Privacy Policy
Last updated: December 9, 2025
VxLabs Security ("we", "us", or "our") is committed to protecting your privacy and handling your personal data in a transparent and secure way.
This Privacy Policy explains how we collect, use, share, and protect personal data when:
- you visit our website (e.g. https://vxlabs.ai and related pages),
- you contact us (e.g. via contact forms, email, events),
- you use or evaluate our products and services (including ThreatZ and related platforms),
- you interact with us as a business customer, supplier, or partner.
1. Data Controller
The data controller for the purposes of the EU General Data Protection Regulation (GDPR) is:
8 The Green, Suite B, Dover, DE 19901, USA
Email (privacy): privacy@threatz.io
EU Representative (Art. 27 GDPR):
VxLabs Security, Franz-Mayer-Str. 1, 93053 Regensburg, Germany
A Data Protection Officer (DPO) appointment is not required under Art. 37 GDPR for our current processing activities. For all privacy inquiries, contact privacy@threatz.io.
2. Categories of Personal Data We Process
We only process personal data that is relevant and necessary for the purposes described below.
2.1 Website Visitors
When you visit our website, we may process:
- Technical data: IP address, date and time of access, browser type and version, operating system, referrer URL, pages visited.
- Usage data: interactions with our website, navigation paths, time spent on pages.
- Cookies and similar technologies: as described in our Cookie Notice (if applicable).
2.2 Contact and Sales Enquiries
When you reach out to us (e.g. via web form, email, phone, LinkedIn, events), we may process:
- Name, job title, role and company name.
- Business contact details (email address, phone number, office address).
- Content of your message, meeting notes, and related correspondence.
- Information about your company's interest in our products and services.
2.3 Customers and Trial Users
When your organisation becomes a customer or starts a trial, we may process:
- Account details (user name, business email, role).
- Contract and billing information (company legal details, PO numbers, invoicing contacts).
- Product usage and configuration metadata (e.g. which modules are used, project names, timestamps).
- Support tickets, change requests, and feedback.
2.4 Job Applicants
If you apply for a position at VxLabs Security, we may process:
- Identification data (name, contact details).
- CV/resume, cover letter, references and other documents you provide.
- Interview notes and assessment results.
3. Purposes and Legal Bases for Processing
We process personal data only where permitted by the GDPR. The main legal bases are:
- Art. 6(1)(b) GDPR - Performance of a contract: To evaluate, enter into and perform contracts with you or your organisation (including pre-contractual steps).
- Art. 6(1)(f) GDPR - Legitimate interests: To operate, secure and improve our website, products and services; to communicate with you in a B2B context; to prevent misuse and fraud.
- Art. 6(1)(a) GDPR - Consent: Where required for optional features (e.g. certain cookies, marketing communications), we rely on your consent.
- Art. 6(1)(c) GDPR - Legal obligations: To comply with legal requirements (e.g. tax, accounting, regulatory retention obligations).
3.1 Examples
- Provide, operate and maintain our website and cloud services.
- Respond to enquiries and provide customer support.
- Set up and manage customer and trial accounts.
- Conduct product analytics and improve functionality (where allowed).
- Protect our systems against misuse, attacks, and security incidents.
- Manage contracts, invoicing and accounting.
- Organise and evaluate recruitment processes.
4. Cookies and Analytics
We may use cookies and similar technologies to:
- enable core website functionality,
- remember your preferences,
- generate anonymous usage statistics,
- improve our content and user experience.
Where required by law, we will ask for your consent before setting non-essential cookies or analytics tools. You can manage or withdraw your consent at any time via your browser settings or our cookie banner (if present).
5. Recipients and Data Sharing
We may share personal data with:
- Service providers / processors (e.g. hosting providers, CRM systems, communication tools, analytics providers, security providers) that process data on our behalf under a Data Processing Agreement.
- Group companies and affiliates where necessary for internal administration, support and service provision.
- Business partners where required for joint projects or integration work and only with appropriate safeguards.
- Public authorities and legal advisors where necessary to comply with legal obligations or to establish, exercise or defend legal claims.
We do not sell personal data.
6. International Data Transfers
Some of our service providers may be located outside the EU/EEA. In such cases, we ensure an appropriate level of data protection by:
- adequacy decisions by the European Commission; or
- standard contractual clauses (SCCs); and
- additional technical and organisational measures as required.
7. Data Retention
We retain personal data only for as long as necessary for the purposes stated in this Privacy Policy, unless longer retention is required by law.
Typical retention periods:
- Contact and enquiry data: as long as needed to process the enquiry and maintain the relationship, plus a reasonable period for documentation.
- Contract and billing data: retained for the statutory retention period (e.g. up to 10 years under German law).
- Product telemetry and logs: retained for the time necessary for security, troubleshooting and analysis.
- Recruitment data: usually up to 6 months after the decision, unless you consent to longer retention.
8. Security
We implement appropriate technical and organisational measures to protect personal data against accidental or unlawful destruction, loss, alteration, unauthorised disclosure or access.
These measures include:
- access control and role-based permissions,
- secure development and deployment practices,
- encryption in transit and at rest (where appropriate),
- regular backups and business continuity planning,
- logging and monitoring of access and system events,
- training and internal policies for staff with access to personal data.
9. Your Rights Under GDPR
As a data subject, you have the following rights (subject to conditions and exceptions under applicable law):
- Right of access (Art. 15 GDPR): obtain confirmation whether we process your personal data and receive a copy of such data.
- Right to rectification (Art. 16 GDPR): request correction of inaccurate or incomplete data.
- Right to erasure (Art. 17 GDPR): request deletion of your personal data, where legally permitted.
- Right to restriction of processing (Art. 18 GDPR): request restriction in certain situations.
- Right to data portability (Art. 20 GDPR): receive personal data you provided in a structured, commonly used format.
- Right to object (Art. 21 GDPR): object to processing based on legitimate interests, including direct marketing.
- Right to withdraw consent (Art. 7(3) GDPR): withdraw consent at any time with effect for the future.
To exercise your rights, please contact us at: privacy@threatz.io
Right to Lodge a Complaint
You also have the right to lodge a complaint with a data protection supervisory authority, in particular in the EU Member State of your habitual residence, place of work, or place of the alleged infringement.
10. Third-Party Websites
Our website and products may contain links to third-party websites or services. We are not responsible for the privacy practices or content of such third parties. We recommend reviewing their privacy policies separately.
11. Changes to This Privacy Policy
We may update this Privacy Policy from time to time, for example to reflect changes in law, technology or our services. The latest version is always available on our website.
12. Contact
If you have any questions or concerns regarding this Privacy Policy or our data protection practices, please contact us at:
Franz-Mayer-Str. 1
93053 Regensburg
Germany
Email: privacy@threatz.io