Legal

Privacy Policy

Effective: September 9, 2026Last updated: September 9, 2026

This Privacy Policy explains how TigerIdentity, Inc. (“TigerIdentity,” “we,” “us,” or “our”) collects, uses, discloses, and safeguards personal data when you visit tigeridentity.com or use the TigerIdentity non-human identity security platform (collectively, the “Service”). We are the controller of the personal data we collect through this website. When you use the Service to process identity data belonging to your organisation, we act as a processor on your behalf under the terms of your subscription agreement.

1. Scope

This policy applies to personal data we collect from (a) visitors to our website, (b) prospects and customers who submit forms, request a trial, or book a demo, and (c) authorised users of the TigerIdentity platform. It does not apply to third-party services that link from our website but operate under their own privacy policies.

2. Information We Collect

2.1 Information you provide directly

  • Account information. Name, work email, company, job title, phone number.
  • Trial and sales enquiries. Company size, use case description, and any other information you submit through our forms.
  • Billing information. Where applicable, billing contact and payment details (payments are processed by our payment provider; TigerIdentity does not store full card numbers).
  • Support and communications. The content of emails, tickets, and messages you send us.
  • Newsletter and marketing preferences. Subscription state and topics of interest.

2.2 Information collected automatically

  • Usage data. Features accessed, pages viewed, buttons clicked, and other product-analytics events.
  • Device and log data. IP address, browser type, operating system, device identifiers, referring URL, and timestamps.
  • Cookies and similar technologies. See §9 below.

2.3 Information you submit to the platform

When you use the Service, you may submit or connect data about your organisation’s non-human identities, secrets, workloads, AI agents, policies, and audit events (“Customer Data”). We process Customer Data on your behalf under your subscription agreement and any applicable Data Processing Addendum.

3. How We Use Personal Data

We use personal data to:

  • Provide, operate, and maintain the Service and website.
  • Provision trial and paid environments requested by prospects.
  • Communicate with you about the Service, security incidents, and product updates.
  • Process payments and manage subscriptions.
  • Analyse and improve product performance and user experience.
  • Detect, prevent, and respond to security incidents and abuse.
  • Meet legal, regulatory, tax, and contractual obligations.

4. Legal Bases (EEA / UK)

Where the GDPR or UK GDPR applies, we rely on the following legal bases:

  • Contract. To provide the Service you have purchased or requested.
  • Legitimate interests. To secure our website, prevent fraud and abuse, understand product usage, and develop new features. Where we rely on legitimate interests, we balance them against your rights and freedoms.
  • Consent. For optional analytics, marketing communications, and certain cookies. You can withdraw consent at any time.
  • Legal obligation. Where processing is required to comply with applicable law.

5. How We Share Personal Data

We do not sell personal data. We share personal data only as follows:

  • Sub-processors. Cloud infrastructure, email, analytics, CRM, and payment providers who process data on our behalf under written contracts. Our current sub-processor list is available on request.
  • Affiliates. Companies within the TigerIdentity corporate group, under equivalent protections.
  • Business transfers. If we are involved in a merger, acquisition, or sale of assets, personal data may be transferred as part of that transaction, subject to standard confidentiality protections.
  • Legal and safety. When required by law or legal process, or to protect our rights, users, or the public.
  • With your consent. Where you have explicitly directed us to share information (for example, in a case study).

6. International Transfers

TigerIdentity operates in the United States. When we transfer personal data from the EEA, UK, or Switzerland, we rely on appropriate transfer mechanisms including the European Commission’s Standard Contractual Clauses, the UK Addendum, and, where applicable, the EU-US Data Privacy Framework. A copy of the relevant safeguards is available on request from privacy@tigeridentity.com.

7. Data Retention

  • Account data. Retained for the duration of your subscription and for a reasonable period afterwards for legal, tax, and audit purposes (typically up to seven years).
  • Customer Data. Retained per your subscription agreement and configurable retention policy. On termination, Customer Data is available for export for thirty (30) days before deletion in the ordinary course of business.
  • Audit logs. Default 90-day retention, configurable per tenant.
  • Marketing data. Retained until you unsubscribe or object.
  • Website logs. Typically retained for up to 30 days for security investigations.

8. Security

We implement administrative, technical, and organisational safeguards designed to protect personal data, including:

  • Encryption in transit (TLS 1.2+) and at rest (AES-256).
  • Least-privilege access controls, SSO, and MFA for internal systems.
  • Tenant isolation and defence-in-depth network segmentation.
  • Continuous vulnerability management and annual third-party penetration tests.
  • SOC 2 Type II attestation and alignment with ISO/IEC 27001 controls.
  • An incident response programme with defined notification obligations.

No security control is perfect. If you believe your data has been compromised, contact security@tigeridentity.com.

9. Cookies and Similar Technologies

We use strictly necessary cookies to operate the website and the platform, and, with your consent where required, analytics cookies to understand how the site is used. You can manage cookie preferences through your browser or the cookie banner shown on first visit. Blocking strictly necessary cookies may affect site functionality.

10. Your Rights

Depending on your location, you may have the right to (a) access personal data we hold about you, (b) request correction of inaccurate data, (c) request deletion, (d) object to or restrict certain processing, (e) request data portability, and (f) withdraw consent. To exercise any of these rights, email privacy@tigeridentity.com. We will respond within the timelines required by applicable law and may need to verify your identity before acting on a request.

You also have the right to lodge a complaint with your local data protection authority. For EU residents, this is typically the authority of the country in which you reside or work.

11. US State Privacy Notices (CCPA / CPRA and others)

If you are a resident of California, Colorado, Connecticut, Virginia, Utah, or another US state with a comprehensive privacy law, you may have specific rights to know, access, delete, correct, and opt out of the sale or sharing of your personal data. TigerIdentity does not sell personal data or share it for cross-context behavioural advertising. To exercise these rights, email privacy@tigeridentity.com. We will not discriminate against you for exercising your rights.

12. Children

The Service is intended for use by organisations and business users, not children. We do not knowingly collect personal data from anyone under 16. If you believe a child has provided personal data to us, contact privacy@tigeridentity.com and we will delete it.

13. Changes to This Policy

We may update this Privacy Policy from time to time. If we make material changes we will provide reasonable notice by email or through the Service. The “Effective” and “Last updated” dates at the top of this page will always reflect the most recent revision.

14. Contact

For privacy questions or to exercise your rights, contact us at:

TigerIdentity, Inc.. Privacy

Email: privacy@tigeridentity.com

131 Continental Dr, Suite 305 Newark, Delaware 19713 United States