New Blog --> Crushing False Positives: Supercharging SOC Efficiency with Smarter Threat Intel
New Blog --> Crushing False Positives: Supercharging SOC Efficiency with Smarter Threat Intel
Start Free Trial

Privacy Policy

ChaosSearch®, Inc. Privacy Policy

Last Updated: May 24, 2023

Introduction

This Privacy Policy explains how information about you is collected, used and disclosed by ChaosSearch, Inc. (“ChaosSearch”, “we”, “us” or “our”) including our wholly-owned subsidiary, ChaosSearch UK Limited. This Privacy Policy applies to Personal Information we collect when you use our website (including https://chaossearch.io and https://chaossearch.com domains) (“Website”) and the ChaosSearch platform and services (the “Platform”) (collectively with the Website, the “Services”) or when you otherwise interact with us. Personal Information is any information that identifies you or would enable someone to contact you, which may include your name, email address, phone number and other non-public information that is associated with such information. It does not include aggregate information, anonymous information, or any other non-personally identifiable information. Unless expressly set forth herein or required by law, this Privacy Policy also does not apply to any unsolicited information you provide to us through the Website or the Services or through any other means, such as information posted to any public areas of the Services or unsolicited submissions (collectively, “Unsolicited Information”). All Unsolicited Information shall be deemed to be non-confidential, and we shall be free to reproduce, use, disclose, and distribute such Unsolicited Information to others without limitation or attribution. This Privacy Policy also describes the choices available to you regarding the use of, your access to, and how to update and correct your Personal Information. By using our Services, you consent to the collection, transfer, processing, storage, disclosure, and other uses described in this Privacy Policy. If you do not agree to the terms set forth herein, please do not use our Services.

Changes to this Privacy Policy

We may change this Privacy Policy from time to time. We will indicate at the top of the Privacy Policy when it was last updated. If we make material changes to this Privacy Policy, we will notify you by email (sent to the email specified in your account) or by means of notice on www.chaossearch.com prior to the change becoming effective and your continued use of the Website and Services will indicate your acknowledgment of such changes and agreement to be bound by the modified Privacy Policy terms. We encourage you to review the Privacy Policy whenever you access the Services to stay informed about our information practices and the ways you can help protect your privacy. Using our Services or continuing to provide Personal Information to us after a notice of changes has been sent to you or published via our Services shall constitute consent to the changed terms and practices. If you disagree with any changes to this Privacy Policy, you will need to stop using our Services.

Please take the time to read this Privacy Policy. Unless stated otherwise, our current Privacy Policy applies to all Personal Information you have provided to us.

Information Related to Data Processed by the ChaosSearch Data Platform

Information Related to Data Processed by the Platform for our Clients: ChaosSearch processes information on its Platform under the direction of its Clients. As a result of the platform architecture, the ChaosSearch Platform does not hold or store any Client data other than account information used to log into the Platform and services. ChaosSearch also has no direct relationship with the individuals whose personal data it may process on behalf of a Client. If you are a customer of one of our Clients and would no longer like to be contacted by one of our Clients that use our service, please contact the Client that you interact with directly. We may transfer personal information to select third parties that help us provide our service. Transfers to third parties are covered by the service agreements with our Clients.

Access and Retention of Data Controlled by our Clients: ChaosSearch acknowledges that you have the right to access your personal data. ChaosSearch has no direct relationship with the individuals whose personal data it may process. An individual who seeks access, or who seeks to correct, amend, or delete inaccurate data should direct his query to the ChaosSearch's Client (the data controller). If requested to remove data we will respond within a reasonable timeframe.

Information We Collect

When you interact with us through the Services or Website, we may collect Personal Information and other information from you, in the following ways:

Information You Provide to Us

  • Contact Information: We collect Personal Information you provide directly to us. For example, we collect information when you create an account, use the Services, fill out a form, request customer support or otherwise communicate with us. The types of information we may collect include your email address, postal address and other contact or identifying information you choose to provide. You may also optionally subscribe to our blog and may unsubscribe from our communications at any time by clicking on the “unsubscribe” link contained at the bottom of our communications.
  • Account Information: We also collect Personal Information from you when you log into our Services. You are solely responsible for the Personal Information you choose to submit. Account information is necessary to facilitate our subscription Services, including providing you with information to help us maintain and improve our Service offerings and material updates to our Terms of Service and Privacy Policy.

