Skip to content
xenXDRby FluenceSecurity
PricingDocs
EN·PL
Sign inBook a demo
  1. XenXDR
  2. Legal
  3. Privacy policy

Privacy policy

How FluenceSecurity processes personal data on this website, in the contact form, in the documentation and when you request a demo or pilot.

Version 1.0Last updated 2026-09-15Effective from 2026-09-15

On this page

  1. 1Who is responsible for your data
  2. 2What we collect and where it comes from
  3. 3Why we process it and on what legal basis
  4. 4Who receives your data
  5. 5Transfers outside the European Economic Area
  6. 6How long we keep it
  7. 7Your rights
  8. 8Is providing data mandatory?
  9. 9Children
  10. 10Cookies
  11. 11Changes to this policy

Who is responsible for your data

The controller of personal data collected through this website is Fluence Security - Paweł Mierzwa, with its registered office at ul. Partyzantów 65B/1, 80-254 Gdańsk, Poland, entered in the Central Registration and Information on Business (CEIDG), NIP 9571182795, REGON 540533818 ("FluenceSecurity", "we").

You can reach us about privacy at privacy@fluencesecurity.com, or by post at the address above.

This policy covers the website at xdr.fluencesecurity.com, including the documentation and the contact form. Personal data processed inside a customer's XenXDR deployment is governed by the customer's own policies and by our data processing agreement with that customer, not by this document.

What we collect and where it comes from

We process the following categories of data:

  • Contact form data you provide: name, work email address, company, country, role, phone number if you give one, the topic of your request and anything you write in the message field.
  • Technical data generated when you visit: IP address, browser type and version, requested pages, referring page, timestamps and error logs. This data is processed by our hosting provider to deliver the site and protect it from abuse.
  • Cookie data limited to what the cookie policy describes. By default the site sets only strictly necessary cookies.

We do not buy data about you, and we do not enrich contact form submissions from third-party sources.

Why we process it and on what legal basis

PurposeDataLegal basis
Answering your request, booking a demo, scoping a pilotContact form dataSteps at your request before entering into a contract (art. 6(1)(b) GDPR) and our legitimate interest in responding to business enquiries (art. 6(1)(f))
Following up on a request with relevant information about XenXDRContact form dataOur legitimate interest in direct business communication (art. 6(1)(f)); you can object at any time
Operating and securing the websiteTechnical dataOur legitimate interest in providing a working, secure service (art. 6(1)(f))
Analytics, only if you consentCookie dataYour consent (art. 6(1)(a) GDPR; art. 173 of the Polish Telecommunications Law or its successor provisions)
Establishing, exercising or defending legal claimsAny of the aboveOur legitimate interest (art. 6(1)(f))

We do not make decisions about you based solely on automated processing, and we do not profile you.

Who receives your data

We share personal data only with providers who process it on our behalf under a written agreement, and only to the extent needed:

  • Cloudflare, Inc. hosts this website and runs the function that relays contact form submissions. Cloudflare may process technical data at the edge location nearest to you.
  • Our email provider receives contact form submissions so that a person can answer them.
  • Our customer relationship tool, if we use one, stores the history of a business conversation.

The current list of subprocessors, with their locations and safeguards, is published on the subprocessors page. We do not sell personal data and we do not share it with advertisers.

We may disclose data when the law requires it, for example to a court or a public authority acting within its powers.

Transfers outside the European Economic Area

Some providers, notably Cloudflare, operate globally. Where personal data leaves the EEA we rely on the European Commission's adequacy decision for the EU-US Data Privacy Framework where the provider participates in it, and otherwise on the standard contractual clauses adopted by the Commission, supplemented by technical measures such as encryption in transit and at rest. You can ask us for a copy of the safeguards in place.

How long we keep it

  • Contact form submissions: for as long as the conversation is active, and then for up to 24 months from the last exchange so that we can pick up a paused discussion. Submissions that lead to a contract are kept for the duration of the relationship and afterwards as the law requires.
  • Technical logs: up to 30 days, unless a log is needed to investigate a security incident.
  • Consent records: for as long as the consent is valid and for 3 years afterwards to demonstrate that it was given.

When data is no longer needed we delete it or anonymise it.

Your rights

Under the GDPR you have the right to:

  • access the personal data we hold about you and receive a copy;
  • have inaccurate data corrected and incomplete data completed;
  • have your data erased where there is no longer a legal ground to keep it;
  • restrict processing while a dispute about accuracy or lawfulness is resolved;
  • receive the data you provided in a structured, machine-readable format and have it transmitted to another controller;
  • object to processing based on our legitimate interests, including direct business communication, at any time;
  • withdraw consent at any time, without affecting the lawfulness of processing carried out before the withdrawal.

To exercise a right, write to privacy@fluencesecurity.com. We answer within one month; for complex requests we may extend this by a further two months and will tell you if so. We may ask you to confirm your identity before acting on a request.

You also have the right to lodge a complaint with a supervisory authority. In Poland this is the President of the Personal Data Protection Office (Prezes Urzędu Ochrony Danych Osobowych), ul. Stawki 2, 00-193 Warsaw, uodo.gov.pl.

Is providing data mandatory?

Providing data in the contact form is voluntary, but without the fields marked as required we cannot answer your request. Technical data is generated automatically by your browser; you can limit it with browser settings, at the cost of some functionality.

Children

This website is addressed to businesses and their staff. We do not knowingly collect data from anyone under 16. If you believe a child has sent us data, write to us and we will delete it.

Cookies

The cookies and similar technologies used on this site are described in the cookie policy. By default we set only strictly necessary cookies and we do not load analytics unless you allow it.

Changes to this policy

We may update this policy when the site, our providers or the law change. The version number and the date at the top of the document tell you which version you are reading. Material changes are announced on this page before they take effect.

Questions about this document?

Write to legal@fluencesecurity.com or privacy@fluencesecurity.com for privacy matters.

xenXDRby FluenceSecurity

A FluenceSecurity product
Made in Gdańsk, Poland

  • GitHub
  • LinkedIn
  • X

Platform

  • Platform overview
  • SIEM and search
  • Endpoint agent
  • Detections
  • AI triage
  • Playbooks and response
  • Alerts, cases and reports
  • Multi-tenancy and access
  • Customer portal
  • Integrations

Solutions

  • For security teams
  • For MSSPs
  • Managed SOC by FluenceSecurity

Resources

  • Documentation
  • Why XenXDR
  • Security and trust
  • Changelog
  • Pricing

Company

  • fluencesecurity.com
  • About FluenceSecurity
  • MDR service
  • Blog
  • Contact

Legal

  • Privacy policy
  • Cookie policy
  • Website terms
  • Software licence terms
  • Data processing
  • Service levels
  • Company details
  • Accessibility
  • Vulnerability disclosure
  • Subprocessors
© 2026 FluenceSecurity. All rights reserved.Sigma, Splunk, Okta, Microsoft, Fortinet and other marks belong to their respective owners.
EN·PL