Privacy

We believe in your right to privacy. We defend it tirelessly.

Privacy principles

Privacy principles

1. We respect your right to privacy

First and foremost, we respect your privacy in everything we do. Your trust is important to us. We respect your control of your personal data and digital content, and it's our priority to prevent unauthorized access to it by anyone. Whenever we ask you for information, it is to better serve you: If we don't need it, we won't ask for it.

2. We will protect you

Not only do we live up to our principles, we also seek to protect you against external threats. We do this through our services and by sharing our insights on digital ecosystems with you. Your digital life should be nobody else's business but yours.

3. You decide how much you share with us

To provide you even better services and relevant messages, we collect information about how our applications are found and used. This means that when you're using our services, we track things like which features are used most and which actions trigger error messages. However, if you are uncomfortable with tracking, we completely appreciate that and therefore WithSecure products offer opt-out possibilities from non-critical data collection.

4. No backdoors

We do not build backdoors into our services or software for access by authorities or anyone else. Officials who want information for criminal investigations must enter through our front door with a warrant.

5. There is no privacy without security

Secure services help keep valuable data safe from malicious intentions and prying eyes. Without security, there is no guarantee of privacy. With our dedication to privacy and expertise in security, we can offer true digital freedom.

6. We keep our messaging relevant

We want to engage you and help you stay safe in the digital world. One way we do this is through relevant messages. Our messages are not just marketing. They are intended to be informative, fun and useful and to help you get the most out of our services. You can always opt out from our messaging if you prefer.

7. We choose service providers we can trust

As part of the Internet ecosystem, like any provider of digital services we must also use external solutions. However, we carefully partner with service providers who share our commitment to privacy and security. We don't share any more data with them than is absolutely necessary.

8. We are the good guys

Great software always has great people behind it. At WithSecure, honesty and integrity are part of our culture. We believe a free and open Internet is for the betterment of humanity, and we can stand for privacy and digital freedom because we have the people to back it up.

9. Transparency

We will be open and honest with you. We won't use your personal data for hidden purposes. We strive for clear and easy to understand communications – not jargon.

 

Privacy statement

WithSecure privacy statement

June 2021

in letter

  • Our core interest is keeping our customers safe with our services.
  • To do that, we need to process data on you and on your devices.
  • We have a culture of respecting your privacy.

Our guiding privacy principles are here.

Our general privacy policy is here and our product and solution-specific privacy policies (for services such as Business Suite and WithSecure Elements products) are here.

Structure

This privacy statement is given by WithSecure Corporation, a Finnish publicly listed corporation with Business ID 0705579-2 (“WithSecure”, “we”, “our”, “us”). All our subsidiaries also apply this policy.

Our data collection can be grouped as follows:

  • Client relationship data; the data that we need to manage our relationship with our clients and to market and sell our services to you or to the legal entity that you represent.
  • Service data; the data that we automatically process to provide you with the services that you have requested. This also includes the data that you actively submit to us when subscribing to our services.
  • Security data; the data that we need to collect to keep you secure.
  • Analytics data; additional anonymous or pseudonymous data that we collect to learn when and how our services are found and used.

This privacy statement describes WithSecure’s common practices for processing all of our customers’ personal data. It also complements the general privacy policy, the solution - specific privacy policies as well as our license terms and other, shorter notices on case-specific data collection (e.g. support tools). Depending on what WithSecure services you use and how much you interact with us, some sections of this policy may not apply to you or may apply to you only in part.

If there is no specific policy for a specific interaction, this privacy statement shall apply as such.

Definitions

This is what we mean when we make certain references within this policy.

“Client”, “you”, refers to a private or corporate user or any other data subjects who buy, register for use, or use our services, whose devices and data traffic are protected by our services, or who may have submitted personally identifiable information to us. This information may have been submitted through the use of our services, websites, telephone, email, registration forms, or other similar channels.

“Personal data” refers to any information on private individuals that is identifiable to them or their family or household members. This information may include names, email and mailing addresses, telephone numbers, billing and account information, and other, more technical information that can be linked to you, your device, or the behavior of either, that we process while providing our services.

“Services” refer to any services or products that are manufactured or distributed by WithSecure, including software, web solutions, tools, and related support services.

“Website” refers to the WithSecure.com website or any other website that WithSecure hosts or controls, including subsites and browser-based service portals.

What do we collect?

The service and interaction-specific policies set out the personal data collected per service type and interaction.

What do we do with it?

The interaction and service-specific privacy policies and notices set out the specific purposes for using the personal data collected by each service or processed in such activity.

In addition to such specific purposes, the following general purposes of personal data use apply across all of our services:

  • Provisioning of services. To deliver our services to you, we process the data for the following purposes:
  • Customer journey. To identify authorized users, process and track transactions, administer user accounts, as well as for shipping, invoicing, and managing licenses.
  • Deliver, fix, and enhance. Delivering, maintaining, and developing our services and websites, and to provide help and support for the services.
  • Analyze. To track that our services are taken into use and how they are used so that we can improve the services, manage your customer relationship, and approach you with relevant messages
  • Communicate. To send you information relating to the services, conduct customer surveys, and market our services to you. The actual communication may be handled either by WithSecure or by our partners.
  • Regulatory. To prevent fraudulent, illegal, or infringing activities and to comply with legal or regulatory requirements.

Legal grounds

This section gives you a more comprehensive explanation of the legal grounds based on which we process personal data. This complements the exact service-specific legal grounds on which our personal data processing relies for the respective activity.

Client relationship data

By using our services, you are our client. To interact with you and to provide our services to our clients, we must process some data on you. Such processing typically occurs when you communicate with us or our business partners relating to our services, install and use our services, fill out a form or survey, register to use our services, submit information through our web solutions, enter a contest or sweepstakes, register your email address with us, or send us email.

Since we need the data to pursue the above legitimate activities, we have a right to process relevant personal data. This right typically takes place in the form of “contract performance”, “legitimate interest”, or “consent”.

Service data and security data

We need to automatically collect and process relevant data for our services to work, to enhance them, and to provide them to you. The data is processed to:

  1. provide WithSecure services to secure our customers’ networks and devices as well as the confidentiality and availability of the data therein;
  2. enable WithSecure to detect emerging threats and security-relevant trends among all of its customers, so that our services can keep on par with evolving threats;
  3. enable WithSecure to provide a centralized security service framework across multiple continents to a large number of customers and partners.

The data processing by the services is mandatory for the efficient protection of the device/network and a prerequisite for WithSecure’s capability to provide its contracted services. As such processing is inseparable from the services that we provide to you, this gives us a valid need to process your data and a justification to do so.

For consumer products, this right takes place in the form of “contract performance”. For corporate products, this right takes place in the form of “legitimate interest”. In some cases, there is also a “legal obligation” to process data for specified purposes.

Analytics data

We also reuse the above service data and security data for data analytics purposes, based on the legal grounds established above. Data analytics are an integral part of our service delivery, as nearly all WithSecure services are dependent on our infrastructure to properly operate. Our data analytics enables us to direct that infrastructure to support your use of the services.

Where our services collect data that is only needed for the purpose of gaining more insight on how people use the services or how to serve you better, but is not necessary for providing our services, we do so only with your separate consent. You also have the right to withdraw your consent later, should you wish to do so. The legal grounds for data that is solely collected for analytics purposes is thus “consent”.

Secondary uses

In addition to above primary legal grounds for data collection, we may also need to use and/or continue to store data i) to meet a “legal obligation” to process data for specified purposes, or ii) under the grounds of “legitimate interest”. For an example list of situations where we may resort to such justifications, see the “Other disclosures” section.

General

We consider you a client of WithSecure, not a client of the individual service. Hence, data collected by different services (e.g. SAFE) and interactions (e.g. contacting support) are combined to your WithSecure account. However, we do not aggregate data against our specific privacy promises (for example, we maintain a hands-off approach to your traffic inside our VPN service).

Transfers and disclosures

We do much ourselves, but also have partners to help us provide our services. This also means that we need to exchange data with our partners. When doing so, we take great care in sharing only the necessary personal data.

The most impactful data exchanges with our sales partners and corporate customers are set out primarily in the service-specific privacy policy. The below details expand on this information and also list other data disclosures and data transfers that take place for all — or nearly all — WithSecure personal data processing activities.

Sales and delivery

We exchange (both disclose and receive) some of your personal data with our distribution partners (resellers of corporate IT services, operators, webstores, etc.), who market, distribute, administer, and support our services. We provide these companies access to such personal data that they may need for their agreed activities. The logic of this data sharing is to provide a seamless customer experience. This includes activities such as customer management, service support, incident management and problem resolution, direct marketing, and invoicing.

