Privacy Policy

Last updated on 31 July 2020

1. General

1.1 Secure Code Warrior Limited, a company incorporated in England and Wales with Company Number 08559432 and its related bodies corporate, listed in Appendix A of this Privacy Policy (Policy) (all referred to as Secure Code Warrior) recognise that the privacy of your personal data (also known as your personal information or personally identifiable information (PII)) is important to you. At Secure Code Warrior we take our data protection and privacy obligations seriously and we are committed to ensuring that we handle personal information in accordance with the applicable data protection and privacy laws, including the Data Protection Act 2018 and the Data Protection, Privacy and Electronic Communications (Amendments etc) (EU Exit) Regulations 2019 in the United Kingdom, the General Data Protection Regulation (EU) 2016/679 (known as the GDPR) in the European Union, the Australian Privacy Principles contained in the Privacy Act 1988, the California Consumer Privacy Act (so far as is applicable) and the Personal Data Protection Act 2012 (PDPA) in Singapore (Privacy Laws).

1.2 This Policy sets out how Secure Code Warrior collects, uses, processes, discloses and secures your personal information. It also sets out the rights you have in respect of your personal information, including your right to access your personal information and to have it corrected. This Policy covers all our activities, including the operation of our website at www.securecodewarrior.com, use of the Security Code Warrior learning platform (SCW Learning Platform), the provision of our products, and services, recruitment, and the operation of our social media accounts including, but not limited to, Twitter, Facebook, Instagram, and YouTube channels.

1.3 This Policy applies exclusively to Secure Code Warrior. Where the SCW Website or the SCW Platform contains links to other websites, Secure Code Warrior is not responsible for the privacy practices and terms of use of other organisations and websites.

2. Collection of your personal information

2.1 We collect personal information relating to our customers, prospective customers, business contacts, suppliers, recruitment candidates, and individuals who access the SCW Platform or participate in our tournaments, competitions, or other promotional activities.

2.2 The type of personal information Secure Code Warrior collects is set out in Appendix B. In most cases the personal information collected will include, but is not limited to, the following: your title, name, address, email address, telephone numbers, birthdate, nationality, location, job title, occupation, transaction and payment details, purchase preferences, and other information reasonably necessary for us to provide our services to you or which is otherwise reasonably necessary for us to carry out our functions and activities.

2.3 Secure Code Warrior generally collects personal information directly from you when you communicate with us including (but not limited to) when you contact us, register for our services, or supply us with goods or services. For example, when we receive an email from you, we are collecting your personal information. However, there may be circumstances where we collect information about you from third parties or via other methods. In some cases we may receive personal information about you from a customer in the context of providing services to that customer. We may also receive information about you from a partner in the context of that partner providing services to us.

2.4 Secure Code Warrior may make a record of information relating to your visit to the SCW Website. Such information includes your server address, domain name, IP address, the date and time of your visit, pages accessed and documents downloaded. We will not collect personal information about you where you follow us on our Secure Code Warrior social media sites. If you do not wish information to be collected and recorded by means of a cookie, you may reconfigure your web browser to not accept cookies. Further information about cookies and how to disable them can be found here. For information on Secure Code Warrior’s Cookie Policy click here.

2.5 If you do not provide some requested personal information, we may be delayed or prevented from providing our services or platform to you, your employer and/ or entity through wish you access the SCW Platform, or satisfying your request or enquiry.

3. Use and disclosure of your personal information

3.1 Secure Code Warrior uses your personal information for its internal business and administrative purposes. In accordance with applicable data protection and privacy laws, we will only process your personal information if we have a lawful basis for doing so.

3.2 In respect of your personal information, these bases are:

A. if it is necessary to provide services to you under the performance of the contract we have with you;

B. if we are required to do so in accordance with legal obligations;

C. if you have given your consent; and,

D. if it is in our legitimate interests to process your personal information, provided that none of these prejudice your own rights, freedoms and interests. Appendix C sets out the purposes for which we process your personal information, and the lawful basis on which we carry out such processing. Please note, that these lawful bases may not be applicable where you are receiving services from a Secure Code Warrior entity based outside of the EU and UK and you are also based outside of the EU and UK, but the following purposes will still apply and the lawful bases should help you better understand the purposes.

3.3 Secure Code Warrior will only use your personal information for the purposes listed in Appendix C or for other related compatible purposes for which you would reasonably expect us to use it (and in such circumstances the lawful bases would be in line with those listed above). We may also use your personal information for other purposes, but only where you have provided your express consent.

