# Morphisec Privacy Policy _Last updated: March 2025_ Morphisec Information Security 2014 Ltd. respects your privacy and explains its data collection, use, and your rights in this policy, which applies to the website https://www.morphisec.com and your interactions with Morphisec. This policy does not apply to Morphisec customers whose data processing is governed by a data processing addendum, or to employees and end-users of Morphisec customers, whose data Morphisec processes as a processor on the customer's behalf. ## Data Collection Morphisec collects personal information you provide directly and obtains information from third parties. You are not legally required to provide data to Morphisec, but failure to provide requested information may prevent you from accessing certain services or functions. **Information you provide directly:** - **Support portal access:** Email and password to log into the support portal. - **Partnership, trial, demo, or meeting requests:** Name, company name, job title, business email, phone number, country, and message text. - **Newsletters and offers:** Email address to receive product updates and promotional communications. - **Job applications:** Name, email, phone number, and resume (mandatory); LinkedIn URL, personal website, cover letter, or other notes (optional). Morphisec retains applications for up to 12 months to consider you for other suitable positions unless you opt out by contacting hrteam@morphisec.com. - **Contract and business data:** Information related to contract conclusion and performance, including services to be provided, feedback, and satisfaction data. - **Inquiries:** Name, email, phone number, company, department, inquiry topic, and message text when you contact Morphisec via contact form, email, telephone, chat, letter, or other communication methods. **Behavioral and preference data:** Morphisec evaluates information about your behavior in its domain and may supplement this with third-party data, including from public sources, to determine your likelihood of using certain services or behaving in a certain way. You may object to this collection or withhold consent without affecting your ability to use core services, though you may receive less personalized recommendations. **Information from third parties:** Morphisec obtains information from Google, LinkedIn, TechTarget, HubSpot, Salesforce, and Salesloft for analytics, advertising, and retargeting purposes. When you connect social networks (Facebook, etc.) to the Website, Morphisec may collect your name, email, profile information, user ID, photo, and other data you permit the social network to share, subject to your privacy settings. You should review and adjust your social network privacy settings before connecting them to the Website. **Analytics and technical information:** Morphisec collects IP address, general location, time and date of access, browser type, language, links clicked, web pages accessed, content viewed, features used, actions taken, and frequency and duration of activities. This includes when you last used the Website and what content you view. ## Data Use Morphisec processes your data for the following reasons: **Service delivery:** To conclude, administer, and perform contracts; deliver services and solutions; process account information; accept and fulfill subscriptions; charge fees; communicate subscription status; provide security and access control; and deliver your requested solution. **Product recommendations:** Morphisec processes information you provide, automatically collects about your preferences, or obtains from third parties such as Facebook or LinkedIn to identify your preferences, personalize your experience, and recommend additional Morphisec products and solutions. **Newsletter and marketing communications:** If you sign up for the newsletter, Morphisec processes your email to send periodic marketing communications. Morphisec also processes data for relationship management and personalized advertising for Morphisec and third-party products and services through newsletters, regular contacts (electronic, email, or telephone), and marketing campaigns (events, contests, etc.). You can object to contacts or withdraw consent at any time by emailing marketing@morphisec.com. **Reporting and business planning:** Morphisec processes your information for accounting, financial record-keeping, website and content adaptation to user preferences, market demand understanding, reporting, and business planning. **Inquiry response:** Morphisec processes inquiry information to handle, respond to, and contact you. Subject to your explicit consent, Morphisec may use inquiry information for profiled marketing purposes to contact you occasionally with information about its products and services. You may opt out by emailing marketing@morphisec.com. **Job assessment:** Morphisec's primary purpose for processing your resume and job application is to assess your suitability for the specific role you applied for and to improve its recruitment process. Unless you opt out by contacting hrteam@morphisec.com, Morphisec may retain your materials for up to 12 months for consideration for other positions. If you opt out, your application will be considered only for the specific