Skip to content
Wingback Security

Privacy Policy

How Wingback Security collects, uses, shares, and protects personal information, and how to exercise your data protection rights.

Effective 2026-02-24 · Updated

1. Introduction

Wingback Security (“we,” “us,” or “our”) operates the AI security platform available at wingback.ai and related services (collectively, the “Platform”). We are committed to protecting the privacy and security of personal information entrusted to us.

This Privacy Policy explains how we collect, use, disclose, and safeguard your personal information when you visit our website, use our Platform, or otherwise interact with us. It applies to all individuals who access our website or services, including customers, prospective customers, and website visitors.

By using our website or Platform, you acknowledge that you have read and understood this Privacy Policy. If you do not agree with our practices, please do not use our services.

2. Information We Collect

Information You Provide Directly

  • Account information: Name, email address, company name, job title when you create an account or request a demo
  • Communications: Information you provide when contacting us for support, submitting feedback, or responding to surveys
  • Data subject requests: Name, email, and details of your request when you submit a data subject access request (DSAR)
  • Platform configuration: Security policies, agent configurations, and MCP toolchain settings you create within the Platform

Information Collected Automatically

  • Log data: IP address, browser type and version, pages visited, time and date of visit, time spent on pages, referring URLs
  • Device information: Operating system, device type, screen resolution, language preferences
  • Cookies and similar technologies: As described in the Cookies section below

Information from Third Parties

  • Business contact information from partners and referral sources
  • Publicly available company and professional information

3. How We Use Your Information

We process your personal information only when we have a valid legal basis to do so. The table below describes each purpose and its corresponding lawful basis under the GDPR:

  • To provide and maintain our AI security platform — Performance of a contract with you or your organization
  • To process demo requests and communicate with you — Legitimate interest in responding to inquiries and building business relationships
  • To analyze usage patterns and improve our services — Legitimate interest in improving and developing our Platform
  • To comply with legal obligations including security incident reporting and regulatory requirements — Legal obligation
  • To protect the security of our Platform and users — Legitimate interest in maintaining the security and integrity of our services
  • To send marketing communications (with opt-out) — Consent, which you may withdraw at any time

4. How We Share Your Information

We do not sell your personal data. We may share your information in the following limited circumstances:

  • Service providers: Third-party vendors who assist us with hosting (AWS), analytics, email delivery, and customer support. These providers are contractually obligated to protect your data and use it only as directed by us.
  • Legal compliance: When required by law, regulation, legal process, or governmental request, including to meet national security or law enforcement requirements.
  • Business transfers: In connection with a merger, acquisition, reorganization, or sale of assets, your information may be transferred as part of that transaction. We will notify you of any such change.
  • With your consent: We may share information for other purposes when you have given us explicit consent to do so.

5. Cookies and Tracking Technologies

We use cookies and similar tracking technologies to enhance your experience. Cookies are small text files stored on your device that help us understand how you interact with our website.

Types of Cookies We Use

  • Essential cookies: Required for the operation of our website and Platform, including session management, security, and load balancing. These cannot be disabled.
  • Analytics cookies: Help us understand usage patterns and improve our services. We use Google Analytics, which you can opt out of using the Google Analytics Opt-out Browser Add-on.
  • Functional cookies: Remember your preferences and settings to provide a personalized experience.

Managing Cookies

Most web browsers allow you to manage cookie preferences through their settings. You can set your browser to refuse cookies or alert you when cookies are being sent. Please note that disabling cookies may affect the functionality of our website.

6. Data Retention

We retain personal information only as long as necessary to fulfill the purposes for which it was collected, or as required by law. Our retention periods are as follows:

  • Account data: Duration of your account plus 30 days after deletion to allow for account recovery
  • Log and analytics data: 24 months from the date of collection
  • Marketing consent records: Duration of consent plus 3 years for compliance documentation
  • Security audit logs: 7 years, consistent with enterprise security standards and regulatory requirements
  • Legal compliance data: As required by applicable law and regulation

When data is no longer needed, we securely delete or anonymize it in accordance with our data handling procedures.

7. International Data Transfers

Our primary data storage and processing takes place in the United States using Amazon Web Services (AWS) infrastructure. If you are located outside the United States, your personal information will be transferred to and processed in the United States.

For transfers of personal data from the European Economic Area (EEA), the United Kingdom, or Switzerland, we rely on appropriate safeguards including Standard Contractual Clauses (SCCs) approved by the European Commission. We also respect adequacy decisions made by relevant data protection authorities.

