Instart Privacy Notice

At Instart Logic, Inc. (“Instart,” “we,” “us,” “our”), your privacy is important to us and we know that users of our Services, visitors to our Websites and other individuals (“you,” “your”) care about your privacy and how your Personal Information is used and shared.

This Privacy Notice ("Notice”) applies to the information that we collect that personally identifies you (“Personal Information”), and how we use, protect and disclose it in connection with:

  • your use of our products and services (collectively the Services)
  • your use of and any other website that contains this Notice is linked to ("Websites")
  • any other interactions you have with Instart online or offline including attendance at events or at our offices.

This Privacy Notice applies to Personal Information where we decide how and why your Personal Information is to be processed (or to use the European terminology, where we act as a data controller). It does not apply where we are acting as service provider to another organization who decides how and why we process your Personal Information (or to use the European terminology, where we act as a data processor).

This Notice does not apply to the practices of companies that we do not own or control, or to individuals that we do not employ or manage. Where you access the Services under a contract with an organization (e.g. your employer), that organization controls the information processed by the Services. For more information, please see Notice to End Users below.

SECTION ONE: Privacy for Users of Our Services

This section applies to Personal Information that we collect and process related to individuals who access the Services and in the usual course of our business (“Service Users“). In this section “you” and “your” refers to Service Users.

Instart creates a more secure internet by enabling organizations to deliver secure and trusted experiences to their customers, partners, and employees. Through its cloud-based web application security solutions, Instart’s intelligent automation reduces the time to detect and mitigate attacks so organizations can stay ahead of advanced and emerging web application and API cyber threats. Learn more about how Instart can protect your apps, customers, and brand at

Personal Information that we collect about Service Users.

Personal Information you provide directly to us in connection with the Services: In connection with the Services, we receive and store any information you knowingly provide to us. This Personal Information may include:  

  • Your name, title, company, email address, phone number, address, and other business contact information.

Typically, it will be obvious why you are being asked to provide this information in connection with a particular element of the Services (e.g. when you provide feedback to us, engage with interactive features, request support or participate in events or promotions we will need your contact information in order to make these things happen). Please see How we use your Personal Information in connection with the Services below for more information.

Personal Information we receive from other sources: We may receive Personal Information about you from:

  • Other Service Users (e.g. if your email address is mentioned in feedback or designated as a contact);
  • Third-party services. The information we receive when you link or integrate our Services with a third-party service depends on the settings, permissions and privacy policy controlled by that third-party service (e.g. if you link your Google Account to the Services, we may receive your name and email address as permitted by your profile settings in order to authenticate you). You should always check the privacy settings and policies in these third-party services to understand what data may be disclosed to us or shared with our Services.
  • Business and channel partners. We work with a global network of partners. Some of these partners help us to market and promote our products, generate leads for us, and resell our products. In this context, we may receive information such as contact information, company name, what products you have purchased or may be interested in, evaluation information you have provided, what events you have attended, and what country you are in. We also may receive information about you and your activities on and off the Services from third-party partners, such as advertising and market research partners who provide us with information about your interest in and engagement with, our Services and online advertisements.

How we use your Personal Information in connection with the Services

How we use the information we collect depends in part on which Services you use, how you use them, and any preferences you have communicated to us. In connection with the Services, we may use your Personal Information:

  • To provide, operate, optimize, manage, repair and otherwise maintain the Services, including customizing and improving the content, navigation and layout, system administration and ensuring the functionality and security of the Services to analyze crash information;
  • To register you for and manage your attendance at events (e.g. if you sign up for an information event, webinar or demo via the Services);
  • For security purposes (e.g. to authenticate you, verify accounts and activity, monitor suspicious or fraudulent activity, and to identify violations of Service policies);
  • To provide support (e.g. to respond to your requests for assistance, to resolve technical issues you encounter and to repair and improve the Services);
  • To process or personalize our interaction with you (e.g., we may use your email domain to infer your affiliation with a particular organization or industry to personalize our interactions with you, or where you use multiple Services, we may combine information about you and your activities to provide an integrated experience, such as to present relevant product information as you travel across our websites);
  • For research and development (we are always looking for ways to make our Services smarter, faster, secure, integrated, and useful to you. We use collective or aggregated learnings about how people use our Services and feedback provided directly to us to troubleshoot and to identify trends, usage, activity patterns and areas for integration and improvement of the Services)
  • To communicate with you about the Services (e.g. responding to your comments, questions and requests, providing support, and sending you notices, updates, security alerts, and administrative messages);
  • To market, promote and drive engagement with the Services: (e.g. we may use your contact information and information about how you use the Services to send promotional communications that may be of specific interest to you, including by email and by displaying ads on other companies' websites and applications, as well as on platforms like Facebook and Google). These communications are aimed at driving engagement and maximizing what you get out of the Services, including information about new features, survey requests, newsletters, and events we think may be of interest to you. We also communicate with you about new product offers, promotions and contests. You can control whether you receive these communications as described below
  • To publish testimonials or featured customer stories to promote the Services, with your permission
  • To protect our legitimate business interests and legal rights: Where required by law or where we believe it is necessary to protect our legal rights, interests and the interests of others, we may use information about you in connection with legal claims, compliance, regulatory, and audit functions, and disclosures in connection with the acquisition, merger or sale of a business
  • To carry out other legitimate business purposes, as well as other lawful purposes

SECTION 2: Privacy for Visitors

This section applies to Personal Information that we collect and process about individuals who visit the Websites or interact with Instart online or offline, such as in connection with our recruitment, events, sales and marketing activities or when you visit our offices (“Visitors“). In this section “you” and “your” refers to Visitors.

Personal Information you provide directly to us when using the Websites or interacting with us online or offline: In connection with these interactions, we receive and store any information you knowingly provide to us This Personal Information may include:

  • Your name, title, company, email address, phone number, address, other contact information and photos.

For example, we may ask you to provide certain Personal Information (such as your name, contact details, company name, profile information) in order to find out more about Instart or the Services, apply for a role with Instart, or otherwise submit inquiries or make contact with us. We may also collect Personal Information, such as your contact and job details and feedback, when you attend our events, take part in surveys, or through other business or marketing interactions that we may have with you. You may choose to provide additional information when you communicate with us or otherwise interact with us, and we will keep copies of any such communications for our records.

The Personal Information that we ask you to provide, and the reasons why, will be made clear to you at the point we ask you to provide it. We will also let you know (prior to collection) whether the provision of the Personal Information we are collecting is compulsory or may be provided on a voluntary basis and the consequences, if any, of not providing the information.

Information we collect automatically through the Websites: When you visit our Websites, we may also collect certain information automatically from your device. In some countries, including countries in the European Economic Area, this information may be considered Personal Information under the law.

Specifically, the information we collect automatically may include:

  • IP addresses or domain names of the computers utilized by the Visitors who use this Website
  • Uniform Resource Identifier (URI) addresses
  • Time of the request and details about the visit (e.g., the time spent on each page on the Website)
  • Method utilized to submit the request to the server
  • Size of the file received in response
  • Numerical code indicating the status of the server's answer (successful outcome, error, etc.)
  • Country of origin
  • Details about the browser and the operating system utilized by the Visitor
  • Details about the path followed within the Websites (including the sequence of pages visited) ("Website Usage Data").

We (including our third party partners) may collect this information as a part of log files as well as through the use of cookies, tags or other tracking technologies. Our use of cookies and other tracking technologies is discussed more below, and in more detail in our Cookie Policy.

B. How we use Personal Information about Visitors

We may use the Personal Information we collect through our Websites for a number of reasons, including:

  • To provide, operate, optimize, manage and maintain the Websites, including customizing and improving the content, navigation and layout, system administration and security
  • To send you information for marketing purposes, in accordance with your marketing preferences
  • For recruitment purposes if you have applied for a role with Instart
  • To respond to your online inquiries and requests, and to provide you with information and access to resources about the Websites or Services that you have requested from us
  • To identify any server, network or other IT issues
  • For security purposes (including to maintain the security and safety of our people and property).
  • To compile aggregated statistics about usage and to better understand the preferences of our Visitors
  • To carry out research and development to improve the Websites
  • To carry out other legitimate business purposes, as well as other lawful purposes

Visitors are responsible for ensuring that they have a lawful basis to use any third-party Personal Information obtained, published or shared through this Website.

