Cofense Privacy Policy
Updated July 17 2026
Overview
Cofense Inc. and its subsidiaries and affiliates (collectively “Cofense” “our,” “we” or “us”) develops, markets, and sells software and services designed to assist our business customers, and the customers of our partners, in their defenses against cybersecurity threats and phishing attacks. We also maintain public-facing websites where visitors can learn more about our solutions and request more information.
We want you to be assured that no matter whether you are our customer, a customer of one of our partners, or someone who is interested in learning more about Cofense, we are handling your personal data carefully and in line with the reason it was shared with us. Because we collect and use personal data for different purposes. We are committed to providing you with exceptional service while protecting privacy and safeguarding personal information. This Privacy Policy tells you how.
The terms “personal data” and "personal information” used throughout this entire Privacy Policy are both defined as any information that does or can identify an individual, or as otherwise defined under applicable data protection legislation and privacy laws. Personal data or personal information may include the following: name, address, date of birth, and contact data (i.e. email address, telephone number, work title, work location and employer name).
Website Privacy Policy
This Website Privacy Policy describes how Cofense Inc. and its affiliated entities (collectively, “Cofense”, “we”, “us”) collects, uses, discloses, stores, and otherwise processes personal data when you use our public websites.
By providing your personal data to Cofense, you agree that you are authorized to provide that data and are accepting this Website Privacy Policy and any supplementary privacy statement that may be relevant to you. If you do not agree to our practices, please do not register, subscribe, create an account, or otherwise interact with our websites.
Personal Data Collected
This Website Privacy Policy applies to personal data and other information collected by Cofense or its service providers from or about visitors to, or users of, Cofense websites. For purposes of applicable data protection legislation and privacy laws, Cofense Inc., located at 44679 Endicott Drive, Suite 300, Ashburn, VA 20147, is the data controller of your personal data when you submit it on our websites, or we otherwise collect it directly from you by your use of our websites.
This Website Privacy Policy does not apply when we receive personal data from customers of our cybersecurity and phishing defense software and services or our employees and job applicants in their capacity as Cofense employees and job candidates. Please refer to our Product Privacy Policy for information on how we process personal data from our customers.
We may collect information that is related to you but that does not personally identify you (“Non-Personal Data”). Non-Personal Data also includes information that could personally identify you in its original form, but that we have modified (for instance, by aggregating, anonymizing or de-identifying such information) to remove or obscure any personal data.
We may also collect Technical Information about you when you visit our websites, which your web browser automatically sends whenever you visit a website on the Internet. “Technical Information” is information that does not, by itself, identify a specific individual but which could be used to indirectly identify you. Our servers automatically record Technical Information, which may include your Internet Protocol (“IP”) address, browser type, browser language, and the date and time of your request.
How We Collect Information
Websites
Cofense collects personal data about you when you submit information through our websites. Examples include requests for Cofense software and services information; registering for Cofense whitepapers, reports, newsletters, or webcasts; or entering promotions.
Email Communication
We use pixel tags and cookies in our marketing emails so that we can track your interactions with those messages, such as when you open the email or click a URL link that’s embedded within them. When recipients click on one of those URLs, they pass through a separate web server before arriving at the destination page on a Cofense website. We use tools like pixel tags and cookies so that we can determine interest in particular topics and measure and improve the effectiveness of our communications.
Log Files
Log files record website activity related to our software and services and enable us to gather statistics about our users’ browsing habits. These entries help Cofense determine how many and how often users have accessed or used our software and services, which pages they’ve visited, and other similar data.
Cookies and Similar Technologies
We may collect information about your use of the websites through cookies and similar technologies. A “cookie” is text that we store through your computer’s web browser so that we can keep track of your interests and/or preferences and recognize you as a return visitor to the websites.
