Legal terms
March 1, 2024
Privacy Notice
This notice explains how we (Snyk Limited and our affiliates) collect, use, and disclose personal information. Snyk is a provider of software-as-a-service that helps developers find and fix vulnerabilities and other issues relating to their software projects. We collect personal information when you interact with our website or use our products and services (together the “Platform”). Please read it carefully.
As used in this notice “personal information” means information that relates to, describes or could be used to identify an individual. It does not include anonymous or de-identified data that does not identify an individual or cannot reasonably be linked to an individual.
Here is a brief summary of the information contained in this notice:
What personal information do we collect? We collect identifiers, customer records, commercial information, geolocation data, and internet or network activity.
How do we use personal information? We use personal information to operate our business, including fulfilling contract obligations, personalizing user experiences, communicating with users, and administering the Platform.
How long do we retain personal information? We keep personal information for as long as reasonably necessary to fulfill the purposes for which we collected, including satisfying any legal, regulatory, tax, accounting or reporting requirements. We may retain your personal information for longer in the event of a complaint or a potential dispute regarding our relationship with you.
Do you sell my personal information? We may share or sell (as defined by California law) your personal information for third-party advertising purposes. For more information, go to the “Additional Information for users in California” section.
If you want to find out more information, you can jump to a specific section by clicking the links below:
What personal information does Snyk collect?
How does Snyk collect my personal information?
How does Snyk use my personal information?
Does Snyk disclose my personal information?
What rights do I have concerning my personal information?
What about third-party links on the Platform?
Additional Information for users in the UK, EEA and Switzerland
Additional information for users in California
Who can I contact with questions or concerns?
What personal information does Snyk collect?
We collect and process the following categories of personal information:
Identifiers. This includes information such as your name, username, and contact information. If you use a third-party authentication tool, we may receive your username and email addresses associated with that service.
Customer Records. This also includes information such as your name and contact information.
Commercial Information. This includes details such as which of our products or services you use.
Geolocation Data. This includes information about your general location.
Internet or Network Activity. This includes information such as your IP address, browser type, operating system, and activity on our website (such as what pages you visited and where you clicked).
Our Platform is not intended for minors so we do not knowingly collect information from or about minors. If we discover that we collected information on a minor, we will promptly take corrective action. If you believe we have collected such information, please contact us at privacy@snyk.io.
How does Snyk collect my personal information?
We collect personal information from:
You. We collect personal information when you give it to us, such as when you fill out a form, log-in to the Platform, or contact us.
Your Devices. We collect personal information from your devices, often through the use of cookies or similar tools. Cookies (and similar tools) help us to provide you with a good experience when you browse our Platform and also allows us to improve our Platform. You can find more information on which cookies we use, why we use them, by reviewing the details in our cookie management tool on our website.
Third Parties. We receive personal information from our vendors, business partners, and any third-party authentication providers you use to access our site. Additionally, if you use the Platform while working for one of our customers, we may receive your information from that customer so we can configure your account.
How does Snyk use my personal information?
We use personal information we collect to operate our business and fulfill our legal and compliance obligations, including:
Carrying out contracts entered into between you and us
Providing you with the information, products and services you request from us;
Providing customer service and support;
Contacting you about your account or changes to our products and services;
Administering and improving our products and services, including troubleshooting, data analysis, testing, research, statistical and survey purposes;
Informing you about other products and services we offer that are similar to those that you have already purchased or enquired about;
Delivering content and services information relevant to you including newsletters, industry updates, marketing communications and advertising;
Personalizing your experience; and
Keeping our products and services secure.
Does Snyk disclose my personal information?
We disclose information to our vendors who help us operate our business. We require our vendors to contractually commit that they will safeguard the information and only use it in connection with purposes we specify.
We may also disclose your information to third-parties: in connection with a corporate reorganization; to enforce applicable contract terms or comply with our legal obligations; with your consent; or to protect the rights, property, or safety of Snyk, our users, or others.
We also provide limited personal information to marketing, analytic, and search-engine companies. These companies help us understand interactions with our Platform and provide you relevant advertising.
What rights do I have concerning my personal information?
You have the following rights concerning your personal information:
Access. You may request that we provide you with a copy of the personal information we hold about you or that we provide you details about that information (such as what categories of data we collected, why we collected it, and what sources provided us the information).
Deletion. You may request that we delete your personal information.
Correction. You may request that we correct information you believe is inaccurate or complete information you believe is incomplete.
Opt-out. You may request that we refrain from selling your personal information or sharing it for targeted advertising.
