Policy Effective Date: 05/01/2020
This Privacy Notice also covers our collection, use and disclosure of personal information that we collect through our services LRCloud and CloudAI. The use of information collected through our service is limited to the purpose of providing the service for which our client has engaged LogRhythm.
EU-U.S. Privacy Shield and Swiss-U.S. Privacy Shield LogRhythm, Inc. participates in and has certified its compliance with the EU-U.S. Privacy Shield Framework and the Swiss-U.S. Privacy Shield Framework. It is committed to subjecting all personal data received from the European Economic Area, United Kingdom and Switzerland, respectively, in reliance on each Privacy Shield Framework, to the Framework’s applicable Principles. To learn more about the Privacy Shield Frameworks, and to view our certification, visit the U.S. Department of Commerce’s Privacy Shield List. [https://www.privacyshield.gov/list/]
LogRhythm, Inc. is responsible for the processing of personal data it receives, under each Privacy Shield Framework, and subsequently transfers to a third party acting as an agent on its behalf. LogRhythm, Inc. complies with the Privacy Shield Principles for all onward transfers of personal data from the European Economic Area, United Kingdom and Switzerland, including the onward transfer liability provisions.
With respect to personal data received or transferred pursuant to the Privacy Shield Frameworks, LogRhythm, Inc. is subject to the regulatory enforcement powers of the U.S. Federal Trade Commission. In certain situations, it may be required to disclose personal data in response to lawful requests by public authorities, including to meet national security or law enforcement requirements.
If you have an unresolved privacy or data use concern that we have not addressed satisfactorily, please contact our U.S.-based third-party dispute resolution provider (free of charge) at https://feedback-form.truste.com/watchdog/request.
Under certain conditions, more fully described on the Privacy Shield website, you may be entitled to invoke binding arbitration when other dispute resolution procedures have been exhausted.
Collection and Use
Information Voluntarily Provided When Visiting our Website
In general, you can visit our site without divulging any personal information about yourself or your organization. However, there are areas of this site that do require this information in order to complete their functions or provide you with a customized experience, and then we may need to know your name, company name, street address, email address, or telephone number. Certain portions of the site may not be available to those choosing not to reveal the information requested.
For online queries and information requests about our service offerings, we may also collect from you information about your contacts, including their name, company name, address and email address. When you provide us with your personal information, we will use this information only to contact you for business to business marketing and sales communications.
Information Voluntarily Provided When Applying for a Job Posting: This information is used to determine if an applicant would be a good fit for the role applied to.
-U.S Equal Opportunity Employment Information (Optional)
-Voluntary Self-Identification of Disability (Optional)
Information Voluntarily Provided When Using Our Service Offerings
You may provide certain personal information, including company server IP addresses, Employee UserID, full names, office location, managers, job titles when you or your company contract and use our CloudAI services. We use the information collected through our CloudAI services by our customers for the following purposes: to identify anomalous user behavior to detect compromised user accounts.
We collect and process different types of product data (described below) when you deploy our service offerings in order to fulfill our legal obligations to you and operate our business. We work hard to help ensure a balance between our legitimate interests and your privacy rights.
- License Usage Data is Information that allows us to identify your account entitlements, such as license consumption, capacity, or type in our systems through an assigned license ID. We use this information to validate accounts and automate license verification
- Usage Data is Information about your operating environment, user/product interactions, and sessions. This includes information such as your network and systems architecture, OS and product versions, page loads and views, searches by number and type, errors, number of active and licensed users, source types and format (e.g., json, xml, and csv), web browser, http referrer page, and app workflows.We use Usage Data to fulfill our legal obligations in providing the Service offerings to you and to fulfill our legitimate interest in supporting and enhancing them. For example, we may use this data to:
- Troubleshoot issues, provide support, and update our Service offerings
- Provide guidance to help you optimize your usage of our Service offerings
- Better understand how our users configure our Service offerings
- Determine which configurations or practices optimize performance (e.g., best practices)
- Benchmark key performance indicators (“KPIs”)
- Recommend enhancements
- Perform data analysis and audits
- Identify, understand, and anticipate performance issues and the factors that affect them
- Identify product security issues that may affect you
- Improve and develop new features and functionality
- Monitor the health, performance, and security of our Service offerings
We may transfer your information to authorized sub-processors that will assist us to provide you with our services. These transfers would be governed by adequate privacy safeguards.
Information Collected Automatically
As is true of most websites, LogRhythm gathers certain information automatically, including IP Address, Operating System, Browser, referred URL, and web pages visited. LogRhythm tracks this information from visitors to this site to collect statistics on its web site traffic for usage and trend analysis purposes. This data enables us to become more familiar with how many people visit our site, what parts of the site they visit most often, and other usage parameters.