Information Collected Automatically When You Use the Services

When you access or use our Services, information about you may be automatically collected by us or by our third party partners and service providers. Interactions with features enabled by our third party partners and service providers are governed by the privacy policy of the company providing it. Users should review the applicable privacy policies for these sites for more detail about information collected and processed by these sites. Information collected about you when you use the Services may include:

  • Log Information. We log information about your use of the Services, including the type of browser you use, internet service provider, clickstream data, date/time stamp, pages and files viewed on our site (e.g., HTML pages, graphics, etc.), your IP address and the page you visited before navigating to our Services.
  • Device Information. We collect information about the computer or mobile device you use to access our Services, including the hardware model, operating system and version, unique device identifiers and mobile network information.
  • Cookies. Like most websites, we use “cookies” and web log files to collect information to track site usage and trends, to improve our Service, and to deliver a customized experience when you use our Services. A cookie is a small data file that is placed on your computer, mobile phone, or other device by a web server and enables us to recognize you when you return to our site or log into our Service. Cookies are uniquely assigned to you, and can only be read by a web server in the domain that issued the cookie to you. One of the primary purposes of cookies is to provide a convenience feature to save you time – for example, when you return to the same website, the information you previously provided can be retrieved, so you can easily use the features that you customized. We may also use “session ID cookies”, which expire after a short period of time or when you close your browser. Session ID cookies are used to identify a particular visit and are used to enable certain features of the site or service, to better understand how you interact with the site and Service, and to monitor aggregate usage and web traffic routing on the site. We set a cookie and use local storage in your browser that contains information that we use to identify you for the functional site features described below with respect to our third party vendors, such as Google Analytics and other common software tools and third party services we use to market our Services. You have the ability to accept or decline cookies. Most Web browsers automatically accept cookies, but you can usually modify your browser setting to decline cookies if you prefer. If you choose to decline cookies, you may not be able to fully experience the interactive features of the Website. We keep track of the pages you visit on the Website, in order to determine what parts of the Website are the most popular. This data is used to deliver customized content and advertising on the Website to visitors whose behavior indicates that they are interested in a particular subject area.
  • Social Media Widgets. Our Website includes social media features, such as Facebook, Twitter, and LinkedIn or interactive mini-programs that run on our Website. These features may collect your Internet protocol address, which page you are visiting on our website, and may set a cookie to enable the feature to function properly. Social media features and widgets are either hosted by a third party or hosted directly on our Website. Your interactions with these features are governed by the privacy policy of the company providing it. Further information on how you can opt-out of web tracking can be referenced under “Opting-Out and Unsubscribing”.
  • Third-party Analytics. We allow third parties to serve advertisements on our behalf across the Internet and to provide analytics services. These third parties may use cookies, web beacons and other technologies to collect information about your use of the Services and other websites, including your IP address, web browser, pages viewed, time spent on pages, links clicked and conversion information. This information may be used by ChaosSearch and third parties to, among other things, analyze and track data, deliver advertising based upon your browsing activities and interests and to better understand your use of the Services. Specifically, ChaosSearch uses an integrated version of Google Analytics. You may opt out from Google Analytics by using Google’s Ads Preferences Manager. We also encourage you to use the Google Analytics opt-out browser add-on.
  • Sales and Marketing Information. To enable marketing and sales of our Services we use common software tools and third party service providers to more effectively communicate, schedule meetings and deliver follow up emails to customers and prospective leads. We may obtain information about you from third party sources, such as public databases and websites and joint marketing partners. We collect and track information on use of the Services including referral sources, search terms, network information, IP addresses, computer and browser types, and content viewed. You may unsubscribe from our communications at any time by clicking on the “unsubscribe” link contained at the bottom of our communications.
  • Account Registration and Support Information. When you create an account or submit a help desk ticket or request, our Services may ask you to “opt-in” to the collection of diagnostic information and communications with you regarding your use of our Services in order for us to provide, maintain, operate, promote and improve our Services. If you opt in, you agree that we may collect, maintain, and use information about the operation of our Services. We may also use third party service providers as part of the Service to collect and track statistical and behavioral information regarding the access to, use of and interaction with the Services.

How We Use Information We Collect

Consent to Use of Your Information. By submitting information, including Personal Information, to us, you are expressly and voluntarily accepting the terms and conditions of this Privacy Policy. You have the right to withdraw your consent to our collection and use of your information, but your withdrawal of consent will not be retroactive.

