Last updated: September 28, 2026
This Privacy Policy explains how ITG Security LLC dba Pistos Trust Labs ("Pistos", "we", "us", or "our") collects, uses, shares, and protects personal information in connection with the pistos.io website, the Pistos vendor risk and compliance management platform, Trust Center pages hosted on our platform, our APIs, and related services (together, the "Services").
Capitalized terms not defined here (such as "Customer", "Customer Data", "Respondent", "Trust Center", and "Partner") have the meanings given in our Terms and Conditions.
1. Our Role: Controller vs. Processor
Pistos handles personal information in two different capacities:
- Pistos as controller. We decide how and why personal information is used when it relates to our own business. This includes visitors to pistos.io, people who request a demo or contact us, Customer account holders and billing contacts, and prospective partners. This Privacy Policy mainly covers this information.
- Pistos as processor (service provider). When our Customers use the Services, they upload and collect information, including information about their employees, their vendors (Respondents), their Clients, and visitors to their Trust Center. We process this Customer Data only on the Customer's behalf and according to its instructions, as set out in our agreement with that Customer and our Data Processing Addendum at pistos.io/dpa. The Customer is the controller of that information. Its own privacy notice governs how it uses the information.
If you are a vendor completing an assessment, or a visitor to a Customer's Trust Center, the organization that invited you or runs that Trust Center is generally responsible for your information. Please direct privacy requests to that organization. If you contact us, we will forward your request to the relevant Customer where appropriate.
2. Information We Collect
2.1 Information you provide to us
- Contact and demo requests: name, work email, phone number, company name, job title, company size, number of vendors, and any message you send us.
- Account information: name, work email, password or SSO identifiers, role, team membership, and profile preferences for Authorized Users.
- Billing information: billing contact name, billing address, tax identifiers, and payment details. Our payment processor collects and stores payment card details. We do not store full card numbers.
- Support communications: the content of emails, chats, and support tickets, and any attachments you send.
- Partner program information: business and contact details submitted when applying to or participating in our partner program.
- Surveys and feedback: your responses if you choose to take part.
2.2 Information collected through the Services (Customer Data)
Depending on how a Customer configures the Services, Customer Data may include:
- names, work emails, job titles, and roles of Customer personnel and Respondent contacts;
- questionnaire responses, comments, and uploaded evidence (such as policies, audit reports, and certificates), which may contain personal information;
- vendor and asset records, business impact analysis data, and risk ratings; and
- for Trust Centers, visitor names, work emails, companies, access and NDA requests, and records of documents accessed.
We process Customer Data as a processor, as described in Section 1.
2.3 Information collected automatically
When you visit our website or use the Services, we automatically collect:
- Device and log data: IP address, browser type and version, operating system, referring URL, pages viewed, date and time stamps, and error logs.
- Usage data: features used, actions taken in the Services, clicks, and session duration.
- Audit and security logs: login events, changes to settings, and access to records, used to secure the Services and, where included in a Customer's plan, provided to the Customer as audit logs.
- Cookies and similar technologies: see Section 7.
2.4 Information from third parties
- Single sign-on providers: when you log in with SSO/SAML, we receive identifiers and profile attributes from your organization's identity provider.
- Your organization: an administrator may create an account for you or invite you to the Services.
- Partners: MSPs and consultancies may provide information about Client personnel when setting up Client workspaces.
- Business and marketing sources: we may receive business contact information from event organizers, referral partners, or publicly available professional sources, in line with applicable law.
3. How We Use Information
We use the information we control to:
- Provide the Services: create and manage accounts, authenticate users, deliver features, and process transactions.
- Communicate with you: respond to inquiries and demo requests, provide support, and send service announcements, security notices, and administrative messages.
- Bill and manage accounts: process payments, manage subscriptions, and enforce plan limits.
- Secure the Services: monitor for, investigate, and prevent fraud, abuse, security incidents, and violations of our Terms.
- Improve the Services: analyze usage trends, troubleshoot, and develop new features, mainly using aggregated or de-identified data.
- Market our Services: send product updates, newsletters, and event invitations to business contacts where permitted by law. You can opt out at any time (see Section 9).
- Meet legal obligations: comply with laws, regulations, legal process, and tax and accounting requirements, and establish, exercise, or defend legal claims.
We use Customer Data only to provide, secure, maintain, and support the Services for that Customer, as instructed by the Customer and described in our agreement with them. We do not sell Customer Data or use it to market to Respondents or Trust Center visitors.
Legal bases (EEA, UK, and Switzerland)
Where the GDPR or UK GDPR applies, we rely on the following legal bases:
- Contract: to provide the Services and manage accounts and billing.
- Legitimate interests: to secure and improve the Services, respond to inquiries, and conduct B2B marketing, where those interests are not overridden by your rights.
- Consent: for non-essential cookies and certain marketing communications. You may withdraw consent at any time.
- Legal obligation: to comply with applicable laws.
4. How We Share Information
We share personal information only as described below:
- Within your organization: information in an Account is visible to other Authorized Users and administrators of that Account according to their permissions.
- Between Customers and Respondents: when you respond to an assessment, your responses and uploads are shared with the Customer that invited you.
- Trust Center: information you submit when requesting access or accepting an NDA on a Customer's Trust Center is shared with that Customer.
- Partners: when a Partner manages a Client workspace, the Partner can access that Client's data within the Services.
- Service providers (subprocessors): we use vendors to host infrastructure, process payments, send email, provide customer support tools, and perform analytics. They may use personal information only to perform services for us. A current list of subprocessors is available at pistos.io/dpa#annex-3-subprocessors.
