Privacy Protected

Privacy Policy

This Privacy Policy describes how Fixure, Inc. (“Fixure,” “Company,” “we,” “us,” or “our”) collects, uses, stores, discloses, and protects personal information when individuals and organizations access our website, platform, and related services (collectively, the “Service”). By accessing or using the Service, you acknowledge that you have read, understood, and agree to the practices described in this Privacy Policy. If you do not agree to this Privacy Policy, you must not access or use the Service.

This Privacy Policy is expressly incorporated into our Terms of Service, and by agreeing to the Terms of Service, you also agree to the terms set forth herein.

Fixure provides a software platform that enables organizations to centralize, correlate, and analyze security-related signals, alerts, logs, vulnerabilities, and other data originating from third-party tools, integrations, or systems you choose to connect. Because our Service involves the ingestion and processing of potentially sensitive operational and security information, including information that may constitute personal data under applicable privacy laws, we are committed to handling all data with diligence, transparency, and industry-recognized security practices.

Where we process personal data on your behalf, we act as a service provider or data processor (as applicable under relevant laws) and process such data only in accordance with your instructions and applicable legal requirements. For customers subject to GDPR or similar regulations, a Data Processing Addendum (DPA) incorporating Standard Contractual Clauses is available upon request.

Fixure maintains industry-standard security certifications and conducts regular security assessments; information about our current certifications is available upon request.

Last Updated: 12/10/2025

1. Information We Collect

Fixure collects information that users provide directly, information collected automatically through use of the Service, and information originating from external systems that users connect to Fixure.

Directly provided information may include your name, email address, authentication credentials, company or organizational affiliation, billing details, support communications, and any other information voluntarily submitted through forms, onboarding flows, demonstrations, or interactions with our team.

We also collect information automatically when you interact with the Service, including IP addresses, device identifiers, browser types, operating systems, referring URLs, timestamps, usage logs, cookies, analytics identifiers, and similar technical data.

When you connect Fixure to external systems or third-party integrations—such as security scanners, cloud environments, SSO providers, alerting tools, vulnerability management systems, or other software services—we receive the data those integrations supply based on your configuration. That data may include alerts, events, vulnerabilities, audit logs, configuration metadata, user identifiers, system-generated messages, and any related operational information necessary for Fixure to provide its core functionality. You represent and warrant that you have obtained all necessary consents, authorizations, and rights to provide such data to Fixure and that such provision complies with all applicable laws and third-party agreements.

2. How We Use Your Information

We distinguish between two categories of information:

  • “Service Data” : Information you provide or that is collected through your use of the Service, including data from connected integrations, which we process on your behalf as a service provider or processor
  • “Business Data”: Information we collect for our own business purposes, such as account management, billing, and Service improvement. The following describes how we use both categories.

We use the information we collect to provide, operate, maintain, improve, and secure the Service. This includes authenticating users; facilitating connections with third-party systems; processing and displaying alerts, events, and vulnerabilities; providing dashboards, analytics, views, and organizational insights; and communicating with you about your account, support requests, updates, and administrative notices.

We also use information to develop and enhance the Service, conduct internal analytics, troubleshoot technical issues, prevent fraud, enforce policies and agreements, protect the integrity of our systems, and comply with applicable laws and regulatory obligations.

Fixure may also generate aggregated or de-identified data for research, product development, usage analysis, or industry insights. Such aggregated or de-identified data is created using techniques designed to prevent re-identification and does not identify any individual or organization. De-identified data may be used for any legitimate business purpose, including internal analysis, improving Fixure’s services, and sharing with third parties for research or industry benchmarking purposes.

3. Legal Bases for Processing (Where Applicable)

Fixure primarily serves users in the United States but also provides services to users in other jurisdictions. Certain jurisdictions, including the European Economic Area, United Kingdom, and Switzerland, require disclosure of the legal bases under which personal information is processed. Where applicable, we process personal information:
  • To perform our contractual obligations to you under the Terms of Service
  • To pursue our legitimate interests in operating, improving, and securing the Service, provided such interests are not overridden by your data protection rights
  • To comply with legal obligations and
  • Where required, based on your explicit consent, which you may withdraw at any time by contacting us

4. Sharing of Information

Fixure does not sell personal information as defined under applicable privacy laws, including the California Consumer Privacy Act (CCPA). However, we may share information with trusted third-party service providers that assist us in operating the Service, such as hosting providers, cloud infrastructure, logging and monitoring tools, analytics services, email and communication tools, customer support platforms, and payment processors. We may share information with integration partners only where such sharing is necessary to enable the features or connections you have selected, where you have authorized such sharing through your configuration settings, and where we have appropriate agreements in place to protect your information.