position and retained only for that recruitment process. **Website analytics:** Morphisec uses analytics information to improve the Website, content, email communications, and customer solutions; adapt the website and content to user preferences; understand its operating market; and support reporting and business planning. ## Data Sharing Morphisec shares personal information with: **Service providers:** HubSpot, Salesforce, SalesLoft, TechTarget, and Comeet assist with mailing, database maintenance, hosting, recruitment, and internal operations. These companies are authorized to use your information only to provide their specific services to Morphisec and not for their own purposes. Morphisec has data processing agreements in place requiring compliance with applicable data protection laws and adherence to its security measures. **Legal and regulatory authorities:** Morphisec shares information if you violated an agreement, abused the Website, violated applicable law, or if legally required by judicial, governmental, or regulatory authority. Information is shared with competent authorities and third parties such as legal counsels and advisors. **Business restructuring:** Morphisec shares data to enable structural change if it reorganizes, merges, consolidates, or operates in any different framework or legal structure or entity, such as due to merger or acquisition. **Emergency situations:** Morphisec shares data if it needs to act immediately to protect the personal safety of its customers or the public. ## Data Storage and Transfer Morphisec transfers data internationally in accordance with applicable data protection laws. When transferring data from Europe to jurisdictions outside Europe, Morphisec relies on European Commission adequacy decisions (for example, when accessing data from Israel) or Standard Contractual Clauses issued by the European Commission. ## Automatic Data Collection Tools **Cookies:** Morphisec uses session cookies (read during your visit, expiring when you close your browser) and persistent cookies (remaining on your computer until expiration or deletion). Morphisec also uses web beacons and web pixels for purposes similar to cookies. Subject to your consent, third-party advertising companies may use cookies to optimize advertisements and serve ads specific to your interests on other websites using retargeting and behavioral advertising technologies. **Cookie management:** Morphisec uses the Cookie Consent add-on Consent Management Platform to provide detailed information about cookies (origin, purpose, expiration date) and enable you to control marketing, personalization, and analytics cookies. You cannot disable necessary cookies, which the website requires to operate. By enabling cookies, you consent to data collection for the cookie's purpose. **Cookie types:** - **Essential cookies** (up to 12 months): Necessary for Website functionality, enabling page navigation without losing form data and maintaining login status. Some Website parts may not function properly without these cookies. You can block or receive alerts via browser configuration. - **Personalization cookies** (up to 24 months): Remember your choices and allow the Website to reflect your preferences. Morphisec requests your consent before use. You can withdraw consent anytime through cookie settings. - **Analytics cookies** (up to 12 months): Help Morphisec understand how you and others interact with the Website by collecting non-directly-identifying data. Morphisec requests your consent before use. You can withdraw consent anytime through cookie settings. - **Marketing cookies** (days to 24 months): Allow Morphisec and advertising partners to record accessed content or concluded contracts to display advertisements Morphisec thinks will interest you on the Website and other websites displaying Morphisec's or its partners' ads. These are subject to your consent. Morphisec may integrate additional third-party offers, particularly from social media providers, which are deactivated by default. Activating them allows the provider to determine you are using the Website. If you have an account with the social media provider, it can assign this information to you and track your online usage. These providers process data as separate controllers. Morphisec is not responsible for the privacy practices of third-party platforms linked on the Website, such as Facebook, Instagram, WhatsApp, Twitter, and YouTube. You should read each platform's privacy statements. ## Data Security Morphisec implements technical and organizational safeguards to reduce risks of damage, information loss, and unauthorized access or use. These measures do not guarantee absolute information security. Although Morphisec takes reasonable precautions and makes appropriate efforts to secure information, the Website and its systems may not be immune to information security risks. ## Data Retention Morphisec retains your data for the duration of your business relationship and as long as necessary for business administration, record-keeping, dispute resolution, legal claim establishment and defense, and agreement enforcement. When data is no longer needed, Morphisec deletes it from its systems and records or anonymizes it. ## Your Privacy Rights