General. We use the information we collect only in compliance with this Privacy Policy. We use information about you for various purposes, including to:

  • Provide, maintain, operate, promote, and improve our Services;
  • Provide and deliver the Services you request, process transactions, and to send you related information, including confirmations and invoices;
  • Send you technical notices, updates, security alerts and support and administrative messages;
  • Communicate with you, including responding to your comments, questions, and requests; providing customer service and support; providing you with information about services, features, surveys, newsletters, offers, promotions, contests and events; providing other news or information about us and our select partners; and sending you technical notices, updates, security alerts, and support and administrative messages. Generally, you have the ability to opt out of receiving any promotional communications as described below;
  • Assist with the development of our Services and other purposes related to ChaosSearch business;
  • Monitor and analyze trends, usage and activities in connection with our Services;
  • Investigate and prevent fraudulent transactions, unauthorized access to our Services, and other illegal activities; and
  • For other purposes about which we notify you.

Use of Personal Information. We may use your Personal Information and other information you provide us to (i) administer your use of our Services, (ii) to provide you with Services that you purchase from us, (iii) to communicate with you and fulfill requests you may make, including requests for technical support, (iv) to provide you with information and announcements with respect to our Services, (v) to provide you with further information and offers from us or carefully selected third parties that we believe you may find useful or interesting, including newsletters, marketing or promotional materials and other information on services and products offered by us or third parties, and (iv) provide other companies with statistical information about our users – but this information will not be used to identify any individual user. We may also use the information provided by you or obtained through your use of our Services to improve our Services and improve your browsing experience by personalizing the Website.

Use of Navigational Information. We use navigational Information to operate and improve the Services. We may also use navigational Information alone or in combination with Personal Information to provide you with personalized information about us and our Services. We use navigational Information we obtain by technical means (such as the automatic recording or logging performed by software tools used to deliver and enhance our Services or through the use of cookies) for the above purposes as well as to monitor, measure and analyze use of our Services, and to generate and derive useful data and information concerning the interests, characteristics and use behavior of our customers and visitors to our Website and their use of our Services.

Use of Credit Card Information. If you give us credit card information, we use it solely to check your financial qualifications and collect payment from you. We use a third-party service provider to manage credit card processing. This service provider is not permitted to store, retain, or use information you provide except for the sole purpose of credit card processing on our behalf.

How We Share Your Information

We Do Not Sell Your Personal Information. We will never sell, rent, or otherwise provide your Personal Information to any third party for marketing purposes.

Service Providers, Agents, Consultants and Third Parties. Occasionally, we enter into contracts with third parties so that they can assist us in servicing you (for example, providing or maintaining databases and cloud object storage, providing product and service functionality, customer service, billing and invoicing, fraud detection, deterrence or access to advertising assets), to assist us in our own marketing, research and advertising activities or to engage in co-marketing activities with us. Our contracts with such third parties prohibit them from using any of your Personal Information for any purpose beyond the purpose for which it was shared.

Partners. We may share your Personal Information with our partners and resellers so that they can assist you in using our Services and sell or resell our Services to you.

Compliance with Legal Process. We may be required to disclose your Personal Information and/or information with respect to your use of our Services if required by governmental or regulatory agency or by court order, subpoena or other legal process or requirement or if we reasonably believe that such disclosure is necessary (i) to investigate, prevent or take action with respect to suspected or actual illegal activities or to assist government enforcement agencies, (ii) to protect the safety of any person from death or serious bodily injury, (iii) to prevent fraud or abuse of our Services or infringement of our intellectual property rights in our Services, (iv) to enforce our terms of use or your agreements with us, or (v) to investigate and defend ourselves against any third party claims or allegations.

Business Transfers. We may share your Personal Information in connection with, or during negotiations of, any merger, sale of company assets, financing or acquisition of all or a portion of our business to another company. In this event, you will be notified via email and/or a prominent notice on our Website, of any change in ownership, uses of your Personal Information, and choices you may have regarding your Personal Information. You agree that any such third party will have the right to continue to use your Personal Information and other information that you provide to us or which we obtain through your use of the Services.

With Your Consent. With your consent, including if we notify you through our Services that the information you provide will be shared in a particular manner and you provide such information. We may also share aggregated or de-identified information, which cannot reasonably be used to identify you.

Frames. Some of our pages utilize framing techniques to serve content to/from our partners while preserving the look and feel of our website. Please be aware that you are providing your Personal Information to these third parties and not to www.chaossearch.io.

Security and Retention of Your Personal Information

ChaosSearch takes reasonable measures to help protect Personal Information from loss, theft, misuse and unauthorized access, disclosure, alteration, and destruction. We follow generally accepted standards to protect the Personal Information submitted to us, both during transmission and once it is received. We also recommend that our customers employ the multi-factor authentication feature available for use with our product. Although we use industry standard security measures, the Internet is not a 100% secure environment and we cannot, and do not, ensure or warrant the security of any information you transmit or store using the Services. There is no guarantee that your information may not be accessed, disclosed, altered, or destroyed by breach of any of our physical, technical, or managerial safeguards and we are not responsible for third party circumvention of your privacy settings or our security measures. You are responsible for maintaining the secrecy of your unique password and account information and for controlling access to your account. If you have any questions about the security of your Personal Information, you can contact us at .

