Privacy Policy
This Privacy Policy describes how Certynx collects, uses, discloses, retains, and protects personal information when you visit our websites, interact with us, use our products and services, or otherwise communicate with Certynx.
Certynx, Inc. (“Certynx,” “we,” “us,” or “our”) respects your privacy and is committed to protecting personal information entrusted to us.
Certynx provides enterprise software for discovering, governing, automating, and remediating machine identities, including certificates, cryptographic assets, workloads, services, and other machine identities.
Because Certynx operates as an enterprise software provider, we may process information in two different capacities:
- As a controller or business, when Certynx determines the purposes and means of processing information, such as information relating to website visitors, prospects, business contacts, account administration, and our own operations; and
- As a processor or service provider, when Certynx processes Customer Data on behalf of an organization using our services.
This distinction is important and is described further below.
01Scope
This Privacy Policy applies to:
- Certynx websites and online properties that link to this Privacy Policy;
- Certynx products and services;
- Customer and user accounts;
- Communications between you and Certynx;
- Sales and business-development activities; and
- Other interactions with Certynx where this Privacy Policy is referenced.
This Privacy Policy does not apply to websites, applications, or services operated by third parties, even where those services are integrated with Certynx.
Where Certynx processes personal information solely on behalf of a customer, the customer’s privacy policy and applicable contractual terms may govern that processing. In those circumstances, Certynx generally acts as a processor or service provider rather than the controller or business responsible for the information.
02Definitions
For purposes of this Privacy Policy:
“Customer”
An organization or entity that has entered into an agreement with Certynx for the use of Certynx products or services.
“Authorized User”
An individual authorized by a Customer to access or use a Certynx service.
“Customer Data”
Information submitted to, collected by, or otherwise made available to Certynx through the Certynx services on behalf of a Customer.
“Machine Identity Data”
Technical information associated with certificates, cryptographic assets, workloads, applications, services, devices, infrastructure, and other machine identities.
“Personal Information”
Information that identifies, relates to, describes, or could reasonably be linked to an identified or identifiable individual, as defined by applicable law.
03Information We Collect
The information we collect depends on how you interact with Certynx.
3.1 Information You Provide to Us
We may collect information you voluntarily provide, including when you:
- Request a demonstration;
- Request early access;
- Contact sales;
- Create or administer an account;
- Register for a service;
- Contact customer support;
- Participate in an event or webinar;
- Subscribe to communications;
- Complete a form;
- Enter into an agreement with Certynx;
- Communicate with us by email or other means; or
- Otherwise provide information to Certynx.
This information may include:
- Name;
- Business email address;
- Business telephone number;
- Job title;
- Employer or organization;
- Business address;
- Account information;
- Authentication information;
- Customer relationship information;
- Communications and correspondence;
- Billing and transaction information; and
- Other information you voluntarily provide.
04Account and Authentication Information
When you create or use a Certynx account, we may collect information necessary to establish, authenticate, secure, and administer that account.
This may include:
- Name;
- Email address;
- Organization;
- Tenant or account identifiers;
- User roles;
- Permissions;
- Authentication events;
- Authorization events;
- Identity-provider information;
- Single sign-on information;
- Multi-factor authentication information;
- Session information;
- Account security events; and
- Other information necessary to administer access to the service.
Where a Customer configures Certynx to integrate with an identity provider or directory service, Certynx may receive identity information from that system according to the Customer’s configuration and authorization.
05Customer Data and Machine Identity Data
Certynx is designed to discover and manage machine identities and related technical infrastructure.
Depending on the products, integrations, and configuration used by a Customer, Certynx may process information including:
- Certificate metadata;
- Certificate subjects;
- Subject Alternative Names;
- Certificate issuers;
- Certificate authorities;
- Certificate validity periods;
- Certificate fingerprints;
- Public keys;
- Cryptographic algorithms and metadata;
- Trust relationships;
- Hostnames;
- Domain names;
- IP addresses;
- Device identifiers;
- Workload identifiers;
- Application identifiers;
- Service identifiers;
- Cloud-resource identifiers;
- Kubernetes resources and metadata;
- Container and workload metadata;
- Infrastructure configuration;
- Discovery results;
- Security findings;
- Policy information;
- Audit events;
- Workflow activity;
- Approval activity;
- Remediation activity;
- Integration metadata; and
- Other technical information made available through Customer-configured integrations.
Machine Identity Data is not inherently personal information.
