Privacy Policy
Last updated: August 30, 2026
This Privacy Policy explains how ObservSecurity (“ObservSecurity,” “we,” “us”) handles personal information when you visit www.observsecurity.com, contact us, or use our products and services, including ObservX and the M365 Audit Tool (together, the “Services”).
1. Scope and roles
This policy covers personal information we handle as a controller — primarily information about website visitors, prospects, customer contacts, and consulting clients.
When we operate ObservX or run an audit for a customer, we process data from that customer's Microsoft 365 tenant on the customer's behalf as a processor / service provider. That processing is governed by our agreement with the customer and our data processing terms (available to customers on request at legal@observsecurity.com), not by this policy.
2. Information we collect
2.1 Information you give us
- Contact and inquiry data — name, email address, company, job title, and the contents of messages you send us by email or through forms.
- Engagement data — information exchanged while scoping, delivering, and invoicing consulting work, including points of contact and billing details.
- Account data — for ObservX, the email address and display name of authorized users, and passkey (WebAuthn) credential identifiers used for authentication.
2.2 Information collected automatically
- Usage and device data — IP address, browser and device type, pages viewed, referring pages, and timestamps, collected through server logs and privacy-friendly product analytics.
- Cookies and similar technologies — see our Cookie Policy.
2.3 Information from third parties
We may receive business contact information from our infrastructure and analytics providers, referral partners, and publicly available sources (such as a company website or professional network).
We do not intentionally collect special categories of personal data (such as health, biometric, or precise geolocation data) about website visitors, and we ask that you not send such information to us.
3. How we use information
- Provide, operate, secure, and improve the Services.
- Respond to inquiries and provide support.
- Scope, deliver, and administer consulting engagements.
- Authenticate users and prevent fraud, abuse, and security incidents.
- Send transactional and service messages.
- Send marketing communications where permitted; you can opt out at any time using the unsubscribe link or by emailing us.
- Comply with legal obligations and enforce our terms.
4. Legal bases (EEA/UK)
Where the EU or UK GDPR applies, we rely on: performance of a contract (providing the Services you request); legitimate interests (operating and securing our business, B2B marketing, analytics), balanced against your rights; consent (certain cookies and marketing, where required); and legal obligation (tax, accounting, and responding to lawful requests).
5. How we share information
We share personal information with:
- Service providers / subprocessors that host and support the Services under written contract, including our cloud hosting, database, email delivery, and AI providers. A current list is available to customers on request at legal@observsecurity.com.
- Professional advisers (lawyers, accountants, auditors) and payment/banking providers.
- Authorities or third parties where required by law, to protect rights and safety, or to investigate abuse.
- A successor entity in connection with a merger, acquisition, financing, or sale of assets.
We do not sell personal information, and we do not share it for cross-context behavioral advertising.
6. International transfers
We are based in the United States and our providers may process data in the United States and other countries. Where we transfer personal data from the EEA, UK, or Switzerland, we use an approved transfer mechanism such as the European Commission's Standard Contractual Clauses and the UK Addendum, together with additional safeguards as needed.
7. Retention
We keep personal information only as long as needed for the purposes above, then delete or de-identify it. Typical periods: inquiry data for up to 24 months after last contact; engagement and financial records for the period required by law (generally 7 years); ObservX account data for the life of the account plus up to 90 days; server logs for up to 12 months.
8. Security
We maintain administrative, technical, and organizational safeguards designed to protect personal information, including encryption in transit and at rest, least-privilege access controls, and logging and monitoring. No method of transmission or storage is completely secure.
9. Your rights
Depending on where you live, you may have the right to access, correct, delete, or receive a copy of your personal information; to object to or restrict certain processing; to withdraw consent; and to opt out of marketing. Residents of California and other U.S. states with comprehensive privacy laws may exercise rights to know, delete, correct, and opt out of “sale”/“sharing” and certain profiling — we do not engage in those activities. EEA/UK residents may lodge a complaint with their supervisory authority.
9.1 New Jersey residents
Under the New Jersey Data Privacy Act (NJDPA), New Jersey residents have the right to: confirm whether we process their personal data and access it; correct inaccuracies; delete personal data; obtain a portable copy; and opt out of processing for targeted advertising, the sale of personal data, or profiling in furtherance of decisions that produce legal or similarly significant effects. We do not sell personal data, use it for targeted advertising, or conduct such profiling. If we deny a request, you may appeal by replying to our decision or emailing legal@observsecurity.com with “NJDPA appeal” in the subject line; if the appeal is denied you may contact the New Jersey Division of Consumer Affairs. We recognize universal opt-out mechanisms such as Global Privacy Control as required by the NJDPA.
To make a request, email legal@observsecurity.com. We will verify your request and respond within the time required by applicable law (45 days under the NJDPA, extendable once by another 45 days). We will not discriminate against you for exercising your rights. You may use an authorized agent where the law allows.
10. Children
The Services are for businesses and are not directed to children under 16. We do not knowingly collect personal information from children.
11. “Do Not Track” and Global Privacy Control
Our website treats the Global Privacy Control (GPC) signal as a valid opt-out request where required, including under the New Jersey Data Privacy Act. There is no common industry standard for “Do Not Track,” so we do not respond to those signals.
12. Changes to this policy
We may update this policy from time to time. We will post the new version here and update the “Last updated” date; material changes will be notified through the Services or by email where appropriate.
13. Contact us
ObservSecurity, New Jersey, United States
Privacy requests and questions: legal@observsecurity.com
Questions about this document? Email legal@observsecurity.com.