Simplifying Zero Trust Security for AWS with Teleport
Jan 23
Virtual
Register Now
Teleport logoTry For Free
Teleport Access Platform

Privacy Policy | Your Data Protection and Privacy Rights

We care about protecting your data. Read Teleport's Privacy Policy to understand what information we collect, how it's used, and your privacy choices. Last Updated: October 23, 2024

This Privacy Policy is the most current version and is applicable after October 23, 2024.

Previous Privacy Policy Versions

This Privacy Policy (the “Privacy Policy”) serves to inform you of our policies and procedures regarding the collection, use and disclosure of the information we receive when you access and use the website (the “Site”), services, software, mobile applications, content, and all other products and services (all of the foregoing collectively, the “Services”) owned, controlled or offered, directly or indirectly, by Gravitational, Inc. (together with its subsidiaries and affiliates, “Gravitational”, “we,” “our” or “us”). Gravitational believes that the privacy of its users is paramount and strives to use Personal Information (as defined below) only in ways outlined in this Privacy Policy. The Privacy Policy is incorporated by reference into our Terms of Service, currently available at https://goteleport.com/legal/tos/ (the “Terms of Service”). Any terms used herein and not defined will have the meanings given to them in the Terms of Service. By using the Services, you hereby warrant and represent that you have read, understand and agree to this Privacy Policy and the Terms of Service and that you are over 18 years of age. PLEASE DO NOT USE, INSTALL OR ACCESS THE SERVICES IF YOU DO NOT AGREE TO THIS PRIVACY POLICY.

What We Mean by Personal Information

For purposes of this Privacy Policy, “Personal Information” means any information that identifies, relates to, or could reasonably be linked, directly or indirectly, with a particular individual.

Information We Collect

Information You Provide To Us

When you use the Services or otherwise communicate with us, we collect information that you provide to us directly. For example, we collect information in the following circumstances: you (i) visit the Site, (ii) register for the Services or create an account or profile or accept the creation of an account or profile on your behalf (an “Account”), (iii) access the Services through third party services, (iv) subscribe to newsletters, register for events, or download whitepapers and other materials, (v) invite others to use or join the Services, “share” the Services on social networking sites, or perform other similar actions, (vi) request technical support, (vii) otherwise use our online Services where Personal Information is required for such use and/or participation, (viii) when you sign up for an automated email or other communication, and (ix) when you contact us via the Site or when you otherwise communicate with us. You can choose not to provide information that is requested of you by us; however, this may limit your ability to use or access the Services.

The information you provide to us directly may include, without limitation, the following information that may, alone or in combination with other data, constitute Personal Information:

  • Information you provide in connection with registering an Account, including your name, email address, and any other information you decide to provide;
  • Information you provide in order to authenticate an Account, including your Account name, password, and any other information you decide to provide;
  • Information you provide in connection with completing a transaction or purchase using the Services;
  • Information you provide in connection with using the Services, including through our forms, via email, chatting or otherwise interacting with chat style bots, or by contacting us in any way, including your name, company name, phone number, e-mail address, and any other information you decide to provide;
  • Information you provide through conferences, events, and surveys, including your name, e-mail address, phone number, and any other information you decide to provide;
  • Information you provide in order to subscribe to our newsletters and updates, including your email address or phone number, the topic for which you wish to receive updates, or any other information you decide to provide us with. You may always unsubscribe from these emails by following the instructions included;
  • If you are one of our customers, suppliers or prospects, we may process limited Personal Information in the course of our business relation with you, for example when you place an order, request a demo or vice versa. Such Personal Information may include your name, company, title, e-mail address, telephone number, address, and transaction data; and
  • Any other information you may want to share with us, such as Personal Information related to recruitment / job applications.

Moreover, if you contact us, a record of such correspondence may be kept.

Additionally, if another user refers you to us by providing us with your e-mail address, we may send you a message.