We retain Personal Information that you provide us as long as we consider it potentially useful in contacting you about our company, products, or services. We retain information about our customers for as long as we need it to provide service to the customer. We will delete this information from our servers at an earlier date if you so request, as described in “Opting-Out and Unsubscribing”.

If you have submitted a valid GDPR data subject access request to exercise your right to be forgotten, we will delete your personal data within 30 days of the request.

If you are an individual based in the EU you can request a copy of your personal data and you can update any incorrect information.

If you are an individual based in the EU, you can ask to have your personal data removed, or in some cases limit our processing of personal data. This does not apply when we need to keep your personal data for legal reasons.

Your Information Choices

Account Information. Upon request ChaosSearch will provide you with information about whether we hold any of your Personal Information. You may update, correct or delete information about you at any time by emailing us at privacy@chaossearch.com. If you wish to delete or suspend your account, please email us at privacy@chaossearch.com, but note that we may retain certain information as required by law or for legitimate business purposes. Also, if you have become aware that a profile has been created about you without your consent or knowledge, you may contact us at privacy@chaossearch.com to request deletion of that said account. We may also retain cached or archived copies of your information for a certain period of time. We will respond to your request within a reasonable timeframe.

Promotional Communications. We will periodically send you free newsletters and emails that directly promote the use of our site or the purchase of our products or services. When you receive newsletters or promotional communications from us, you may indicate a preference to stop receiving further communications from us – you will have the opportunity to “opt-out” by following the unsubscribe instructions provided in the email you receive or by contacting us directly. Should you decide to opt-out of receiving future mailings, we may share your email address with third parties to ensure that you do not receive further communications from third parties. Despite your indicated email preferences, we may send you non-promotional emails about your account for Services you requested and notices of any material updates to our Terms of Service or Privacy Policy.

Testimonials. We display personal testimonials of satisfied customers on our website in addition to other endorsements. With your consent, we may post your testimonial along with your name. If you wish to update or delete your testimonial, you can contact us at privacy@chaossearch.com.

Accessing Your Information. You may access, review, revise, correct, or delete the Personal Information provided in your registration or account profile by changing your “account settings.” If you update any of your information, we may keep a copy of the information that you originally provided to us in our archives for uses documented in this Privacy Policy.

Links to Third Party Sites

Our websites provide links to other websites. We do not control, and are not responsible for, the content or practices of these other websites. Our provision of such links does not constitute our endorsement of these other websites, their content, their owners, or their practices. This Privacy Policy does not apply to these other websites, which are subject to any privacy and other policies they may have. You should use caution and review the privacy policies of any web sites, services or third party providers that you visit from our Website or our products to learn more about their information practices, which may be significantly different from ours.

If you have opted-in to receive email communications from a third party site and later wish to discontinue receipt of these emails, please contact the third party directly to update your preferences.

Children

Children are not eligible to use our Services and we ask that minors (under the age of 18) do not submit any Personal Information to us or use our Services. Our Services are not directed to children under 18 years of age. We do not knowingly collect personally identifiable information from children under 13. If a parent or guardian becomes aware that his or her child has provided us with Personal Information without their consent, he or she should contact us by email at privacy@chaossearch.com. If we become aware that a child under 13 has provided us with Personal Information, we will delete such information from our files.

Your Rights as an Individual Based in the EU

Access to your information: You have the right to request a copy of the personal data we hold about you.

Correcting your information: We want to have accurate data. Please contact us if you think the personal data you provided to us is not up to date or correct.

Deletion of your information: You have the right to ask us to delete personal data about you if it no longer is required for the purpose it was collected, you have withdrawn your consent, you have a valid objection to us using your personal data, or our use of your personal data is contrary to law or our other legal obligations.

Objecting to how we may use your information: You have the right at any time to require us to stop using your personal data for direct marketing purposes. In addition, where we use your personal data to perform tasks carried out in the public interest then, if you ask us to, we will stop using that personal data unless there are overriding legitimate grounds to continue.

Restricting how we may use your information: In some cases, you may ask us to restrict how we use your personal data. This right might apply, for example, where we are checking the accuracy of personal data about you that we hold or assessing the validity of any objection you have made to our use of your personal data. The right might also apply where this is no longer a basis for using your personal data, but you don’t want us to delete the data. Where this right to validity is exercised, we may only use the relevant personal data with your consent, for legal claims or where there are other public interest grounds to do so.

