
Privacy Policy
Note: Our privacy policy is changing effective September 17, 2024. The policy will be updated to reflect technological changes to the site and to account for multiple new privacy laws and rights that have been implemented since the last update in 2022. One main change is more robust documentation of collection and disclosure of information by Wonk Security and third-party services used to run this site.
In plain terms (not to supersede the actual legal terms below), by accessing this site, your IP address and location will be processed by services like Cloudflare and WordFence WAF to determine you are not a bot or up to shady things. If you’re not doing anything shady, your information will delete after 30 days; if you are doing something shady then you will be banned forever – your data will be retained forever to maintain this ban. Akismet anti-spam will process any messages sent to me to prevent me getting inundated with junk. Cloudflare and Bluehost will serve you site content from their CDN to speed up site access. WordPress.org will also process your information if you use any features like comments or logins (if they are opened in the future). Complianz will process your cookie preferences and will attempt to auto-opt you out of cookies if you have Do Not Track enabled. If you email me or use a WPForms contact form, I will get your name and email address, obviously. These are strictly necessary for me to respond to you.
Tl;dr – this site collects and discloses the bare amount of information necessary to prevent abuse, ban or block suspicious activity, and stop spam through WordPress plugins and third-party services. I do not advertise to, track, or collect sophisticated analytics on legitimate users (however, suspicious visitors attempting to access forbidden directories, for example, are robustly monitored). As a privacy advocate, I do not want your PII past what is necessary to protect my site and my work. Once your data has served one of the purposes described above, it is deleted. Now for many words saying that in formal terms.
PRIVACY POLICY
- Visit our website
at https://wonksecurity.com or any website of ours that links to this Privacy Notice
- Use
Threat Intelligence and Consulting Services .Wonk Security offers analytic and research products via reports and blog posts, or by request (when we are accepting new clients). Wonk Security also provides strategic risk consulting services aimed at helping clients prepare for and mitigate risks from geopolitical, reputational, and digital threats.
- Engage with us in other related ways, including any marketing or events
SUMMARY OF KEY POINTS
TABLE OF CONTENTS
1. WHAT INFORMATION DO WE COLLECT?
Personal information you disclose to us
In Short: We collect personal information that you provide to us.names
email addresses
2. HOW DO WE PROCESS YOUR INFORMATION?
In Short: We process your information to provide, improve, and administer our Services, communicate with you, for security and fraud prevention, and to comply with law.- To deliver and facilitate delivery of services to the user. We may process your information to provide you with the requested service.
- To respond to user inquiries/offer support to users. We may process your information to respond to your inquiries and solve any potential issues you might have with the requested service.
- To protect our Services. We may process your information as part of our efforts to keep our Services safe and secure, including fraud monitoring and prevention.
- To save or protect an individual’s vital interest. We may process your information when necessary to save or protect an individual’s vital interest, such as to prevent harm.
3. WHAT LEGAL BASES DO WE RELY ON TO PROCESS YOUR INFORMATION?
In Short: We only process your personal information when we believe it is necessary and we have a valid legal reason (i.e.- Consent. We may process your information if you have given us permission (i.e.
, consent) to use your personal information for a specific purpose. You can withdraw your consent at any time. Learn more about withdrawing your consent.
- Performance of a Contract. We may process your personal information when we believe it is necessary to
fulfill our contractual obligations to you, including providing our Services or at your request prior to entering into a contract with you.
- Legitimate Interests. We may process your information when we believe it is reasonably necessary to achieve our legitimate business interests and those interests do not outweigh your interests and fundamental rights and freedoms. For example, we may process your personal information for some of the purposes described in order to:
- Diagnose problems and/or prevent fraudulent activities
- Legal Obligations. We may process your information where we believe it is necessary for compliance with our legal obligations, such as to cooperate with a law enforcement body or regulatory agency, exercise or defend our legal rights, or disclose your information as evidence in litigation in which we are involved.
- Vital Interests. We may process your information where we believe it is necessary to protect your vital interests or the vital interests of a third party, such as situations involving potential threats to the safety of any person.