3.4 You will always have the opportunity to opt-out of, object to, or unsubscribe from receiving marketing materials. You can do this either via links in the message or by contacting Secure Code Warrior, security@securecodewarrior.com.

3.5 Secure Code Warrior may disclose your personal information in order to fulfil the purposes outlined set out in Appendix C. This will include sharing your personal information with other members of our corporate group and with external service providers such as those listed in Appendix E (on a confidential basis and in circumstances where those service providers may only use your information for the purpose of Secure Code Warrior’s activities) to communicate with you and/or to store your contact details.

3.6 Secure Code Warrior may also disclose your personal information to:

A. specialist advisers to Secure Code Warrior who have been engaged to provide us with legal, accounting, administrative, financial, insurance, research, marketing or other services;

B. law enforcement bodies which may have a reasonable requirement to access your personal information; and

C. any other person authorised and specified by you.

3.7 In addition, Secure Code Warrior may use or disclose your personal information:

A. where required or authorised by or under the applicable Privacy Laws or an order of a court or tribunal;

B. in accordance with the applicable Privacy Laws, including where we hold a reasonable belief that the use or disclosure is required for certain enforcement or health and safety purposes, or that use or disclosure is necessary in relation to certain suspected unlawful activity or misconduct;

C. whilst negotiating any takeover, purchase, merger, joint venture, partnership or other similar arrangement; or

D. if reasonably necessary for the establishment, exercise or defence of a legal or equitable claim or for the purposes of confidential alternative dispute resolution.

3.8 Secure Code Warrior may at other times notify you about our disclosure practices in respect of specific services that we provide in relation to our activities.

4. Storage and security of your personal information

4.1 Secure Code Warrior may hold your personal information in a number of different formats, including software programs (located both onsite and offsite, including in the cloud), databases, filing systems and in offsite backup storage.

4.2 Personal information held by Secure Code Warrior may also be stored in email accounts that are accessible through mobile devices. Given the nature of our business and corporate structure we may disclose personal information about an individual to one of our related companies overseas for the purpose of the provision and improvement of our services. Where the recipient territory does not offer the same level of privacy and data protection legislation, Secure Code Warrior will ensure that adequate safeguards are in place to protect your personal information, including, in respect of transfers from the UK and EU, standard contractual clauses and EU-US Privacy Shield Framework. if you would further information about where we may disclose your personal information, please contact Secure Code Warrior’s Privacy Officer at security@securecodewarrior.com.

4.3 Secure Code Warrior takes all reasonable steps to protect your personal information from loss, unauthorised access, modification, disclosure or misuse. However, we cannot ensure the security of any information that you transmit to us over the Internet and you do so at your own risk.

5. Sensitive information

5.1 With the exception of sensitive information that Secure Code Warrior collects about its employees, Secure Code Warrior does not generally collect any sensitive information about you. If Secure Code Warrior holds any sensitive information about you, that information will only be used and disclosed by Secure Code Warrior for the purpose for which it was provided by you, and otherwise in accordance with the applicable Privacy Laws.

6. Unsolicited information received by us

6.1 Where Secure Code Warrior receives any personal information either in error or which was not requested by us, we will as soon as practicable delete and destroy that information. With your consent if the information was sent for the purpose of securing employment with us, we may keep this information subject to the retention periods set out in Appendix B.

7. Retention

7.1 Secure Code Warrior will only retain your personal information for so long as is necessary for the purposes outlined in this Policy (and Appendix B). In some circumstances we will be obliged by law to retain personal information for longer periods.

8. Your rights to your personal information

8.1 Privacy Laws give you certain rights in respect of your personal information, including the right to:

A. request access to your personal information;

B. request correction of the personal information that we hold about you as described below;

C. where required by law, request erasure of your personal information where there is no good reason for us continuing to process it or where you have exercised a right to object to processing (see (D) below);

D. object to processing of your personal information where we are relying on a “legitimate interest” (or the interests of a third party) and there is no compelling reason for us to continue processing your personal information;

E. object to processing your personal information for direct marketing purposes;

F. object to automated decision-making including profiling by us using your personal information which has a legal effect or similar significant effect on you;

G. request the restriction of processing of your personal information (for example, to suspend the processing of your personal information due to inaccuracy or our stated reason for processing it);

H. request that we provide you or a third party the personal information we hold regarding you in an electronically useable format; and

I. withdraw your consent for those purposes where we rely on consent, in which case we will no longer process your information for the purpose or purposes to which you originally consented, unless we have another lawful basis for doing so.