Our distribution partners are likely to have a pre-existing customer relationship with you or — in the case of our corporate services — with your employer. Such partners and corporate customers process your personal data as an independent entity, based on their applicable privacy policies. Regardless, our distribution partners and corporate customers must also comply with the agreements and legislation when handling your personal data. Each such entity is by default independently responsible for its own treatment of personal data, for its own purposes.

Subcontracting

We may transfer or disclose some of your personal data to WithSecure group companies and our subcontractors who help us create the services.

Where our clients’ personal data needs to be transferred or disclosed to our subcontractors, we require, in our contracts with them, that they use such information solely for providing their agreed services (for example, to solve a support case, to send it to logistics partners for product delivery, or to send marketing mails on our behalf). We require our subcontractors to process data pertaining to you in a manner that is consistent with our statements herein.

International transfers

WithSecure operates globally. Consequently, some of our affiliates, subcontractors, distributors, and partners are located outside the European Economic Area to ensure the global reach and availability of our services. The locations of WithSecure affiliates can be viewed from WithSecure’s public web pages

When we transfer personal data outside the European Economic Area, we secure such transfers of personal data according to the requirements of the law. We do this by imposing appropriate technical and contractual safeguards on relevant subcontractors and WithSecure group companies, for example by using data transfer clauses that are approved by the European Union — the fixed content of such clauses is available here.

We only do global or cross-border data transfers for a good reason and after assessing the resulting privacy risk.

We store more sensitive customer data within Finland or the European Economic Area and keep it under our own control.

Other uses and disclosures

There are circumstances not covered by this privacy policy where the use or disclosure of personal data may be justified or permitted, or where we may be obligated by applicable laws to disclose information without acquiring your consent or independent of service provisioning.

One example includes complying with a court order or a warrant issued by the authorities in the relevant jurisdiction to compel the production of information.

Similarly, there may be other circumstances where there is a justifiable legitimate interest to disclose limited sets of information to a third party. Examples of such disclosures include cases where we need to protect ourselves against liability or to prevent fraudulent activity, where we analyze your use of our products to ensure that our products are working the way you would expect them to and that we are able to react to adverse experiences, where it is necessary to solve or contain an ongoing problem, or where we need to meet the legitimate information requirements of our insurers or governmental regulatory agencies. In any such action, we will act according to the applicable laws.

We may also need to transfer your personal data as part of a corporate transaction, such as a sale, merger, spin-off, or other corporate reorganization of WithSecure, where the information is provided to the new controlling entity in the regular course of business. WithSecure group discloses and transfers data internally as required by our then current operational model. We do, however, limit the disclosures internally to only those group companies, units, teams, and individuals who have a need to know such information for the intended purposes of processing it.

We weigh each disclosure requirement carefully and take the possibility of such disclosure requests into account when deciding where and how we store your personal data.

Sources

While we collect the majority of the above-mentioned data directly from you or your device, we also receive data from our affiliates, distribution partners (such as operators and retailers), and corporate entities from whom you have purchased the services. Such entities may be our resellers, but also include our external webstore partners. We also acquire some basic personal data (order data on purchases) and aggregate analytical data from app stores in which our services are sold. Such other sources may further include subcontractors who have provided you with support for our services, or advertising partners who have assisted us in conducting our marketing activities.

We do this to create a seamless customer experience and to have the necessary information for solving support cases.

Typical examples of third-party sources are:

  • information on your purchase made in our external webstore,
  • we acquire your credentials from previous sign-in data from our operator reseller partner, so that we can provide our service to you directly,
  • we acquire your contact data from corporate decision-maker registries for marketing purposes, and
  • when you use your social media account to register to our services, we collect the email address from your account to enable us to authenticate your registration and to contact you.

Third parties

Our services are provided in conjunction with our partners and our services and websites may embed or interoperate with third-party services. This privacy document only applies to personal data as long as that data is within WithSecure’s realm of influence. Where your personal data is processed by other entities for their independent purposes, such other party is responsible for processing your personal data in a justified manner in accordance to their policies as well as for fulfilling your rights under data protection laws.

The most prevalent such scenarios are the following:

  • Webstore. Our webstore is partially run by a third-party reseller. While the data you enter in the registration phase is handled under WithSecure policies, our webstore providers’ policies apply to the actual purchase and related activities.
  • Device location queries. When you query the location of your device via our services, the provider of maps needs to process the related geographical data. On the publication date of this policy, WithSecure uses Google maps in our device location and search features. Google privacy policies shall apply accordingly to your use of the features.

Retention

This text complements the service-specific retention times. The default rule under the law is that personal data should be deleted or anonymized once it is no longer needed for its purpose.

However, some personal data needs to be nonetheless stored for longer periods of varying lengths due to varying reasons.

Typical reasons why we deviate from the primary retention times include the following examples:

  • grace periods and backups (e.g. keeping your personal data stored for a designated time after the end of your subscription, so that we can safeguard the data against erroneous deletion);
  • applicable laws require us to store the data (e.g. to keep track of the purchase and payment of our services);
  • to pursue available remedies or to limit any damages that we may sustain (e.g. due to an ongoing dispute or investigation);
  • to solve or contain a recurring problem or to have enough information to respond to future issues (e.g. your support ticket related to a problem that was not permanently corrected during your customership);
  • to prevent fraudulent activity (e.g. to enforce a ban on our community);
  • your personal data is incorporated to other data for a secondary purpose (e.g. retaining logs);
  • other similar circumstances, where there continues to be a legitimate need for the ongoing storage of personal data.

The final removal of your account may be delayed to avoid disturbing the other interactions you have with us. This is the case when you have an WithSecure account (e.g. you have subscribed to our consumer services with your email address) and also i) have an WithSecure Community account or ii) you continue to subscribe to our marketing messages. The WithSecure Community account deletion policy is set out in its terms of service. You can opt out from our marketing messages at any time.

If you have purchased our service via one of our operator partners, account deletion is controlled by said operator partner. Upon the partner notifying us that your subscription has been terminated, WithSecure subsequently removes the account. This removal leads to the deletion or anonymization of any personal data related to the account.

If we have received your information when providing you with technical support, the information is stored as long as the respective support case remains unsolved. Once solved, the information is gradually deleted or anonymized within two years from closing the case.

Analytics data collected with the user’s consent is retained for statistical purposes and is not deleted on removal of personal data and the user account. After termination of the account, analytics data cannot be linked to any personally identifiable user.

Data that does not contain personal data (e.g. aggregate analytical data) is retained as long as such data continues to be useful for the purpose it was collected.

Security

We apply strict security measures to protect the confidentiality, integrity, and availability of your personal data when transferring, storing, or processing it.

We use physical, administrative, and technical security measures to reduce the risk of loss, misuse, or unauthorized access, disclosure, or modification of your personal data.

All personal data is stored on secure servers operated by WithSecure or our partners with access limited to authorized personnel only.

Your rights

You have the right to the data that we have on you. In particular, you have the following rights to the personal data that we hold on you:

  • Access and rectification. You have the right to ask us what personal data we have on you and to get a copy of the data that we can identify pertaining to you in this context. Should you find any errors (e.g. obsolete information) in such data, we urge you to contact our customer care to resolve the issue. Some of our service portals allow you to update your customer information. For such, you should update any changes to your personal data, for example change of address or email address. If you cannot update the changes yourself, you may inform us of the necessary changes.
  • Objection. You are entitled to object to certain processing of personal data, including for example the processing of your personal data for marketing purposes or when we otherwise base our processing of your data on a legitimate interest. In the latter case, you need to establish a legally valid rationale for your objection.
  • Right to be forgotten. You also have the right to request us to cease storing your personal data and erase it. In this case you need to establish a legally valid rationale for your request.
  • Portability. You also have the right to ask for personal data that you yourself have provided — pursuant to a contract or your consent. You may request the data in a structured, commonly used, and machine-readable format and further that the data is transmitted to another controller, where technically feasible.
  • Withdrawing consent. In cases where the processing is based on your consent, you have the right to withdraw your consent at any time via relevant settings. For identifiable service analytics data, you can find the settings in the service user interface. You also have the right to opt out from our marketing communications via the preference center accessible through the link.
  • Restriction. If you establish that the data we have on you is incorrect or we have no legal right to use it, you may request that we cease any further processing of your personal data, and merely keep it in store until the issue is resolved.

You can exercise your rights via our customer care function. The links to contact us are in the “Contact information” section.

Note that there may be situations where our confidentiality obligations, our right of professional secrecy, and/or our obligations to provide our services (e.g. to your employer) may prohibit us from disclosing or deleting your personal data or otherwise prevent you from exercising your rights. Your above rights are also dependent on the legal grounds based on which we process your personal data.