Automatically Collected Information

Most of the data we collect in and through the Site and the Services is technical in nature and is collected and processed automatically through so-called application programming interfaces, software development kits, cookies, and similar software-based technologies. Alone or in combination with other data, such automatically collected data may constitute Personal Information. The data we may collect by automated means may include, without limitation:

  • Device data: including, but not limited to, data on device advertising IDs and similar hardware qualifiers, and precise location data.
  • Network and usage data: including, but not limited to, URLs, Internet Protocol addresses, location information, active (TCP/IP) ports, network/Wi-Fi access points, use of spoofing, number of sessions initiated, bounce rates, click streams, search terms entered, browsing history, pages or content viewed or accessed, and any other actions taken through the Services.
  • Information we collect on the use of the Site via cookies: please see the “How We Use Cookies and Other Technologies” section below for more information.

Information You Post on the Services

The Services may provide chat, forum, or bulletin board tools to users. Information that you provide through the use of these tools may be available to the public generally. Gravitational has no obligation to keep private any information that you disclose to other users or the public using these functions. You should exercise caution when deciding to disclose Personal Information through the use of these tools or functions. We strongly recommend that you do not post any information through the Services that allows strangers to identify or locate you or that you otherwise do not want to share with the public.

Information You Share on Third Party Websites or through Social Media Services

The Services may include links to third party websites and social media services where you will be able to post comments, stories, reviews or other information. Your use of these third party websites and social media services may result in the collection or sharing of information about you by these third party websites and social media services. We encourage you to review the privacy policies and settings on the third party websites and social media services with which you interact to make sure you understand the information that may be collected, used, and shared by those third party websites and social media services.

How We Use Cookies and Other Technologies

Some of the features on the Site and the Services require the use of “cookies” - small text files that are stored on your device’s hard drive. We use cookies in a variety of ways, including to measure which pages are being accessed, understand the discoverability of pages, how best to advertise to users, and which features are most frequently used.

We and our service providers may use “pixel tags,” “web beacons,” “clear GIFs,” or similar means in connection with the Services and HTML-formatted email messages to, among other things, track the actions of users, to determine the success of marketing campaigns and to compile aggregate statistics about Site usage and response rates. Our advertisement partners may use a “pixel tag” to collect information about your visits to the Site and to other websites, and they may use that information to target advertisements for goods and services. This information is collected in a manner that may identify you directly and may be linked to the actions you take on the Site and other websites.

Analytics providers also collect information through the Site. For example, by using cookies, Google Analytics collects and stores data such as time of visit, pages visited, time spent on each page of the Site, the Internet Protocol address, and the type of operating system used in the devices used to access the Site.

Use of Collected Information

We use the information you provide to us for the following purposes: (i) to provide the Services, including without limitation to collect and remit payment for paid features, (ii) to administer your use of the Services and any Accounts you may have with us, (iii) to personalize your experience, (iv) to provide to you Service announcements or inform you of new releases and features, (v) to provide you with further information and offers from us or third parties that we believe you may find useful or interesting, such as newsletters, advertisements, marketing or promotional materials, (vi) to perform tasks on behalf of and according to instructions of a third party, such as payment processors, third party-service providers or our advertising partners, (vii) to enforce our Terms of Service, (viii) to resolve any disputes between users of the Site or between such users and us, (ix) comply with a legal requirement or process, including, but not limited to, civil and criminal subpoenas, court orders or other compulsory disclosures; (x) to protect our rights, property, or safety and the rights, property and safety of the Services, our users or the public, and (xi) to contact you to obtain feedback from you regarding the Site and the Services.

In addition to the purposes described above, we use the information collected automatically to (i) to monitor and analyze the use of the Services and for the technical administration of the Site, (ii) improve the Site and the Services, (iii) generate and derive useful data and information concerning the interests, characteristics and website use behavior of our users, and (iv) verify that users of the Services meet the criteria required to process their requests. We and our advertising partners may use audience demographic and location inferred from your IP address, as well as information logged from your hardware or device, including data such as IP address, device model and ID, MAC address, operating system, application usage data, device time zone, region and language, and click ID, to ensure relevant content or advertising is presented within the Services.

We perform the activities above on the grounds that they are necessary: (i) to provide the Services and fulfill the terms of our agreements with you, (ii) for purposes of our and our users’ legitimate interests, or (iii) for compliance with our legal obligations.