However, technical information may contain or become associated with personal information depending on the Customer’s environment. For example, a directory record, certificate subject, hostname, audit event, or workflow record may contain a person’s name, email address, username, or other identifier.
Customers are responsible for determining what information they make available to Certynx through their environments and integrations.
06Secrets, Credentials, and Cryptographic Material
Certynx is designed to operate with enterprise security infrastructure and may support integrations requiring authentication credentials, tokens, certificates, or other access mechanisms.
Customers determine which integrations they enable and what permissions they grant.
Certynx does not require Customers to provide private keys or secret cryptographic material merely to use ordinary discovery and governance functionality.
Where a particular Certynx feature requires credentials, tokens, secrets, or other authentication material, Certynx will process that information as necessary to provide the applicable functionality and in accordance with the applicable Customer agreement.
Customers should not provide Certynx with information that is unnecessary for the intended use of the service.
07Automatically Collected Information
When you visit our websites or use our services, we may automatically collect certain technical information.
This may include:
- IP address;
- Browser type;
- Operating system;
- Device type;
- Approximate geographic information derived from IP address;
- Referring and exit pages;
- Pages and features accessed;
- Date and time of access;
- Session information;
- Diagnostic information;
- Error information;
- Performance information;
- Security events; and
- Other information transmitted by your browser or device.
We use this information to operate, secure, maintain, troubleshoot, and improve our websites and services.
08Information We Receive From Other Sources
We may receive information about you from sources other than directly from you.
These sources may include:
- Your organization;
- Your organization’s identity provider;
- Directory services;
- Customer-configured integrations;
- Business partners;
- Service providers;
- Publicly available business information;
- Event organizers; and
- Other lawful sources.
We may combine information obtained from these sources with information we already maintain where permitted by applicable law.
09How We Use Information
We may use information to:
- Provide and operate the Certynx services;
- Create and administer accounts;
- Authenticate and authorize users;
- Discover and manage machine identities;
- Monitor certificates and machine identities;
- Provide alerts and notifications;
- Execute workflows;
- Automate authorized actions;
- Support remediation functionality;
- Provide customer support;
- Respond to inquiries;
- Communicate with Customers and users;
- Process transactions and manage billing;
- Maintain and improve service availability;
- Monitor performance and reliability;
- Detect, investigate, and prevent security incidents;
- Detect fraud, abuse, and unauthorized access;
- Protect Certynx, Customers, users, and other parties;
- Develop and improve products and features;
- Conduct analytics and operational research;
- Comply with legal and regulatory obligations;
- Enforce our agreements and policies;
- Establish, exercise, or defend legal claims; and
- Carry out other purposes disclosed when information is collected or otherwise permitted by law.
We do not use Customer Data to create advertising profiles about Customer users.
10Legal Bases for Processing
Where applicable law requires a legal basis for processing personal information, Certynx may rely on one or more of the following:
Contractual Necessity
We may process information when necessary to provide products or services under an agreement with you or your organization.
Legitimate Interests
We may process information where necessary for legitimate interests, including:
- Operating and securing our services;
- Preventing fraud and abuse;
- Improving our products;
- Maintaining business relationships;
- Communicating with business contacts;
- Protecting our legal rights; and
- Maintaining the security and integrity of our systems.
Where we rely on legitimate interests, we consider the applicable privacy rights and interests of individuals.
Consent
We may process information based on consent where consent is required by applicable law.
Where applicable, you may withdraw consent, although withdrawal does not affect processing that occurred before withdrawal.
Legal Obligations
We may process information where necessary to comply with applicable laws, regulations, legal process, or governmental requirements.
11Certynx as Controller or Business
Certynx acts as a controller or business when we determine the purposes and means of processing personal information.
Examples include personal information relating to:
- Website visitors;
- Prospective customers;
- Business contacts;
- Sales activities;
- Customer relationship management;
- Account administration;
- Billing;
- Marketing communications;
- Customer support;
- Security operations; and
- Certynx’s own business administration.
For these activities, Certynx determines how and why the relevant personal information is processed.
12Certynx as Processor or Service Provider
Certynx acts as a processor or service provider when a Customer determines the purposes and means of processing personal information and Certynx processes that information on the Customer’s behalf.
Examples may include personal information contained in:
- Customer directories;
- Certificate metadata;
- Machine identity records;
- Audit events;
- Workflow records;
- Infrastructure metadata;
- Cloud resources;
- Kubernetes environments;
- Service inventories;
- Security findings; and
- Other Customer Data.