You, your authorized agent, or another person authorized by law may request to exercise the above rights. If you wish to exercise the above rights, please submit a Privacy Request Form. Once you complete this form, you will receive an email to verify your identity so we can process your request.
To opt out of sales or targeted advertising, update your settings in our cookie manager, use a universal opt-out signal, or email us at privacy@snyk.io.
You can also opt-out by setting a universal opt-out signal on your browser. Opt-out signals are browser specific, so you must set the signals in each of the browsers you use – we cannot honor them if they are not set in the browser you are using to access the Platform. We recommend following the instructions from your browser provider on how to set universal opt-out signals. We do not charge for or change your experience based on your use of universal opt-out signals. We do not display pop-ups or other notifications, except in some cases a display acknowledging your request, in response to your use of opt-out signals.
To remove your account from app.snyk.io please follow the steps in the “How Can I Delete my Account?”guide.
What about third-party links on the Platform?
Our Platform may contain links to web properties operated by third parties. If you follow any of these links, your usage of that web property will be subject to the third-party’s privacy policy. We do not accept any responsibility or liability for these policies. Please check these policies before you submit any personal information to these websites.
Additional Information for users in the UK, EEA and Switzerland
As a global company, Snyk adheres to the General Data Protection Regulation (“EU GDPR”) and the UK General Data Protection Regulation (“UK GDPR”, together with the EU GDPR “GDPR”).
Snyk is controller. Because Snyk determines the means and purpose for which your personal information is processed, pursuant to the GDPR, Snyk is the data controller with respect to your personal information.
Legal Bases for processing. We only process your personal information pursuant to one of the following legal bases:
Consent. You provided us with consent to process your personal information.
Contract. We may process your personal information to execute a contract with you or your employer.
Legal Compliance. We may process your personal information to comply with our legal obligations.
Legitimate Interest. Where it is necessary for us to process the information in order pursue our legitimate interests, including:
providing and improving our products and services;
maintaining the security and integrity of our offerings;
minimizing claims and financial losses for us, and our customers;
promoting our products, services and brand; and
conducting research and analytics.
Additional Rights. In addition to your rights specified above, you have the right to:
object to our processing of your personal information,
request that we restrict our processing of your information,
transfer your personal information to another party
withdraw your consent to any processing premised on your consent, or
file a complaint with the applicable supervisory authority.
We will not discriminate against you for exercising any of your rights. To exercise these rights, please submit a Privacy Request Form.
International Transfer. Because Snyk is an international business, we may need to transfer your personal information out of the UK, EEA or Switzerland to other countries. We only transfer your information if (1) the recipient is in a country providing an adequate level of protection; (2) we use appropriate safeguards, such as standard contractual clauses; or (3) there is an applicable exception (such as consent). Please contact us at privacy@snyk.io if you would like additional information regarding the international transfer of your personal information.
Questions or concerns. If you have questions or concerns about our GDPR compliance, you can contact our GDPR representative—the European Data Protection Office (“EDPO”) using their online request form or by writing to them at Avenue Huart Hamoir 71, 1030 Brussels, Belgium.
If you are in the UK, you may submit a complaint to the Information Commissioner's Office (“ICO”) (www.ico.org.uk); however, we request that you first give us an opportunity to address your concerns before you contact the ICO.
Additional information for users in California
In the last twelve months we have collected the personal information identified in the “What personal information does Snyk collect?” section of this notice.
We do not intentionally collect sensitive personal information, as defined in the California Consumer Privacy Act. If you provide us with such information, we will only use that information for purposes permitted by California Civil Code section 1798.121(a) and the related regulations.
We allow (and in the last 12 months we have allowed) trusted partners to collect personal information - namely internet or network activity - on your activity on our Platform in order to provide you with more useful, targeted advertisements. California considers that to be selling or sharing your information for targeted advertising. Although we do not currently respond to Do Not Track signals, we do provide other options for you to request that we do not sell or share your personal information. To opt-out of sharing or sale of your information follow the instructions in the “What rights do I have concerning my personal information?” section of this notice.
We do not have actual knowledge that we sold or shared personal information concerning minors—those under 16 years of age.
Will Snyk change this policy?
We may change this policy from time to time, such as when the law changes. If we make a change, we will post the new version on this website and, if required by law, notify you of the updates. Please check back frequently to see any updates or changes to our privacy policy.
Who can I contact with questions or concerns?
If you have questions or concerns, please contact us at privacy@snyk.io.