Our websites use the following types of cookies for the purposes set out below:
| Type of cookies | Purpose |
|---|---|
| Essential Cookies | services that you have requested cannot be provided. |
| Functionality Cookies | These cookies allow our websites to remember choices you make when you use our websites, such as remembering your user preferences. The purpose of these cookies is to provide you with a more personal experience and to avoid you having to re-enter your preferences every time you visit our websites. |
| Analytics and Performance Cookies | These cookies are used to collect information about traffic to our websites. The information gathered does not identify any individual visitor. The information is aggregated and anonymous. We use this information to help operate our websites more efficiently, to gather broad demographic information and to monitor the level of activity on our website. We may use Google Analytics and other third party analytics services for this purpose. Google Analytics uses its own cookies. It is only used to improve how our websites work. You can find out more information about Google analytics here: https://developers.google.com/analytics/resources/concepts/gaconceptscookies You can find out more about how Google protects your data here: www.google.com/analytics/learn/privacy .html You can prevent the use of Google Analytics relating to your use of our websites by downloading and installing the browser plugin available via this link: http://tools.google.com/dlpage/gaoptout?hl=en-GB. |
Social Media Cookies
These cookies are used when you share information using a social media sharing button or “like” button on our websites or you link your account or engage with our content on or through a social networking website such as Facebook or X/Twitter. The social network will record that you have done this.
Social Media
Our websites may contain social media features. These features may collect your IP address, the pages visited on our site and may set a cookie to enable the feature to function properly. Social media features and widgets are either hosted by a third party or hosted directly on our site. Your interactions with these features are governed by the privacy policy of the organization providing it.
Links to Other Websites
Our websites may link to third party web websites, and Cofense is not responsible for any personal data collected by these third-party websites. Information collected is governed through the third party’s website’s privacy policy. This website Privacy Policy no longer applies once you leave our websites. Any interactions you have with these websites, or any services or applications they offer, are beyond the control of Cofense. When you post information to or through such services, those websites’ privacy policies and cookie usage policies apply directly. We urge you to read the privacy and security policies of any third-party websites before providing any personal data while accessing those websites.
Public Forums, Blogs and the Customer Reference Program
Cofense websites may feature bulletin boards, blogs or forums (collectively, “Forums”). Any personal data that you choose to submit via such a Forum may be read, collected, or used by others who visit these Forums, and may be used to send you unsolicited messages.
Purposes for Processing Personal Data
We will only process your personal data in accordance with applicable data protection legislation and privacy laws. We need certain personal data to provide you with access to the Cofense websites. If you registered with us, you would have been asked to check a box indicating your agreement to provide personal data to access our websites or view our content related to the same. This consent, together with the other legal bases described in this Website Privacy Policy — such as our legitimate interest in improving our websites and services, personalizing content, and analyzing website usage through log files, as described elsewhere in this Policy — provides us with the legal basis we require under applicable law to process your personal data. You maintain the right to withdraw such consent at any time. If you do not agree to our use of your personal data in line with this Website Privacy Policy, please do not use our Cofense websites.
Where we use automated tools on our website (for example, chat-based lead qualification or content personalization features) that produce legal or similarly significant effects about you, we will identify such tools and provide information about the logic involved, consistent with the EU Artificial Intelligence Act and other applicable law in this Policy. You may also contact privacy@cofense.com.
Use of Information Collected
We may use your personal data:
- To provide you with personalized content;
- To process and respond to inquiries;
- For the purposes for which you provided the data;
- To improve the content and navigability of our websites; and
- To alert you about new features, special events and important announcements.
We may use Non-Personal Data for our legitimate business purposes, such as improving our websites and services, and may share such information with third parties on that basis; where any such information could reasonably be used to identify you (for example, an IP address in some contexts), we will treat and protect it as personal data in accordance with this Website Privacy Policy.
Cofense gives you choices about the ways we collect, use, share and overall process your personal data. You can choose what contact will be stored in your account and preferences. However, if you choose not to provide certain details, some of your experiences with us may be affected.
If you would like to know what personal data we hold about you, you may submit a request to us reaching out
to: privacy@Cofense.com. We will supply personal data about you that we hold in our own files within the reasonable timeframes stipulated by applicable law. Please note that some requests may be subject to a reasonable fee.
Sharing of Information Collected
Cofense will not rent or sell your personal data to others but may disclose personal data with contracted third-party vendors and service providers (including cloud service providers) that work with Cofense and are contractually bound by confidentiality obligations. We will only share personal data with these vendors and service providers to help us maintain the Cofense public websites and provide certain content and services via our public websites.
