PRIVACY POLICY
Privacy Policy
INNORIX processes personal information and service data necessary for the use of its website and the INNORIX Platform.
This Privacy Policy explains what information INNORIX processes and how it is used when you use the INNORIX website, Account, Cloud Service, Software, API, and related services.
Where INNORIX processes Personal Data as a Processor on behalf of a Customer, the Data Processing Addendum (DPA) may apply together with this Privacy Policy.
Information We Collect
The information INNORIX processes depends on how the Services are used.
Website Information
When you visit the INNORIX website, the following information may be processed.
-
IP address
-
Browser and device information
-
Pages visited
-
Referrer information
-
Cookie and preference information
-
Website interaction information
This information is used for website operation, security, performance analysis, and improving the user experience.
More information about Cookies is available in the Cookie Policy.
Cookie PolicyAccount Information
When you create an INNORIX Account or join an organization, the following information may be processed.
-
Name
-
Business email address
-
Organization
-
User identifier
-
Role and permissions
-
Account settings
-
Authentication information
If you sign in through Google or another supported Identity Provider, that Provider may provide INNORIX with information required for authentication.
INNORIX uses this information for Account creation, authentication, permission management, and customer support.
Device & Connection Information
When a Server, PC, VM, Kubernetes Node, Object Storage, or other Endpoint is connected to INNORIX, Device information required to operate the Service may be processed.
For example:
-
Device ID
-
Device name
-
Operating system
-
Software version
-
IP address
-
Connection status
-
Device type
-
Last connection information
-
Workspace or organization association
This information is used to identify Devices, maintain connection status, execute transfer operations, and monitor operational status.
Transfer & Operational Metadata
When file transfers and automation are executed, Metadata required for Service operation may be generated.
For example:
-
Source and destination identifiers
-
Run ID
-
Transfer ID
-
Flow information
-
Transfer status
-
Start and completion time
-
File transfer result
-
File size
-
Error and retry information
-
Audit information
Where required by product functionality, this may include information such as File names or paths.
INNORIX uses this information for transfer execution, Monitoring, Audit, troubleshooting, and Service operation.
Customer Files
Direct transfer keeps file content on the transfer path
When using INNORIX's Direct Transfer configuration, files move directly between the connected Source and Destination.
In this architecture, INNORIX Cloud is not used as intermediate storage for file transfers.
Instead, the INNORIX Control Plane manages operational information such as the following.
-
Connected Devices
-
Transfer instructions
-
Policies
-
Transfer status
-
Results
-
Operational metadata
The actual data path may vary depending on the customer's Deployment, Routing, and additional service configuration.
Object Storage Connections
When Object Storage is connected, INNORIX may process authentication and connection information required to operate that Connection.
INNORIX does not store Raw Credentials in Metering or Billing records.
Credentials or security References required for Service operation may be used, while usage records contain only the necessary identifying information.
The customer's Cloud Account, Storage permissions, and Bucket permissions are managed by the customer and the applicable Cloud or Storage Provider.
API Information
When the API is used, the following information may be processed.
-
API credential identifier
-
Organization and Workspace information
-
Request information
-
API operation
-
Request time
-
Response status
-
Security and rate-limit information
API request records may be used for authentication, security, troubleshooting, Usage management, and Audit.
Usage & Metering Information
INNORIX processes Usage information to operate Subscriptions and measure usage.
For example:
-
Active Devices
-
Additional Device usage
-
Successfully delivered payload volume
-
API usage
-
Run and Transfer counts
-
Log usage
-
Applicable Plan and entitlement information
The Metering system primarily processes information required for Service operation and usage calculation.
File contents, Passwords, Raw Access Tokens, and Raw Storage Credentials are not stored as usage data.
Billing Information
When using a paid Subscription, the following Billing information may be processed.
-
Organization and billing account
-
Legal or business name
-
Billing address
-
Country
-
Tax information
-
Subscription
-
Currency
-
Invoice information
-
Purchase Order information
-
Payment status
-
Credits and adjustments
When Card Payment is used, Payment Card processing may be handled through an external Payment Provider.
INNORIX may process Payment Provider References and Transaction information required for Service operation.
Support Information
When a customer contacts INNORIX or requests technical support, the following information may be processed.