In these circumstances, the Customer generally determines:
- What information is processed;
- Why the information is processed;
- Which individuals are included;
- Which integrations are enabled;
- What permissions are granted; and
- How long information should be retained.
Certynx processes Customer Data according to the Customer’s documented instructions, the applicable Customer agreement, applicable Data Processing Addendum, and applicable law.
This processor relationship is consistent with the general GDPR framework under which a processor acts on behalf of a controller pursuant to an appropriate contractual arrangement.
13Customer Control of Customer Data
Customer Data remains under the Customer’s ownership or control, as applicable under the Customer’s agreement.
Certynx does not acquire ownership of Customer Data merely by providing the services.
Except as necessary to provide, secure, maintain, support, and improve the services as permitted by the applicable agreement, Certynx does not use Customer Data for purposes independent of the Customer’s relationship with Certynx.
Customers are responsible for determining what information they provide to Certynx and for ensuring that their use of the services complies with applicable privacy and data-protection requirements.
14How We Share Information
We may disclose information in the following circumstances.
Service Providers
We may disclose information to third-party service providers that support our operations, including providers of:
- Cloud infrastructure;
- Data hosting;
- Authentication;
- Identity services;
- Communications;
- Email delivery;
- Security services;
- Logging and observability;
- Analytics;
- Customer support;
- Payment processing;
- Professional services; and
- Other operational services.
These providers may process information only as necessary to provide services to Certynx and are subject to appropriate contractual and confidentiality obligations.
Customer-Directed Disclosures
When you use Certynx through an organization, authorized administrators and other authorized users may access information made available through that organization’s Certynx environment.
Certynx does not control how an organization uses information accessible to its authorized administrators and users.
Legal Requirements
We may disclose information when reasonably necessary to:
- Comply with applicable law;
- Respond to lawful governmental requests;
- Respond to legal process;
- Protect rights, property, or safety;
- Investigate security incidents or abuse;
- Enforce agreements; or
- Establish, exercise, or defend legal claims.
Corporate Transactions
Information may be transferred in connection with a merger, acquisition, financing, reorganization, sale of assets, bankruptcy, dissolution, or similar corporate transaction.
With Your Direction
We may disclose information when you direct us to do so or otherwise provide appropriate authorization.
15Subprocessors
Certynx may engage third-party subprocessors to provide infrastructure, hosting, authentication, communications, security, support, analytics, and other services necessary to operate the Certynx platform.
Where Certynx processes Customer Data on behalf of a Customer, subprocessors that process Customer Data will be subject to appropriate contractual obligations concerning confidentiality, security, and data protection.
Certynx may maintain a separate Subprocessor List identifying subprocessors used to provide the applicable services.
Where required by applicable law or contractual commitments, Certynx will provide appropriate notice regarding material changes to subprocessors and applicable rights concerning such changes.
16Sale of Personal Information and Targeted Advertising
Certynx does not sell personal information for monetary consideration.
Certynx does not share personal information for cross-context behavioral advertising.
We may disclose information to service providers and other business partners as necessary to operate our websites and services. Such disclosures are not intended to constitute a sale of personal information or sharing for cross-context behavioral advertising.
If our practices materially change, we will update this Privacy Policy and provide any notices or choices required by applicable law.
17Cookies and Similar Technologies
Certynx may use cookies, local storage, pixels, tags, and similar technologies.
These technologies may be used for:
- Authentication;
- Session management;
- Security;
- Preferences;
- Website functionality;
- Performance monitoring;
- Analytics;
- Fraud prevention; and
- Understanding website usage.
Where applicable law requires consent for non-essential technologies, Certynx will obtain consent before using those technologies.
You can configure your browser to reject or delete cookies. Certain features may not function correctly if required cookies are disabled.
18Marketing Communications
We may send marketing communications about Certynx products, services, events, research, and other business activities.
You may unsubscribe from promotional communications at any time by:
- Using the unsubscribe mechanism included in the communication; or
- Contacting us at privacy@certynx.com.
We may continue to send transactional, administrative, security, and service-related communications where necessary.
19Security
Certynx maintains administrative, technical, and organizational safeguards designed to protect information against unauthorized access, use, alteration, disclosure, or destruction.
