Privacy Policy

LayerX Security Ltd. (“LayerX Security”, or “we”) is committed to maintaining the privacy of its users (“user”, “you”). The following information describes how LayerX Security, collects and processes information about you when you use our website (the “Website”) and Services (as defined below).

Our Privacy Policy explains:

  • What information we collect and why we collect it.
  • How we use that information.
  • Your rights with regard to the collection of such information.

By using our Website and Services, you agree to this Privacy Policy.

General

LayerX Security offers a browser extension (“Platform”) that enables enterprises (“Customers”), to secure the systems and platforms they utilize. The Platform enhances data security via various technological tools that include analyzing Customer’s users (“End Users”) web sessions, to prevent attacker-controlled webpages from executing malicious activities as well as to prevent End Users from imposing a risk on Customer’s resources. The Platform enables Customers to review and control the activity it designates LayerX Security to prevent, while providing the Customer with risk alerts and enforcing policies and procedures (“Services”). The Website provides information about LayerX Security and its Services and enables its Customers to login to the Services dashboard, request a demo, apply for a job, become a LayerX Security partner, contact for support via a chat and subscribe to LayerX Security’s mailing list.

Collecting Information

Please note that the scope of this Privacy Policy is limited only to information collected by LayerX Security through your use of its Website and Services. Some information may be automatically collected, and some is collected when you interact with our Website and Services. The type of information that may be automatically collected is non-personal information, which includes your session durations, the content you accessed on the Website and Services, the frequency and scope of your use of the Website and Services and information about your computer and internet connection including the operating system you use and browser type.

Information from which you can be personally identified may also be collected, including but not limited to your full name, email address, phone number, company name, job title, CV, the content you’ve submitted and the location of the computer through which you used the Website and Services (hereinafter: “Personal Information”). Personal Information shall be collected only if received voluntarily from you, including, without limitation, via the following ways:

  1. Login to the Services’ Dashboard

If you wish to login to the Services’ dashboard, we may collect your email address to allow you to use the Services.

Per your consent, we will interact with your Google account using Google APIs, and/or Microsoft account using Microsoft APIs. Our use of the Personal Information received from Google APIs will adhere to Google API Services User Data Policy, including the ‘Limited Use’ requirements. When you use the Services’ dashboard we will solicit your consent to connect your Google, or Microsoft account to your LayerX Security account (using among other means Google’s OAuth authentication method), thereby providing us with access to see the Chrome browsers under your organization, view organization units on your domain, view groups on your domain, and see info about End Users on your domain.

 

Users and End Users may revoke their consent for the processing of their Personal Information in connection with their Microsoft account at any time by visiting the following Microsoft sites: https://account.live.com/consent/Manage and/or https://myapps.microsoft.com.

 

  1. Updating your profile

If you wish to update your profile, we will collect your name, email, or any other information you wish to provide. In addition, we may collect personal information such as your picture generated from an integration with your company’s platforms.

 

  1. Request a Demo

If you wish to request a demo via the Website, we will collect your full name, email address, company name, job title, phone number and the content you submitted to provide you with a relevant demo to use our Services.

 

  1. Careers

We will collect your Personal Information when you wish to apply to a job at LayerX Security. Such information includes your full name, phone number, email address, CV, LinkedIn profile URL and other related information.

 

  1. Partner

If you wish to become a LayerX Security partner, we will collect your full name, email address, phone number, job title, company name, and the content you submitted to your request.

 

  1. Newsletter

If you wish to subscribe to our newsletter and to be provided with information on the Services, subject to your consent, we will collect your full name, company name, phone number, email address, and will send you the required materials.

 

  1. Chat

If you wish to contact us for support regarding our Website, Platform, Services, or any other matter, we will collect your full name, company name, phone number, email address, and the content you submitted to facilitate your inquiry.

End User Personal Information

In order to provide the Services, we will collect End Users’ Personal Information, such as their web sessions, which may include sensitive information. Please note that in case you are a Customer utilizing the Services, and in the course of which you are providing us with access to such End User’s Personal Information, you are responsible for providing adequate notice to the End Users whose Personal Information may be processed by LayerX Security for the provision of the Services. This includes, to the extent required, sufficient reference to the processing of their Personal Information via the Services, and any other information necessary to comply with all applicable privacy and data protection laws and obtaining all approvals and consents from individuals as required under the applicable laws.

 

Use of Information

We use the Personal Information we collect from you for a range of different business purposes according to different legal bases of processing. We may use or process your Personal Information for the following purposes. One or more purposes may apply simultaneously.

