ExtraHop Privacy Notice

This Privacy Notice explains how ExtraHop Networks, Inc. and its affiliates (collectively, "ExtraHop", "we", or "us") collect, use, disclose and otherwise process Personal Information that identifies or could be identifiable to you, and the choices we offer, including how to access, update, or delete your information. Personal Information means information that identifies, relates to, describes, is reasonably capable of being associated with, or could reasonably be linked, directly or indirectly, with you.

This Notice Applies to:

Personal Information that may be collected when you visit, interact with or use any of our websites, social media pages, marketing or sales communications, evaluation or purchase of our products and services, implementation and use of our products and services, online or offline interactions, and other means offered and controlled by us. We may also collect information about you from other sources such as public databases, joint marketing partners, social media platforms, conference/event hosts, and partners when you interact with them.

This Notice Does Not Apply to:

The content that our customers and their end users upload, capture, or store in connection with our products and services. In those circumstances: (i) ExtraHop is processing such content on behalf of a customer and that customer is responsible for the collection and use of your data; (ii) the customer’s privacy notice will apply to the customer’s collection and use of such content; and (iii) you should refer to their privacy notice and direct any queries regarding your information to them.

Information Collected

ExtraHop collects Personal Information from you directly, through automated means, and from third parties, as each source is described more fully below.

From You

We collect Personal Information when you voluntarily provide it to us (including to our service providers, partners, or other parties who collect it on our behalf). For example, we collect Personal Information when you evaluate, order, purchase, use, or request information about ExtraHop products and services, request or subscribe to marketing communications, complete surveys, provide such data in product feedback, or sign up for an ExtraHop event or webinar. We may also collect Personal Information from you when you attend one of our events, during phone calls with sales representatives, or when you contact customer support.

The Personal Information we collect from you may include:

  • Identifiers or contact information (such as your name, address, telephone number, or email address);
  • Professional information (such as your employer’s name, address, job title, department or job role);
  • Commercial information regarding which ExtraHop products or materials in which you express interest
  • User IDs and passwords such as those to access your ExtraHop account;
  • Your contact preferences;
  • Information you choose to provide when completing any "open text" boxes in our forms (for example, for event sign-up, product feedback, or survey requests;
  • Information disclosed by you on message boards, chat features, blogs, and other services or platforms to which you can post information and materials (including third party services and platforms); and
  • Billing and transactional information.

Automatically

We use technology that is integrated into our online assets such as cookies, web beacons, and embedded URLs to provide us with automated data collection when you use, access, or interact with our online assets. This information may include:

  • Computer or device information, such as computer type, screen resolution, operating system name and version, device manufacturer and model, language, Internet browser type and version, and the name and version of the website, product, and/or service you are using;
  • Information collected by tracking technologies, including cookies, web beacons, and other tracking technologies that collect information about you when you interact with our sites or emails, such as your browsing and engagement behavior; and
  • IP address, which is a number automatically assigned to your computer or device, and information derived from your IP address such as geographic location;

We automatically collect certain data relating to the performance and configuration of our products and services and our customers’ and end users’ consumption, use of, and interaction with the products and services. Such information may include:

  • Technical information, or data obtained from APIs, software or systems hosting the products and services and devices accessing these products and services, log files generated during such use;
  • License usage data, including account entitlements, license consumption, capacity, or type in our systems through an assigned license ID;
  • Usage data, including information about operating environments, performance metrics, error counts, string data, and user/product interactions; and
  • Data and metadata about an end user, such as user ID, email, IP address, other data about the user’s computer or other device, browser and connecting software (e.g., OS and software versions).

Third Parties

We may also acquire data from other sources including affiliates, our partners, or others that we use to make our information better or more useful. For example, we may compare the geographic information acquired from commercial sources with the IP address collected by our automatic data collection tools to derive your general geographic area. Information may also be linked via a unique identifier, such as a cookie or account number. This information may include any of the information we collect from you directly or that is collected automatically via our online assets.