Automated processing: If we use your personal data on an automated basis to make decisions which significantly affect you, you have the right to ask that the decision be reviewed by an individual to whom you may make representations and contest the decision. This right only applies where we use your personal data with your consent or as part of a contractual relationship with you.

Withdrawing consent using your information: Where we use your personal data with your consent you may withdraw that consent at any time, and we will stop using your personal data for the purpose(s) for which consent was given.

Please contact us if you wish to exercise any of these rights. You can find the contact details below under “Opting-Out and Unsubscribing”.

Rights for Residents of the State of California

Residents of the State of California, under California Civil Code § 1798.83, have the right to request from companies conducting business in California a list of all third parties to which the company has disclosed Personal Information during the preceding year for direct marketing purposes. Alternatively, the law provides that if the company has a privacy policy that gives either an opt-out or opt-in choice for use of your Personal Information by third parties (such as advertisers) for marketing purposes, the company may instead provide you with information on how to exercise your disclosure choice options.

ChaosSearch qualifies for the alternative option. We have a comprehensive privacy statement and provide you with details on how you may either opt-out or opt-in to the use of your Personal Information by third parties for direct marketing purposes. Therefore, we are not required to maintain or disclose a list of the third parties that received your Personal Information for marketing purposes during the preceding year.

If you are a California resident and wish to request information about how to exercise your third party disclosure choices, please contact us. You can find the contact details below under “Opting-Out and Unsubscribing”.

Rights for Residents of the Commonwealth of Massachusetts

Massachusetts law permits residents of Massachusetts to request certain details about how their information is shared with third parties for direct marketing purposes. However, under the law, a business is not required to provide this information if it permits Massachusetts residents to opt into, or opt out of, this type of sharing. ChaosSearch qualifies for this alternative option. If you are a Massachusetts resident and would like to opt out of having your information shared with third parties for direct marketing purposes, please contact us. You can find the contact details below under “Opting-Out and Unsubscribing”.

Opting-Out and Unsubscribing

Reviewing, Correcting and Removing Your Personal Information. If you provide us with your Personal Information, you have the following rights with respect to that information:

  • To review the user information that you have supplied to us
  • To request that we correct any errors, outdated information, or omissions in user information that you have supplied to us
  • To request that your user information not be used to contact you
  • To request that your user information be removed from any solicitation list that we use
  • To request that your user information be deleted from our records
  • To otherwise opt out of receiving solicitations

To exercise any of these rights, please contact us by email at privacy@chaossearch.com or by sending us postal mail to:

ChaosSearch, Inc.,

226 Causeway St., Ste 301

Boston, MA 02114

Attn: Privacy

We will promptly change, correct, or delete your information.

To Unsubscribe From Our Communications. You may unsubscribe from our marketing communications by clicking on the “unsubscribe” link located on the bottom of our emails, or by contacting us by email at privacy@chaossearch.com or by sending us postal mail to:

ChaosSearch, Inc.,

226 Causeway St., Ste 301

Boston, MA 02114

Attn: Privacy

How You Can Opt Out of Web Tracking. There are several ways to opt out of web tracking:

  • Most browsers allow you to block third-party cookies or prevent cross-domain tracking. This will limit the cookies that can be set by third-party scripts. This will not completely eliminate tracking by some third-party services though as they may use first-party cookies. Most browsers also allow you to ask not to be tracked (it sends the “Do Not Track” request header). If you have enabled this feature, we will not track the pages you visit in a way that enables us to connect them to your Personal Information. Your page views may still be collected anonymously though. Many of the third-party services we use for collecting anonymous data also respect the Do Not Track setting.
  • To opt-out of interest-based advertising by participating companies in the following consumer choice mechanisms, please visit:
    • Digital Advertising Alliance (DAA)’s self-regulatory opt-out page (http://optout.aboutads.info/) and mobile application-based "AppChoices" download page (https://youradchoices.com/appchoices)
    • European Interactive Digital Advertising Alliance (EDAA)'s consumer opt-out page (http://youronlinechoices.eu)
    • Network Advertising Initiative (NAI)’s self-regulatory opt-out page (http://optout.networkadvertising.org/)

Contact us

If you have any questions about this Privacy Policy, please contact us using the information below:

ChaosSearch, Inc.

226 Causeway Street, Suite 301

Boston, MA 02114

Attn: Privacy

privacy@chaossearch.com