  1. Providing the Requested Services
    We collect your Personal Information according to the manners mentioned in the previous section to this Privacy Policy to provide you with the requested Services.
    Such collection of information will enable us to provide you with technical and professional assistance, with regard to the Services you are provided with or wish to be provided with.

     

    We process the Personal Information where it is necessary for the adequate performance of the contract regarding the requested Services.

  2. Improvement and Development of the Services
  • We collect Personal Information to improve and develop our Services and understand feedback on LayerX Security Services and Platform to help provide more information on the use of our Platform and Services quickly and easily.
  • We collect Personal Information for ongoing review and improvement of the information provided on our Website and Services to ensure it is user friendly.
  • We collect Personal Information to improve the management and administration of our business and maintain compliancy with our internal policies and procedures.
  • We conduct surveys and research, test features in development, and analyze the information we have to evaluate and improve our Services, develop new features, and conduct audits and troubleshooting activities.

 

We process this information in light of our legitimate interest in improving the Services to allow our users to have the best experience.

  1. Maintain a Safe and Secure Environment
    We may use your information to detect and prevent fraud, abuse and security incidents in the following ways;

    Verify and authenticate your identity and prevent unauthorized or illegal activity;
    Enhance the safety and security of our Website and Platform;
    Conduct security investigations and risk assessments;
    Prevent or take action against activities that are, or may be, in breach of our terms of service or applicable law.

    We process this information in light of our legitimate interest in improving our Services and enabling our users to browse in a secure environment.

  2. Personalize Content, Advertising and Marketing
  • If you have used LayerX Security Services in the past, we have a legitimate business interest for matching the data we collect with other data we had already collected.
  • This enables us to understand your needs and interests, optimize the content we send you and make it more suitable and relevant to your needs.
  • This also enables us to improve your experience on the Website and Services by providing you with personalized content, recommendations, and features.

 

We process this information in light of our legitimate interest to personalize your experience on the Website and Services and customize our content.

Disclosure of Information and Transfer of Data

Except as otherwise provided in this Privacy Policy, we reasonably attempt to ensure that we never intentionally disclose any of your Personal Information, to any third party without having received your permission, except as provided for herein or otherwise as permitted or required under law.

In order to perform our contractual and other legal responsibilities or purposes, we may, from time to time, need to share your Personal Information with third parties. We may as well share your Personal Information with our affiliates, subsidiaries or any third-party service providers and individuals to facilitate our Services or any portion thereof, such as marketing, data management or maintenance services. We may also share your information with analytics service providers, such as Google Analytics, for analytics services. Such analytics service providers set their own cookies or other identifiers on your computer, through which they can collect information about your usage of our Website. This helps us compile aggregated statistics about the effectiveness of our Website, Platform and Services.

The above mentioned third parties may be located in countries other than your own, and we may send them information we receive. When such third-party service providers process your Personal Information on our behalf, we will assure that they comply with obligations similar to those which are set forth in this Privacy Policy. We will also assure that they will abide by our data privacy and security requirements and will be allowed to use the Personal Information solely for the purposes we set. We will transfer your Personal Information while using appropriate and suitable safeguards, while using a variety of legal mechanisms, including contracts, to ensure your rights and protections travel with your data.

We may also transfer your information, including Personal Information, in connection with a corporate merger, consolidation, the sale of related assets or corporate division or other fundamental corporate changes. Furthermore, information about you may also be released in order to comply with any valid legal obligation or inquiry or process such as a search warrant, subpoena, statute or court order. We will also release specific information in special cases, such as if you use the Website and/or Services to perform an unlawful act or omission or take any act or omission that may damage LayerX Security, its property and goodwill, or if there is an attempted breach of the security of the Website or Services or a physical or property threat to you or others. With respect to our data protection practices, you have the right to file a complaint to any relevant supervisory data protection authority.

Roles and Responsibilities

Please note that certain data protection laws and regulations, such as the GDPR or the California Privacy Laws (as defined below) typically distinguish between two main roles for parties processing Personal Information: the “Data Controller” (or under the California Privacy Laws, “Business”), who determines the purposes and means of processing; and the “Data Processor” (or under the California Privacy Laws, “Service Provider”), who processes the data on behalf of the Data Controller (or Business). Please see the below explanation where we elaborate on how these roles apply to our Services, to the extent that such laws and regulations apply.

