1. Who We Are
Data Controller: BreachFin LLC
Address: 971 US Highway 202 N, Site N, Branchburg, NJ 08876, United States
Email: [email protected]
Phone: +1 (908) 587-3269
Website: https://breachfin.com
For privacy-related questions or to exercise your rights, contact us at [email protected].
2. Scope
This Privacy Policy applies to personal information processed through:
- Our website and marketing pages
- Demo scheduling through Calendly
- Email and other communications with BreachFin
- Our software and services when you become a customer (supplemented by your agreement with us)
If you use BreachFin on behalf of an organization, your employer may also have policies that apply to you.
3. Information We Collect
3.1 Information You Provide
- Identity and contact data (name, email, phone, company, job title)
- Communications (emails, demo requests, support messages)
- Account and billing information if you purchase services
- Any other information you choose to provide
3.2 Information Collected Automatically
- IP address, browser type, device identifiers, operating system
- Pages viewed, referring URLs, date and time of access
- Security logs, diagnostic data, and anti-abuse signals
- Cookie and similar technology data (see our Cookie Policy)
3.3 Information from Third Parties
We may receive information from scheduling providers (such as Calendly), hosting and security providers, analytics tools, and publicly available business sources where permitted by law.
4. How We Use Personal Information
We use personal information to:
- Respond to inquiries and schedule product demonstrations
- Provide, operate, maintain, and improve our services
- Communicate about products, updates, and security notices
- Detect, prevent, and investigate fraud, abuse, and security incidents
- Comply with legal obligations and enforce our agreements
- Analyze website performance and user experience
We do not sell personal information. We do not use personal information for cross-context behavioral advertising.
5. Legal Bases for Processing (EEA / UK GDPR)
Where the GDPR applies, we process personal information on the following bases:
- Contract: to perform a contract with you or take steps at your request before entering a contract
- Legitimate interests: to operate, secure, and improve our website and services, communicate with prospects and customers, and protect our business, where not overridden by your rights
- Consent: where required for non-essential cookies, marketing communications, or other optional processing
- Legal obligation: where processing is necessary to comply with applicable law
You may withdraw consent at any time where processing is based on consent, without affecting the lawfulness of processing before withdrawal.
6. How We Share Information
We may share personal information with:
- Service providers that help us operate our website and business (hosting, security, scheduling, email, analytics)
- Professional advisers (lawyers, accountants, insurers) under confidentiality obligations
- Authorities or other parties when required by law or to protect rights, safety, and security
- Successors in connection with a merger, acquisition, or asset sale, subject to this Privacy Policy
We require service providers to process personal information only on our instructions and with appropriate safeguards.
7. International Data Transfers
BreachFin is based in the United States. If you access our website or services from outside the United States, your information may be transferred to, stored in, or processed in the United States and other countries that may have different data protection laws than your country.
Where required, we implement appropriate safeguards for international transfers, such as Standard Contractual Clauses approved by the European Commission or UK authorities, and supplementary measures where appropriate.
8. Data Retention
We retain personal information only as long as reasonably necessary for the purposes described in this Privacy Policy, including to satisfy legal, accounting, or reporting requirements. Retention periods vary depending on the type of data and our relationship with you.
9. Security
We implement administrative, technical, and organizational measures designed to protect personal information, including HTTPS encryption, access controls, security monitoring, and infrastructure protections through providers such as Cloudflare. No method of transmission or storage is completely secure, and we cannot guarantee absolute security.
10. Your Rights
10.1 EEA / UK (GDPR)
Subject to applicable law, you may have the right to:
- Access your personal information
- Rectify inaccurate information
- Erase information in certain circumstances
- Restrict or object to certain processing
- Data portability where applicable
- Withdraw consent where processing is based on consent
- Lodge a complaint with your local supervisory authority
10.2 California (CCPA / CPRA)
California residents may have the right to:
- Know the categories and specific pieces of personal information we collect, use, and disclose
- Request deletion of personal information, subject to exceptions
- Request correction of inaccurate personal information
- Opt out of the sale or sharing of personal information (we do not sell or share personal information for cross-context behavioral advertising)
- Not receive discriminatory treatment for exercising privacy rights
To submit a request, email [email protected] with the subject line “Privacy Request.” We will verify your request as required by law. You may designate an authorized agent to submit a request on your behalf where permitted.
10.3 Other Regions
Depending on your location, you may have additional rights under local law. Contact us and we will respond in accordance with applicable requirements.
11. Cookies and Similar Technologies
We use cookies and similar technologies as described in our Cookie Policy. Where required, we obtain consent before placing non-essential cookies.
12. Third-Party Services
Our website may link to or integrate with third-party services, including Calendly, Cloudflare, Google reCAPTCHA, and hosting providers. Those services are governed by their own privacy policies. We encourage you to review them.
13. Children
Our website and services are intended for business professionals and are not directed to children under 16 (or under 13 in the United States). We do not knowingly collect personal information from children. If you believe we have collected information from a child, contact us and we will take appropriate steps to delete it.
14. Enterprise Customers
If your organization purchases BreachFin services, additional terms in your order form, master services agreement, or data processing agreement (DPA) may govern processing of personal information. In the event of conflict between this Privacy Policy and a signed enterprise agreement, the signed agreement controls for that customer relationship.
15. Changes to This Privacy Policy
We may update this Privacy Policy from time to time. The updated version will be posted on this page with a revised Effective Date. Material changes may also be communicated by email or a notice on our website where appropriate.
16. Contact Us
BreachFin LLC
971 US Highway 202 N, Site N, Branchburg, NJ 08876, United States
Email: [email protected]