This Privacy Policy explains how FortiSense (“we”, “us”) collects and uses information when you use the Service.
1. Information we collect
Depending on configuration and device activity, we may collect:
- Account data: email, account ID, subscription state.
- Device identifiers: device ID, last seen time, basic device metadata.
- Process telemetry: process names, parent/child relationships, executable paths.
- File identifiers: cryptographic hashes (e.g. SHA-256) of observed executables.
- Resource telemetry: CPU, memory, and network throughput metrics.
- Security events: alerts, classifications, and threat labels/scores.
- Operational logs: API requests, error logs, and audit trails (e.g. “marked safe”).
2. Why we use this information
- To detect suspicious activity and generate security alerts.
- To operate the Service (device enrolment, alert resolution, quarantine/restore requests).
- To improve accuracy and reduce false positives (including “ignore policies” you create).
- To secure the Service and prevent abuse.
- To support customers and troubleshoot issues.
3. Legal bases (UK GDPR)
We process data under one or more legal bases: performance of a contract (providing the Service), legitimate interests (security and fraud prevention), and where applicable consent (optional settings).
4. Sharing
We do not sell your personal data. We may share data with service providers (e.g. hosting, analytics, email) under contractual safeguards. We may also share if required by law.
5. Retention
We retain data for limited periods described in Data Retention. You can delete devices or close your account; some audit records may remain where required for security, billing, or legal compliance.
6. Security
We use reasonable technical and organisational measures to protect data. No system is perfectly secure; if you suspect a security issue, see Security Contact.
7. International transfers
If data is transferred outside the UK, we use appropriate safeguards (e.g. standard contractual clauses) where required.
8. Your rights
- Access, correction, deletion, and portability (where applicable).
- Object or restrict processing in certain circumstances.
- Complain to the ICO (Information Commissioner’s Office).
9. Contact
Privacy questions: privacy@FortiSense.io.