Use of Information

We may use information we collect about you, including any Personal Information, to:

  • operate, audit and improve our websites, products and services;
  • provide customer service and support;
  • provide and to facilitate the delivery of products and services you request;
  • send you related information, including confirmations, invoices, technical notices, updates, security alerts, training and support and administrative messages;
  • maintain your account;
  • enhance security, monitor and verify identity or service access, combat fraud, spam, malware or other network and/or information security risks;
  • detect bugs, report errors and perform activities to maintain the quality or safety of our websites and services;
  • conduct research and development;
  • understand you and your preferences to enhance and personalize your experience and enjoyment when using our sites, products and services;
  • develop and send you marketing, sales and promotional communications (where this is in accordance with your marketing preferences);
  • communicate with you about one of our events or our partner events, including webinars, conferences and demos;
  • facilitate the delivery of ExtraHop certification courses or training in which you may enroll;
  • respond to your comments or questions or provide information requested by you;
  • link or combine it with other personal information we get from third parties, to help understand your needs, provide you with better service and to prevent fraud;
  • process and deliver contest entries and rewards;
  • display and measure engagement with advertisements across different devices and sites;
  • maintain legal and regulatory compliance, exercise our legal rights, and administer and perform under our contracts;
  • short-term, temporary use, such as customizing content that we or our service providers display on websites or services; and
  • process your information for other legitimate business purposes, such as customer surveys, data analysis, audits, collecting and assessing feedback, identifying usage trends, determining the effectiveness of our marketing campaigns and to evaluate and improve our websites, products, services, marketing and customer relationships.

We may store or process Personal Information in the United States and other countries.

Disclosure of Information

If we disclose your information, we require the recipients (as appropriate) to comply with security standards, and privacy and confidentiality requirements. We may disclose information we collect about you in the following ways, and remain responsible for such onward transfers to third parties.

  • We may disclose your information to our affiliates subject to these obligations. We may transfer your Personal Information to other ExtraHop entities in the US and worldwide for the purposes outlined in this Privacy Statement. We protect your Personal Information per this Statement wherever it is processed and take appropriate contractual or other steps to protect it under applicable laws.
  • We may disclose your information to our service providers, contractors, vendors, subprocessors, and other third parties we use to support our business. We may disclose your information to third parties, such as vendors, consultants, agents and other service providers who provide services such as IT and system administration and hosting, research and analytics, marketing, targeted advertising, training and certifications, customer support, and data enrichment for the purposes and according to the legal bases described below. Our service providers are required by contract to safeguard any Personal Information they receive from us and are prohibited from using the Personal Information for any purpose other than to perform the services as instructed by ExtraHop. These service providers may be located in the US or other global locations.
  • We may disclose your information to our partners, such as distributors and resellers, and to other business partners, to fulfil product and information requests, to effectively deliver unified support, to provide customers and prospective customers with information about ExtraHop, and for event purposes. From time to time, ExtraHop may engage in joint sales, product promotions, or events with selected business partners. If you purchase or express interest in a jointly-offered product, promotion, service, or event, we may share relevant Personal Information with those partners. Such partners are responsible for managing their use of the Personal Information collected in these circumstances, including providing information to you about how they use your personal information. We recommend you review the privacy notices of the relevant partner to find out more about their handling of your personal information.
  • In the preceding 12 months, we have disclosed the above categories of personal information to third-party advertising partners, such as in connection with our use of tracking technologies for cross-context behavioral advertising or by providing lists of email addresses for potential customers, so that we can reach you across the web with advertisements for our products and services.
  • We may disclose your Personal Information when we believe, in good faith, that we must: (i) respond to duly authorized information requests of law enforcement agencies, regulators, courts, and other public authorities, including to meet national security or other law enforcement requirements; (ii) comply with any law, regulation, subpoena, or court order; (iii) investigate and help prevent security threats, fraud or other criminal or malicious activity; (iv) enforce/protect the rights and properties of ExtraHop or our affiliates; or (v) protect the rights or personal safety of ExtraHop's and our affiliates' employees, and third parties on or using ExtraHop property when allowed and in line with the requirements of applicable law.
  • We may disclose your information where, whether for strategic or other business reasons, ExtraHop decides to sell, buy, merge, reorganize, or otherwise convey of some or all of our assets; In such transactions, we may disclose or transfer your Personal Information to prospective or actual purchasers or receive your Personal Information from sellers. Our practice is to seek appropriate protection for your Personal Information in these types of transactions.
  • We may disclose your information upon your consent.