SECTION 3: General Information

Cookies and Tracking Technologies

We and our partners may use cookies, pixels and web beacons and various other tracking technologies to collect and store information when you use our Services or the Websites (including the Services Usage Data and the Websites Usage Data). Our use of cookies and other tracking technologies is discussed in more detail in our Cookie Policy.

How we share the Personal Information we collect

We do not rent or sell your Personal Information to anyone. However, we do share your Personal Information with third parties as described below:

  • Businesses and third party websites we do not control: In certain situations, businesses or third party websites we’re affiliated with may sell items or provide services to you through the Website or the Services (either alone or jointly with us). You can recognize when another business is associated with such a transaction or service, and we will share your Personal Information with that business only to the extent that it is related to such transaction or service.  The Services may include links that direct you to other websites or services whose privacy practices may differ from ours. If you are submitting information to any such third party through our Websites or Services, we recommend that you review and understand that party's applicable policies, including their privacy policy. .
  • Social Media Companies: Some of our Services may contain widgets and social media features. These widgets and features may collect your IP address, which page you are visiting on the Services, and may set a cookie to enable the feature to function properly. Widgets and social media features are either hosted by a third party or hosted directly on our Services. Your interactions with these features are governed by the privacy notice of the company providing it.
  • Advertising, Analytics and Digital Marketing Partners: We may partner with third-party advertising networks and exchanges to display advertising on our Websites or to manage and serve our advertising on other sites or to better understand our Websites or Services. We may share your Personal Information with them for this purpose. We and our third-party partners may use cookies and other tracking technologies, such as pixels and web beacons, to gather information about your activities on our Websites and other sites in order to provide you with targeted advertising based on your browsing activities and interests. For more information about cookies and other tracking technologies, please see our Cookie Policy.
  • Agents and Third-Party Service Providers: We employ other companies and people to perform tasks on our behalf and may need to share your information with them to provide the Services or the Websites to you. We make sure that these third parties are subject to data protection obligations, policies and procedures to ensure that they do not use the Personal Information we share with them beyond what is necessary to assist us.
  • Other Website Visitors or Service Users: If we make a forum, message board or similar facility available, you should be aware that any information you provide - including profile information associated with the account you use to post the information - may be read, collected, and used by any person who accesses these facilities. Your posts and certain profile information may remain even after you terminate your account (subject to you exercising of any rights over your Personal Information). We urge you to consider the sensitivity of any information you input into these Websites or Services.
  • Business transfers: We may choose to buy or sell assets. In these types of transactions, Personal Information is typically one of the business assets that would be transferred. Also, if we (or our assets) are acquired, or if we go out of business, enter bankruptcy, or go through some other change of control, Personal Information would be one of the assets transferred to or acquired by a third party (including prospective affiliates, acquirers or similar). The protections of this Notice apply to the information we share in these circumstances. You will be notified via email and/or a prominent notice on the Services if a transaction takes place, as well as any choices you may have regarding your information.
  • Protection of Instart and others: Strictly to the extent permitted by law, we reserve the right to access, read, preserve, and disclose any information, including Personal Information, that we reasonably believe is necessary to comply with law or court order; enforce or apply our conditions of use and other agreements; or protect the rights, property, or safety of Instart, our employees, our users, or others. This may include exchanging information with other companies and organizations for fraud protection.
  • For other purposes, with your consent: If you register for or access the Services using an email address with a domain that is owned by your employer or organization, and such organization wishes to establish an account or site, certain information about you including your name, contact info, content and past use of your account may become accessible to that organization’s administrator and other End Users sharing the same domain.


We endeavor to protect the privacy of your Personal Information by implementing appropriate technical and organizational security measures.

The safety and security of your information also depends on you. Where we have given you (or where you have chosen) a password for access to certain parts of our Services, you are responsible for keeping this password confidential. We ask you not to share your password with anyone. We urge you to be careful about giving out information in public or forum areas of the Services or the Website, such as forums or message boards.

Unfortunately, the transmission of information via the internet and mobile platforms is not completely secure. Although we do our best to protect your Personal Information, we cannot guarantee the security of your Personal Information transmitted through the Services or the Websites.