If Cofense sells any part of its operations, Cofense may transfer personal data in connection with the sale. If a sale does occur, Cofense will attempt to notify you of the disclosure of your personal data.
We reserve the right to disclose information, including personal data, by law, litigation, or as a matter of national security to comply with valid legal process including subpoenas, court orders or search warrants, and as otherwise required by applicable law. We may also need to disclose personal data in the event of an emergency that threatens an individual’s life, health, or security.
Individual Rights
Opt-out. You may contact us anytime to opt-out of: (i) direct marketing communications; (ii) automated decision-making and/or profiling;
(iii) our collection of sensitive personal data; (iv) any new processing of your personal data that we may carry out beyond the original purpose; or (v) the transfer of your EEA/EU, UK or Swiss personal data outside the EEA/EU, UK and Switzerland. Please note that your use of the Cofense websites may be impacted upon opt-out.
Access. You may access the personal data we hold about you at any time by contacting us directly. Amend. You can also contact us to update or correct any inaccuracies in your personal data.
Delete. You can request that we erase your personal data.
Automated Decision-Making. Where we make a decision about you based solely on automated processing, including profiling, that produces legal effects concerning you or similarly significantly affects you, you have the right to request human intervention in that decision, to express your point of view, and to contest the decision. To exercise this right, please contact privacy@cofense.com.
Right to Lodge a Complaint. Depending on where you are located, you may also have the right to lodge a complaint with your local data protection or privacy authority. This includes, without limitation, the Information Commissioner's Office (“ICO”) in the United Kingdom, the Irish Data Protection Commission (or the supervisory authority of your own EU/EEA member state, for EU/EEA individuals), and the Personal Data Protection Commission (“PDPC”) in Singapore. Complaint rights for the Philippines and the United Arab Emirates are addressed in the applicable sections below.
U.S. State Privacy Rights
If you are a resident of California, Virginia, Colorado, Connecticut, Utah, or another U.S. state with a comprehensive consumer privacy law, you may have rights under that state's law relating to your personal information, including the right to confirm whether we process it, access, correct, or delete it, obtain a portable copy of it, and opt out of processing for targeted advertising, sale of personal information, or certain profiling. To exercise these rights, please contact privacy@cofense.com. Where technically feasible, Cofense also recognizes and honors opt-out preference signals, such as the Global Privacy Control ("GPC"), as a valid method of submitting an opt-out request under applicable state law. Cofense will not discriminate against you for exercising your privacy rights.
Right to Appeal. If we decline to take action on your request under this section, you may appeal our decision by contacting our Data Protection Officer at privacy@cofense.com. Our Data Protection Officer will review your appeal and respond in writing within forty-five (45) days of receipt, which we may extend by an additional forty-five (45) days when reasonably necessary, provided we notify you of the extension and the reason for it within the initial period. If we deny your appeal, we will provide you with information on how to contact your state Attorney General to submit a complaint.
Further, if you are a California resident, the California Consumer Privacy Act of 2018 (“CCPA”) may give you certain rights relating to your personal information (as defined in the CCPA). Please visit the California Attorney General’s privacy laws page for more information.
Singapore Privacy Rights
If you are located in Singapore, we process your personal data in accordance with the Personal Data Protection Act 2012 (“PDPA”). Where we rely on your consent to collect, use, or disclose your personal data, you may withdraw that consent at any time by contacting privacy@cofense.com, subject to any legal or contractual restrictions and reasonable notice. You may also request access to, and correction of, your personal data held by us.
Philippines Privacy Rights
If you are located in the Philippines, we process your personal data in accordance with the Data Privacy Act of 2012 (Republic Act No. 10173) and its implementing rules and regulations. You have the right to be informed, to access, to object, to correct, to erasure or blocking, to data portability, to file a complaint with the National Privacy Commission, and to damages for violations of your rights under the Data Privacy Act. To exercise these rights, please contact privacy@cofense.com.
