and to improve the Service.
We use the information we collect to run the Service reliably, keep it secure, and make it better over time. We process your information only for the purposes described in this Policy or for other compatible purposes you would reasonably expect.
Specifically, we use information to:
We do not use your personal data for unrelated purposes without first letting you know and, where required, obtaining your consent.
Where data protection law applies, we only process personal data when we have a valid legal basis to do so. The basis we rely on depends on the context in which we collect and use your information.
We treat your information as confidential and we do not sell it. We share information only where it is necessary to provide the Service, comply with the law, or protect our users and the public.
We may share information with:
When we engage service providers, we require them to protect your information and to use it only for the purposes we specify.
We retain personal data for as long as necessary to provide the Service and fulfill the purposes described in this Policy. The exact retention period depends on the type of data, the reason we hold it, and any legal or contractual obligations that apply.
When personal data is no longer needed, we securely delete, anonymize, or aggregate it so that it can no longer be associated with you. Residual copies in backups are removed on a rolling schedule.
Protecting your information is central to what we do. We maintain administrative, technical, and organizational measures designed to protect personal data against unauthorized access, loss, misuse, or alteration.
These measures include:
While we work hard to protect your information, no method of transmission or storage is completely secure, and we cannot guarantee absolute security.
Depending on where you live, you may have certain rights over your personal data. We are committed to honoring these rights and making them straightforward to exercise.
These rights may include the ability to:
To exercise any of these rights, contact us using the details below. We will respond within the timeframes required by applicable law and will not charge a fee unless your request is excessive or repetitive.
We operate globally, which means your information may be transferred to, stored in, and processed in countries other than the one in which you reside. These countries may have data protection laws that differ from those in your jurisdiction.
Where we transfer personal data internationally, we put appropriate safeguards in place, such as standard contractual clauses, to ensure your information remains protected wherever it is processed.
We use cookies and similar technologies to operate the Service, remember your preferences, and understand how the Service is used. Cookies are small files stored on your device that help us recognize you and improve your experience.
The cookies we use generally fall into three categories:
You can manage your preferences through your browser settings at any time, though some features may not function properly without certain cookies.
We may update this Policy from time to time to reflect changes in our practices, technology, or legal requirements. When we make material changes, we will notify you through the Service or by other reasonable means and update the date at the top of this page.
We encourage you to review this Policy periodically to stay informed about how we protect your information.
Welcome to the Way Security privacy notice. This privacy notice (“Privacy Notice”) explains how Way Security Inc. and its affiliates (“Company,” “we,” “us,” “our”) collect, process, share, and protect personal data of you (“Users,” “you,” “your”) in connection with the Company’s website available at https://www.way.security/ (the “Site”), our platform, and our services (collectively, the “Services”). It also outlines your rights and how to exercise them. For this Privacy Notice, “Personal Data” shall mean personal data or personal information pursuant to applicable data protection law.
The Company is the database owner and holder under the Protection of Privacy Law, 5741-1981, with respect to the Personal Data processed through the Services. For users in the United States, the Company acts as the “business” under applicable U.S. state privacy laws, including the California Consumer Privacy Act, as amended by the California Privacy Rights Act (collectively, the "CPRA"). For users in the European Economic Area ("EEA"), the United Kingdom, or Switzerland, the Company is the controller responsible for your Personal Data under the General Data Protection Regulation (collectively, the "GDPR").
Our principal place of business is:251 Little Falls Drive, Wilmington, New Castle, Delaware United states, 19808
This Privacy Notice applies to anyone using our Services, including customers purchasing our products. This Privacy Notice, together with the Terms of Use, forms an integral part of the Services offered by the Company.
You are not under any legal obligation to submit Personal Data to the Company. However, providing Personal Data is a condition for using the Services, and if you choose not to do so, certain Services offered by the Company may not be available to you. By using the Services, you consent to the collection, storage, and use of your Personal Data in the Company’s databases in accordance with the purposes set forth in this Privacy Notice.
By attempting to use or access, or by using or accessing the Site, platform, or Services, you express your consent that you have read and accepted the terms of this Privacy Notice and that the Company will collect your Personal Data and make use thereof as described herein. If you do not agree to any of the terms set forth herein, you must refrain from accessing and/or using the Services.
The Company may collect information you provide voluntarily and of your own free will, so that we may provide the Services to you. The Company may collect information such as:
Only correct, accurate, and complete details should be provided. Incorrect information or failure to provide the full details required may prevent you from using the Services, impair the quality of the service provided to you, and impair the ability to contact you. If your details have changed, you are required to update the Company by contacting us at privacy@way.security
The Company may collect data automatically when you use the Services, including:
We may receive Personal Data about you from third parties, including: business partners, marketing partners, social media platforms (if you interact with our social media presence), publicly available sources, and service providers who assist us in verifying information or preventing fraud.
We may collect and retain metadata and statistical information concerning the use of the Services which are not subject to the deletion procedures in this Privacy Policy and may be retained by us for no more than required to conduct our business. Some data may be retained also on our third-party service providers’ servers in accordance with their retention policies. You will not be identifiable from this retained metadata or statistical information.
The Company may use Personal Data to:
We process your Personal Data based on applicable legal requirements. If you are located in the EEA, United Kingdom, or Switzerland, we process your Personal Data based on the following legal bases under the GDPR:
We may share or disclose your Personal Data to third parties in the following cases:
The Company uses cookies and similar tracking technologies to collect information about your browsing activities and to distinguish you from other users. This helps us provide you with a better experience, analyze usage, and deliver relevant content. Further details regarding our cookie policy are available at: https://way.security/cookies-policy.
