Last Updated: March 5, 2025.
This Privacy Policy describes how Tufin Software Technologies Ltd., including our subsidiaries and affiliates worldwide (“Tufin”, “we”, “our” or “us”), collects, stores, uses and discloses the following categories of personal data:
a. Customer Data: personal data (as defined in Section 1) that we collect, process, and manage on behalf of our business customers (the “Customers”) as a part of the Tufin solutions and services described on one or more applicable order forms and commercial agreements with the Customer (the “Solutions”).
If we process any Customer Data, we will do so solely on behalf of and under the instruction of the Customer and in accordance with the commercial agreement and data processing addendum with them. Accordingly, this Privacy Policy (which describes Tufin’s privacy and data protection practices) does not apply to such processing done on our Customers’ behalf. To learn more about the privacy policy and practices of our Customer, please contact them directly.
b. User Data: personal data relating to our Customers’ internal focal persons who directly engage with Tufin concerning their organizational account, and users of the Services on behalf of such Customers, e.g., the account administrators and users, billing contacts and authorized signatories on behalf of the Customer (collectively, “Users”); as well as the Customer’s business needs and preferences, as identified to us or recognized through our engagement with them;
c. Prospect Data: personal data relating to visitors of our websites at www.tufin.com and www.tufinnovate.com, participants at our events, and any other prospective customer, user or partner (collectively, “Prospects”) who visits or otherwise interacts with our websites, online ads and content, emails or communications under our control (the “Sites” and collectively with the Solutions, the “Services”).
Specifically, this Policy describes our practices regarding:
Data Collection & Processing
Data Uses
Data Location
Data Retention
Data Disclosure
Cookies and Data Collection Technologies
Communications
Data Security
Data Subject Rights
Data Controller/Processor
Additional Notices and Contact Details
If you are a Customer, User or Prospect, please read this Privacy Policy carefully and make sure that you fully understand it.
Our Services are designated for businesses and are not intended for personal or household use. Accordingly, we treat all personal data covered by this Privacy Policy, including information about any visitors to our Sites, as pertaining to individuals acting as business representatives, rather than in their personal capacity.
You are not legally required to provide us with any personal data. If you do not wish to provide us with your personal data, or to have it processed by us or any of our Service Providers (as defined below), please do not provide it to us and avoid any interaction with us or with our Sites, or use our Services.
When we use the terms “personal data” or “personal information” in this Privacy Policy, we mean information that identifies, relates to, describes, is reasonably capable of being associated with, or could reasonably be linked, directly or indirectly, to an individual. It does not include aggregated or deidentified information that is maintained in a form that is not reasonably capable of being associated with or linked to an individual.
Types of personal data collected. We may collect or generate the following types of personal data about individuals through the Services:
Categories of sources from which personal data is collected. We obtain personal data from the following categories of sources:
We use personal data for the following purposes (and in reliance on the legal bases for processing noted next to them, as appropriate):
User personal data
User and Prospect personal data
If you reside or are using the Services in a territory governed by privacy laws under which “consent” is the only or most appropriate legal basis for the processing of personal data as described herein (in general, or specifically with respect to the types of personal data you expect or elect to be processed by or via the Services, or due to nature of such processing), your acceptance of our Terms & Conditions (and/or the terms that govern your use of a Solution) (collectively, the “Terms”) and this Privacy Policy will be deemed as your consent to the processing of your personal data for all purposes details herein. If you wish to revoke such consent, please contact us at dpo@tufin.com.
We and our authorized Service Providers maintain, store and process personal data in the United States of America, Israel, European Union, and in other locations as reasonably necessary for the proper delivery and performance of our Services, or as may be required by law.
While privacy laws may vary between jurisdictions, Tufin and its affiliates and service providers are each committed to protect personal data in accordance with this Privacy Policy, customary industry standards, and such appropriate lawful mechanisms and contractual terms requiring adequate data protection, regardless of any lesser legal requirements that may apply in the jurisdiction to which such data is transferred.
Tufin is headquartered in Israel, which is considered by the European Commission, the Swiss Federal Data Protection and Information Commissioner (FDPIC) and the UK Secretary of State to be offering an equally adequate level of protection for the personal data of residents of the EEA, Switzerland and the UK, respectively. We transfer personal data from the EEA, Switzerland and the UK to Israel on this basis. For data transfers from the EEA, Switzerland or the UK to countries which are not considered to be offering an adequate level of data protection (including to our US entity – Tufin Software North America Inc.), we and the relevant data exporters and importers have entered into Standard Contractual Clauses as approved by the European Commission, FDPIC and UK Information Commissioner’s Office (ICO). We will be liable in cases of onward transfers of your personal data to third parties (including our Service Providers). You can obtain a copy by contacting us as indicated in Section 11 below.