- If collection is clearly in the interests of an individual and consent cannot be obtained in a timely way
- For investigations and fraud detection and prevention
- For business transactions provided certain conditions are met
- If it is contained in a witness statement and the collection is necessary to assess, process, or settle an insurance claim
- For identifying injured, ill, or deceased persons and communicating with next of kin
- If we have reasonable grounds to believe an individual has been, is, or may be victim of financial abuse
- If it is reasonable to expect collection and use with consent would compromise the availability or the accuracy of the information and the collection is reasonable for purposes related to investigating a breach of an agreement or a contravention of the laws of Canada or a province
- If disclosure is required to comply with a subpoena, warrant, court order, or rules of the court relating to the production of records
- If it was produced by an individual in the course of their employment, business, or profession and the collection is consistent with the purposes for which the information was produced
- If the collection is solely for journalistic, artistic, or literary purposes
- If the information is publicly available and is specified by the regulations
- We may disclose de-identified information for approved research or statistics projects, subject to ethics oversight and confidentiality commitments
- Content
Optimization
- Data Backup and Security
- Functionality and Infrastructure
Optimization
- User Commenting and Forums
- Website Hosting
- Business Transfers. We may share or transfer your information in connection with, or during negotiations of, any merger, sale of company assets, financing, or acquisition of all or a portion of our business to another company.
6. IS YOUR INFORMATION TRANSFERRED INTERNATIONALLY?
In Short: We may transfer, store, and process your information in countries other than your own.7. HOW LONG DO WE KEEP YOUR INFORMATION?
In Short: We keep your information for as long as necessary to8. HOW DO WE KEEP YOUR INFORMATION SAFE?
In Short: We aim to protect your personal information through a system of9. DO WE COLLECT INFORMATION FROM MINORS?
In Short: We do not knowingly collect data from or market to10. WHAT ARE YOUR PRIVACY RIGHTS?
In Short:11. CONTROLS FOR DO-NOT-TRACK FEATURES
Most web browsers and some mobile operating systems and mobile applications include a Do-Not-Track (12. DO UNITED STATES RESIDENTS HAVE SPECIFIC PRIVACY RIGHTS?
In Short: If you are a resident ofCategories of Personal Information We Collect
The table below shows the categories of personal information we have collected in the past twelve (12) months. The table includes illustrative examples of each category and does not reflect the personal information we collect from you. For a comprehensive inventory of all personal information we process, please refer to the section| Category | Examples | Collected |
|---|---|---|
A. Identifiers | Contact details, such as real name, alias, postal address, telephone or mobile contact number, unique personal identifier, online identifier, Internet Protocol address, email address, and account name |
B. Personal information as defined in the California Customer Records statute | Name, contact information, education, employment, employment history, and financial information |
Gender, age, date of birth, race and ethnicity, national origin, marital status, and other demographic data | ||
Transaction information, purchase history, financial details, and payment information | ||
Fingerprints and voiceprints | ||
Browsing history, search history, online | ||
Device location | ||
Images and audio, video or call recordings created in connection with our business activities | ||
Business contact details in order to provide you our Services at a business level or job title, work history, and professional qualifications if you apply for a job with us | ||
Student records and directory information | ||
Inferences drawn from any of the collected personal information listed above to create a profile or summary about, for example, an individual’s preferences and characteristics | ||
- Receiving help through our customer support channels;
- Participation in customer surveys or contests; and
- Facilitation in the delivery of our Services and to respond to your inquiries.
- Category A –
30 days
- Category
F – 30 days
- Category
G – 30 days
Sources of Personal Information
Learn more about the sources of personal information we collect inHow We Use and Share Personal Information
- Category A. Identifiers
Your Rights
You have rights under certain US state data protection laws. However, these rights are not absolute, and in certain cases, we may decline your request as permitted by law. These rights include:How to Exercise Your Rights
To exercise these rights, you can contact us Request Verification
Upon receiving your request, we will need to verify your identity to determine you are the same person about whom we have the information in our system. We will only use personal information provided in your request to verify your identity or authority to make the request. However, if we cannot verify your identity from the information already maintained by us, we may request that you provide additional information for the purposes of verifying your identity and for security or fraud-prevention purposes.Appeals
Under certain US state data protection laws, if we decline to take action regarding your request, you may appeal our decision by emailing us at California
California Civil Code Section 1798.83, also known as the 13. DO OTHER REGIONS HAVE SPECIFIC PRIVACY RIGHTS?
In Short: You may have additional rights based on the country you reside in.Australia
Republic of South Africa
At any time, you have the right to request access to or correction of your personal information. You can make such a request by contacting us by using the contact details provided in the section 14. DO WE MAKE UPDATES TO THIS NOTICE?
In Short: Yes, we will update this notice as necessary to stay compliant with relevant laws.15. HOW CAN YOU CONTACT US ABOUT THIS NOTICE?
If you have questions or comments about this notice, you may 16. HOW CAN YOU REVIEW, UPDATE, OR DELETE THE DATA WE COLLECT FROM YOU?