If you have any complaints about how we process your personal data, or would like further information, please contact us at any time. If you feel that we are not enabling your statutory rights, you have the right to lodge a complaint with a supervisory authority. In most cases, this authority is the Finnish Data Protection Ombudsman (www.tietosuoja.fi).

Analytics

This section outlines our general practices for the collection and processing of data for analytics purposes.

When speaking about WithSecure data analytics, it comprises both reused service data, reused security data, and the data that is collected for analytics purposes to begin with.

We want to give you a more personal customer experience and provide you with even better services in the future. For that we need to track usage patterns and create customer segments. For example, what features are used most, where the service fails, what needs fixing, and how you found out about our services.

What we collect. The data that we process for the purposes of data analytics include things like device identifier and relations between devices / users / user groups, operation environment, service operation time, license type (trial or paid version), device metrics (such as phone model and operating system, language), partial IP address, service errors, problematic files and URLs, service performance data, how you interact with our services (such as which features are used and how often), the domain name from which you connect to the service, elements clicked, timestamps, regional location, effectiveness of our in-service messaging, service activation (such as tracking that you have received the related messages and that installation was successful), installation and activation paths, service performance, connections, data routing, quota, and other similar data.

On a practical level, when we ask for your consent in our services’ user interface, it controls whether the following data is sent: i) additional data, like which features are used and how often, and service metrics, and ii) the number of attributes sent in a given data set.

The above relates to your use of our cyber security services. Data analytics running on our websites are described in our website privacy policy.

Opting out. We really appreciate your help in improving our services. However, if you want to minimize all data traffic towards WithSecure, we respect that. Those of our services that employ additional analytics give you the choice on whether to contribute. You can opt out at any time from the subsequent collection of analytical data that is non-essential to our service provisioning.

If you have opted out from all analytics data collection, our messaging directed to you will be based only on the service data collection (the data that we collect in any case to provide you with the services) and some of our messaging is likely to be less relevant.

If you oppose all collection of data from your online life (including our websites), the more wholesale method for preventing online advertisers from profiling your mobile device usage is to reset the advertising identifier from time to time and to turn on the do-not-track setting in your device settings, or to use our privacy product.

Analytics data retention. In our data analytics activities, we combine analytics data with the service data. The resulting combined data set then continues to be processed based on a “legitimate interest”. The previously collected analytical data is retained as part of the service statistics, as its retroactive removal would break the statistics. When you cease subscribing to our services (i.e. your account is deleted), the analytical data related to your service use will be reverted to anonymous data, and we are no longer able to associate it with you.

Data exchange. Because of the technical environment (that is, the internet, the app store ecosystem, and social media), we are not able to do all of the collection and activities related to data analytics ourselves. We have to exchange some data (such as “Android marketing identifier” and other like identifiers) with our online analytics and marketing partners to enable our digital analytics and marketing activities. The vast majority of the data that we have on you is not shared with others.

Some of our subcontractors who provide us with analytical capabilities for our products may also create and publish aggregate reports on the data that they have collected. In such cases, the statistics and aggregate reports do not contain any data that could be linked to any individual person.

We do not sacrifice your privacy. Where we differ from most companies doing this is in that we understand how the ecosystem works and go through great pains to select our few partners with care, removing all data that is not absolutely necessary for the above purpose. You can naturally opt out from the collection of analytics data at any time via the service settings.

When we process the data for analytical or statistical purposes, we pseudonymize the data. In other words, our data analysts do not know the individual to which a specific data set refers to. The pseudonymization is only reversed in specified use cases. For example, when we communicate with you, we connect the results — not the full data — of our data analytics to your email address. Another example is that we may use the data to resolve issues you may have with our product, when providing you with technical support services.

We also limit such added analytics only to the surface of our services and keep them at arm’s length from the core privacy areas of our services. For example, we do not have any external analytics in our Security Cloud or in the traffic inside our VPN service.

Changes

This version of the policy clarifies, updates, and replaces the previous version. To continue keeping this document up to date, we will make changes and additions to this from time to time also in the future.

We will publish the changed policy document on our website or at another interaction point where it has previously been made available. If the changes are significant, we may also notify you by other means. Any changes will apply starting from the date that we publish the revised policy document.

Contact information

If you have any questions or concerns about the matters discussed in our privacy policies, please contact:

WithSecure Corporation
Tammasaarenkatu 7
PO Box 24
00181 Helsinki
Finland

How to contact us:

  • If you are a client of our consumer line of products, please contact us via our consumer support channels.
  • If you are a client of our corporate line of products, please contact us via corporate support channels.
  • You can contact WithSecure’s Data Protection Officer by sending a message to privacy@WithSecure.com. If you wish to exercise your rights as a data subject, please use the above links instead.
General Privacy Policy

Corporate business privacy policy

September 2019

This policy is provided on behalf of WithSecure Corporation and explains the processing of your personal data by companies belonging to WithSecure's group of companies. It sets out how the personal data that we collect from you, or that you provide to us, will be processed by us.

The data controller for this policy is WithSecure Corporation, a Finnish company with business ID 0705579-2. Our contact information can be found at the end of this policy.

The personal data of individuals discussed in this policy is primarily collected because WithSecure is in, or is seeking to enter in, a commercial relationship with the entities you are employed by.

The collected information and its use varies based on whether we have a pre-existing, commercial relationship between WithSecure and your employer (see section for CUSTOMERS AND PARTNERS) or we have no prior engagement with your employer (see section about MARKETING).

Marketing

What kind of data we collect on you

From persons visiting our website, we acquire data on the device used, your IP address, the route by which you arrived at our website, and your activities therein, as well as any information you have submitted to us through forms. For more detailed information, see our website privacy policy.

If you provide us your data via forms – online or offline – we ask you the following information: names of the person and company, email address, country, industry, size of company, telephone number, and area or service of interest.

We may also collect your information via our discussion boards or other social media hosted by WithSecure, competitions, promotion, surveys, webinars, and other such events or points of interaction.

If you have been identified as a decision maker or influencer by a third party, or listed as such in public sources, we typically obtain the following information on you and the organization that you represent: company name, title, name, function, language, email, zip code, city and state, country, phone number, industry, turnover, and size of company.

We may aggregate such data with general data on your organization.

For what purposes do we use it

We collect and process the data so that we can, based on your position in your organization, send you information relating to the services, conduct customer surveys, arrange competitions, advertise and market our services (both personalized and in aggregate), and share information and know-how about cyber security and on our services. We also make use of the collected data in market research, product and service development, and business offering development.

Should you or the organization that you represent become our customer, we combine data collected at this pre-sales phase for you when your organization becomes our customer. In such cases, we use it in accordance to the same practices that we employ with the representatives of our corporate customers and partners.

Legal grounds

We collect data on individuals in influential, decision-making positions in companies that would benefit from our services. We consider such activity to be in the legitimate interests of both WithSecure as a vendor and your employer as a buyer.

Where legitimate interest is not suitable or applicable to a type of data processing, we will seek your consent. For example; consent is the legal grounds for data that we collect on your browsing of our websites. Where we base our processing on consent, you may withdraw your consent at any time.

Customers and partners

What kind of data we collect on you

Regarding individuals, with whose employers we are in a commercial relationship, we process the following personal data on you: your name, your position / role / title, your email address and phone number, which legal entity that has purchased the license or service, such entity’s street / mailing address, country, your language and messaging preferences, available LinkedIn information, relevant access credentials to and logs in our systems.

WithSecure collects this data:

  • Via marketing activities (more information under Corporate Business - marketing),
  • Via our website, our discussion boards or other social media hosted by WithSecure,
  • Via competitions, promotion, surveys, webinars, and other such events or points of interaction,
  • Through sales, support, and account management activities, and
  • Through partner sales and customer management activities (e.g. a partner orders a license to an end customer or changes an end customer’s information).

For what purposes do we use it

We collect and process the data so that we can manage our customer relationships, provide you with information, products and services that you request from us, run joint planning sessions, analyze the data for business development purposes, deliver license certificates, undertake all steps of order fulfillment and payment processes, perform personalized marketing activities, communicate in relation to both the initial sales of our services as well as license and service renewals, our other offerings and other relevant information, collect your feedback and identify authorized users for selected systems and administer user accounts, and provide help and support for the services.

As you may approach us or submit information to us via multiple channels – such as our resellers, events, or website – we combine such information to make our communications relevant to your needs.

Legal grounds

WithSecure has a legitimate interest to process personal data of the employees of its customers and partners to enable and facilitate provisioning its commercial services to its corporate customers and partners, including undertaking relevant sales and marketing activities as enabled by applicable laws on different forms of marketing-related communications.