You may request a copy of the applicable transfer safeguards by contacting us at security@wingback.ai.

8. Information Security

We implement appropriate technical and organizational measures to protect your personal information against unauthorized access, alteration, disclosure, or destruction. These measures include:

  • Encryption of data in transit (TLS) and at rest (AES-256)
  • Role-based access controls with the principle of least privilege
  • Regular security assessments and penetration testing
  • Alignment with ISO 42001 AI management system standards
  • Defined incident response procedures with notification protocols
  • Continuous monitoring and logging of access to personal data

While we strive to protect your personal information, no method of transmission over the Internet or electronic storage is completely secure. We cannot guarantee absolute security but are committed to maintaining industry-standard protections.

9. Your Rights and Choices

Depending on your location, you may have the following rights regarding your personal information under applicable data protection laws, including the GDPR:

  • Right of Access: Request a copy of the personal data we hold about you
  • Right to Rectification: Request correction of inaccurate or incomplete personal data
  • Right to Erasure: Request deletion of your personal data, subject to legal retention requirements
  • Right to Restriction: Request that we restrict the processing of your personal data
  • Right to Data Portability: Receive your personal data in a structured, commonly used, machine-readable format
  • Right to Object: Object to processing of your personal data based on our legitimate interests
  • Right to Withdraw Consent: Withdraw your consent at any time, without affecting the lawfulness of processing carried out prior to withdrawal

To exercise any of these rights, you may email us at security@wingback.ai or use the Data Subject Request Form below. We will respond to your request within 30 days as required by applicable law. We may need to verify your identity before processing your request.

10. Stakeholder Obligations (ISO 42001)

As a provider of AI security controls, we recognize our responsibilities to multiple stakeholders under ISO 42001 AI management system standards. This section outlines how we address these obligations.

Our Obligations

  • Maintain transparent AI governance practices and documentation
  • Conduct regular AI risk assessments and implement appropriate mitigations
  • Ensure continuous improvement of our AI management system
  • Provide clear documentation of how our AI security controls operate
  • Promptly notify customers of security incidents that may affect their data or AI operations

Customer Obligations

  • Responsible deployment and use of AI security controls provided by our Platform
  • Accurate configuration of security policies and agent permissions
  • Timely reporting of security incidents or suspected vulnerabilities
  • Compliance with applicable AI governance regulations in your jurisdiction

Regulatory Alignment

  • We cooperate with data protection authorities and regulators upon request
  • We maintain records of processing activities as required by GDPR Article 30
  • We support compliance reporting for customers subject to AI-specific regulations

Societal Considerations

  • We are committed to the ethical use of AI security technology
  • Our controls are designed to prevent misuse of AI systems and protect against adversarial threats
  • We participate in industry standards development to advance responsible AI governance

11. California Residents (CCPA/CPRA)

If you are a California resident, you have additional rights under the California Consumer Privacy Act (CCPA) and the California Privacy Rights Act (CPRA):

  • Right to Know: You may request that we disclose the categories and specific pieces of personal information we have collected about you
  • Right to Delete: You may request the deletion of personal information we have collected
  • Right to Opt-Out of Sale: We do not sell personal information. If this changes, we will provide a clear opt-out mechanism
  • Right to Non-Discrimination: We will not discriminate against you for exercising any of your privacy rights

You may designate an authorized agent to submit requests on your behalf. Authorized agents must provide proof of written authorization and we may still require you to verify your identity directly.

12. Children’s Privacy

Our website and Platform are not directed to individuals under the age of 16. We do not knowingly collect personal information from children under 16. If we become aware that we have inadvertently collected personal information from a child under 16, we will take steps to delete that information promptly. If you believe we have collected data from a child, please contact us at security@wingback.ai.

13. Changes to This Policy

We may update this Privacy Policy from time to time to reflect changes in our practices, technologies, legal requirements, or other factors. When we make material changes, we will notify you by posting the updated policy on our website with a revised “Last Updated” date and, where required, by sending you an email notification.

We encourage you to review this Privacy Policy periodically to stay informed about how we protect your information.

14. Contact Us

If you have any questions, concerns, or requests regarding this Privacy Policy or our data practices, please contact us at:

Wingback Security

Email: security@wingback.ai

We aim to respond to all inquiries within 30 days. For data subject access requests, please use the form below.

15. Submit a Data Request

Use this form to exercise your data protection rights. All requests are logged and tracked. We will respond within 30 days as required by applicable law.

Submit a data request

We respond within 30 days as required by applicable law.