-
Contact information
-
Support request
-
Communications
-
Relevant Device or Transfer identifiers
-
Error information
-
Logs provided by the customer
-
Other diagnostic information provided for troubleshooting
Customers should avoid including personal or confidential information in Support materials when it is not necessary for troubleshooting.
How We Use Information
INNORIX uses collected information for the following purposes.
Provide the Service
-
Create and operate Accounts
-
Connect Devices
-
Execute file transfers
-
Run automation
-
Provide API access
-
Display operational status
-
Maintain transfer history
Secure the Service
-
Authenticate users and systems
-
Protect Accounts and Devices
-
Detect unauthorized access
-
Apply security controls
-
Investigate suspicious activity
-
Maintain audit records
Operate and Improve the Service
-
Monitor performance
-
Diagnose errors
-
Maintain reliability
-
Analyze service usage
-
Improve product operation
Manage Subscriptions and Billing
-
Measure usage
-
Apply Plan entitlements
-
Generate invoices
-
Process payments
-
Manage credits and adjustments
-
Prevent billing errors and abuse
Provide Support
-
Respond to inquiries
-
Investigate technical problems
-
Restore service operation
-
Communicate with administrators
Meet Legal Obligations
INNORIX may process or retain information where necessary to comply with applicable:
-
laws
-
tax requirements
-
accounting requirements
-
regulatory obligations
-
valid legal requests
Legal Basis for Processing
Where applicable law requires a legal basis for processing Personal Data, INNORIX may rely on one or more of the following:
-
performance of a contract
-
steps requested before entering into a contract
-
legitimate interests in operating and securing the Services
-
compliance with legal obligations
-
consent where required
Where INNORIX processes Customer Personal Data solely on behalf of a Customer, the Customer determines the legal basis for that processing and INNORIX acts according to the applicable DPA.
Customer and INNORIX Roles
INNORIX may process Personal Data in different roles depending on the context.
INNORIX as Controller
INNORIX generally determines the purposes of processing for information such as:
-
INNORIX Account administration
-
Website operations
-
Billing administration
-
Security of INNORIX services
-
Communications with INNORIX customers
INNORIX as Processor
Where Customer Personal Data is processed through the Services according to a Customer's instructions, INNORIX may act as a Processor on behalf of that Customer.
The applicable Processing terms are described in the DPA.
Data Processing AddendumHow We Share Information
INNORIX does not disclose Personal Data except as necessary for legitimate business and service purposes, including the circumstances described below.
Service Providers
INNORIX may use external providers to support functions such as:
-
Cloud infrastructure
-
Service operations
-
Authentication
-
Communications
-
Payment processing
-
Customer support
-
Monitoring
Providers that process Customer Personal Data on behalf of INNORIX are managed according to applicable contractual and data protection requirements.
The relevant providers can be found in the Subprocessor List.
SubprocessorsBusiness Transactions
Information may be transferred as part of:
-
merger
-
acquisition
-
corporate restructuring
-
financing
-
sale of business assets
where permitted by applicable law and subject to appropriate confidentiality and data protection requirements.
Legal Requirements
INNORIX may disclose information when reasonably necessary to:
-
comply with applicable law
-
respond to valid legal process
-
protect INNORIX, customers or others
-
investigate fraud or security incidents
-
enforce applicable agreements
Where legally permitted, INNORIX may notify the affected customer of a government request involving Customer Personal Data.
International Data Processing
INNORIX operates across multiple regions and may use service providers located in different countries.
Personal Data may therefore be processed outside the country in which it was originally collected.
Where applicable law requires safeguards for international data transfers, INNORIX uses legally recognized transfer mechanisms as applicable to the relevant processing.
Additional terms governing Customer Personal Data are described in the DPA.
Data Location
The location in which information is processed may depend on:
-
Service
-
Deployment
-
Cloud region
-
Customer configuration
-
Subprocessor
-
support requirements
On-Premises, Hybrid, Sovereign Cloud and Air-Gapped deployments may provide different data-processing architectures.
A specific data residency commitment applies only where it is part of the selected Service or applicable customer agreement.
Data Retention
INNORIX retains information for the period reasonably necessary for the purpose for which it is processed.
Different categories of information have different retention periods.
Account Information
Account information is retained while necessary to operate the Customer Account and applicable Services.
Operational Logs
Searchable operational log retention depends on the applicable Plan and configuration.
Billing and Contract Records
Invoice, payment, tax and contract records may be retained after service termination where necessary for accounting, tax, legal or dispute-resolution purposes.