Tufin complies with the EU-US Data Privacy Framework (EU-US DPF), the UK Extension to the EU-US DPF, and the Swiss-US Data Privacy Framework (Swiss-US DPF) as set forth by the US Department of Commerce.
Tufin has certified to the US Department of Commerce that it adheres to the EU-US Data Privacy Framework Principles (EU-US DPF Principles) with regard to the processing of personal data received from the European Union in reliance on the EU-US DPF, and from the United Kingdom (and Gibraltar) in reliance on the UK Extension to the EU-US DPF.
Tufin has certified to the US Department of Commerce that it adheres to the Swiss-US Data Privacy Framework Principles (Swiss-US DPF Principles) with regard to the processing of personal data received from Switzerland in reliance on the Swiss-US DPF.
If there is any conflict between the terms in this policy and the EU-US DPF Principles and/or the Swiss-US DPF Principles, the Principles shall govern for personal data transferred under the DPF. To learn more about the Data Privacy Framework (DPF) program, and to view our certification, please visit https://www.dataprivacyframework.gov/.
We retain personal data for as long as we deem it as reasonably necessary in order to maintain and expand our relationship and provide you with our Services and offerings; in order to comply with our contractual obligations; or to protect ourselves from any potential disputes (i.e. as required by laws applicable to log-keeping, records and bookkeeping, and in order to have proof and evidence concerning our relationship, should any legal issues arise following your discontinuance of use), all in accordance with our data retention policy.
To determine the appropriate period for personal data, we consider the amount, nature, and sensitivity of the personal data, the potential risk of harm from unauthorized use or disclosure of your personal data, the purposes for which we process your personal data and the applicable legal requirements.
If you have any questions regarding our data retention practices, please contact us by email at privacy@tufin.com.
We disclose personal data in the following ways:
In certain cases, other Users from your organization may control your account and will be entitled to monitor, process and analyse your data and associated content, including (i) view any content you submit and your activities on the Services; (ii) view statistics regarding your account; (iii) change your account password or other access credentials or privileges; (iv) suspend or terminate your account access; and (v) access or retain data stored as part of your account. Please note that in these circumstances Tufin is not responsible for and does not control any further disclosure, use or monitoring by or on behalf of your organization, that acts as the “Data Controller” of such data (as further described in Section 10 below).
We and our Service Providers use cookies and other similar technologies to enable and improve the Services we provide, to track the performance of our Sites, perform analytics and gain insights on the use of our Services and the performance of our activities, and for personalization purposes including personalization of ads if we have obtained your consent.
Cookies are packets of information sent to your web browser and then sent back by the browser each time it accesses the server that sent the cookie. Some cookies are removed when you close your browser session. These are the “Session Cookies”. Some last for longer periods and are called “Persistent Cookies”. We use both types.
Some cookies are necessary for the Services to function properly, and cannot be declined or disabled unless you delete and block them through your web browser settings. Other cookies, which are used for functional, performance, analytics and marketing purposes, are optional. These include web and app analytics tools and tools that provide us with insights on the performance of our ads and campaigns.
Specifically, we use Google Analytics (“GA”) and Google Offline Conversion Imports (“GOCI”). GA is used to understand better how Users’ and Prospects’ interact and use our Services, and GOCI provides us with insights that help us in facilitating and optimizing our marketing campaigns, ad management and sales operations. To learn more about how we use personal data and for what purposes, please see Section 2 above. Further information about the privacy practices of GA and GOCI can be found at https://policies.google.com/technologies/partner-sites. Further information about your option to opt-out is available at: https://tools.google.com/dlpage/gaoptout. For more information on our cookie and data collection technologies practices, please visit our Cookie Policy.
You can also opt-in to or opt-out from the use of optional cookies through the “Cookie Settings” feature available on our website. If you choose to opt-out of certain cookies, this will typically generate a new cookie which will preserve your choice, and indicate it to our Services in your next visits so that the cookies you opted-out of will not be utilized. You can also manage your cookies preferences, and accept, remove or entirely block cookies, through your browser settings. Please note that certain web browsers may transmit “Do Not Track” signals to websites with which the browser communicates, telling the website not to follow its online movements. Because of differences in how web browsers interpret this feature and send those signals, and lack of standardization, we currently do not respond to such “Do Not Track” signals.
Please note that if you get a new device, install a new browser, erase or otherwise alter your browser’s cookie file (including upgrading certain browsers), you may also clear the opt-out cookies installed once you opt-out, so an additional opt-out will be necessary to prevent additional tracking.
Service Communications: Tufin may contact you with important information regarding our Services. For example, we may notify you (through any of the means available to us) of changes or updates to our Services, billing issues, service maintenance or changes, password retrieval notices, etc. You will not be able to opt-out of receiving such service communications while using our Services, as they are integral to such use.
