
ThreatConnect and GDPR
CertReports found no public GDPR evidence for ThreatConnect as of unknown date. This does not mean the vendor is non-compliant. It means CertReports found no public evidence at the last check.
Evidence
- Kind
- listing
- Issued or listed
- 6 Aug 2024
- Scope
- ThreatConnect processes two types of personal data. We collect personal data from our customers that is submitted to us voluntarily when a user registers an account or uses any of our sites and/or services. We ask or collect information such as name, email address, job title, ip address, cookie information, to create user accounts, track usage, to market our products, and to provide customer/product service. Information may be disclosed with third-parties such as Amazon Web Services, Pendo, Google, Slack, DataDog, SingleStore, 6Sense, Pardot, WebFX, Navattic, Qualified, LinkedIn, Zapier, Sequel, UserGems, UserEvidence, Salesforce, Outreach, Gong, Giftsenda, Zoominfo, Mercury - SMS, Cacheflow, and ChurnZero. Not all of the subprocessors will be engaged for all users or services. We also collect HR related data for our own employees. This personal data will include information such as name, address, birthday, and banking information. This information is used to onboard employees, process employee pay, and to fulfill our contractual and regulatory duties. This information will be strictly guarded and only shared with relevant processors such as ADP, ADP UK, and Google Drive.
| Source | Captured | Quote | Links |
|---|---|---|---|
Data Privacy Framework list Official registry · HTTP 200 | 17 Sep 2026 | ThreatConnect: Inactive | Live pagesha256 a5bf0d3feb |
What GDPR means, and what it does not
"GDPR compliant" is a claim, not a certification. The verifiable facts are a public DPA, SCC usage, an EU representative, data residency options and a Data Privacy Framework listing.
Read the GDPR guide and browse all vendors with evidenceQuestions buyers ask
Is ThreatConnect GDPR compliant?
There is no GDPR certification in general use. The verifiable facts are a public data processing agreement, standard contractual clauses, an EU representative and a Data Privacy Framework listing. See the legal artefacts and the DPF row on this page, each with its capture date.
How does CertReports verify this?
Every state carries a capture date, a source and a snapshot link. Registry rows come from the official registry data; vendor statements come from the vendor’s own page or trust centre; nothing is inferred. Vendors can dispute any row and corrections ship within two business days.
Alternatives with GDPR evidence
Similar vendors (shared product tags or the Security category) whose GDPR row is verified or vendor-stated, ranked by similarity.