Castle and GDPR
CertReports found no public GDPR evidence for Castle as of unknown date. This does not mean the vendor is non-compliant. It means CertReports found no public evidence at the last check.
Evidence
- Kind
- listing
- Issued or listed
- 8 Dec 2020
- Scope
- Personal data Castle.io collects and how it is shared: Castle.io suite of security tools protect user accounts by detecting automated credential stuffing attacks and human-powered account takeovers, automating the recovery process, and reducing false lockouts and related support tickets. Through the course of business and marketing activities Castle collects Personal Information regarding its current, prospective clients, customers, Users, visitors, and guests (collectively “Individuals”). • Business contact information Name and identity, email address, physical and virtual and physical contact information (for example client business address), professional information financial information, including credit card and/or bank account numbers and information required for billing and fraud prevention. • Information from Other Sources. Castle may receive information about users from other sources, including through Third-Party services and organizations to supplement information provided by users. For example, if users access our Services through a Third-Party application, such as an App Store or Social Network Service (“SNS”), we may collect information about users from that Third-Party application that users have made public via user’s privacy settings. Information we collect through App Stores or SNS accounts may include usersr name, usersr SNS user identification number, usersr SNS user name, location, sex, birth date, email, profile picture, and usersr contacts on the SNS. This supplemental information allows Castle to verify information that users have provided to Castle and to enhance our ability to provide users with information about our business, products, and Services. • Posting on the Site. Castle may offer publicly accessible blogs, private messages, or community forums. users should be aware that, when users disclose information about them on Castle’s blogs, private messages, and community forums, the Site will collect the information users provide in such submissions, including any Personal Information. If users choose to submit content to any public area of the Site, such content will be considered “public” and will not be subject to the privacy protections set forth herein. • Website visitors and and sales prospects. Castle may collect certain information automatically through our Services or other methods of web analysis, such as Internet protocol (IP) address, cookie identifiers, mobile carrier, mobile advertising identifiers, MAC address, IMEI, Advertiser ID, Game Center ID, and other device identifiers that are automatically assigned to a computer or device when users access the Internet, browser type and language, geo-location information, hardware type, operating system, Internet service provider, pages that users visit before and after using the Services, the date and time of the visit, the amount of time users spend on each page, information about the links users click and pages users view within the Services, and other actions taken through use of the Services such as preferences. • Communications with Us. We may collect Personal Information from users such as email address, phone number or mailing address when users choose to request information about our Services, register for Castle’s newsletter that we may offer from time to time, request to receive customer or technical support, or otherwise communicate with us Delivering the Castle products and services under contract with customers: • Name and identity, email address, physical and virtual and physical contact information (including for example business address), professional information, log-in data, and • Information response to surveys, or requested in order to provide brochures or information about our business, products or services.
| Source | Captured | Quote | Links |
|---|---|---|---|
Data Privacy Framework list Official registry · HTTP 200 | 17 Sep 2026 | Castle: Inactive | Live pagesha256 ef46c06f42 |
What GDPR means, and what it does not
"GDPR compliant" is a claim, not a certification. The verifiable facts are a public DPA, SCC usage, an EU representative, data residency options and a Data Privacy Framework listing.
Read the GDPR guide and browse all vendors with evidenceQuestions buyers ask
Is Castle GDPR compliant?
There is no GDPR certification in general use. The verifiable facts are a public data processing agreement, standard contractual clauses, an EU representative and a Data Privacy Framework listing. See the legal artefacts and the DPF row on this page, each with its capture date.
How does CertReports verify this?
Every state carries a capture date, a source and a snapshot link. Registry rows come from the official registry data; vendor statements come from the vendor’s own page or trust centre; nothing is inferred. Vendors can dispute any row and corrections ship within two business days.
Alternatives with GDPR evidence
Similar vendors (shared product tags or the Security category) whose GDPR row is verified or vendor-stated, ranked by similarity.