Notifications and Promotional Communications: We may send you notifications concerning new features, offerings, events, and special opportunities or any other information we think you will find valuable. We may provide such notices through any of the contacts means available to us (e.g., phone, mobile or email), through the Services, or through our marketing campaigns on any other websites or platforms.
If you do not wish to receive such promotional communications, you may notify us at any time by sending an email to privacy@tufin.com or by following the “unsubscribe”, “stop” or “change email preferences” instructions contained in the promotional communications you receive.
Tufin and its Service Providers implement systems, applications, and procedures to secure your personal data, to minimize the risks of theft, damage, loss of information, or unauthorized access or use of information. These measures provide sound industry-standard security. However, please be aware that regardless of any security measures used or implemented, we cannot and do not guarantee the absolute protection and security of any personal data stored with us or with any third parties.
Individuals have rights concerning their personal data. Please contact us by e-mail at: privacy@tufin.com if you wish to exercise your privacy rights under any applicable law, including the EU or UK General Data Protection Regulation (GDPR), the Swiss Federal Act on Data Protection (FADP), or the California Consumer Privacy Act (CCPA) as amended from time to time, the Virginia Consumer Data Protection Act (VCDPA), the Colorado Privacy Act (CPA) and other similar US State Laws. Such rights may include – to the extent applicable – the right to know/request access to (specific pieces of personal data collected; categories of personal data collected; categories of sources from whom the personal data was collected; purpose of collecting personal data; categories of third parties with whom we have shared personal data), to request rectification or erasure of your personal data held with Tufin, or to restrict or object to such personal data’s processing (including the right to direct us not to sell your personal data to third parties now or in the future), or to port such personal data, or the right to equal services and prices (e.g. freedom from discrimination) (each to the extent available to you under the laws which apply to you). If you are a GDPR-protected individual, you also have the right to lodge a complaint with the relevant supervisory authority in the EU or the UK, as applicable.
When you ask us to exercise any of your rights, we may need to ask you to provide us certain credentials to make sure that you are who you claim you are, to avoid disclosure to you of personal data related to others and to ask you to provide further information to better understand the nature and scope of data that you request to access. If your request relates to personal data contained in Customer Data (i.e., personal data we process on our Customer’s behalf as its “data processor” or “service provider”, as further explained in Section 10 below), such Customer exclusively determines how the data may be processed, as well as if and how your request should be handled – so we advise that you submit your request directly to them. We may not be able to fulfill your request unless you have provided sufficient information that enables us to reasonably verify that you are the individual about whom we collected the personal data, and if such data is processed on behalf of any of our Customers – to which Customer it particularly relates, so that we may forward it to them for their further handling. Such additional information may be then retained by us for legal purposes (e.g., as proof of the identity of the person submitting the request, or proof of request fulfillment). We may redact from the data which we will make available to you, any personal data or confidential information related to others.
In compliance with the EU-U.S. DPF and the UK Extension to the EU-U.S. DPF and the Swiss-U.S. DPF, Tufin commits to resolve DPF Principles-related complaints about our collection and use of your personal information. EU and UK individuals and Swiss individuals with inquiries or complaints regarding our handling of personal data received in reliance on the EU-U.S. DPF and the UK Extension to the EU-U.S. DPF, and the Swiss-U.S. DPF should first contact Tufin at privacy@tufin.com.
Additionally, in compliance with the EU-U.S. DPF and the UK Extension to the EU-U.S. DPF and the Swiss-U.S. DPF, Tufin commits to cooperate and comply respectively with the advice of the panel established by the EU data protection authorities (DPAs) and the UK Information Commissioner’s Office (ICO) and the Swiss Federal Data Protection and Information Commissioner (FDPIC) with regard to unresolved complaints concerning our handling of personal data received in reliance on the EU-U.S. DPF and the UK Extension to the EU-U.S. DPF and the Swiss-U.S. DPF.
Please note that under certain conditions (as described under the DPF Principles) you can invoke a binding arbitration by delivering a notice to Tufin via privacy@tufin.com. Please also note that Tufin is being subject to the investigatory and enforcement powers of the Federal Trade Commission (FTC).
Certain data protection laws and regulations, such as the EU GDPR, UK GDPR, the FADP and CCPA, typically distinguish between two main roles for parties processing personal data: the “Data Controller” (or under the CCPA, the “Business”), who determines the purposes and means of processing; and the “Data Processor” (or under the CCPA, the “Service Provider”), who processes the data on behalf of the Data Controller. Below we explain how these roles apply to our Services and Solutions, to the extent that such laws and regulations apply.
Tufin is the “Data Controller” of its Prospects and Users Personal Data. With respect to such data, we assume the responsibilities of Data Controller (solely to the extent applicable under law), as set forth in this Privacy Policy. In such instances, our Service Providers processing such data will assume the role of “data processor”.