If you use our community/customer forums, you should be aware that any information, including Personal Information, you submit there can be read, collected, or used by other users of such forums. We are not responsible for other party’s use of any information you choose to submit in a forum.

Other than your ExtraHop account access credentials, we do not collect and you are discouraged from disclosing to us any Sensitive Personal Information. In the event Sensitive Personal Information is disclosed to us, we will not disclose such information to a non-agent third party or use such information for a purpose other than the purpose for which it was originally collected unless we have received your consent. We do not collect or process Sensitive Personal Information for the purpose of inferring characteristics about consumers.

Cookies

A cookie is a small data file sent to your browser from a web server and stored on your hard drive. We use cookies to collect certain information about our website visitors, such as remembering preferences, facilitating navigation, displaying information more effectively, understanding usage patterns, collecting statistics regarding website usage, and providing us with other business and marketing information. We may also combine this information with other information we collect about you for various purposes, such as improving our websites, understanding campaign effectiveness, tailoring communications, and for other internal business purposes. If you do not want us to collect cookies on the ExtraHop website, you may set your browser to refuse cookies or to alert you when cookies are being sent; you may also indicate that by using our cookie management platform accessible through our cookie banner. If you do so, please note that some parts of our website may become unavailable or may not function properly.

A web beacon, also known as an Internet tag, is a small graphic image that may be included on our websites or emails. We may use web beacons or similar technologies for certain business purposes, such as tracking the number of visitors to our websites, monitoring how users navigate our websites, and counting how many emails were opened or articles or links were viewed.

We may work with online ad networks to place cookies on your computer and use similar technologies to understand your interests based on your online activities and tailor more relevant ads to you. If you do not wish to receive such tailored advertising, you can visit this page to opt out of most companies that engage in such advertising. Opting-out will not prevent you from seeing ads; the ads will not be delivered through these targeting methods. We also use cookies through Google Analytics or other similar services to compile reports and improve our site. The Google Analytics cookies do not identify you, but instead collect information in an anonymous form that will be transmitted to and stored by Google in accordance with its privacy practices. You can read more about Google Analytics' privacy practices here and control Google Ads here.

We only use your Personal Information in a lawful, transparent, and fair manner. Depending on the specific Personal Information concerned and the factual context, we rely on the following legal bases:

  • As necessary to prepare and enter into a contract;
  • Consistent with specific revocable consents;
  • As necessary to comply with our legal obligations;
  • To protect your vital interests or those of others; and
  • As necessary for our (or others') legitimate interests, unless those interests are overridden by your interests or fundamental rights and freedoms.

Information Security

ExtraHop implements reasonable physical, administrative, and technical safeguards designed to protect your Personal Information from loss, misuse, unauthorized access or disclosure, alteration, and destruction. We also contractually require our service providers and other third parties we use to support the business to protect such information from loss, misuse, unauthorized access or disclosure, alteration, and destruction. The safety and security of your information also depends on you. Where we have given you (or where you have chosen) a password for access to certain parts of our products and services, you are responsible for keeping this password confidential.

Retention of Information

We will retain and use your Personal Information as necessary to fulfill the purposes for which it was collected, comply with our business requirements and legal obligations, resolve disputes, protect our assets, and enforce our agreements. We will also take reasonable steps to delete your information if you request deletion of your information.