Location and Retention of your Personal Information:

If you are using our Services from outside the United States, be aware that your information will be transferred to, and maintained on, IT infrastructure located within the United States and further that your information may be accessed within the United States and/or our teams in the UK, Czech Republic and India. Notwithstanding any relevant data transfer mechanisms, the collection, use, retention and any other processing of your information will be governed by United States law and further by the specific jurisdictions within the United States where that information is stored, unless otherwise specified.

How long we keep Personal Information we collect about you depends on the type of information, as described in further detail below. After such time, we will either delete or anonymize your information or, if this is not possible (e.g., because the information has been stored in backup archives), then we will securely store your information and isolate it from any further use until deletion is possible. Our retention practices include:

  • We may retain account information for as long as your account is active and a reasonable period thereafter in case you decide to re-activate
  • We may also retain some of your information as necessary to comply with our legal obligations, to resolve disputes, to enforce our agreements, to support business operations, and to continue to develop and improve the Websites or Services
  • Where we retain information for service improvement and development, we take steps to eliminate information that directly identifies you, and we only use the information to uncover collective insights about the use of our Services, not to specifically analyze any personal characteristics about you
  • If you posted information to a forum or similar, it may remain visible even if you delete or deactivate your account
  • If you have elected to receive marketing emails from us, we retain information about your marketing preferences for a reasonable period of time from the date you last expressed interest in our Services, such as when you last opened an email from us
  • We retain information derived from cookies and other tracking technologies for a reasonable period of time from the date such information was created. Please see our Cookie Policy for more.

How we transfer information internationally:

We collect information globally and primarily store that information in the United States. We may transfer, process and store your information outside of your country of residence, in locations where we (or our third-party service providers) operate from to provide the Services. Whenever we transfer your information, we take steps to protect it. Some of these countries may not have equivalent privacy and data protection laws to the laws of many of the countries where you reside. In addition, some of the third parties described in this Notice, who provide services to us under contract, are based in other countries that may not have equivalent privacy and data protection laws to the country in which you reside. When we share information about you in this way, we endeavor to provide appropriate protections including by making use of standard contractual data protection clauses (approved by the European Commission), binding corporate rules for transfers to data processors, or other appropriate mechanisms to safeguard the transfer.

Your rights and choices over your Personal Information:

Depending on relevant laws in your country, you may have rights to request to access, port, object, correct and erase the Personal Information that we hold about you. In addition to any legal obligations, we strive to provide you with choices regarding the Personal Information you provide to us, where it makes sense.

This section summarizes the rights and choices which may be available to you and how you can exercise them:

  • Accessing, Porting, Objecting or Deleting your Personal Information: You may request access to, portability of or deletion of your information or object to the processing of your Personal Information by emailing us at Please note that some information may remain in our records, e.g. in our archives, after your request of deletion of such information. Please also note that comments you post publicly on our website, such as comments on our blog posts, will remain visible to the public.
  • Updating your Personal Information or deactivating your account or profile: Some of our Services provide functionality to keep your Personal Information up to date or to deactivate your account or profile yourself. If you believe that some of your Personal Information needs to be updated or you would like to deactivate your account or profile, and you are unable to do it yourself, please contact us at
  • Withdrawing your consent or exercising your right to object to marketing or third party sharing: Where you gave us consent to use your information for a limited purpose, you can contact us to withdraw that consent, but this will not affect any processing that has already taken place at the time. You can also opt-out of our use of your information for marketing purposes by contacting us, as provided herein, or by clicking on the unsubscribe link in any marketing email that you receive. You can also withdraw your consent to our collection of Cookies, please see our Cookie Policy. When you make such requests, we may need time to investigate and facilitate your request. If there is delay or dispute as to whether we have the right to continue using your information, we will restrict any further use of your information until the request is honored or the dispute is resolved, provided your administrator does not object (where applicable). If you object to information about you being shared with a third-party app, please disable the app or contact your administrator to do so.
  • Complaining to your local data protection authority: If you have unresolved concerns, you may have the right to complain to a data protection authority in the country where you live, where you work or where you feel your rights were infringed.