  1. LayerX Security is the “Data Controller” of its Website users and Customer’s contact details required to contractually engage with Customer. With respect to such data, we assume the responsibilities of the Data Controller (solely to the extent applicable under the law), as set forth in this Privacy Policy. In such instances, our service providers processing such data will assume the role of “data processor”.
  2. LayerX Security is the “Data Processor” of the Personal Information of End Users which we process on behalf of our Customer (who is the “Data Controller” of such Personal Information). Our service providers who process such user Personal Information on our behalf are the “Sub-processors” of such Personal Information.

For the avoidance of doubt, each Customer is solely responsible for providing adequate notice to the End Users whose Personal Information may be processed by LayerX Security for the provision of the Services. This includes, to the extent required, sufficient reference to the processing of their Personal Information via the Services, and any other information necessary to comply with all applicable privacy and data protection laws and obtaining all approvals and consents from individuals as required under the applicable laws.

Your Rights

You have the right at any time to request to access or modify your information. To exercise these options, please contact us at: info@layerxsecurity.com.

In some jurisdictions, in particular those located within the European Union (the “EU“) or within the European Economic Area (the “EEA“), you may be afforded specific rights regarding your Personal Information. Subject to such eligibility, you may have the following rights to:

  1. Request a rectification of your Personal Information where the information we hold about you is incorrect or incomplete.
  2. Object to the processing of your Personal Information for direct marketing purposes.
  3. Object to the processing of your Personal Information where our legal basis for that processing is that such processing is necessary for our legitimate interests.
  4. Object to an automated decision-making (including profiling) in certain circumstances.
  5. Request the erasure of your Personal Information in certain circumstances, such as where processing is no longer necessary for the purpose it was originally collected for, and there is no compelling reason for us to continue to process or store it.
  6. Receive your Personal Information, or ask us to transfer it to another organization that you have provided to us, which we process by automated means, where our processing is either based on your consent or is necessary for the performance of a contract with you.

 

If you wish to file a request regarding any of the above, you may contact us at: info@layerxsecurity.com.

Representation for data subjects in the EU

We value your privacy and your rights as a data subject and have therefore appointed Prighter Group with its local partners as our privacy representative and your point of contact. Prighter gives you an easy way to exercise your privacy-related rights (e.g. requests to access or erase personal data). If you want to contact us via our representative, Prighter or make use of your data subject rights, please visit the following website: : Prighter | Compliance Landing Page of LayerX Security LTD.

Cookies

We may use “cookies” and/or other technologies or files (collectively, “cookies”) to identify how visitors make use of our Website/Services. This aggregated tracking information may be used to help us improve and enhance the Website/Services experience for all of our users. In addition, cookies are used for adjusting the Website/Services to your personal preferences. Cookies contain information such as the pages you visited, the length of time you stayed on the Website/Services, the location from which you accessed the Website/Services and more. If you would prefer not to have cookies stored on your computer, you may modify your browser settings to reject most cookies, or manually remove cookies that have been placed on your computer. However, by rejecting the cookies, you may be unable to fully access the offerings on this Website/Services. For further information regarding cookies, please check our cookies policy at: https://layerxsecurity.com/cookie-policy/

Opt In or Opt Out

You are always in control of your data, and if you choose to receive information from us, or others, you can change your mind later. If, at any time, you would like to stop receiving such information or opt out of a feature, you may notify us by writing to info@layerxsecurity.com. You should be aware, however, that it is not always possible to completely remove or modify information in our databases and servers, although we will always make reasonable efforts to do so upon your request.

Links to Other Websites

This Website and Services may provide links to other websites. Please be aware that these other websites are not covered by our Privacy Policy. This Privacy Policy does not cover the information practices exercised by other providers of products or services, advertisers or other websites, companies or individuals, which are not owned or controlled by LayerX Security. We suggest that when linking to another website, you always read that website’s privacy policy before volunteering any personally identifiable information.

Data Security

We deploy industry standard measures to ensure the security, confidentiality, integrity and availability of the Personal Information we process. We maintain physical, technical and administrative safeguards, and test and update these periodically. We endeavor to restrict access to Personal Information on a ‘need to know’ basis for the provision of the Website, Platform and Services to you. No such measures are perfect or impenetrable. In the event of a security breach, we will take all reasonable action to minimize any harm. Although we will do our best to protect Personal Information, we cannot guarantee the security of data transmitted to us and transmission is at the users own risk.