Cross Border Data Flows

ExtraHop is a global organization and the information we collect from you, including Personal Information, may be transferred to and stored in a country other than the country in which the information was collected (including, but not limited to, servers and data centers located in the United States). To facilitate data transfers, we utilize recognized data transfer frameworks such as Standard Contractual Clauses and the EU-U.S. Data Privacy Framework (EU-U.S. DPF), the UK Extension to the EU-U.S. DPF, and the Swiss-U.S. Data Privacy Framework (Swiss-U.S. DPF) as set forth by the U.S. Department of Commerce.  ExtraHop has certified to the U.S. Department of Commerce that it adheres to the EU-U.S. Data Privacy Framework Principles (EU-U.S. DPF Principles) with regard to the processing of personal data received from the European Union in reliance on the EU-U.S. DPF and from the United Kingdom (and Gibraltar) in reliance on the UK Extension to the EU-U.S. DPF.  ExtraHop has certified to the U.S. Department of Commerce that it adheres to the Swiss-U.S. Data Privacy Framework Principles (Swiss-U.S. DPF Principles) with regard to the processing of personal data received from Switzerland in reliance on the Swiss-U.S. DPF.  If there is any conflict between the terms in this privacy policy and the EU-U.S. DPF Principles and/or the Swiss-U.S. DPF Principles, the Principles shall govern.  To learn more about the Data Privacy Framework (DPF) program, and to view our certification, please visit https://www.dataprivacyframework.gov/.

In certain situations, we may be required to disclose Personal Information in response to lawful requests by public or government authorities, including to meet national security or law enforcement requirements. We will work with the appropriate regulatory authorities, including local data protection authorities, to resolve any complaints regarding the transfer of your data that we cannot resolve with you directly. With respect to Personal Information received from the European Union, United Kingdom, and Switzerland, ExtraHop is subject to the regulatory enforcement powers of the U.S. Federal Trade Commission.

Enforcement and Dispute Resolution

In compliance with the Data Privacy Framework Principles, ExtraHop commits to resolve complaints about our collection or use of your Personal Information. Individuals from the European Union, United Kingdom, or Switzerland with inquiries or complaints regarding our Privacy Notice should first contact us using the methods described in the Contact section below. We will respond to complaints regarding the collection or use of your Personal Information within forty-five (45) days.

ExtraHop has further committed to refer unresolved Data Privacy Framework complaints to JAMS, an alternate dispute resolution service located in the United States. If you do not receive timely acknowledgment of your DPF Principles-related complaint from us, or if we have not addressed your DPF Principles-related complaint to your satisfaction, please visit https://www.jamsadr.com/DPF-Dispute-Resolution for more information or to file a complaint. The services of JAMS are provided at no cost to you. If neither ExtraHop nor JAMS is able to resolve your inquiry, you have the right to invoke binding arbitration.

Our websites, products and services may link to third-party content. This Privacy Notice does not address, and we are not responsible for, the practices of any third parties. The inclusion of a link within our websites, products and services does not imply endorsement of the linked site or service by our affiliates or us. We encourage you to review the privacy policies and learn about the privacy practices of those companies whose websites you choose to visit.

Information from Children

ExtraHop does not direct its websites, products or services to children under the age of 16 and does not knowingly collect Personal Information from children under the age of 16 without appropriate parental or guardian consent. If you believe we may have collected Personal Information from someone under the applicable age of consent in your country without proper consent, please let us know using the methods described in the Contact section below, and we will take appropriate measures to investigate and address the issue.