Multi-site or cross-app tracking
We and our service providers collect and store information about users’ interactions with unaffiliated websites and applications that use our technologies, including cookies, persistent cookies, and similar tracking technologies. This allows us to infer the presence of a common user or behind multiple devices or browsers, for instance, and then link those browsers and devices into a device graph. We do so in order to provide personalized advertising on each device that is inferred from the browsing patterns on all of the devices. For information on your advertising choices and opt-out, please see the “Unsubscribe” section of this Privacy Notice
Accessing, Correcting and Deleting Your Information. LogRhythm respects your control over your information and, upon request, we will confirm whether we hold or are processing information that we have collected from you. You also have the right to amend or update inaccurate or incomplete personal information, request deletion of your personal information, or request that we no longer use it. Under certain circumstances we will not be able to fulfill your request, such as if it interferes with our regulatory obligations, affects legal matters, we cannot verify your identity, or it involves disproportionate cost or effort, but in any event we will respond to your request within a reasonable timeframe and provide you an explanation. If you would like to review, correct, delete or update your personal information contact us at [email protected] with your instructions.
Please note that for personal information about you that we have obtained or received for processing on behalf of a separate, unaffiliated entity–which determined the means and purposes of processing, all such requests should be made to that entity directly. We will honor and support any instructions they provide us with respect to your personal information.
Sharing of the Personal Information
We share your personal information according to this Privacy Notice, with your consent or as necessary to provide you the products or services you request, as well as to operate our business. The ways in which we share your personal information are set forth below.
Service Providers We may share your information with third parties who provide services on our behalf to help with our business activities. These companies are authorized to use your personal information only as necessary to provide these services to us, pursuant to written instructions. In such cases, these companies must abide by our data privacy and security requirements and are not allowed to use PI they receive from us for any other purpose. Representative business processes that our service providers/vendors assist us with include:
- Sending marketing communications;
- Displaying tailored content through personalized advertising;
- Fulfilling subscription services
- Providing cloud computing infrastructure/storage/processing, etc.
- Technical administration, such as hosting, managing and maintaining [our sites, services, applications, etc.]
Within Our Corporate Family We disclose PI to affiliated companies related by common ownership or control within LogRhythm, Inc. to carry out regular business activities, such as to provide, maintain and personalize our sites and services, to communicate with you, and to accomplish our legitimate business purposes, pursuant to contractual safeguards.
Legal Compliance In certain situations, LogRhythm may be required to disclose personal data in response to lawful requests by public authorities, including to meet national security or law enforcement requirements. We may also disclose your personal information as required by law, such as to comply with a subpoena or other legal process, when we believe in good faith that disclosure is necessary to protect our rights, protect your safety or the safety of others, investigate fraud, or respond to a government request.
Corporate Transaction If LogRhythm is involved in a merger, acquisition, or sale of all or a portion of its assets, we reserve the right to sell or transfer your information as part of the transaction. In such an event, you will be notified via email and/or a prominent notice on our website, of any change in ownership, uses of your personal information, and choices you may have regarding your personal information.
Tracking LogRhythm and its service providers use (session and persistent) “cookies” or similar tracking technologies like tags or setting scripts which are small data files that the site may place on your system for identification purposes. These tracking technologies collects the following type of personal data: IP Address, Operating System, and Browser. These files are used for site registration and customization the next time you visit us. Your web browser may allow you to be notified when you are receiving a cookie, giving you the choice to accept it or not. By not accepting cookies, some pages may not fully function, and you may not be able to access certain information on this site. To manage Flash cookies, please click this link.
- Digital Advertising Alliance (DAA)’s self-regulatory opt-out page
- The European Economic Area, United Kingdom European Interactive Digital Advertising Alliance (EDAA)’s consumer opt-out page
- Network Advertising Initiative (NAI)’s self-regulatory opt-out page.
International Transfers To facilitate our operations, we may transfer, store and process your personal information in jurisdictions other than where you live, including in the United States. Laws in these countries may differ from the laws applicable to your country of residence. For instance, if you are a European Economic Area (EEA) data subject and your personal information is shared with our affiliates, partners, or third-party service providers acting on our behalf outside of the EEA, then it is done so pursuant to necessary means to ensure an adequate level of protection.
Unsubscribe You may sign-up to receive e-mail communications from us. If you would like to discontinue receiving this information, you may update your e-mail preferences by using the “Unsubscribe” link found in e-mails we sent to you or by contacting us at [email protected].
If at any time you wish to no longer receive any marketing or sales correspondence from LogRhythm, you may opt out of any/all future electronic communications by clicking here.
Security The security of your personal information is important to us.
We have implemented commercially reasonable technical and organizational safeguards to appropriately protect your personal information against accidental, unauthorized, or unlawful access, use, loss, destruction or damage. Still, no system can be guaranteed to be 100% secure. If you have questions about the security of your personal information, or if you have reason to believe that the personal information that we hold about you is no longer secure, please contact us immediately as described in this Privacy Notice. We follow generally accepted standards to protect the personal information submitted to us, both during transmission and once it is received. If you have any questions about the security of your personal information, you can contact us at [email protected].
Data retention We may retain your personal information for the period necessary to fulfill the purposes outlined in this Privacy Notice, for as long as your account is active or as needed to provide you services, comply with our legal obligations, resolve disputes and enforce our agreements, unless a longer retention period is required or permitted by law.
4780 Pearl E Cir,
Boulder, CO 80301