- Business transfers: in connection with a merger, acquisition, financing, reorganization, or sale of assets, information may be transferred to the successor, subject to this Privacy Policy.
- Legal and safety: when we believe in good faith that disclosure is required by law or legal process, or is needed to protect the rights, property, or safety of Pistos, our users, or others. Where legally permitted, we will notify the affected Customer of any request for its Customer Data.
- With your consent: for any other purpose you agree to.
We do not sell personal information and do not "share" it for cross-context behavioral advertising, as those terms are defined under California law.
5. International Data Transfers
Pistos is based in the United States of America, and our service providers may process information in other countries. Data protection laws in those countries may differ from those where you live. When we transfer personal information from the EEA, UK, or Switzerland to countries not recognized as providing adequate protection, we use appropriate safeguards such as the European Commission's Standard Contractual Clauses and the UK International Data Transfer Addendum, or rely on an applicable adequacy framework such as the EU-U.S. Data Privacy Framework where we are certified.
Customer Data is hosted in the United States. Customers on eligible plans may choose an alternative hosting region.
6. Data Retention
We keep personal information only as long as needed for the purposes described in this Privacy Policy:
- Account and billing information: for the life of the Account, and afterwards as needed for legal, tax, accounting, and dispute-resolution purposes (generally up to 7 years for financial records).
- Customer Data: for the subscription term and for 30 days after termination to allow export, then deleted according to our retention practices. Backups are overwritten in the ordinary course within 90 days. A Customer may ask us to delete its Customer Data sooner.
- Marketing and demo-request information: until you opt out, or for up to 24 months after our last meaningful interaction with you.
- Logs: security and system logs are generally retained for up to 12 months, unless needed longer to investigate an incident.
7. Cookies and Similar Technologies
We use cookies, local storage, and similar technologies on our website and in the Services:
| Type | Purpose | Can you opt out? |
|---|---|---|
| Strictly necessary | Log-in sessions, security, load balancing, and remembering your cookie choices | No. The Services will not work without them. |
| Functional | Remembering preferences such as language and interface settings | Yes |
| Analytics | Understanding how visitors use our website so we can improve it | Yes |
| Marketing | Measuring the effectiveness of our campaigns | Yes |
Where required by law, we ask for your consent before setting non-essential cookies. You can change your choices at any time through your browser settings. Blocking some cookies may affect how the website works. We honor Global Privacy Control (GPC) signals as an opt-out where required by applicable law.
8. Security
We use administrative, technical, and physical safeguards designed to protect personal information. These include encryption in transit and at rest, logical separation of Customer data (and of Client data within Partner Accounts), role-based access controls, SSO support, access logging, and regular security reviews. No method of transmission or storage is completely secure, so we cannot guarantee absolute security. If we become aware of a security incident affecting your personal information, we will notify you and/or the relevant Customer as required by law and our agreements.
9. Your Choices and Rights
9.1 Choices available to everyone
- Marketing emails: click "unsubscribe" in any marketing email or contact us. You will still receive service and administrative messages related to your Account.
- Account information: Authorized Users can update much of their profile information in the Services. Your organization's administrator may control some settings.
- Cookies: see Section 7.
9.2 Privacy rights
Depending on where you live, you may have the right to:
- access the personal information we hold about you and get a copy of it;
- correct inaccurate information;
- delete your information;
- restrict or object to certain processing, including processing based on legitimate interests and direct marketing;
- data portability;
- withdraw consent where processing is based on consent; and
- not be discriminated against for exercising your rights.
To exercise these rights, email privacy@pistos.io. We will verify your identity before responding and respond within the time required by law. You may use an authorized agent where the law allows, and we may ask for proof of the agent's authority. If we deny your request, you may appeal by replying to our decision.
If your information is Customer Data (for example, you are a Respondent, a Trust Center visitor, or an employee of a Customer), please send your request to the relevant Customer, which controls that information. We will help the Customer respond as required by our agreement with them.
EEA, UK, and Swiss residents also have the right to lodge a complaint with their local data protection authority.
9.3 California residents
This section supplements this Privacy Policy for California residents under the California Consumer Privacy Act, as amended (CCPA). In the past 12 months, we have collected the following categories of personal information for the business purposes described in Section 3: identifiers (such as name, email, and IP address); professional or employment-related information (such as company and job title); commercial information (such as subscription and billing records); internet or other electronic network activity (such as usage and log data); and, for account holders, account log-in credentials, which are sensitive personal information and which we use only as permitted by the CCPA. We collect this information from the sources described in Section 2 and disclose it to the categories of recipients described in Section 4. We do not sell or share personal information and have no actual knowledge of selling or sharing the personal information of anyone under 16.
10. Children's Privacy
The Services are intended for businesses and are not directed to children under 16. We do not knowingly collect personal information from children. If you believe a child has given us personal information, contact us and we will delete it.
11. Third-Party Links and Integrations
Our website and the Services may link to or integrate with third-party websites and services, such as identity providers or storage tools a Customer chooses to connect. Their own privacy policies govern how they handle your information, and we are not responsible for their practices.
12. Changes to This Privacy Policy
We may update this Privacy Policy from time to time. When we do, we will change the "Last updated" date above. If we make material changes, we will notify Customers by email or through the Services before the changes take effect.
13. Contact Us
If you have questions about this Privacy Policy or our privacy practices, contact us:
ITG Security LLC
30 N Gould St Ste R
Sheridan, WY 82801
USA
Email: privacy@pistos.io