Where processing is required for an activity, it is necessary that we are able to process the required data. This is the case e.g. when we need to effectively communicate with the representatives of our partners and customers, deliver and invoice the agreed services, respond to an enquiry or support request, or enable your participation in our corporate customer beta program.

Where legitimate interest is not suitable or applicable to a type of data processing, we will seek your consent. For example; consent is the legal grounds for data that we collect on your browsing of our websites. Where we base our processing on consent, you may withdraw your consent at any time.

Profiling

To keep our interaction focused on the services that you are primarily interested in, some of the data that we collect may be based on your activity on our corporate web pages. This occurs in the event that you have consented to having such traffic linked to you, for example by filling any of our web forms. We do not record your web traffic outside WithSecure websites. The more activity and interest you show towards our solutions, the more likely it is that we will approach you. This is elaborated in our cookie banners and in our website privacy policy.

If you do not wish us to have your email address for this purpose, you may freely request that we remove it from our records. The impact on you is that the messaging that you may receive from us may be less relevant for you and your employer.

We do not disclose such profile information to external parties. We may share general data on your interest with our reseller to better serve your needs (e.g. to enable you to purchase via our local reseller), but only in the event that we have actually started sales negotiations.

Transfers and disclosures

Personal data is primarily processed by WithSecure's local company that you are interacting with the most. In addition to local processing, the most common reason for exchange of information between different WithSecure offices is to enable us to efficiently serve you and manage our relationship. See the list of our local country offices here).

Personal data can also be made available to WithSecure's channel partners when - and to the extent that - disclosure of data is necessary for the relevant purposes of processing data (listed above). For example, if you are interested in purchasing our services, we provide such information to our reseller partner in the area.

Some of WithSecure's affiliated companies, subcontractors, and distributing partners are located outside the European Economic Area (EEA). Even if the data is stored within the EEA, it may also be processed by our staff operating outside the EEA who work for us or for one of our suppliers. Such staff may be engaged in, among other things, the fulfilment of your order, the processing of your payment details, and the provisioning of support services.

Where personal data is transferred from the EEA to outside the EEA, WithSecure undertakes to safeguard the security and integrity of processing by implementing the appropriate measures as required by law, and by imposing appropriate contractual safeguards on such data importers (for example by adhering to data transfer clauses approved by the European Union).

Advertisers and advertising networks that require the data to select and serve relevant advertisements to you and others are listed on our website privacy policy.

Third parties

We also work closely with third parties (including, for example, business partners, subcontractors in technical, payment, and delivery services, advertising networks, analytics providers, search information providers, credit reference agencies) and may receive information about you from them. These vendors have collected this information from private or public sources or directly from you.

Other uses and disclosures

Information on secondary purposes for which personal data may occasionally be processed.

There are circumstances not covered by this privacy policy where the use or disclosure of personal data may be justified or permitted, or where we may be obligated by applicable laws to disclose information without acquiring your consent or independent of service provisioning.

One example includes complying with a court order or a warrant issued by the authorities in the relevant jurisdiction to compel the production of information.

Similarly, there may be other circumstances where there is a justifiable legitimate interest to disclose limited sets of information to a third party. Examples of such disclosures include cases where we need to protect ourselves against liability or to prevent fraudulent activity, where it is necessary to solve or contain an ongoing problem, or where we need to meet the legitimate information requirements of our insurers or governmental regulatory agencies. In any such action, we will act according to the applicable laws.

We may also need to transfer your personal data as part of a corporate transaction, such as a sale, merger, spin-off, or other corporate reorganization of F-Secure, where the information is provided to the new controlling entity in the regular course of business. WithSecure group discloses and transfers data internally as required by our then current operational model. We do, however, limit the disclosures internally to only those group companies, units, teams, and individuals who have a need to know such information for the intended purposes of processing it.

We weigh each disclosure requirement carefully and take the possibility of such disclosure requests into account when deciding where and how we store your personal data.

Retention

On a monthly basis, we purge our direct marketing records from all contacts who have not reacted to our messaging or visited our web pages during the last 24 months and who are not affiliated with any of our customers or partners.

If you become our customer or partner, the data is retained for the duration of your organization's relation. User data in our corporate customer registry is stored for the duration of the license/subscription/engagement and up to five years after the last engagement or subscription with the customer or partner has expired.

Security

Information on the security practices that we employ to keep your data secure.

We apply strict security measures to protect the confidentiality, integrity, and availability of your personal data when transferring, storing, or processing it.

We use physical, administrative, and technical security measures to reduce the risk of loss, misuse, or unauthorized access, disclosure, or modification of your personal data.

All personal data is stored on secure servers operated by WithSecure or our partners with access limited to authorized personnel only.

Your rights

Information on your statutory rights and how to contact us.

You have the right to the data that we have on you. In particular, you have the following rights to the personal data that we hold on you:

  • Access and rectification. You have the right to ask us what personal data we have on you and to get a copy of the data that we can identify pertaining to you in this context. Should you find any errors (e.g. obsolete information) in such data, we urge you to contact our customer care to resolve the issue. Some of our service portals allow you to update your customer information. For such, you should update any changes to your personal data, for example change of address or email address. If you cannot update the changes yourself, you may inform us of the necessary changes.
  • Objection. You are entitled to object to certain processing of personal data, including for example the processing of your personal data for marketing purposes or when we otherwise base our processing of your data on a legitimate interest. In the latter case, you need to establish a legally valid rationale for your objection.
  • Right to be forgotten. You also have the right to request us to cease storing your personal data and erase it. In this case you need to establish a legally valid rationale for your request.
  • Portability. You also have the right to ask for personal data that you yourself have provided — pursuant to a contract or your consent. You may request the data in a structured, commonly used, and machine-readable format and further that the data is transmitted to another controller, where technically feasible.
  • Withdrawing consent. In cases where the processing is based on your consent, you have the right to withdraw your consent at any time via relevant settings. For identifiable service analytics data, you can find the settings in the service user interface. You also have the right to opt out from our marketing communications via the preference center accessible through the link.
  • Restriction. If you establish that the data we have on you is incorrect or we have no legal right to use it, you may request that we cease any further processing of your personal data, and merely keep it in store until the issue is resolved.

You can exercise your rights via our customer care function. The links to contact us are in the “Contact information” section.

Note that there may be situations where our confidentiality obligations, our right of professional secrecy, and/or our obligations to provide our services (e.g. to your employer) may prohibit us from disclosing or deleting your personal data or otherwise prevent you from exercising your rights. Your above rights are also dependent on the legal grounds based on which we process your personal data.

If you have any complaints about how we process your personal data, or would like further information, please contact us at any time. If you feel that we are not enabling your statutory rights, you have the right to lodge a complaint with a supervisory authority. In most cases, this authority is the Finnish Data Protection Ombudsman (www.tietosuoja.fi).

Contact information

If you have any questions or concerns about the matters discussed in our privacy policies, please contact:

WithSecure Corporation
Tammasaarenkatu 7
PL 24
00181 Helsinki
Finland

How to contact us:

  • If you are a client of our consumer line of products, please contact us via our consumer support channels.
  • If you are a client of our corporate line of products, please contact us via corporate support channels.
  • You can contact WithSecure’s Data Protection Officer by sending a message to privacy@withsecure.com. If you wish to exercise your rights as a data subject, please use the above links instead.

General

Information on definitions and change management.

Definitions

This is what we mean when we make certain references within this policy.

“Client”, “you”, refers to a private or corporate user or any other data subjects who buy, register for use, or use our services, whose devices and data traffic are protected by our services, or who may have submitted personally identifiable information to us. This information may have been submitted through the use of our services, websites, telephone, email, registration forms, or other similar channels.

“Personal data” refers to any information on private individuals that is identifiable to them or their family or household members. This information may include names, email and mailing addresses, telephone numbers, billing and account information, and other, more technical information that can be linked to you, your device, or the behavior of either, that we process while providing our services.

“Services” refer to any services or products that are manufactured or distributed by WithSecure, including software, web solutions, tools, and related support services.

“Website” refers to the WithSecure.com website or any other website that WithSecure hosts or controls, including subsites and browser-based service portals.

Changes

This version of the policy clarifies, updates, and replaces the previous version. To continue keeping this document up to date, we will make changes and additions to this from time to time also in the future.

We will publish the changed policy document on our website or at another interaction point where it has previously been made available. If the changes are significant, we may also notify you by other means. Any changes will apply starting from the date that we publish the revised policy document.

Support tools

Support tool

In brief

When the WithSecure™ Support tool is run, it gathers information about your computer system and configuration, as well as the logs created by our services. The information is used for troubleshooting and solving problems in our services.

