Scope

This Privacy Policy applies to HunterIQ Security websites, contact forms, pricing inquiries, assessments, and managed security services, including Microsoft-focused MDR, XDR, security assessments, compliance evidence support, exposure management, and response readiness services.

For customers under a signed master services agreement, statement of work, data processing agreement, business associate agreement, or similar contract, that agreement controls if it conflicts with this policy.

Information We Collect

We may collect information you provide directly, including your name, work email, phone number, company name, job title, organization size, Microsoft licensing or environment details, service interests, messages, and information submitted through contact, pricing, assessment, or partner forms.

When providing security services, we may process customer-authorized security data, including tenant identifiers, endpoint and identity alerts, audit logs, device information, IP addresses, usernames or business contact details, investigation notes, configuration data, vulnerability or exposure findings, incident evidence, and related security telemetry.

We may also collect website and device data, including IP address, browser type, pages visited, referring pages, approximate location, cookie identifiers, form activity, and similar analytics or security data.

Information We Do Not Want Through Public Forms

Do not submit passwords, access tokens, private keys, patient records, financial account numbers, regulated personal data, incident evidence, or confidential customer files through public website forms. If sensitive material is required, HunterIQ Security will arrange a more appropriate transfer method.

How We Use Information

We use information to respond to inquiries, schedule calls, prepare proposals, deliver assessments, provide managed security services, investigate security events, support customers, maintain service records, improve our website and services, prevent abuse, protect our systems, and comply with legal or contractual obligations.

Customer security data is used to provide, secure, support, measure, and improve the contracted security services. We do not use customer security data for unrelated advertising or sell it to third parties.

How We Share Information

We may share information with service providers that help us operate our business and deliver services, such as website hosting, form processing, email, customer relationship management, cloud infrastructure, ticketing, security tools, analytics, professional advisors, and managed security technology platforms.

We may also share information when required by law, legal process, regulation, contractual obligation, security investigation, emergency response, corporate transaction, or to protect the rights, safety, systems, customers, or property of HunterIQ Security or others.

We do not sell personal information. We do not rent or lease personal information to third parties.

Cookies and Analytics

Our website may use cookies, pixels, analytics tools, or similar technologies to operate the site, remember preferences, understand site performance, detect abuse, and improve user experience. You can control cookies through your browser settings. Some site features may not work as intended if cookies are disabled.

Security Service Data

Managed security services may require authorized access to customer systems, Microsoft tenants, security consoles, endpoints, logs, alerts, reports, and incident records. Access is used only for the services authorized by the customer and is subject to the applicable service agreement.

Customers remain responsible for authorizing access, maintaining appropriate user permissions, managing licensing, approving response actions, and limiting the data they provide to what is necessary for the requested service.

Retention

We retain information for as long as reasonably necessary to provide services, respond to requests, maintain business and security records, meet legal or contractual requirements, resolve disputes, and protect our systems and customers.

Retention periods may vary by data type. For example, contact inquiries, proposals, customer records, assessment findings, security logs, investigation notes, and incident evidence may have different retention periods based on the service, contract, legal requirement, or security need. When information is no longer required, we will delete, anonymize, or securely dispose of it using reasonable methods.

How We Protect Information

We use administrative, technical, and organizational safeguards designed to protect information from unauthorized access, disclosure, alteration, and destruction. These safeguards may include access controls, authentication, encryption where appropriate, monitoring, logging, least-privilege practices, vendor review, and internal security procedures.

No website, network, or service can be guaranteed to be completely secure. If you believe information provided to HunterIQ Security has been exposed or misused, contact us promptly.

Data Transfers

HunterIQ Security is based in the United States. Information may be processed in the United States or other locations where our service providers, security tools, or customer-authorized platforms operate. Privacy and data protection laws may differ by location.

Your Privacy Choices

Depending on your location and applicable law, you may have rights to request access, correction, deletion, portability, restriction, objection, withdrawal of consent, or information about how personal information is used or shared.

You may opt out of marketing communications by using the unsubscribe link in an email or by contacting us. We may still send service, security, legal, or transactional messages when appropriate.

California and Other U.S. State Privacy Rights

Some U.S. state privacy laws provide additional rights for residents, including rights to know what categories of personal information are collected, the purposes of collection, categories of recipients, deletion, correction, and opt-out rights for certain sharing or targeted advertising. HunterIQ Security will respond to applicable privacy requests as required by law.

We do not knowingly sell personal information. If our practices change in a way that requires additional notices or opt-out mechanisms, we will update this policy.

Children's Privacy

Our website and services are intended for businesses and are not directed to children under 13. We do not knowingly collect personal information from children under 13.

Incident and Breach Notice

If HunterIQ Security determines that a security incident involving personal information requires notice, we will provide notice as required by applicable law. Incidents involving customer environments or service data are handled according to the applicable customer agreement and authorized escalation process.

Third-Party Websites

Our website may link to third-party websites, tools, platforms, or resources. Their privacy and security practices are governed by their own policies, not this policy.

Changes to This Policy

We may update this Privacy Policy to reflect changes in our services, technology, legal requirements, or business operations. The updated version will be posted on this page with a revised effective date.

Contact Us

For privacy questions or requests, contact HunterIQ Security at privacy@hunteriqsecurity.com or use the contact form. For security-related reports, contact security@hunteriqsecurity.com.