Data Retention

Generally, LayerX Security does not retain information longer than necessary and for its reasonable business and lawful needs. If you withdraw your consent to us processing your Personal Information, we will erase your Personal Information from our systems, unless the Personal Information is required for LayerX Security to establish, exercise or defend against legal claims or it is necessary for the performance of the requested Services.

Notice to California Residents

This section is designated for California residents and is provided under the California Consumer Privacy Act, as amended by the California Privacy Rights Act of 2020 (“California Privacy Laws”). It explains your privacy rights, provides “notice at collection”, and provides certain mandated disclosures about how we handle your Personal Information. This section uses certain terms that have the meanings given to them by the California Privacy Laws, unless otherwise specified. Please note that some of the disclosure obligations required under the California Privacy Laws are satisfied within other sections of this Privacy Policy.

The California Privacy Laws permit some users to request to exercise certain rights. If these rights are applicable to you, you are afforded with the following rights:

  1. Right of access

You can request LayerX Security for certain information about our practices with respect to your Personal Information. In particular, you can request to receive information on the following:

  • The categories and specific pieces of your Personal Information that we have collected.
  • The categories of sources from which we collected your Personal Information.
  • The business or commercial purposes for which we collected or share your Personal Information.
  • The categories of third parties with which we shared your Personal Information.

 

  1. Right to Opt Out of Sale of your Personal Information

You can be rest assured that we do not sell your Personal Information.

  1. Exercising your California Law Rights

Please note that we will be required to verify your identity and request before an action is taken to exercise your rights. As a part of this process, government identification may be required. Moreover, you may designate an authorized agent to make a request on your behalf. We make our best efforts to respond to a verifiable consumer request within 45 days of its receipt. If we require more time (up to 90 days), we will inform you of the reason and extension period in writing. Any disclosures we provide, will only cover the 12 months period preceding your verifiable request’s receipt. If, for some reason, we cannot reply within such time frame, our response will include an explanation for our inability to comply. If you wish to exercise your California Privacy Laws rights, please contact us at: info@layerxsecurity.com.

  1. Right of No Retaliation Following Opt-Out or Exercise of your Rights

If you choose to exercise your rights, we will not charge you different prices or provide different quality of our Services, unless those differences are related to your provision of your Personal Information. We will not discriminate against you for exercising any of your rights and unless permitted by the California Privacy Laws, we will not:

  1. Deny you goods or services.
  2. Charge you different prices or rates for goods or services, including through granting discounts or other benefits, or imposing penalties.
  3. Provide you with a different level or quality of goods or services.

Suggest that you may receive a different price or rate for goods or services or a different level or quality of goods or services.

CAN SPAM Act

The CAN-SPAM Act is a Federal US law that sets the rules for commercial email, establishes requirements for commercial messages, gives recipients the right to have emails stopped from being sent to them, and spells out tough penalties for violations.

To be in accordance with CAN SPAM, we agree to the following:

  • Not use false or misleading subjects or email addresses.
  • Identify the commercial message sent to you as an advertisement when required.
  • Include the physical address of our business or site headquarters.
  • Monitor third-party email marketing services for compliance, if one is used.
  • Honor opt-out/unsubscribe requests quickly.
  • Allow users to unsubscribe by using the link at the bottom of each email.

If at any time you would like to unsubscribe from receiving future emails, you can email us at info@layerxsecurity.com and we will promptly remove you from ALL correspondence.

Children’s Privacy

The Website, Services and Platform are not intended for children under the age of 16. We do not, knowingly or intentionally, collect information about children who are under 16 years of age.

IF YOU ARE UNDER THE AGE OF 16 YOU MAY NOT USE THE WEBSITE/ PLATFORM/ SERVICS UNLESS PARENTAL CONSENT IS PROVIDED ACCORDINGLY.

Questions Regarding Our Privacy Policy

If you have any questions regarding this Privacy Policy or the practices described above, you are always welcome to contact us at info@layerxsecurity.com

Revisions and Modifications to our Privacy Policy

We reserve the right to revise, amend, or modify this Privacy Policy at any time. When changing the policy, we will update this posting accordingly. Please review this Privacy Policy often so that you will remain updated regarding our current policies.

Governing Law and Jurisdiction

This Privacy Policy will be governed and interpreted pursuant to the laws of the State of Israel without giving effect to its choice of law rules. You expressly agree that the exclusive jurisdiction for any claim or action arising out of or relating to this Privacy Policy shall be to the competent courts in Tel Aviv, Israel, to the exclusion of any other jurisdiction.

 

This page was updated in July 2024.