In most cases, you may review and edit the information before you send the archive file to customer support.

In full

This service-specific policy focuses on the items we believe are the most relevant for you. Such items are in particular 1) the type of personal and private data that the service collects, 2) what we use it for, 3) our justification, 4) typical disclosures, and 5) for how long we store it. More information on such topics as well as on other aspects (data subject rights, contact information, etc.) of the processing of your personal data is also available via the embedded links.

What do we collect and what do we do with it?

Information collected from WithSecure service logs

The information includes WithSecure service logs. This information contains detailed information of the service activity, for example downloading and installing updates, communication between the service components, engaging a feature, and security events. The information may contain service crash dumps, file paths, banking web sites, and blocked web pages.

Information collected from the operating systems logs

The information contains the current configuration of your operating system, for example the network configuration, installed applications, operating system services (e.g. OS update services) and running processes and applications (e.g. internet browser), mapped drives and device and user names, system crash dumps and logs. The submitted information also includes a snapshot of the system event history.

Purposes

Service log information is collected to establish whether our service has operated as intended, including resolving potential incorrectly categorized issues. Operating system information is collected for the purpose of troubleshooting problems in cases where our own service logs provide insufficient information. The archive file is also used as a data source to support our development activities, so that we can prevent the re-occurrence of the issue on your device or on those of other customers.

 

What do we do with it?

The interaction and service-specific privacy policies and notices set out the specific purposes for using the personal data collected by each service or processed in such activity.

In addition to such specific purposes, the following general purposes of personal data use apply across all of our services:

  • Provisioning of services. To deliver our services to you, we process the data for the following purposes:
  • Customer journey. To identify authorized users, process and track transactions, administer user accounts, as well as for shipping, invoicing, and managing licenses.
  • Deliver, fix, and enhance. Delivering, maintaining, and developing our services and websites, and to provide help and support for the services.
  • Analyze. To track that our services are taken into use and how they are used so that we can improve the services, manage your customer relationship, and approach you with relevant messages.
  • Communicate. To send you information relating to the services, conduct customer surveys, and market our services to you. The actual communication may be handled either by F‑Secure or by our partners.
  • Regulatory. To prevent fraudulent, illegal, or infringing activities and to comply with legal or regulatory requirements.

Adjustments

If you have been asked (by WithSecure Customer Care or by our partners or your company IT administrator) to change the logging level to "full" prior to (re)running this tool to record information from an WithSecure service, the following scan performed by this tool includes additional data compared to the above. The type of collected additional data varies according to the target of the debugging activity. Our Customer Care can advise you on what kind of data would be likely collected for the issue at hand. We typically need to do this when we do not have enough data to diagnose the problems on your device.

If you are manually running the support tool yourself – i.e. the tool is not activated remotely – the information collected by the tool is saved as an archive file to your desktop or computer. In such cases, you can extract the files and edit the information before recompressing and sending it to us.

Legal grounds

Our legal grounds for the processing of personal data varies depending on whether you are running this tool as a consumer or as a corporate customer. In each case, the collection of the above data is necessary for us to be able to effectively provide you / your employer with our support services. Absent of this data, it will be more difficult to help you in solving the incident with our services.

If you are a consumer, the data is collected so that we can deliver the service that you have made a contract for (i.e. so we can help you to solve the technical problem with your use of WithSecure services). Such contracts may have been made either directly with us or with another entity (such as our webstore or operator partner) that has tendered our services to you.

If you are a corporate customer or employee of our corporate customers, we have a legitimate interest to use the collected / submitted data to solve the problems that have given rise to support cases and also to store the data for the time that is necessary to prevent the incident from re-occurring in our services. Regardless of our justification, you retain control over whether to send / allow sending of the information package to WithSecure.

Transfers and disclosures

The archive file may be handled by WithSecure Corporation, our affiliated companies, relevant subcontractors, and our support partners, but only for the purposes set out in this policy. Where the service has been provided to you via our corporate reseller or operator partner, your support contact is likely via these entities. These entities will typically forward the archive file to WithSecure for analysis and in-depth problem resolution activities. In some cases, the archive file may also be handled by such reseller if they have the capability to perform the problem resolution activities independently from WithSecure.

Sales and delivery

We exchange (both disclose and receive) some of your personal data with our distribution partners (resellers of corporate IT services, operators, webstores, etc.), who market, distribute, administer, and support our services. We provide these companies access to such personal data that they may need for their agreed activities. The logic of this data sharing is to provide a seamless customer experience. This includes activities such as customer management, service support, incident management and problem resolution, direct marketing, and invoicing.

Our distribution partners are likely to have a pre-existing customer relationship with you or — in the case of our corporate services — with your employer. Such partners and corporate customers process your personal data as an independent entity, based on their applicable privacy policies. Regardless, our distribution partners and corporate customers must also comply with the agreements and legislation when handling your personal data. Each such entity is by default independently responsible for its own treatment of personal data, for its own purposes.

Subcontracting

We may transfer or disclose some of your personal data to WithSecure group companies and our subcontractors who help us create the services.

Where our clients’ personal data needs to be transferred or disclosed to our subcontractors, we require, in our contracts with them, that they use such information solely for providing their agreed services (for example, to solve a support case, to send it to logistics partners for product delivery, or to send marketing mails on our behalf). We require our subcontractors to process data pertaining to you in a manner that is consistent with our statements herein.

International transfers

WithSecure operates globally. Consequently, some of our affiliates, subcontractors, distributors, and partners are located outside the European Economic Area to ensure the global reach and availability of our services. The locations of WithSecure affiliates can be viewed from WithSecure’s public web pages

When we transfer personal data outside the European Economic Area, we secure such transfers of personal data according to the requirements of the law. We do this by imposing appropriate technical and contractual safeguards on relevant subcontractors and WithSecure group companies, for example by using data transfer clauses that are approved by the European Union — the fixed content of such clauses is available here.

We only do global or cross-border data transfers for a good reason and after assessing the resulting privacy risk.

We store more sensitive customer data within Finland or the European Economic Area and keep it under our own control.

Other uses and disclosures

There are circumstances not covered by this privacy policy where the use or disclosure of personal data may be justified or permitted, or where we may be obligated by applicable laws to disclose information without acquiring your consent or independent of service provisioning.

One example includes complying with a court order or a warrant issued by the authorities in the relevant jurisdiction to compel the production of information.

Similarly, there may be other circumstances where there is a justifiable legitimate interest to disclose limited sets of information to a third party. Examples of such disclosures include cases where we need to protect ourselves against liability or to prevent fraudulent activity, where we analyze your use of our products to ensure that our products are working the way you would expect them to and that we are able to react to adverse experiences, where it is necessary to solve or contain an ongoing problem, or where we need to meet the legitimate information requirements of our insurers or governmental regulatory agencies. In any such action, we will act according to the applicable laws.

We may also need to transfer your personal data as part of a corporate transaction, such as a sale, merger, spin-off, or other corporate reorganization of WithSecure, where the information is provided to the new controlling entity in the regular course of business. WithSecure group discloses and transfers data internally as required by our then current operational model. We do, however, limit the disclosures internally to only those group companies, units, teams, and individuals who have a need to know such information for the intended purposes of processing it.

We weigh each disclosure requirement carefully and take the possibility of such disclosure requests into account when deciding where and how we store your personal data.

Sources

While we collect the majority of the above-mentioned data directly from you or your device, we also receive data from our affiliates, distribution partners (such as operators and retailers), and corporate entities from whom you have purchased the services. Such entities may be our resellers, but also include our external webstore partners. We also acquire some basic personal data (order data on purchases) and aggregate analytical data from app stores in which our services are sold. Such other sources may further include subcontractors who have provided you with support for our services, or advertising partners who have assisted us in conducting our marketing activities.

We do this to create a seamless customer experience and to have the necessary information for solving support cases.

Typical examples of third-party sources are:

  • information on your purchase made in our external webstore,
  • we acquire your credentials from previous sign-in data from our operator reseller partner, so that we can provide our service to you directly,
  • we acquire your contact data from corporate decision-maker registries for marketing purposes, and
  • when you use your social media account to register to our services, we collect the email address from your account to enable us to authenticate your registration and to contact you.

Third parties

Our services are provided in conjunction with our partners and our services and websites may embed or interoperate with third-party services. This privacy document only applies to personal data as long as that data is within WithSecure’s realm of influence. Where your personal data is processed by other entities for their independent purposes, such other party is responsible for processing your personal data in a justified manner in accordance to their policies as well as for fulfilling your rights under data protection laws.