Your Personal Data may be transferred to and stored in countries outside your jurisdiction, including in countries where the laws of information protection and privacy may be different from those applicable in the EEA, the United Kingdom, or Switzerland. We transfer Personal Data only to countries that ensure an adequate level of protection or where we have implemented appropriate safeguards consistent with requirements under Israeli law and this Privacy Notice.
For transfers from the EEA, United Kingdom, or Switzerland, we shall rely on the following safeguards:
Adequacy Decisions: Transfers to countries recognized by the European Commission as providing adequate data protection (including Israel).
Standard Contractual Clauses: For transfers to countries without an adequacy decision, we shall use the European Commission’s Standard Contractual Clauses (SCCs) adopted pursuant to Commission Implementing Decision (EU) 2021/914.
The Company implements industry-standard technical and organizational measures to protect Personal Data from unauthorized access, loss, or misuse. These measures include encryption of data in transit and at rest, access controls limiting data access to authorized personnel, regular security assessments, and employee training on data protection. Access to Personal Data is limited to employees and contractors who need such access in order to process it for the Company or perform specific work, and such persons are subject to confidentiality obligations. While these measures reduce the risks of unauthorized intrusion, they do not provide absolute security. Therefore, the Company does not guarantee that the Services will be absolutely immune from unauthorized access to the information stored therein, and in the event that a third party gains unauthorized access to Personal Data, the User will not have any claim against the Company, provided the Company has complied with its security obligations under applicable law.
The Company will act in accordance with the law in the event of any breach of security, confidentiality, or integrity of your Personal Data. , we will notify the relevant supervisory authority and affected individuals where required by applicable law. Furthermore, in events that are not dependent on the Company and/or in cases arising from force majeure, the User will not have any claim for any damage, indirect or direct, if any information is lost or reaches an unauthorized party.
The Company retains Personal Data only for as long as necessary to fulfill the purposes for which it was collected or to comply with legal, accounting, or reporting requirements. The retention period depends on the nature and sensitivity of the Personal Data, the purposes for which we process the data, applicable legal and contractual requirements, and our legitimate business needs. When Personal Data is no longer needed, we will securely delete or anonymize it in accordance with applicable law.
Depending on your jurisdiction, you may have certain rights regarding your Personal Data. Subject to the Protection of Privacy Law, 5741-1981 and the regulations enacted thereunder, as well as other applicable law, the following rights may be available to you:
If you are located in the EEA, United Kingdom, or Switzerland, you may also have the following rights under the GDPR:
Data Portability: Where processing is based on consent or contract and is automated, you may request your Personal Data in a structured, commonly used, machine-readable format.
Restriction: You may request that we restrict the processing of your Personal Data in certain circumstances (e.g., while we verify the accuracy of your data).
Objection: You may object to processing based on our legitimate interests. We will cease processing unless we demonstrate compelling legitimate grounds that override your interests.
Automated Decision-Making: You have the right not to be subject to decisions based solely on automated processing, including profiling, that produce legal effects or similarly significantly affect you. We do not currently make decisions based solely on automated processing that produce legal effects concerning you.
If you are a resident of California, you may have rights under the CPRA, including the right to know/access, delete, correct, opt out of the sale or sharing of personal information, and limit the use and disclosure of sensitive personal information. If you are a resident of Virginia, Colorado, Connecticut, or another U.S. state with a comprehensive privacy law, you may have similar rights, including the right to access, correct, delete, and port your personal data, and the right to opt out of targeted advertising, profiling, and the sale of personal data (as those terms are defined under your state’s law).
To exercise any of these rights, please contact us at privacy@way.security We may need to verify your identity before processing your request. We will respond to your request within the timeframe required by applicable law . If we cannot fulfill your request, we will explain why.
If you voluntarily confirmed the use, you agree that we will use your details to inform you about the Company’s services, marketing and/or advertising information (including advertising messages pursuant to the Communications Law (Telecommunications and Broadcasting), 5742-1982), benefits and services of third parties that are business partners of the Company, which will be forwarded to you via email, SMS, and/or push messages. You may withdraw your consent at any time by contacting us at privacy@way.security , or alternatively, by following the instructions for removal from the mailing list which appear in the messages sent to you. You acknowledge that the Company has informed you that you may refuse to accept such advertisements.
Our Site and Services may contain links to third-party websites, applications, or services that are not operated by us. This Privacy Notice does not apply to those third-party services, and we are not responsible for their privacy practices. We encourage you to review the privacy policies of any third-party services you access. We may integrate third-party services (such as analytics providers, payment processors, and social media platforms) into our Services. These third parties may collect information directly from you or receive information from us. Their collection and use of information is governed by their own privacy policies.
The provisions of this Privacy Notice are an integral part of the Services and may not be separated from the Terms of Use. The Company reserves the right to change this Privacy Notice at any time and asks all Users to review this page regularly. We will notify you of any material changes to this Privacy Notice by posting a prominent notice on the Site and/or by email. Changes will take effect on the date of the last update, and continued use of the Services after such date will constitute consent to the changes. To the extent that this Privacy Notice is amended to meet any legal requirement, the amendments may enter into force immediately, as required by applicable law, and without prior notice.
If you have questions, concerns, or requests regarding this Privacy Notice or our privacy practices, please contact us at:
Way Security
Attn: Privacy Team
Email: privacy@way.security