Depending on the service and information involved, safeguards may include:
- Encryption in transit;
- Encryption at rest where appropriate;
- Identity and access management;
- Role-based access controls;
- Least-privilege principles;
- Authentication controls;
- Multi-factor authentication;
- Network security controls;
- Logging and monitoring;
- Security event detection;
- Vulnerability management;
- Secure development practices;
- Backup and recovery controls;
- Personnel confidentiality requirements; and
- Incident response procedures.
No system or method of transmission can be guaranteed to be completely secure.
Customers are responsible for protecting their accounts, credentials, integration configurations, and systems connected to Certynx.
20Data Retention
Certynx retains information for as long as reasonably necessary for the purposes described in this Privacy Policy, including to:
- Provide services;
- Maintain accounts;
- Fulfill contractual obligations;
- Maintain security and audit records;
- Comply with legal obligations;
- Resolve disputes;
- Enforce agreements; and
- Protect legitimate business interests.
Customer Data retention may additionally be governed by the applicable Customer agreement, Data Processing Addendum, product configuration, or Customer instructions.
When information is no longer required, Certynx may delete, anonymize, or securely isolate it in accordance with applicable requirements and our retention practices.
Information may remain temporarily in backups or disaster-recovery systems after deletion and may be retained where required for security, legal, or regulatory purposes.
21International Data Transfers
Certynx is based in the United States and may process information in the United States and other countries where Certynx, its affiliates, or service providers operate.
Where applicable law restricts the transfer of personal information across jurisdictions, Certynx will use an appropriate lawful transfer mechanism.
Depending on the circumstances, these mechanisms may include:
- Adequacy decisions;
- Standard Contractual Clauses;
- Other legally recognized contractual safeguards; or
- Other mechanisms permitted by applicable law.
Additional transfer terms may be established in a Data Processing Addendum.
22Privacy Rights
Depending on your location and applicable law, you may have rights concerning your personal information.
These may include:
- The right to access personal information;
- The right to know how personal information is collected and used;
- The right to request correction of inaccurate information;
- The right to request deletion;
- The right to data portability;
- The right to object to certain processing;
- The right to restrict certain processing;
- The right to withdraw consent where processing is based on consent;
- The right to opt out of certain sales or sharing;
- The right to limit certain uses or disclosures of sensitive personal information where applicable; and
- The right to lodge a complaint with an applicable supervisory authority.
These rights vary by jurisdiction and may be subject to legal exceptions.
23How to Exercise Privacy Rights
You may submit a privacy request by contacting:
Certynx, Inc.
6000 Poplar Avenue, Suite 250
Memphis, Tennessee 38119
United States of America
Please include enough information for us to understand and process your request.
We may need to verify your identity before completing certain requests. Verification information will be used for the purpose of processing and securing the request.
We will respond within the time required by applicable law.
Where Certynx processes information on behalf of a Customer, we may refer your request to that Customer because the Customer may be the controller or business responsible for the relevant information.
24California Privacy Notice
This section applies to California residents to the extent the California Consumer Privacy Act, as amended, applies to Certynx’s processing of their personal information.
California law provides applicable consumers with rights including rights to know, delete, correct, opt out of sale or sharing, limit certain uses of sensitive personal information, and receive equal treatment for exercising applicable rights.
Categories of Personal Information
Depending on how you interact with Certynx, we may collect categories of personal information including:
| Category | Examples |
|---|---|
| Identifiers | Name, email address, username, account identifiers |
| Contact information | Business email, business telephone number, business address |
| Professional information | Employer, job title, professional role |
| Internet or network information | IP address, browser information, device information, usage information |
| Account and authentication information | Account credentials, authentication events, session information |
| Commercial information | Subscription, transaction, purchasing, and account information |
| Geolocation information | Approximate location inferred from IP address |
| Inferences | Preferences or interests inferred from interactions with Certynx |
| Other information | Information voluntarily provided through communications, support, forms, or other interactions |
Some Customer Data processed through the Certynx platform may contain additional categories of personal information determined by the Customer’s configuration and use of the services.
Sources
We may collect personal information from:
- You;
- Your organization;
- Your browser or device;
- Your organization’s identity provider;
- Customer-configured integrations;
- Service providers;
- Business partners;
- Publicly available sources; and
- Other lawful sources.
Purposes
We may use personal information for the purposes described in Section 9, including providing services, security, account administration, support, business operations, communications, product improvement, and legal compliance.
Sale and Sharing
Certynx does not sell personal information.
Certynx does not share personal information for cross-context behavioral advertising.
Sensitive Personal Information
Certynx does not intentionally request or require sensitive personal information for ordinary use of its services.