The most prevalent such scenarios are the following:

  • Webstore. Our webstore is partially run by a third-party reseller. While the data you enter in the registration phase is handled under WithSecure policies, our webstore providers’ policies apply to the actual purchase and related activities.
  • Device location queries. When you query the location of your device via our services, the provider of maps needs to process the related geographical data. On the publication date of this policy, WithSecure uses Google maps in our device location and search features. Google privacy policies shall apply accordingly to your use of the features.

 

Retention

The file is stored by WithSecure as long as necessary for ascertaining that the encountered issues will be fixed and will remain fixed in future service releases and for a maximum of two years from closing the support case.

While the archive file is under WithSecure care, we respect the possibly private and confidential nature of the information in the archive file and do not use it or share it except as necessary for the above purposes.

This text complements the service-specific retention times. The default rule under the law is that personal data should be deleted or anonymized once it is no longer needed for its purpose.

However, some personal data needs to be nonetheless stored for longer periods of varying lengths due to varying reasons.

Typical reasons why we deviate from the primary retention times include the following examples:

  • grace periods and backups (e.g. keeping your personal data stored for a designated time after the end of your subscription, so that we can safeguard the data against erroneous deletion);
  • applicable laws require us to store the data (e.g. to keep track of the purchase and payment of our services);
  • to pursue available remedies or to limit any damages that we may sustain (e.g. due to an ongoing dispute or investigation);
  • to solve or contain a recurring problem or to have enough information to respond to future issues (e.g. your support ticket related to a problem that was not permanently corrected during your customership);
  • to prevent fraudulent activity (e.g. to enforce a ban on our community);
  • your personal data is incorporated to other data for a secondary purpose (e.g. retaining logs);
  • other similar circumstances, where there continues to be a legitimate need for the ongoing storage of personal data.

The final removal of your account may be delayed to avoid disturbing the other interactions you have with us. This is the case when you have an WithSecure account (e.g. you have subscribed to our consumer services with your email address) and also i) have an WithSecure Community account or ii) you continue to subscribe to our marketing messages. The WithSecure Community account deletion policy is set out in its terms of service. You can opt out from our marketing messages at any time.

If you have purchased our service via one of our operator partners, account deletion is controlled by said operator partner. Upon the partner notifying us that your subscription has been terminated, WithSecure subsequently removes the account. This removal leads to the deletion or anonymization of any personal data related to the account.

If we have received your information when providing you with technical support, the information is stored as long as the respective support case remains unsolved. Once solved, the information is gradually deleted or anonymized within two years from closing the case.

Analytics data collected with the user’s consent is retained for statistical purposes and is not deleted on removal of personal data and the user account. After termination of the account, analytics data cannot be linked to any personally identifiable user.

Data that does not contain personal data (e.g. aggregate analytical data) is retained as long as such data continues to be useful for the purpose it was collected.

 

Security

Information on the security practices that we employ to keep your data secure.

We apply strict security measures to protect the confidentiality, integrity, and availability of your personal data when transferring, storing, or processing it.

We use physical, administrative, and technical security measures to reduce the risk of loss, misuse, or unauthorized access, disclosure, or modification of your personal data.

All personal data is stored on secure servers operated by WithSecure or our partners with access limited to authorized personnel only.

Your rights

Information on your statutory rights and how to contact us.

You have the right to the data that we have on you. In particular, you have the following rights to the personal data that we hold on you:

  • Access and rectification. You have the right to ask us what personal data we have on you and to get a copy of the data that we can identify pertaining to you in this context. Should you find any errors (e.g. obsolete information) in such data, we urge you to contact our customer care to resolve the issue. Some of our service portals allow you to update your customer information. For such, you should update any changes to your personal data, for example change of address or email address. If you cannot update the changes yourself, you may inform us of the necessary changes.
  • Objection. You are entitled to object to certain processing of personal data, including for example the processing of your personal data for marketing purposes or when we otherwise base our processing of your data on a legitimate interest. In the latter case, you need to establish a legally valid rationale for your objection.
  • Right to be forgotten. You also have the right to request us to cease storing your personal data and erase it. In this case you need to establish a legally valid rationale for your request.
  • Portability. You also have the right to ask for personal data that you yourself have provided — pursuant to a contract or your consent. You may request the data in a structured, commonly used, and machine-readable format and further that the data is transmitted to another controller, where technically feasible.
  • Withdrawing consent. In cases where the processing is based on your consent, you have the right to withdraw your consent at any time via relevant settings. For identifiable service analytics data, you can find the settings in the service user interface. You also have the right to opt out from our marketing communications via the preference center accessible through the link.
  • Restriction. If you establish that the data we have on you is incorrect or we have no legal right to use it, you may request that we cease any further processing of your personal data, and merely keep it in store until the issue is resolved.

You can exercise your rights via our customer care function. The links to contact us are in the “Contact information” section.

Note that there may be situations where our confidentiality obligations, our right of professional secrecy, and/or our obligations to provide our services (e.g. to your employer) may prohibit us from disclosing or deleting your personal data or otherwise prevent you from exercising your rights. Your above rights are also dependent on the legal grounds based on which we process your personal data.

If you have any complaints about how we process your personal data, or would like further information, please contact us at any time. If you feel that we are not enabling your statutory rights, you have the right to lodge a complaint with a supervisory authority. In most cases, this authority is the Finnish Data Protection Ombudsman (www.tietosuoja.fi).

 

Contact information

If you have any questions or concerns about the matters discussed in our privacy policies, please contact:

WithSecure Corporation
Tammasaarenkatu 7
PL 24
00181 Helsinki
Finland

How to contact us:

  • If you are a client of our consumer line of products, please contact us via our consumer support channels.
  • If you are a client of our corporate line of products, please contact us via corporate support channels.
  • You can contact WithSecure’s Data Protection Officer by sending a message to privacy@withsecure.com. If you wish to exercise your rights as a data subject, please use the above links instead.

General

Information on definitions and change management.

Definitions

This is what we mean when we make certain references within this policy.

“Client”, “you”, refers to a private or corporate user or any other data subjects who buy, register for use, or use our services, whose devices and data traffic are protected by our services, or who may have submitted personally identifiable information to us. This information may have been submitted through the use of our services, websites, telephone, email, registration forms, or other similar channels.

“Personal data” refers to any information on private individuals that is identifiable to them or their family or household members. This information may include names, email and mailing addresses, telephone numbers, billing and account information, and other, more technical information that can be linked to you, your device, or the behavior of either, that we process while providing our services.

“Services” refer to any services or products that are manufactured or distributed by WithSecure, including software, web solutions, tools, and related support services.

“Website” refers to the WithSecure.com website or any other website that WithSecure hosts or controls, including subsites and browser-based service portals.

Changes

This version of the policy clarifies, updates, and replaces the previous version. To continue keeping this document up to date, we will make changes and additions to this from time to time also in the future.

We will publish the changed policy document on our website or at another interaction point where it has previously been made available. If the changes are significant, we may also notify you by other means. Any changes will apply starting from the date that we publish the revised policy document.

Surveys

Survey

In brief

In this privacy policy, we at WithSecure explain how we handle personal data in our surveys.

We collect survey data on our customers’ experience of working with us and our products and services. We use your responses to improve our products, services, and for other collaboration with our customers.

In full

WithSecure deploys customer surveys to acquire feedback on security services. We use this feedback to increase our customer understanding and consequently to improve our products and services, as well as the way that we operate on the market.

This service-specific policy focuses on the items we believe are the most relevant for you. Such items are in particular 1) the type of personal and private data that the service collects, 2) what we use it for, 3) our justification, 4) typical disclosures, and 5) for how long we store it. More information on such topics as well as on other aspects (data subject rights, contact information, etc.) of the processing of your personal data is also available via the embedded links.

What data do we collect?

We prepopulate our survey with the data that we have on you. This typically includes your email address, phone number, name, language, country, and other customer relationship data. We may additionally ask for some more information, such as age and gender, to help categorize responses. In the survey we ask about your experience with us.

Choices

We collect this data only where you consent to it by responding to our survey. You do not have to respond to us. However, we would very much appreciate that you do so, so that we know what you value to better serve you.

Operator partners

In some cases, we also conduct surveys on our operator partners’ end customers. To effectively approach you as an operator partner’s end customer and to get usable results, the operator provides us with baseline data on intended survey recipients. Such data typically includes email addresses, names, phone numbers, contact IDs, number of activated licenses, details on the offer (e.g. fixed or mobile, number of paid licenses). We share your responses with the operator for analysis and as feedback for future improvements. The operator processes and stores such data according to their practices.

  • If the operator manages the communication preferences and/or holds all identifying data for the recipient, the operator is responsible for removing those end customers who have opted out.
  • If WithSecure manages the communication preferences relating to distributed security services for the recipient, WithSecure is responsible for removing the recipients who have opted out.