8.2 Please also note that your rights above are not absolute and we may be unable to comply with your request (in whole or in part). If we reasonably determine that your request is manifestly unfounded we reserve the right to refuse to comply with your request.

8.3 If you wish to exercise a right that you have regarding your personal information, please contact our Privacy Officer using the details below or clicking here.

8.4 We may need to request specific information from you to help us confirm your identity and ensure your right to access the information (or to exercise any of your other rights). This is a security measure to ensure that personal information is not disclosed to any person who has no right to receive it and to prevent unauthorised modification of your personal information.

8.5 Secure Code Warrior will process your request within a reasonable time and in any event and unless otherwise stated within one month from the date that we received your request. In the event of particularly complex requests we may have to extend this period by up to two further months, but we will notify you of this.

8.6 Please note that these rights may vary depending on the Privacy Laws that apply to you.

9. Correction of your personal information

9.1 You may ask Secure Code Warrior at any time to correct personal information we hold about you by contacting our Privacy Officer.

9.2 You should promptly notify Secure Code Warrior if there are any changes to your personal information. If you have a direct account with us, please use the email address connected to your account to make your request. If you have an account via your employer, please direct your request to your supervisor or HR department.

10. Complaints

10.1 If you have any cause for complaint about our use of your personal information, you have the right to lodge a complaint with your national data protection supervisory authority (details of some are set out at the end of this Policy), although we would ask that you contact us in the first instance using the contact details given below.

11. Changes to this Policy

11.1 This Policy was last updated on 31 July 2020.

11.2 Secure Code Warrior may amend this Policy from time to time by publishing a revised Policy on our website. Any changes will be effective as of the date they are published. In the event of any material changes to this Policy, Secure Code Warrior may take additional reasonable steps to notify you of the changes.

12. Contact details and further information

12.1 If you have any questions in relation to privacy or you wish to access or correct your personal information, please contact our Privacy Officer directly by email at security@securecodewarrior.com.

12.2 For further information about privacy issues (and to make complaints), see the UK Information Commissioner’s Office website at www.ico.org.uk, the Office of the Australian Information Commissioner’s website at www.oaic.gov.au, and the European Data Protection Supervisor’s website at www.edps.europa.eu.

Appendix A - Secure Code Warrior Legal Entities

 
  1. UNITED KINGDOM (incorporated in England and Wales)
    Secure Code Warrior Limited
    Company Number 08559432
    Ironstone House
    4 Ironstone Way
    Brixworth, Northampton. NNG 9UD
    United Kingdom
  2. AUSTRALIA
    Secure Code Warrior Pty Limited
    ABN 97 608 498 639
    c/o Vital Addition
    5, 120 Sussex Street
    Sydney. NSW 2000
    Australia
  3. BELGIUM
    Secure Code Warrior BVBA
    Baron Ruzettelaan 5
    bus 3 8310 Brugge
    Belgium
  4. USA
    Security Code Warrior Inc
    265 Franklin Street, Suite 1702
    Boston MA 02110
    USA
  5. ICELAND
    Motherji ehf
    Borgatun 24, 105,
    Reykjavik,
    Iceland

 

Appendix B - Collection of Personal Information

  1. PLATFORM USER
    1. As a user of the Secure Code Warrior platform we will hold the following information about you
      1. User name
      2. Password
      3. Employer
      4. Job title
      5. Location
      6. Test results
      7. IP Address
      8. IMEI number
      9. MAC Address
      10. Browser type
    2. This personal information will be held about you for so long as you have access to our platform and thereafter for a further period of twelve (12) months or as specified in your employers contract with us (whichever is the lower).
  2. RECRUITMENT CANDIDATES
    1. As potential employee of Secure Code Warrior we hold the following information about you:
      1. Contact details
      2. CV
      3. Date of Birth
      4. Qualifications
      5. References
    2. Should you be unsuccessful we will retain this data for a period of twelve (12) months so that we may contact you regarding any future opportunities, unless you request that we delete the data beforehand.
  3. CUSTOMERS
    1. As an email contact or prospective customer to Secure Code Warrior we hold the following information about you:
      1. Name
      2. Contact details
      3. Employer
      4. Job Title
      5. Location
    2. We will retain this data for up to 7 years from our last contact with you, unless you request that we delete the data beforehand.
  4. PARTICIPANTS IN TOURNAMENTS AND OR COMPETITIONS
    1. As a registrant, or participant in a tournament or competition we hold the following information about you:
      1. Name
      2. Email address
      3. Physical address where there may be a prize to be delivered
      4. Region
    2. This personal information will be held about you for so long as you have access to our platform and thereafter for a further period of twelve (12) months.
  5. SUPPLIERS
    1. As a supplier to Secure Code Warrior we hold the following information about you:
      1. Name
      2. Business/ Company Name
      3. Contact details
      4. Bank Details (if acting as a sole trader or using a personal account)
      5. We will retain this data for up to 7 years from our last contact with you, unless you request that we delete the data beforehand.

