1. Introduction & scope
This Privacy Policy explains how Deflected.ai ("Deflected," "we," "us," or "our") handles personal information when you visit our website at deflected.ai, request a demo, contact us, or use our products and services (together, the "Services").
Deflected provides quantum-grade AI cybersecurity for the modern enterprise. This policy covers the personal information we process as a business — for example, when you interact with our marketing site or engage us as a customer. Where we process personal information on behalf of a customer as part of delivering the Services (for example, data flowing through a product deployed in a customer's environment), we act as a processor or service provider, and that processing is governed by our agreement with that customer rather than by this policy.
The data controller responsible for the personal information described here is [[Legal entity name]], located at [[Registered address]]. If you have any questions about this policy, contact us using the details in Section 13.
2. Information we collect
Information you provide to us
- Contact and demo requests — when you email us, request a demo, or fill in a form, we collect your name, business email address, company name, job title, and the contents of your message.
- Account and customer information — if your organization becomes a customer, we process business contact details, account credentials, billing and administrative information, and records related to the Services you use.
- Communications — correspondence with our sales, support, and security teams, including any information you choose to share with us.
Information we collect automatically
- Log data — when you access our website, our servers automatically record information such as your IP address, browser type, referring pages, pages viewed, and the date and time of your visit.
- Device and usage data — technical details about the device and software you use, and how you interact with our site, so we can keep it secure and improve it.
- Cookies and similar technologies — small files and identifiers stored on your device. See Section 6 for details and your choices.
We do not intentionally collect special categories of personal data (such as health or biometric data) through our website, and we ask that you do not submit such information to us unless it is necessary and lawful for a specific engagement.
3. How we use information
We use personal information for the following purposes:
- Provide and secure the Services — operate, maintain, protect, and administer our website and the products and services you use.
- Respond to inquiries — reply to demo requests, sales questions, and support tickets, and manage our relationship with you.
- Improve our offering — understand how our site and Services are used so we can develop new features, fix problems, and enhance performance and security.
- Communications — send you administrative messages and, where permitted, relevant updates about our products; you can opt out of marketing at any time.
- Legal and compliance — meet our legal, regulatory, and contractual obligations, enforce our terms, and protect our rights, users, and systems against fraud and abuse.
4. Legal bases for processing
Where the GDPR or similar laws apply, we rely on one or more of the following legal bases to process your personal information:
- Consent — where you have given clear consent, for example to non-essential cookies or marketing communications. You may withdraw consent at any time.
- Contract — where processing is necessary to enter into or perform a contract with you or your organization, such as delivering the Services.
- Legitimate interests — where processing is necessary for our legitimate interests — such as securing our website, understanding usage, and growing our business — provided those interests are not overridden by your rights.
- Legal obligation — where we must process information to comply with the law.
5. How we share information
We share personal information only in the limited circumstances below:
- Service providers and subprocessors — trusted vendors who process information on our behalf, such as cloud hosting, analytics, email, and customer-relationship tools. They are bound by contract to protect the information and use it only to provide services to us.
- Legal requirements — where disclosure is necessary to comply with applicable law, a valid legal request, or to protect the rights, safety, and property of Deflected, our customers, or the public.
- Business transfers — in connection with a merger, acquisition, financing, or sale of assets, personal information may be transferred as part of that transaction, subject to appropriate safeguards.
Deflected does not sell personal information, and we do not share it for cross-context behavioral advertising, as those terms are defined under the CCPA/CPRA and similar laws.
6. Cookies & analytics
We use cookies and similar technologies for two broad purposes:
- Essential cookies — required for the website to function, remember your preferences, and keep it secure. These cannot be switched off without affecting how the site works.
- Analytics cookies — help us understand how visitors use our site so we can improve it. These are used only where permitted, and where required, with your consent.
You can control cookies through your browser settings, which let you block or delete cookies, and — where we offer one — through any cookie-preference control presented on our site. Blocking some cookies may affect your experience of certain features.
7. Data retention
We keep personal information only for as long as necessary to fulfill the purposes described in this policy, including to provide the Services, maintain security, resolve disputes, and comply with our legal and contractual obligations. When information is no longer needed, we delete it or anonymize it. Retention periods vary depending on the type of information and the reason we hold it; where the law sets a minimum retention period, we honor it.
8. Data security
Security is our core business, and we apply it to our own systems. We protect personal information using strong technical and organizational measures, including:
- Encryption in transit and at rest, including post-quantum cryptography designed to resist both classical and quantum attackers.
- Access controls based on least privilege, with authentication and monitoring for our internal systems.
- Continuous security practices, including logging, testing, and incident-response readiness.
You can read more about our security posture on our security page. No method of transmission or storage is ever completely secure, but we work continuously to protect your information and to improve our safeguards.
9. International data transfers
We may process and store personal information in countries other than the one in which you are located. Where we transfer personal information across borders — including out of the European Economic Area, the United Kingdom, or Switzerland — we put appropriate safeguards in place, such as the European Commission's Standard Contractual Clauses or another lawful transfer mechanism, so that your information continues to receive an adequate level of protection.
10. Your rights
Depending on where you live and the laws that apply to you, you may have some or all of the following rights over your personal information:
- Access — request a copy of the personal information we hold about you.
- Correction — ask us to correct information that is inaccurate or incomplete.
- Deletion — ask us to delete your personal information in certain circumstances.
- Portability — receive certain information in a portable, machine-readable format.
- Objection and restriction — object to, or ask us to restrict, certain processing, including processing based on legitimate interests.
- Opt-out — opt out of marketing communications, and exercise the opt-out rights provided under the CCPA/CPRA.
Under the GDPR, you may also lodge a complaint with your local supervisory authority. Under the CCPA/CPRA, California residents have the right to know, delete, correct, and opt out, and the right not to be discriminated against for exercising those rights. To exercise any right, contact us using the details in Section 13. We will verify your request and respond within the timeframes required by law. You may use an authorized agent where the law permits.
11. Children's privacy
Our website and Services are directed to businesses and are not intended for children. We do not knowingly collect personal information from children under 16. If you believe a child has provided us with personal information, please contact us and we will take appropriate steps to delete it.
12. Changes to this policy
We may update this Privacy Policy from time to time to reflect changes in our practices, technology, or legal requirements. When we make material changes, we will update the "Last updated" date above and, where appropriate, provide additional notice. We encourage you to review this page periodically.
13. Contact us
If you have questions, concerns, or requests regarding this policy or your personal information, please contact us:
- Email: privacy@deflected.ai
- Data controller: [[Legal entity name]]
- Registered address: [[Registered address]]
- Privacy contact: [[Data Protection Officer / privacy contact, if applicable]]
- Governing jurisdiction: [[Governing jurisdiction]]
Questions about your data?
Our team is happy to help with privacy requests or to walk you through how Deflected protects information across your AI layer.