Your Privacy Rights

You may contact us at any time to opt-out of: (a) direct marketing communications; (b) automated decision-making and/or profiling; or (c) any new processing of your Personal Information that we may carry out beyond the original purpose. If you choose not to provide certain information depending on the nature of your relationship with us, you may be unable to engage in certain activities or use certain websites, features, products, or services. Completing the “unsubscribe” option in a marketing email from ExtraHop is a form of opt-out and will prevent you from receiving future marketing emails directly from ExtraHop. Opt-out processes may take some time to complete, but we will work to meet your request as quickly as possible. In certain circumstances, you may still continue to receive administrative messages or other required communications that are part of certain products and services unless you stop using or cancel the product or service in accordance with its terms.

Depending on the applicable privacy laws, you may have certain rights relating to your Personal Information. These rights may include:

  • You may request a copy of your personal information or request to correct, update, or delete your personal information.
  • You may request that we disclose what personal information we collect, including the categories of personal information, the categories of sources from which the personal information is collected, the business or commercial purpose for collecting, selling, or sharing personal information, and the categories of third parties to whom we disclose personal information.
  • Where required by law, you can object to processing of your personal information, ask us to restrict processing of your personal information, or request portability of your personal information.
  • If we collected and processed your personal information with your consent, where required by law, you can withdraw your consent at any time. Withdrawing your consent will not affect the lawfulness of any processing we conducted prior to your withdrawal, nor will it affect processing of your personal information conducted in reliance on lawful processing grounds other than consent.
  • Where applicable, if you wish to submit a complaint to a data protection authority about our collection and use of your personal information, you can find contact details for data protection authorities in the EEA available here, in the United Kingdom here, and in Switzerland here.
  • Californians also have the right to opt out of the sale of personal information or the sharing of personal information for cross-context behavioral advertising, as well as the right to limit the use or disclosure of sensitive personal information for purposes other than those permitted by the CCPA if sensitive personal information is collected. As described above, we do not collect, use or disclose sensitive personal information but for the limited purpose of administering access to your ExtraHop account or as otherwise permitted by the CCPA. You may opt-out of the sharing of Personal Information via Cookies as described in the Cookies section above.

To exercise your rights under applicable data protection laws, you can contact us using the methods described in the Contact section below. When contacting us, please specify what Personal Information the request is concerning and which of the above rights you would like to exercise. ExtraHop will verify that the information you submit (which may include your first name, last name, email address, company, and country/state) matches our records before we fulfill the request. You may use an authorized agent to submit a consumer rights request on your behalf, however, ExtraHop will require the authorized agent to provide signed permission to submit the request on your behalf and may still contact you to confirm your identity and that this request was submitted with your permission. We will use commercially reasonable efforts to comply with your request. In certain circumstances, we may not be able to fulfill your request if we believe such request would violate any law or legal requirement or cause the information to be incorrect. Additionally, we may need to retain certain information for recordkeeping purposes, legal purposes and/or to complete any transactions that you began prior to your request.

ExtraHop will not discriminate against you if you exercise any of your rights under applicable privacy laws.

If we obtained your Personal Information from an ExtraHop Customer or third party acting on your behalf, you should directly contact such ExtraHop Customer or third party to whom you provided your information. We are not responsible for and have no control over the privacy and data security practices of ExtraHop Customers or other third parties, which may differ from those set forth in this Privacy Notice.

Contact

If you have any questions or concerns regarding this Privacy Policy, please contact us by email at privacy@extrahop.com
by phone at 1-877-333-9872
or write to the following address:

Attention: Legal Department
ExtraHop Networks, Inc.
520 Pike Street
Suite 1600
Seattle, WA 98101
United States

Difficulty Accessing Our Privacy Policy

Individuals with disabilities who are unable to usefully access our Privacy Notice online may contact us to inquire how they can obtain a copy of our policy in another, more easily readable format.

Privacy Policy Changes

We may modify this Privacy Notice at any time and will post any changes we make to the Privacy Notice on this page. You can determine when this Privacy Notice was last revised by referring to the last updated date at the bottom of this page under the Effective Date section.

Effective Date

This Privacy Notice was last updated on January 4, 2024.