However, Customer environments and integrations may contain information that qualifies as sensitive personal information under applicable law. Customers are responsible for configuring the services and integrations appropriately.
California Requests
California residents may submit applicable privacy requests by contacting privacy@certynx.com.
We may verify requests as permitted or required by law.
We will not discriminate against an individual for exercising rights provided by applicable California law.
California privacy laws may require additional disclosures or rights depending on Certynx’s business activities and applicable thresholds. This notice will be updated as necessary to reflect those requirements. The California Attorney General identifies rights and disclosure obligations under the CCPA, including rights to know, delete, correct, opt out of sale/sharing, and limit certain uses of sensitive personal information.
25European Economic Area and United Kingdom Privacy Rights
If you are located in the European Economic Area or United Kingdom and applicable data-protection law applies, you may have rights under the GDPR, UK GDPR, or other applicable law.
Depending on the circumstances, these rights may include:
- Access;
- Rectification;
- Erasure;
- Restriction of processing;
- Data portability;
- Objection to processing; and
- Withdrawal of consent.
Where Certynx acts as a processor, the relevant Customer generally acts as controller and is responsible for responding to individual rights requests.
Where Certynx acts as controller, requests may be submitted to privacy@certynx.com.
You may also have the right to lodge a complaint with the data-protection authority in your jurisdiction.
26Customer Data and Individual Requests
If your information is contained in Customer Data processed by Certynx on behalf of an organization, the organization that provided the information to Certynx may be responsible for responding to your request.
For example, if your employer uses Certynx and your name or email address appears in:
- A directory integration;
- A certificate record;
- An audit event;
- An approval workflow; or
- Another Customer-controlled record,
you should generally direct your request to your employer or organization.
Certynx will provide reasonable assistance to Customers in responding to applicable requests in accordance with our contractual obligations.
27Third-Party Services and Integrations
Certynx may integrate with third-party systems including:
- Identity providers;
- Directory services;
- Certificate authorities;
- Cloud platforms;
- Kubernetes environments;
- Infrastructure platforms;
- Security tools;
- Monitoring systems;
- Ticketing systems; and
- Other enterprise technologies.
The information exchanged through an integration depends on the integration, permissions, and configuration selected by the Customer.
Third-party services are governed by their own privacy policies and terms.
Certynx is not responsible for the privacy practices of third-party services that Customers choose to connect to the platform.
28De-identified and Aggregated Information
Where permitted by applicable law, Certynx may create aggregated, statistical, or de-identified information from information it processes.
We may use such information for purposes including:
- Service analytics;
- Reliability analysis;
- Security analysis;
- Product improvement;
- Product development;
- Capacity planning; and
- Business analysis.
Where applicable law imposes restrictions on re-identification of de-identified information, Certynx will comply with those requirements.
29Children
Certynx provides enterprise software and does not direct its services to children.
We do not knowingly collect personal information from children under 13 through our public websites.
If you believe a child has provided personal information to Certynx in circumstances where collection was not appropriate, please contact us at privacy@certynx.com.
30Do Not Track and Global Privacy Signals
Some browsers provide a “Do Not Track” signal.
There is no universally accepted technical standard for responding to all Do Not Track signals, and Certynx may not respond to such signals in every circumstance.
Where applicable law requires Certynx to recognize a recognized opt-out preference signal, Certynx will process that signal as required by law.
31Security Incidents
Certynx maintains processes designed to detect, investigate, respond to, and recover from security incidents.
If Certynx determines that an incident involving personal information requires notification under applicable law, Certynx will provide notice as required by law.
Where Certynx processes Customer Data on behalf of a Customer, notification obligations will also be governed by the applicable Customer agreement and Data Processing Addendum.
32Changes to This Privacy Policy
We may update this Privacy Policy from time to time.
Changes may reflect:
- New products or services;
- Changes to our data practices;
- Changes in applicable law;
- Changes to our security practices; or
- Changes to our business operations.
When we update the policy, we will update the Last Updated date.
If we make material changes requiring additional notice under applicable law, we will provide appropriate notice.
We encourage you to review this Privacy Policy periodically.
33Contact Us
Questions, concerns, and privacy requests may be directed to:
Certynx, Inc.
6000 Poplar Avenue, Suite 250
Memphis, Tennessee 38119
United States of America
For privacy-related requests, you may use the subject line “Privacy Request.”
LAST UPDATED: AUGUST 17, 2026