Third Parties We Share Personal Information With

We may disclose Personal Information you provide to us or that we collect automatically on the Site and in and through the Services with the following categories of third parties:

  • Service providers, such as payment processors, web hosting and data storage service providers, communications service providers, advertising and marketing providers and partners, and analytics providers;
  • Public authorities, such as law enforcement, if we decide to do so or if we need to protect our rights or the rights of third parties or other users; and
  • Our subsidiaries and affiliates; or a subsequent owner, co-owner or operator of the Site and/or the Services and their advisors in connection with a corporate merger, consolidation, restructuring, the sale of substantially all of our stock and/or assets, or in connection with bankruptcy proceedings, or other corporate reorganization, in accordance with this Privacy Policy.

We frequently make content or services from other websites available to you from links located on the Site. We may present links in a format that enables us to keep track of whether these links have been followed. In addition, you may opt to link your Account to other third party accounts, which are governed by the respective policies of these third parties. This Privacy Policy applies only to the Site and the Services. We do not exercise control over third party services or other websites that provide information, or links from within the Site or the Services. Your interactions with these third party services are governed by the privacy policy of the company providing it. These other sites and services may place their own cookies or other files on your computer’s browser, collect data or solicit Personal Information from you. Other websites and services follow different rules regarding the use or disclosure of the Personal Information that you submit, and the collection and use of such information and access of any third party websites are subject to such third party’s privacy policy. We encourage you to read the privacy policies and other terms of such third parties before using their services.

Security

We understand the importance of privacy and security of Personal Information to our users and have made them a priority. Gravitational uses a variety of industry-standard security technologies and procedures to help protect Personal Information about you from unauthorized access, use, or disclosure and trains Gravitational employees on privacy and security issues. However, we cannot guarantee that unauthorized third parties will never be able to overcome those measures or use your Personal Information for improper purposes, and we do not promise that Personal Information about you or private communications will be protected from unauthorized disclosure or use. If you have reason to believe that the security of your account may have been compromised or that someone else is using your account, please change your password immediately and let us know at [email protected].

Do Not Track Signals

Some web browsers transmit “do-not-track” signals to websites. Because of differences in how web browsers incorporate and activate this feature, it is not always clear whether users intend for these signals to be transmitted, or whether they even are aware of them. We currently do not take action in response to these signals.

Managing Your Privacy

You can correct or terminate and delete your Account information by following the instructions on the Services or by email at [email protected], which you may also access for further assistance and questions regarding the Privacy Policy or for a copy of your Account data. If you request us to delete your information, Gravitational will limit its access to Personal Information to perform what is requested by you and will delete information accessible to Gravitational within the maximum time provided by the applicable privacy law.

Your Rights

We take steps to allow you to exercise your rights regarding Personal Information about you in accordance with applicable law. If you would like to access, review, erase, withdraw your consent, or object to, or restrict the processing of Personal Information we collect about you, you may submit a request to [email protected]. We will promptly review all such requests in accordance with applicable laws. Depending on where you live, you may also have a right to lodge a complaint with a supervisory authority or other regulatory agency if you believe that we have violated any of the rights concerning Personal Information about you. We encourage you to first reach out to us at [email protected], so we have an opportunity to address your concerns directly before you do so.

California Residents

How we Handle your Personal Information

The California Consumer Privacy Act (CCPA) requires that we make certain disclosures to California residents, including the categories of Personal Information we collect, the categories of sources of Personal Information, the purposes for which we use that Personal Information, and the categories of third parties to whom we disclose Personal Information for a business purpose or to whom we “Sell” Personal Information or "Share" Personal Information for cross-context behavioral advertising (as described below). The sections below lay out this information in the manner specified by the CCPA, but do not differ in substance from the information above in our Privacy Policy.

Sources of Personal Information

All the categories of Personal Information we collect come from the following categories of sources:

  • You (either via voluntary submission or automatic collection, such as when you use the Services);
  • Our affiliates; and
  • Third parties (such as service providers, other users, advertising or marketing partners who may refer you to our services, and your organization if they are our customer).

