Phylaxa

Privacy Policy

Last updated: 2026-07-21

This Privacy Policy explains how Phylaxa, Inc. (“Phylaxa”, “we”, “us” or “our”) collects, uses, discloses and safeguards personal data in connection with the Phylaxa bot management platform, the phylaxa.example website and related services (collectively, the “Service”).

1. Overview

This Policy applies to three categories of individuals: visitors to our website, representatives of customers who register for or administer the Service, and end users of the websites, mobile applications and APIs on which our customers deploy Phylaxa detection. The data we process — and the capacity in which we process it — differs across these categories and is described below.

This Policy does not apply to third-party properties that we do not control, including customer properties on which Phylaxa is deployed. Those properties are governed by the privacy policies of the respective customers.

2. Controller and Processor Roles

Phylaxa is a bot detection service, and this shapes our privacy role. When you visit our website, request a demo or administer a customer account, Phylaxa acts as the data controller of your personal data. When a customer deploys Phylaxa on its own digital properties, the roles reverse: the customer determines why and how end-user traffic is analyzed, and Phylaxa processes the resulting telemetry strictly as a data processor acting on the customer’s documented instructions.

For end-user telemetry, the customer is the controller (or “business” under the CCPA) and Phylaxa is the processor (or “service provider”). That processing is governed by our Data Processing Addendum rather than by this Policy. If you are an end user of a Phylaxa-protected property, please direct privacy requests to the operator of that property; we will reasonably assist the operator in responding.

3. Information We Collect

We collect only the data required to operate, secure and improve the Service:

  • Account data — name, work email address, company, job role, authentication credentials and billing details, provided when you register, request a demo or contact us.
  • Usage and telemetry data — IP addresses, device and browser characteristics, TLS and HTTP/2 connection parameters, interaction timing and navigation patterns, collected from end-user sessions on customer properties solely to distinguish human from automated traffic.
  • Cookie and tracking data — strictly necessary cookies required to operate our website and customer dashboard. We do not use third-party advertising cookies and do not engage in cross-site tracking.

4. How We Use Information

We use the data we collect for the following purposes:

  • to provide, operate and maintain the Service, including scoring traffic and returning risk verdicts to customers;
  • to secure the Service, prevent abuse of our own systems and improve our detection models using aggregated or de-identified traffic data;
  • to communicate with you about your account, product updates, security incidents and — where permitted — product news and event invitations;
  • to comply with legal obligations, enforce our agreements and defend our legal rights.

5. Legal Bases for Processing

Where the GDPR or UK GDPR applies, we process personal data on the following legal bases:

  • performance of a contract (Art. 6(1)(b) GDPR), for example to deliver the Service to the customer you represent;
  • legitimate interests (Art. 6(1)(f) GDPR), such as securing the Service, detecting automated abuse and improving detection accuracy, where those interests are not overridden by your rights;
  • consent (Art. 6(1)(a) GDPR), for optional cookies and certain marketing communications, which you may withdraw at any time;
  • compliance with a legal obligation (Art. 6(1)(c) GDPR), for example tax, accounting and law-enforcement requirements.

6. Data Sharing and Subprocessors

We do not sell personal data, and we do not share it for cross-context behavioral advertising. We disclose personal data only to:

A current list of subprocessors is maintained in our Data Processing Addendum and is available to customers on request.

  • subprocessors that host, deliver and support the Service — including cloud hosting, content delivery, email delivery, billing and error-monitoring providers — each bound by written data protection terms no less protective than our own;
  • professional advisers, regulators, courts and law-enforcement authorities, where disclosure is required by law or necessary to protect rights, safety and security;
  • a successor entity in connection with a merger, acquisition, financing or sale of assets, subject to the continued application of this Policy.

7. Data Retention

We retain account data for the duration of the customer relationship and for a limited period afterward, as required for legal, accounting and audit purposes. End-user detection telemetry is retained in identifiable form for no more than 30 days by default; customers may configure shorter retention windows.

After the applicable retention period, telemetry is deleted or irreversibly de-identified. Aggregated statistics that can no longer be linked to an individual may be retained to measure and improve detection performance.

8. International Data Transfers

Phylaxa is headquartered in the United States and processes data in the regions where the Service operates. Where personal data is transferred from the European Economic Area, the United Kingdom or Switzerland to a country without an adequacy decision, we rely on the European Commission’s Standard Contractual Clauses (and the UK addendum), together with supplementary technical and organizational measures.

Regional data residency options are available for enterprise deployments, allowing detection telemetry to be processed and stored within a chosen region.

9. Security

We maintain technical and organizational measures designed to protect personal data against accidental or unlawful destruction, loss, alteration and unauthorized access or disclosure. These include encryption in transit using TLS and at rest, least-privilege access controls, audit logging, segregated environments and security controls aligned with SOC 2 criteria.

No method of transmission or storage is completely secure. If we become aware of a personal data breach, we will notify affected customers and, where required, supervisory authorities and individuals, in accordance with applicable law.

10. Your Privacy Rights

Depending on your jurisdiction — including under the GDPR, the UK GDPR and the CCPA as amended by the CPRA — you may have some or all of the following rights:

To exercise these rights, contact us at privacy@phylaxa.example. We will verify your request and respond within the period required by applicable law. If your data was collected on a customer’s property, please contact that customer directly; as a processor, we will assist the customer in honoring your request.

  • to access the personal data we hold about you, and to receive a copy in a portable format;
  • to correct inaccurate data and to request deletion of your data;
  • to restrict or object to processing based on legitimate interests, and to withdraw consent where processing is based on consent;
  • to opt out of the sale or sharing of personal data — which we do not conduct — and to be free from discrimination for exercising your rights;
  • to lodge a complaint with your local supervisory authority.

11. Cookies and Similar Technologies

Our website and customer dashboard use only strictly necessary cookies and similar technologies required for authentication, security and load balancing. Because we do not use analytics or advertising cookies, no cookie-consent banner is required on our website.

You can configure your browser to refuse cookies; doing so may prevent the customer dashboard from functioning. On customer properties, any cookies set by the Phylaxa agent are first-party cookies controlled by the customer.

12. Children's Privacy

The Service is directed to businesses and is not intended for children under the age of 16. We do not knowingly collect personal data from children. If you believe a child has provided us with personal data, contact us at privacy@phylaxa.example and we will delete it.

13. Changes to This Policy and Contact

We may update this Policy from time to time. If we make material changes, we will notify customers by email or through the dashboard before the changes take effect, and we will always indicate the date of the latest revision at the top of this page.

Questions, requests and complaints about this Policy or our data practices may be directed to our privacy team at privacy@phylaxa.example.

This is a sample document. Have legal counsel review it before production use.