Note these rights are not absolute and your request and/or choices may be limited in certain cases: e.g., if fulfilling your request would reveal information about another person, or if you ask to delete information which we have compelling legitimate interests to keep.

Your California Privacy Rights: Under California Civil Code Sections 1798.83-1798.84, California residents are entitled to ask us for a Policy identifying the categories of Personal Information which we share with our affiliates and/or third parties for marketing purposes, and providing contact information for such affiliates and/or third parties. If you are a California resident and would like a copy of this Notice, please submit a written request to

Notice to End Users: Where the Services are made available to you through an organization (e.g. your employer), that organization is the administrator of the Services and is responsible for the accounts and/or Service sites over which it has control. If this is the case, please direct your data privacy questions to your administrator, as your use of the Services is subject to that organization's policies. We are not responsible for the privacy or security practices of an administrator's organization, which may be different than this Notice. If you use an email address provided by an organization (such as your work email address) to access the Services, then the owner of the domain associated with your email address (e.g. your employer) may assert administrative control over your account and use of the Services at a later date. If you do not want an administrator to be able to assert control over your account or use of the Services, use your personal email address to register for or access the Services (if permitted).

Legal basis of processing (for individuals from the European Economic Area)

If you are from the European Economic Area, our legal basis for collecting and using the Personal Information described above will depend on the Personal Information concerned and the specific context in which we collect it.

However, we will normally collect and use Personal Information from you where the processing is in our legitimate interests and not overridden by your data-protection interests or fundamental rights and freedoms. Typically, our legitimate interests include improving, maintaining, providing, and enhancing our technology, products, and services; ensuring the security of the Services; and for our marketing activities.

If you are someone who has signed up for one of our events, white papers or demonstrations, we need your Personal Information to perform a contract with you (that is providing you with the event, white paper, demonstration or any other service you request).

We rely on individual's consent in limited circumstances.  For example, we get your consent to collect Website Usage Data using tracking technologies such as cookies. We also send you electronic marketing messages where you have agreed to us doing so. Our subsequent processing of that Website Usage Data will be based on our legitimate interests to pursue our business purposes, such as outlined in this Notice, having balanced those interests against any privacy rights of any individuals.

In some other limited cases, we may also have a legal obligation to collect Personal Information from you. If we ask you to provide Personal Information to comply with a legal requirement, we will make this clear at the relevant time and advise you whether the provision of your Personal Information is mandatory or not, as well as of the possible consequences if you do not provide your Personal Information.

In any case, we will gladly help to clarify the specific legal basis that applies to any of the purposes for which we process your Personal Information, and in particular whether the provision of Personal Information is a statutory or contractual requirement, or a requirement necessary to enter into a contract. Please contact us at

The provision of additional notices

In addition to the information contained in this Notice, this Website may provide you with additional and contextual information concerning particular Services or the collection and processing of Personal Information upon request.


We do not knowingly collect or solicit Personal Information from children or anyone under the age of 16 or knowingly allow such persons to use access or register for the Services. Neither our Websites, Services, nor this Notice, are directed to such persons. If you are a child or under 16, please cease use of the Websites, do not attempt to use the Services or send any information about yourself to us, including your name, address, telephone number, or email address. In the event that we learn that we have collected Personal Information from such persons without a lawful basis, we will delete that information as quickly as possible. If you believe that we may have any information from or about such a person, please contact us immediately at

“Do Not Track” requests

Our Websites do not support “Do Not Track” requests.

Changes to this Notice

We reserve the right to make changes to this Notice at any time by giving Notice to its Service Users and Visitors on this page and possibly within this Website and/or - as far as technically and legally feasible - sending a Notice to Service Users and Visitors via any contact information available to us. We strongly recommended you check this page often, referring to the date of the last modification listed at the bottom. 

Should the changes affect processing activities performed on the basis of the your consent, we shall collect new consent from you, where required.

Latest update: October 3, 2019

Questions or Concerns?

If you have any questions or concerns regarding our privacy policies or this Notice, please contact us at, and we will do our very best to resolve your concerns.

Data Controller: Instart Logic, Inc. 
450 Lambert Avenue 
Palo Alto 
California 94306