Categories, Purposes of Use, and Disclosures of Personal Information

Category of Personal InformationPurposes of UseCategories of Third Parties to Whom We Disclose this Personal InformationCategories of Third Parties to Whom We “Sell” this Personal InformationCategories of Third Parties to Whom We “Share” this Personal Information
Contact and account informationProvide the Services; Business Operations; Communicate with you; Marketing and advertising; Improve the Services; With your consentAffiliated entities; Service providers; Online advertising partners; Connected third-party services; Entities for legal purposes; Entities for business transactionsAd networks and advertising partners; Analytics providersAd networks and advertising partners
Financial and transactional informationProvide the Services; Business Operations; Communicate with you; Marketing and advertising; Improve the Services; With your consentAffiliated entities; Service providers; Entities for legal purposes; Entities for business transactionsAd networks and advertising partners; Analytics providersAd networks and advertising partners
Customer service interaction informationBusiness Operations; Communicate with you; Improve the Services; With your consentAffiliated entities; Service providers; Entities for legal purposes; Entities for business transactionsWe do not shareWe do not share
Surveys and sweepstakes informationBusiness Operations; Communicate with you; Marketing and advertising; Improve the Services; With your consentAffiliated entities; Service providers; Entities for legal purposes; Entities for business transactionsWe do not shareWe do not share
Employment application informationTo process your employment application and for our legal purposesAffiliated entities; Service providers; Entities for legal purposes; Entities for business transactionsWe do not shareWe do not share
Information collected through automated technologies (including internet network and device activity data)Provide the Services; Business Operations; Marketing and advertising; Improve the Services; With your consentAffiliated entities; Service providers; Online advertising partners; Connected third-party services; Entities for legal purposes; Entities for business transactionsAd networks and advertising partners; Analytics providersAd networks and advertising partners

For more information about each category, purpose of use, and the third parties to whom we disclose information, please see the sections “Information We Collect,” “Use of Collected Information,” and “Third Parties We Share Personal Information With” in this Privacy Policy above.

Additional Rights

Furthermore, subject to certain exemptions, California residents have the rights below with respect to Personal Information we may have collected about them. Please also see the “Managing Your Privacy” and “Your Rights” sections of this Privacy Policy for information about the additional rights you have with respect to your Personal Information and how to exercise them.

Requests to Know

You have the right to request that we disclose:

  • The categories of Personal Information we have collected about you;
  • The categories of Personal Information about you we have sold or disclosed for a business purpose;
  • The categories of sources from which we have collected Personal Information about you;
  • The business or commercial purposes for selling or collecting Personal Information about you;
  • The categories of Personal Information sold or shared, if any, about you, as well as the categories of third parties to whom the Personal Information was sold, by category of Personal Information for each party to whom Personal Information was sold; and
  • The specific pieces of Personal Information collected.

You may submit a request to know using one of the methods described below in “Methods for Submitting Consumer Requests and our Response to Requests”. The delivery of our response may take place electronically or by mail. We are not required to respond to requests to know more than twice in a 12-month period.

Requests to Correct

You have the right to request that we correct inaccurate Personal Information about you. You may submit a request to correct your Personal Information using one of the methods described below in “Methods for Submitting Consumer Requests and our Response to Requests”.

Requests to Delete

You have the right to request that we delete any Personal Information about you that we have collected. Upon receiving a verified request to delete Personal Information, we will do so unless otherwise required or authorized by law. You may submit a request to delete Personal Information using one of the methods described below in “Methods for Submitting Consumer Requests and our Response to Requests”. If you ask us to delete certain information, you may no longer be able to access or use our Services.

Authorized Agents

You may designate an authorized agent to make requests on your behalf. You must provide an authorized agent written permission to submit a request on your behalf, and we may require that you verify your identity directly with us. Alternatively, an authorized agent that has been provided power of attorney pursuant to Probate Code sections 4000-4465 may submit a request on your behalf.

Methods for Submitting Consumer Requests and Our Response to Requests

You may submit a request to access, correct, or delete Personal Information about you by:

  • Emailing us at [email protected] with a subject line of “Personal Information Request,” or
  • Calling us at (855) 790-7253

Certain information may be exempt from such requests under applicable law. For example, we need certain types of information so that we can provide the Services to you and for compliance with applicable law.

Upon receipt of a request, we may ask you for additional information to verify your identity. Any additional information you provide will be used only to verify your identity and not for any other purpose. We will acknowledge the receipt of your request within 10 days of receipt. Subject to our ability to verify your identity, we will respond to your request within 45 days of receipt. If we require more time (up to 90 days), we will inform you of the reason and extension period in writing. In order to protect your privacy and the security of Personal Information about you, we verify your request by authenticating your Account or asking for submission of identifying information.