We may also disclose information if required by law, regulation, subpoena, court order, legal process, or government request, or if we believe in good faith that such disclosure is necessary to protect the rights, property, or safety of Fixure, our users, or the public. In the event of a merger, acquisition, financing transaction, corporate restructuring, or sale of assets, your information may be transferred to the acquiring or successor entity, subject to continued protections consistent with this Privacy Policy.

5. Data Security

Fixure implements industry-standard administrative, technical, and physical safeguards to protect personal and organizational information from unauthorized access, alteration, disclosure, or destruction. These measures include encryption of data in transit, secure hosting environments, access controls, multi-factor authentication for internal systems, audit logging, and routine internal reviews.

While Fixure strives to maintain a secure environment, no online service can guarantee absolute security. In the event of a security incident resulting in the confirmed unauthorized access, acquisition, or disclosure of personal information under our control, we will notify you and any applicable regulatory authorities as required by applicable law, including, but not limited to, the GDPR and relevant U.S. state data breach notification statutes. We will provide such notice without undue delay after confirming the scope of the incident and the data affected. Your use of the Service is at your own risk, and you are responsible for maintaining the confidentiality of your account credentials and protecting your systems and devices.

6. Data Retention

We retain personal information for as long as necessary to provide the Service, fulfill the purposes described in this Privacy Policy, support our legitimate business interests, comply with legal obligations, resolve disputes, enforce our agreements, and maintain appropriate business records. Upon termination of your account, we will delete or anonymize your personal information within ninety (90) days, except for information we are required to retain by law or that is contained in backup systems, which will be deleted in accordance with our standard backup deletion schedule (typically within one hundred eighty (180) days).

You may request deletion of certain information by contacting us at [Insert Specific Email Address - e.g., legal@fixure.io], subject to applicable legal restrictions, our legitimate business needs, and technical limitations. We will respond to your request within the timeframe required by applicable law, typically within 30-45 days depending on jurisdiction, and will inform you if we require an extension.

7. International Data Transfers

Fixure is based in the United States and primarily stores and processes information within the United States. However, we may store or process information in other jurisdictions through our service providers. Where information is transferred from the European Economic Area, United Kingdom, or Switzerland to countries that do not provide an adequate level of data protection, we implement appropriate safeguards consistent with applicable data protection laws, such as the European Commission’s Standard Contractual Clauses or other approved transfer mechanisms. You may request a copy of these safeguards by contacting us.

8. Your Rights

Depending on your jurisdiction, you may have rights regarding your personal information, including:
  • The right to access and obtain a copy of your personal information
  • The right to correct or update inaccurate data
  • The right to delete your data
  • The right to object to or restrict certain forms of processing
  • The right to data portability
  • The right to withdraw consent where processing is based on consent
  • The right to lodge a complaint with a supervisory authority
To exercise these rights, please contact us using the information provided below. We will respond to your request within the timeframe required by applicable law, typically within 30-45 days. In some cases, we may need to verify your identity before processing your request, and we may deny requests that are manifestly unfounded, excessive, or otherwise not required by law.

9. Children’s Privacy

The Service is intended solely for use by organizations and individuals acting in a professional or business capacity. The Service is not directed to children under the age of 16 (or 13 in the United States under COPPA, or the applicable age in other jurisdictions), and we do not knowingly collect personal information from children. If we learn that we have inadvertently collected such information, we will take prompt steps to delete it. If you believe we have collected information from a child, please contact us immediately.

10. Changes to This Privacy Policy

We may update this Privacy Policy from time to time to reflect changes in our practices, technologies, legal requirements, or other factors. When material changes occur, we will provide notice by updating the “Last Updated” date above and, where required by law or where changes materially affect your rights, by sending you an email notification or posting a prominent notice on the Service at least 30 days before the changes take effect. Your continued use of the Service after the effective date of such modifications constitutes acceptance of the revised Privacy Policy, except where applicable law requires your affirmative consent for material changes. If you do not agree to the revised Privacy Policy, you must discontinue use of the Service and may contact us to close your account.

7. Contact Us

If you have questions about this Privacy Policy or wish to submit a privacy-related request, you may contact us at:

Fixure, Inc.

Email: legal@fixure.io

Address: 1111B S Governors Ave STE 39760 Dover, DE 19904

This privacy policy is effective as of 12/10/2025 and may be updated from time to time.