Support Information
Support communications and diagnostic information may be retained for support, service improvement, security and audit purposes.
Account Termination & Data Deletion
When a paid Subscription ends, INNORIX may provide a limited Read-only Grace Period under the applicable Terms.
During this period, available information such as:
-
Logs
-
Receipts
-
Configuration
-
Operational records
may remain accessible for review or export.
After the applicable Grace Period, INNORIX begins deletion of active service data that is no longer required.
Information that must be retained for legal, tax, accounting, security or dispute purposes may be retained for the applicable period.
Backups
Information that has been deleted from active systems may remain temporarily in Backup copies until removed through normal Backup Rotation.
Backup data is maintained for recovery and continuity purposes and is protected from ordinary active use.
Security
INNORIX uses technical and organizational safeguards appropriate to the Services to protect information against unauthorized access, loss, alteration or disclosure.
Security controls include protections relating to areas such as:
-
Access control
-
Authentication
-
Data transmission
-
Device security
-
Audit
-
Monitoring
-
Operational security
-
Backup and recovery
More information is available on the Security page.
SecurityYour Choices and Rights
Depending on applicable law and the context in which INNORIX processes Personal Data, individuals may have rights to:
-
access Personal Data
-
correct inaccurate information
-
request deletion
-
restrict certain processing
-
object to certain processing
-
receive portable data
-
withdraw consent where processing is based on consent
Some rights may be subject to legal limitations or exceptions.
Customer-Managed Personal Data
Where Personal Data is processed by INNORIX on behalf of a Customer, individuals should generally direct privacy requests to the organization that controls that data.
INNORIX assists Customers with applicable requests according to the DPA and available Service functionality.
Account Information
Users can manage certain Account and Organization information directly through available product settings.
Where information cannot be managed through the product, privacy-related requests may be submitted through INNORIX's website contact channels.
INNORIX may need to verify identity or authority before completing a request.
Cookies
INNORIX uses Cookies and similar technologies where necessary to operate its website and, where applicable, understand website usage or remember preferences.
Users can manage non-essential Cookies through Cookie Preferences.
Cookie PolicyMarketing Communications
Where INNORIX sends optional marketing communications, recipients can use the unsubscribe option provided in the communication.
Unsubscribing from marketing does not prevent INNORIX from sending operational or contractual communications necessary for an Account or Service.
Third-Party Services
Customers may connect INNORIX with third-party services such as:
-
Cloud providers
-
Object storage
-
Identity providers
-
Monitoring services
-
SIEM platforms
-
Collaboration tools
Personal Data processed directly by those providers is also subject to their own privacy policies and contractual terms.
Customers are responsible for selecting and configuring third-party services they connect to INNORIX.
On-Premises & Customer-Managed Environments
For Customer-managed deployments, the Customer controls its own:
-
Infrastructure
-
Storage
-
Network
-
Operating systems
-
Local databases
-
access permissions
Personal Data stored exclusively in Customer-managed Infrastructure remains under the Customer's direct technical control unless it is transmitted to an INNORIX-managed Service.
Air-Gapped Environments
Air-Gapped deployments may operate without routine online communication with INNORIX Cloud.
Information may still be provided to INNORIX when the Customer chooses to submit:
-
support information
-
license information
-
signed usage information
-
diagnostic data
Such information is handled according to this Privacy Policy and applicable agreements.
Children
INNORIX Services are designed for organizations and business use and are not directed to children as consumer services.
Changes to This Privacy Policy
INNORIX may update this Privacy Policy to reflect changes in:
-
Services
-
data-processing practices
-
legal requirements
Material changes will be communicated through appropriate website, Account or contractual channels where required.
Privacy Questions
Questions concerning this Privacy Policy or INNORIX's processing of Personal Data can be submitted through the Contact channel provided on the INNORIX website.
Where the request concerns Customer Personal Data processed on behalf of an INNORIX Customer, the request should generally be directed to that Customer first.
Related Resources
Security
Security architecture and safeguards for INNORIX Services.
Data Processing Addendum
Terms governing Customer Personal Data processed by INNORIX on behalf of Customers.
Subprocessors
Service providers involved in processing data for eligible INNORIX Services.
Cookie Policy
Information about Cookies and similar technologies.
Controls for non-essential Cookies.
Terms
General terms governing use of INNORIX Services.