Appendix C - Processing of Personal Information

  1. PLATFORM USER
    1. Necessary to enable us to perform our contract with you:
      1. to set up, administer and manage a user’s account, verify a user’s identity, provider users with our platform and services, and to receive and respond to a user’s communications and requests.
      2. to notify our users of updates to our platform and services necessary for the performance of the contract we have with you.
      3. to support any other purpose necessary for performance of our contractual obligations or specifically stated at the time at which you provided your personal information.
    2. Necessary for the performance of our contract with you where such communication relates specifically to our services, and legitimate interest to be able to handle such queries:
      1. to receive and respond to a user’s communications and requests.
    3. For legitimate interest to enable Secure Code Warrior to:
      1. carry out market research campaigns so that we can better understand the functionality of our platform and how we can improve our platform and our services.
      2. prepare statistics relating to the use of our platform and services by our users so that we can understand the use of, and improve our platform and services.
    4. For legitimate interests to allow Secure Code Warrior to improve customer services offering:
      1. to record and review customer service communications for training and performance improvements to enable us to improve customer services.
    5. To enable Secure Code Warrior to comply with a legal obligation:
      1. to enable Secure Code Warrior to comply with legal obligations.
    6. With consent:
      1. to send users marketing materials where marketing materials have been specifically requested.
  2. RECRUITMENT
    1. To enable Secure Code Warrior to recruit employees and assess potential candidates, that is to:
      1. consider applications for roles for which you may have applied, directly or via a recruitment, and the negotiation of employment opportunities,
      2. consider applicants for other roles within Secure Code Warrior for which they may be suited,
      3. obtain references from former employers.
  3. CUSTOMERS, PROSPECTIVE CUSTOMERS or BUSINESS CONTACTS
    1. Necessary for the performance of a contract
      1. conducting business and make our services available to customers,
    2. For legitimate interests to enable Secure Code Warrior to conduct business
      1. to send and receive business communications
      2. to administer our relationship with customers, prospective customers and business contacts
    3. For legitimate interests to contact those who may benefit from our services
      1. informing prospective customers and business contacts about our services.
    4. With consent
      1. to send out marketing materials where these have been specifically requested.
  4. PARTICIPANTS IN TOURNAMENTS AND OR COMPETITIONS
    1. Necessary for the running of the competition and/ or tournament
    2. With consent
      1. to send out marketing materials
  5. SUPPLIERS
    1. for legitimate interests to enable Secure Code Warrior for the performance of a contract where the supplier is an individual
      1. to assess and appoint suppliers
    2. Legitimate interests to conduct business
      1. to send and receive business communications
      2. to administer our relationship with our suppliers.

Appendix D - Secure Code Warrior Related Websites

  1. securecodewarrior.com
  2. help.securecodewarrior.com
  3. insights.securecodewarrior.com
  4. discover.securecodewarrior.com
  5. leadersinappsec.com
  6. leadersindevsec.com
  7. softwaresecuritygurus.com
  8. scw.io

Appendix E - External Service Providers

  1. Google Analytics, Google Data Studio, Google Tag Manager, and Gmail from Google, Inc.
  2. MailChimp and Mandrill from The Rocket Science Group, LLC.
  3. ChurnZero from ChurnZero Inc.
  4. Marketo Engage from Adobe Inc.
  5. Salesforce from Salesforce.com Inc.
  6. ZoomInfo from Zoom Information Inc.
  7. Zendesk from Zendesk Inc.
  8. Amazon Web Services (AWS) from Amazon Web Services Inc.
  9. Webflow from Webflow Inc
  10. Matomo Analytics from InnoCraft