The Operator is the first point of contact for any additional queries from the survey recipient.

 

Transfers and disclosures

We share our customers’ contact data with our affiliates and subcontractors to enable our affiliates and subcontractors to contact customers for conducting surveys and to provide visibility of survey results to the relevant affiliates. The affiliates and subcontractors agree to process personal data solely as instructed by WithSecure. They are not allowed to use survey data for any other purposes. They are themselves responsible for cookie practices on their sites.

Learn more

Sales and delivery

We exchange (both disclose and receive) some of your personal data with our distribution partners (resellers of corporate IT services, operators, webstores, etc.), who market, distribute, administer, and support our services. We provide these companies access to such personal data that they may need for their agreed activities. The logic of this data sharing is to provide a seamless customer experience. This includes activities such as customer management, service support, incident management and problem resolution, direct marketing, and invoicing.

Our distribution partners are likely to have a pre-existing customer relationship with you or — in the case of our corporate services — with your employer. Such partners and corporate customers process your personal data as an independent entity, based on their applicable privacy policies. Regardless, our distribution partners and corporate customers must also comply with the agreements and legislation when handling your personal data. Each such entity is by default independently responsible for its own treatment of personal data, for its own purposes.

Subcontracting

We may transfer or disclose some of your personal data to WithSecure group companies and our subcontractors who help us create the services.

Where our clients’ personal data needs to be transferred or disclosed to our subcontractors, we require, in our contracts with them, that they use such information solely for providing their agreed services (for example, to solve a support case, to send it to logistics partners for product delivery, or to send marketing mails on our behalf). We require our subcontractors to process data pertaining to you in a manner that is consistent with our statements herein.

International transfers

WithSecure operates globally. Consequently, some of our affiliates, subcontractors, distributors, and partners are located outside the European Economic Area to ensure the global reach and availability of our services. The locations of WithSecure affiliates can be viewed from WithSecure’s public web pages

When we transfer personal data outside the European Economic Area, we secure such transfers of personal data according to the requirements of the law. We do this by imposing appropriate technical and contractual safeguards on relevant subcontractors and WithSecure group companies, for example by using data transfer clauses that are approved by the European Union — the fixed content of such clauses is available here.

We only do global or cross-border data transfers for a good reason and after assessing the resulting privacy risk.

We store more sensitive customer data within Finland or the European Economic Area and keep it under our own control.

Other uses and disclosures

There are circumstances not covered by this privacy policy where the use or disclosure of personal data may be justified or permitted, or where we may be obligated by applicable laws to disclose information without acquiring your consent or independent of service provisioning.

One example includes complying with a court order or a warrant issued by the authorities in the relevant jurisdiction to compel the production of information.

Similarly, there may be other circumstances where there is a justifiable legitimate interest to disclose limited sets of information to a third party. Examples of such disclosures include cases where we need to protect ourselves against liability or to prevent fraudulent activity, where we analyze your use of our products to ensure that our products are working the way you would expect them to and that we are able to react to adverse experiences, where it is necessary to solve or contain an ongoing problem, or where we need to meet the legitimate information requirements of our insurers or governmental regulatory agencies. In any such action, we will act according to the applicable laws.

We may also need to transfer your personal data as part of a corporate transaction, such as a sale, merger, spin-off, or other corporate reorganization of WithSecure, where the information is provided to the new controlling entity in the regular course of business. WithSecure group discloses and transfers data internally as required by our then current operational model. We do, however, limit the disclosures internally to only those group companies, units, teams, and individuals who have a need to know such information for the intended purposes of processing it.

We weigh each disclosure requirement carefully and take the possibility of such disclosure requests into account when deciding where and how we store your personal data.

Sources

While we collect the majority of the above-mentioned data directly from you or your device, we also receive data from our affiliates, distribution partners (such as operators and retailers), and corporate entities from whom you have purchased the services. Such entities may be our resellers, but also include our external webstore partners. We also acquire some basic personal data (order data on purchases) and aggregate analytical data from app stores in which our services are sold. Such other sources may further include subcontractors who have provided you with support for our services, or advertising partners who have assisted us in conducting our marketing activities.

We do this to create a seamless customer experience and to have the necessary information for solving support cases.

Typical examples of third-party sources are:

  • information on your purchase made in our external webstore,
  • we acquire your credentials from previous sign-in data from our operator reseller partner, so that we can provide our service to you directly,
  • we acquire your contact data from corporate decision-maker registries for marketing purposes, and
  • when you use your social media account to register to our services, we collect the email address from your account to enable us to authenticate your registration and to contact you.

Third parties

Our services are provided in conjunction with our partners and our services and websites may embed or interoperate with third-party services. This privacy document only applies to personal data as long as that data is within WithSecure’s realm of influence. Where your personal data is processed by other entities for their independent purposes, such other party is responsible for processing your personal data in a justified manner in accordance to their policies as well as for fulfilling your rights under data protection laws.

The most prevalent such scenarios are the following:

  • Webstore. Our webstore is partially run by a third-party reseller. While the data you enter in the registration phase is handled under WithSecure policies, our webstore providers’ policies apply to the actual purchase and related activities.
  • Device location queries. When you query the location of your device via our services, the provider of maps needs to process the related geographical data. On the publication date of this policy, WithSecure uses Google maps in our device location and search features. Google privacy policies shall apply accordingly to your use of the features.

 

Retention

If you are our consumer customer, your survey responses are stored in our customer registry for six (6) months from the response date of the respective survey – unless you request that it be deleted sooner. The purpose for retention is to ensure enough time for conducting a successful survey and analyzing the data. After this, the results will be anonymized and continue to be stored as aggregate results.

If you are our corporate customer or partner, your survey responses are stored in our customer registry in accordance to its retention rules.

Learn more

This text complements the service-specific retention times. The default rule under the law is that personal data should be deleted or anonymized once it is no longer needed for its purpose.

However, some personal data needs to be nonetheless stored for longer periods of varying lengths due to varying reasons.

Typical reasons why we deviate from the primary retention times include the following examples:

  • grace periods and backups (e.g. keeping your personal data stored for a designated time after the end of your subscription, so that we can safeguard the data against erroneous deletion);
  • applicable laws require us to store the data (e.g. to keep track of the purchase and payment of our services);
  • to pursue available remedies or to limit any damages that we may sustain (e.g. due to an ongoing dispute or investigation);
  • to solve or contain a recurring problem or to have enough information to respond to future issues (e.g. your support ticket related to a problem that was not permanently corrected during your customership);
  • to prevent fraudulent activity (e.g. to enforce a ban on our community);
  • your personal data is incorporated to other data for a secondary purpose (e.g. retaining logs);
  • other similar circumstances, where there continues to be a legitimate need for the ongoing storage of personal data.

The final removal of your account may be delayed to avoid disturbing the other interactions you have with us. This is the case when you have an WithSecure account (e.g. you have subscribed to our consumer services with your email address) and also i) have an WithSecure Community account or ii) you continue to subscribe to our marketing messages. The WithSecure Community account deletion policy is set out in its terms of service. You can opt out from our marketing messages at any time.

If you have purchased our service via one of our operator partners, account deletion is controlled by said operator partner. Upon the partner notifying us that your subscription has been terminated, WithSecure subsequently removes the account. This removal leads to the deletion or anonymization of any personal data related to the account.

If we have received your information when providing you with technical support, the information is stored as long as the respective support case remains unsolved. Once solved, the information is gradually deleted or anonymized within two years from closing the case.

Analytics data collected with the user’s consent is retained for statistical purposes and is not deleted on removal of personal data and the user account. After termination of the account, analytics data cannot be linked to any personally identifiable user.

Data that does not contain personal data (e.g. aggregate analytical data) is retained as long as such data continues to be useful for the purpose it was collected.

 

Security

Information on the security practices that we employ to keep your data secure.

Learn more

We apply strict security measures to protect the confidentiality, integrity, and availability of your personal data when transferring, storing, or processing it.

We use physical, administrative, and technical security measures to reduce the risk of loss, misuse, or unauthorized access, disclosure, or modification of your personal data.

All personal data is stored on secure servers operated by WithSecure or our partners with access limited to authorized personnel only.

Your rights

Information on your statutory rights and how to contact us.