Any disclosures we provide will only cover the 12-month period preceding the verifiable consumer request's receipt. The response we provide will also explain the reasons we cannot comply with a request, if applicable. We do not charge a fee to process or respond to your verifiable consumer request unless it is excessive, repetitive, or manifestly unfounded. If we determine that the request warrants a fee, we will tell you why we made that decision and provide you with a cost estimate before completing your request.

Your Choices Regarding “Sales” and “Sharing”

California residents may opt out of the "Sale" or “Sharing” of their Personal Information. We disclose some information to unaffiliated third-party advertising providers for targeted advertising purposes, so that we can provide you with more relevant and tailored ads regarding our Services, or use analytics partners to assist us in analyzing use of our Services and understanding our user/customer base. We also disclose some information to data providers who combine that information with their data to provide us with more information about our customers. The disclosure of your Personal Information to these third parties to assist us in providing these services may be considered a “Sale” of Personal Information under the CCPA or the “Sharing” of your Personal Information for purposes of “cross-context behavioral advertising.” We mean this definition of “Sharing” in this Privacy Policy only when the term is capitalized.

The chart in the section “Categories, Purposes of Use, and Disclosures of Personal Information” above lists the categories of Personal Information we have Sold or Shared over the last 12 months and the categories of third parties to which we have Sold or Shared. We do not otherwise “Sell” (as defined by the CCPA) your Personal Information, and have not engaged in such activity in the 12 months prior to the effective date of this Privacy Policy.

To opt out of our Sales and Sharing of your Personal Information for purposes of cross-context behavioral advertising, please click here.

We do not knowingly Sell or Share the Personal Information of children under 16.

The CCPA also allows you to limit the use or disclosure of your “sensitive personal information” (as defined in the CCPA) if your sensitive personal information is used for certain purposes. Please note that we do not use or disclose sensitive personal information other than for purposes for which you cannot opt out under the CCPA.

The Right to Non-Discrimination

You have the right not to be discriminated against for the exercise of your California privacy rights described above. Unless permitted by the CCPA, we will not:

  • Deny you goods or services;
  • Charge you different prices or rates for goods or services, including through granting discounts or other benefits, or imposing penalties;
  • Provide you a different level or quality of goods or services; or
  • Suggest that you may receive a different price or rate for goods or services or a different level or quality of goods or services.

Shine the Light Law

California Civil Code Section 1798.83 (the “Shine the Light” law) requires certain businesses that share certain customer Personal Information as defined under that Section with third parties for the third parties’ direct marketing purposes to respond to requests from California customers asking about the businesses’ practices related to such information-sharing. If we change our practices in the future, we will implement an opt-out policy as required under California law.

International Transfers of Personal Information

Gravitational is based in the United States (U.S.). As a result, Personal Information that we collect in and through the Services and on the Site may be transferred to the U.S. In addition, we may work with third-party service providers in the U.S. and in other countries to support our business activities. Thus, Personal Information may be transferred to, stored on servers in, and accessed from the U.S. and countries other than the country in which the Personal Information was initially collected. In all such instances, we use, transfer, and disclose Personal Information solely for the purposes described in this Privacy Policy and in compliance with applicable laws.

Data Retention

We keep Personal Information related to your Account for as long as it is needed to fulfill the purposes for which it was collected, to provide our services, to deal with possible legal claims, to comply with our business interests and/or to abide by all applicable laws. Thereafter, we either delete Personal Information about you or de-identify it. Please note that even if you request the deletion of Personal Information about you, we may be required (by law or otherwise) to retain the Personal Information and not delete it. However, once those requirements are removed, we will delete Personal Information about you in accordance with your request.

Changes to the Privacy Policy

Our Privacy Policy is periodically reviewed and enhanced as necessary. This Privacy Policy might change as we update and expand the Services. You can tell when this Privacy Policy was last updated by reviewing the Last Updated legend on top of this page. We also encourage you to review this Privacy Policy periodically. If you do not understand any of the terms or conditions of any of our policies, you may inquire regarding the same via email at [email protected]. Your continued use of the Services after any change in this Privacy Policy will constitute your acceptance of such change.

Contacting Us

If you have any concerns or questions about this Privacy Policy, please contact us at [email protected] or via postal mail to Privacy Officer, Gravitational, Inc., 440 North Barranca Avenue No. 8219, Covina, CA 91723.