United Arab Emirates Privacy Rights
If you are located in the United Arab Emirates, we process your personal data in accordance with Federal Decree-Law No. 45 of 2021 on the Protection of Personal Data and, where applicable to processing carried out by or through our Dubai/DMCC branch, any relevant free zone data protection regulations. You may have the right to request access to, correction of, or erasure of your personal data, to object to or restrict certain processing, and to lodge a complaint with the UAE Data Office or the relevant free zone data protection authority. To exercise these rights, please contact privacy@cofense.com.
Security
Cofense uses reasonable administrative, technical and physical safeguards to protect the security of your personal data from unauthorized disclosure, access or use, and overall processing. We also try to ensure that only necessary people and third parties have access to personal data. Nevertheless, such security measures cannot prevent all loss, misuse or alteration of personal data and we are not responsible for any damages or liabilities relating to any such incidents to the fullest extent permitted by applicable law. Where required under applicable law, we will notify you of any such loss, misuse or alteration of personal data that may affect you so that you can take the appropriate actions for the due protection of your rights. Cofense also reviews its security procedures periodically to consider appropriate new technology and updated methods.
We require that our third-party vendors, service providers and partners agree to keep all confidential information we share with them confidential and to use the information, inclusive of personal data, only to perform their obligations in the agreements we have in place with them. While we provide these third parties with no more information than is necessary to perform the function for which we engaged them, any information that you provide to these third parties independently, including personal data, is subject to their respective privacy policies and practices.
Data Retention and Storage
Cofense retains your information, including personal data, for its legitimate business purposes. We retain such information for as long as necessary to fulfil the purposes for which it was collected, including to provide you with access to our websites and respond to your inquiries, or until you request that we delete it, whichever is applicable. Cofense will also retain your information, including personal data, as reasonably necessary to comply with our legal obligations, resolve disputes and enforce our agreements. We may also retain cached or archived copies of your information, including personal data, for a reasonable period of time.
Location of Personal Data Processing
Any personal data collected about EU/EEA, UK and Swiss visitors via our Cofense websites is processed in the United States by Cofense or by a third party acting on our behalf. Our Cofense websites are hosted in the United States.
Cofense maintains offices in the United Kingdom, Ireland, Singapore, the Philippines, and the United Arab Emirates (Dubai/DMCC). Personal data collected from visitors in these jurisdictions may also be processed by, or transferred to, Cofense affiliates or Subprocessors located in these or other countries, including the United States, as further described in this Website Privacy Policy. Where required by applicable law, Cofense relies on appropriate transfer mechanisms (including the EU Commission Standard Contractual Clauses and the related UK International Data Transfer Addendum and the Data Privacy Framework) to safeguard such transfers.
At points throughout our websites, you may be able to provide personal information, including contact information. If you provide your contact information, we will maintain that information until you request that we delete it. If you want us to delete your contact information, please email us from the email address you provided originally. Cofense will not discriminate against you for exercising your privacy rights.
Cofense does not sell any personal information to third parties and has not done so in the previous twelve (12) months.
Changes to the Website Privacy Policy
Cofense may review and update this Website Privacy Policy periodically without any prior notice. Cofense will post a notice to its main website at www.cofense.com to inform you of any changes to our Website Privacy Policy and indicate when it was most recently updated. Your continued use of our websites after changes have been posted to this Website Privacy Policy will constitute your acceptance of such changes. In the case of material changes that may adversely affect you, Cofense may notify you directly of changes to this Website Privacy Policy.
Contact
Our data protection officer is our General Counsel, Chief Privacy and Compliance Officer. If you have any questions, concerns, or suggestions regarding this Website Privacy Policy, or would like to reach our data protection officer or UK representative, or EU representative please contact us by email at privacy@cofense.com.
Cofense Inc.
44679 Endicott Drive, Suite 300
Ashburn, VA 20147
Tel: +1 703-652-0717
For Singapore, the Philippines, and the United Arab Emirates, our Data Protection Officer (the General Counsel, Chief Privacy and Compliance Officer) also serves as the designated privacy contact for inquiries under the PDPA, the Philippine Data Privacy Act, and the UAE PDPL, respectively, and can be reached at privacy@cofense.com.