and Choices Morphisec provides the ability to: - **Access** data Morphisec processes and have about you and receive a copy. - **Rectify** incorrect, inaccurate, or incomplete personal data. **EU residents have the following additional rights:** - **Object** to data processing for marketing purposes or Morphisec's other legitimate interests. Morphisec may override your objection if it demonstrates compelling legitimate grounds or for the establishment, exercise, or defense of legal claims. You can also object to direct marketing by opting out of newsletters or marketing emails at any time. - **Restrict** data processing to verify accuracy or during Morphisec's review of your objection. You can also restrict processing if you consider it unlawful or need the data for legal claim establishment, exercise, or defense. - **Withdraw consent** to processing at any time. This does not affect the lawfulness of processing carried out based on your consent before withdrawal. Morphisec will still process certain information on a legal basis other than consent. - **Erase** your data when no longer needed (for example, when withdrawing consent to newsletters). Morphisec may still process your data if legally required, subject to law, or for legal claim establishment, exercise, or defense. - **Data Portability:** Receive your personal data in a structured, commonly used, and machine-readable format and send it to other businesses. Where technically feasible, you have the right to have your data transmitted directly from Morphisec to another business you designate. **California residents have the following additional rights:** In addition to the rights described above, you have the right to opt out of the sale of your personal information to third parties, limit the use and disclosure of your sensitive personal information, and opt out of sharing your personal information for cross-context behavioral advertising. You may designate an authorized agent to make requests on your behalf. Morphisec may ask for reasonable evidence to confirm your identity before providing requested data. If Morphisec cannot provide data you requested, it will explain the reason. ## Additional Information for EU Users **Data controller:** Morphisec is the data controller for personal data collected through its Website. Morphisec's registered address is 77, Haenergia St., Gav Yam Park Bldg. 1, Beer-Sheva, Israel 8470912. Contact Morphisec at Legal@morphisec.com. **Legal bases for processing:** - Contract performance: Collection and processing of account data for subscription fulfillment and billing. - Explicit consent: Collection and processing of email address for marketing emails. - Legitimate interest: Processing inquiry information to respond to questions or requests; processing preference information to offer suitable solutions; processing Website analytics to manage the Website and business development; collecting and processing information from third parties for marketing to offer suitable solutions; sharing data with service providers for business functions; sharing data if you breach terms to protect Morphisec from abuse; sharing data to enable business structural change for continuity. - Legal obligation: Disclosing data to judicial, governmental, or regulatory authority. - Vital interests: Sharing data in emergencies to protect your or another person's vital interests. - Steps before contract: Processing job application data to take steps at your request before entering a contract. **Supervisory authority:** You have the right to complain to your local data protection authority. If in the EU, you can complain to the supervisory authority in your state of residence, place of work, or place of alleged GDPR infringement. Names and contact information of competent supervisory authorities in the European Union are at https://edpb.europa.eu/about-edpb/about-edpb/members_en. **European representative:** Morphisec's European representative pursuant to Article 27 of the GDPR is European Data Protection Office (EDPO). If within the European Economic Area, you may contact EDPO via online request form at https://edpo.com/gdpr-data-request/ or by writing to EDPO at Avenue Huart Hamoir 71, 1030 Brussels, Belgium. ## Children Morphisec's Website is intended for users 18 years of age and older. Morphisec is a business-to-business company with products and solutions directed to and intended for use only by those 18 years of age or over. Morphisec does not knowingly collect personal information of children under 16 through its Website. If you are under 18, you should not use the Website. ## Policy Changes If Morphisec modifies this Privacy Policy, it will publish a revised version with an updated revision date on its Website. If you continue using the Website after changes are in effect, you agree to the new policy. If changes are significant, Morphisec may provide a more prominent notice or obtain consent as required by law. ## Contact If you have questions, complaints, or suggestions, you may contact Morphisec at Legal@morphisec.com. Morphisec will do its best to resolve your issue promptly. --- **Related legal documents:** [Terms of Use](https://www.morphisec.com/terms-of-use/) | [Cookie Policy](https://www.morphisec.com/cookie-policy/)