Learn more

You have the right to the data that we have on you. In particular, you have the following rights to the personal data that we hold on you:

  • Access and rectification. You have the right to ask us what personal data we have on you and to get a copy of the data that we can identify pertaining to you in this context. Should you find any errors (e.g. obsolete information) in such data, we urge you to contact our customer care to resolve the issue. Some of our service portals allow you to update your customer information. For such, you should update any changes to your personal data, for example change of address or email address. If you cannot update the changes yourself, you may inform us of the necessary changes.
  • Objection. You are entitled to object to certain processing of personal data, including for example the processing of your personal data for marketing purposes or when we otherwise base our processing of your data on a legitimate interest. In the latter case, you need to establish a legally valid rationale for your objection.
  • Right to be forgotten. You also have the right to request us to cease storing your personal data and erase it. In this case you need to establish a legally valid rationale for your request.
  • Portability. You also have the right to ask for personal data that you yourself have provided — pursuant to a contract or your consent. You may request the data in a structured, commonly used, and machine-readable format and further that the data is transmitted to another controller, where technically feasible.
  • Withdrawing consent. In cases where the processing is based on your consent, you have the right to withdraw your consent at any time via relevant settings. For identifiable service analytics data, you can find the settings in the service user interface. You also have the right to opt out from our marketing communications via the preference center accessible through the link.
  • Restriction. If you establish that the data we have on you is incorrect or we have no legal right to use it, you may request that we cease any further processing of your personal data, and merely keep it in store until the issue is resolved.

You can exercise your rights via our customer care function. The links to contact us are in the “Contact information” section.

Note that there may be situations where our confidentiality obligations, our right of professional secrecy, and/or our obligations to provide our services (e.g. to your employer) may prohibit us from disclosing or deleting your personal data or otherwise prevent you from exercising your rights. Your above rights are also dependent on the legal grounds based on which we process your personal data.

If you have any complaints about how we process your personal data, or would like further information, please contact us at any time. If you feel that we are not enabling your statutory rights, you have the right to lodge a complaint with a supervisory authority. In most cases, this authority is the Finnish Data Protection Ombudsman (www.tietosuoja.fi).

Contact information

If you have any questions or concerns about the matters discussed in our privacy policies, please contact:

WithSecure Corporation
Tammasaarenkatu 7
PL 24
00181 Helsinki
Finland

How to contact us:

  • If you are a client of our consumer line of products, please contact us via our consumer support channels.
  • If you are a client of our corporate line of products, please contact us via corporate support channels.
  • You can contact WithSecure’s Data Protection Officer by sending a message to privacy@withsecure.com. If you wish to exercise your rights as a data subject, please use the above links instead.

General

Information on definitions and change management.

 

Learn more

Definitions

This is what we mean when we make certain references within this policy.

“Client”, “you”, refers to a private or corporate user or any other data subjects who buy, register for use, or use our services, whose devices and data traffic are protected by our services, or who may have submitted personally identifiable information to us. This information may have been submitted through the use of our services, websites, telephone, email, registration forms, or other similar channels.

“Personal data” refers to any information on private individuals that is identifiable to them or their family or household members. This information may include names, email and mailing addresses, telephone numbers, billing and account information, and other, more technical information that can be linked to you, your device, or the behavior of either, that we process while providing our services.

“Services” refer to any services or products that are manufactured or distributed by WithSecure, including software, web solutions, tools, and related support services.

“Website” refers to the WithSecure.com website or any other website that WithSecure hosts or controls, including subsites and browser-based service portals.

Changes

This version of the policy clarifies, updates, and replaces the previous version. To continue keeping this document up to date, we will make changes and additions to this from time to time also in the future.

We will publish the changed policy document on our website or at another interaction point where it has previously been made available. If the changes are significant, we may also notify you by other means. Any changes will apply starting from the date that we publish the revised policy document.

Websites

Website

In brief

  • We use cookies, web beacons, and other tracking technologies to learn how our websites are used and how they perform.
  • We do this to improve your experience on the sites, and to be better able to market our products and services to you.
  • The specific set of technologies used varies depending on the product, service, and site you are interested in or use.

 

In full

This policy describes the privacy practices on our websites. By websites (or sites) this description refers to groups of pages within the WithSecure.com domain. Our online resellers (e.g. Cleverbridge AG) have their own privacy policies and are not included in this policy. For our personal data processing practices in general, please see the WithSecure privacy statement. If you are looking for information about how we process your data in a particular service, you may also find our service-specific privacy policies, e.g. that of the EPP privacy policy, relevant to you.

We use cookies on our websites to assist us in content personalization, website improvements and development, and to create relevant online marketing activities. When you visit our sites, you agree to the use of such cookies. You can also adjust your choices from our cookie preference settings. Your cookie preferences remain active for one year from your choice. The expiration date of a cookie is dependent on the cookie provider. If you wish to remove the cookies prior to their expiration date, you can do so from your browser settings.

Some cookies (functional cookies) are required for proper functioning of the site or for security reasons, and are always set. For the sake of keeping this document relevant, such essential cookies are not discussed herein.

Website personalization and development

The information collected via cookies and other web technologies helps us understand when and how visitors discover, interact with, and leave our websites. We then use this information to

  • improve the visibility and usability of our sites,
  • locate and address technical issues you might experience,
  • deliver customized and relevant content, including pricing, to you, and
  • direct you to the most relevant localized web page (based on geographic IP address).

By default, we do not use cookies to identify the individuals who visit our websites. However, if you have voluntarily submitted your contact information to WithSecure — when purchasing a product, downloading a product trial, completing a survey or entering a contest, for example — we may, with your consent, tie your website usage to your individual record through the use of cookies. If you are a visitor interested in our corporate-oriented communication, this will also include your previous browsing on WithSecure websites. If you already have a business relationship with WithSecure, this will be combined with the pre-existing information we have about you stored in our Customer Relations Management platform. Read more.

We generate statistics and aggregate reports for internal use, as well as for sharing with WithSecure group companies, partners, and subcontractors. Our third-party web analytic providers may also create and publish aggregate reports of the data collected. The statistics and aggregate reports do not contain any data that could be linked to an individual website visitor.

Web marketing activities

The data we collect can also be used for marketing purposes. Information about the pages you have visited or the products you bought in the past helps us market more relevant services to you in the future.

We also work with data aggregators and ecommerce sites to provide targeted advertising to our customers. In practice, this means that when you visit our site or a third-party website we have partnered with, or click an advertisement for WithSecure products or services, your activity may be tracked through cookies. These cookies are generated by our marketing partners and used to display personalized WithSecure-related advertisements on other websites.

We do not sell your personal data to any third parties. Information that is not personally identifiable may be shared with our advertising or business partners. They may also use cookies to track what advertisements you have seen and what products or services you appear to be interested in.

General information about cookies

Cookies help us collect information about the use of our website. This information includes, among other things,

  • the web browsers and operating systems used,
  • the domains of referring sites (traffic origin),
  • the date, time, number, and duration of visits,
  • which pages or elements within pages were viewed,
  • which links, buttons, or other items were clicked,
  • and what was typed into text fields in forms.

Cookies may contain IDs, typically random strings of numbers and letters, that are unique to your browser. This helps us recognize your browser when you visit our website again.

We use both first-party (set by WithSecure) and third-party cookies (set by a vendor other than WithSecure). Third-party cookies convey information to that third-party site upon your visit to an WithSecure site.

Cookies are also used to track your reaction to emails sent to you, so that we know whether we have been successful in relaying the messaging to you.

Change your cookie settings

You can discontinue cookie-based data collection at any time, by opting out from the cookies (see the options below) or by adjusting your browser settings. Do note that some features of our website rely on cookies to function.

 

Please note that these opt-out mechanisms work by placing a cookie on your browser. Therefore, your browser must be configured to accept cookies for your preference to take effect. If you delete your cookies or switch to a different web browser, you will need to set your preferences again.

Third-party cookie providers

We use the following service providers to achieve some of the collection of data via cookies, as described above.

Cookie providerCookie purposeRead more
DemandbaseWebsite measuring and improvement, providing relevant advertisementsRead more
FacebookProviding relevant advertisementsRead more
Google AdsProviding relevant advertisements (including via Google signals)Read more
Google AnalyticsWebsite measuring and improvement (including via Google signals)Read more
Google Marketing PlatformProviding relevant advertisements (including via Google signals)Read more
HotjarWebsite measuring and improvementRead more
LinkedInProviding relevant advertisementsRead more
Microsoft AdvertisingProviding relevant advertisementsRead more
TaboolaProviding relevant advertisementsRead more
TwitterProviding relevant advertisementsRead more

 

Third-party websites

We are not responsible for any third-party websites you enter via our website, and their practices are not covered by this policy. Our website privacy policy does not cover data collected by any third-party websites, so you should read the privacy statements of those websites carefully.

WithSecure does not control cookies from third-party websites. The third parties are responsible for how these cookies work and how the personal data is processed.

The practices related to accepting or blocking third-party cookies vary by marketing campaign and are defined by the third party and applicable laws.