Tufin is the “Data Processor” of Customer Data. Such data is being processed by Tufin on behalf of the Customer (who is the “Data Controller” of such data; and our Service Providers who process such Customer Data on our behalf are the “sub-processors of such data). Accordingly, Tufin processes Customer Data strictly in accordance with our Customer’s reasonable instructions and as further stipulated in our data processing addendum and other commercial agreement with such Customer.
Our Customers are solely responsible for determining whether and how they wish to use our Services, and for ensuring that all individuals using the Services on the Customer’s behalf or at their request, as well as all individuals whose personal data may be included in Customer Data processed through the Services, have been provided with adequate notice and given informed consent to the processing of their personal data, where such consent is necessary or advised, and that all legal requirements applicable to the collection, recording, use or other processing of data through our Services are fully met by the Customer, including specifically in the context of an employment relationship. Our Customers are also responsible for handling data subject rights requests under applicable law, by their Users and other individuals whose data they process through the Services.
Updates and Amendments: We may update and amend this Privacy Policy from time to time by posting an amended version on our Services. The amended version will be effective as of the published date. We will provide prior notice if we believe any substantial changes are involved via any of the communication means available to us or via the Services. After such notice period, all amendments to this Privacy Policy shall be deemed accepted by you.
Requirements under US State Privacy Laws: This policy describes the categories of personal information we may collect and the sources of such information (in Section 1 above), and our retention (Section 4) and deletion practices (Section 9). We also included information about how we may process your information (in Sections 2 through 7), which includes for “business purposes” under the California Consumer Privacy Act (CCPA), as amended/Virginia Consumer Data Protection Act (VCDPA)/Colorado Privacy Act (CPA) and similar state laws, as applicable. We do not sell or “share” your personal information for the intents and purposes of the CCPA or CPRA, nor disclose personal information that we “control” to any third party for their direct marketing purposes. We may disclose personal data to third parties or allow them to collect personal data from our Services as described in Section 5 above, if those third parties are our Customers (with respect to Customer Data processed on their behalf), or our authorized Service Providers or business partners who have agreed to our contractual limitations as to their retention, use, and disclosure of such personal data, or if you integrate the services of third parties with our Services, or direct us to disclose your personal data to third parties, or as otherwise described in Section 5 above. You may also designate, in writing or through a power of attorney, to request to exercise your privacy rights on your behalf. The authorized agent may submit a request to exercise these rights be emailing us. Note that we will not discriminate against you by withholding our Services from you or providing a lower quality of service to you for requesting to exercise your rights under the law. If you have any questions or would like to exercise your rights under the CCPA/CPRA/VCDPA/CPA or other similar state laws, you can contact privacy@tufin.com or our DPO at dpo@tufin.com.
External Links: While our Services may contain links to other websites or services, we are not responsible for their privacy practices, and encourage you to pay attention when you leave our Services for the website or services of such third parties and to read the privacy policies of each and every website and service you visit. This Privacy Policy only applies to our Services.
Children’s Privacy: Our Services are not intended for use by children under the age of 18. We do not knowingly collect personal data from minors under the age of 18 and do not wish to do so. In the event that it comes to our knowledge that a minor is using the Services, we will prohibit and block such user from accessing the Services (to the extent reasonably possible) and will make all efforts to promptly delete any personal data stored with us with regard to such user.
Language: This Privacy Policy was written in English, and may be translated by Tufin into other languages for your convenience. If a translated (non-English) version of this Privacy Policy conflicts in any way with its English version, the provisions of the English version shall prevail.
EU Representative: Tufin has designated Tufin Software Germany GmbH as its representative in the European Union, for data protection matters pursuant to Article 27 of the GDPR. Tufin Software Germany GmbH may be contacted only on matters related to the processing of personal data. To make such an inquiry, please send an email to privacy@tufin.com.
UK Representative: Tufin has designated Prighter as its representative in the United Kingdom for data protection matters pursuant to Article 27 of the UK GDPR. Inquiries regarding our UK privacy practices may be sent to: Prighter (Attn: Tufin), Kemp House 160 City Road, EC1V 2NX, London, United Kingdom.
Data Protection Officer: Tufin has appointed PrivacyTeam Ltd. As its Data Protection Officer, for monitoring and advising on Tufin’s ongoing privacy compliance and serving as a point of contact on privacy matters for data subjects and supervisory authorities. If you have any comments or questions regarding our Privacy Policy, if you have any concerns regarding your privacy, or if you wish to make a complaint about how your personal data is being processed by Tufin, you can contact privacy@tufin.com or our DPO at dpo@tufin.com.
Contacting Us: If you have any comments or questions about this Privacy Policy or if you have any concerns regarding your personal data held with us, please contact us at privacy@tufin.com.