We take your privacy seriously and process personal data collected on our website according to applicable laws. This Privacy Policy outlines how we handle data, fulfilling our obligation under the GDPR, & more.
The protection of your privacy and your personal data is an important concern to which we pay special attention. Personal data collected during visits to our website is processed according to the legal provisions valid for the countries in which the website is maintained. In the following paragraphs we provide you with information on how we are following these rules, which data we collect, and how we use it. Thereby, we fulfill our obligation of information under Art. 13 GDPR (General Data Protection Regulation).
The provider (and data controller within the meaning of GDPR) of this website is indicated in the imprint of our website. If you have any questions, do not hesitate to contact us via the e-mail address you will find at the end of this Privacy Policy.
1) DEFINITIONS
Our privacy policy should be understandable for everyone. Generally, the official terms of the GDPR are used. The official definitions are explained in Art. 4 GDPR.
2) DATA PROTECTION RIGHTS
Depending on where you live, you may have certain state- or country-specific rights with respect to your personal information. Please see the region and state-specific terms below.
a) European Economic Area – General Data Protection Regulation
If you are a resident of the United Kingdom (and Gibraltar) (EU), European Economic Area (EEA), and Switzerland, you may have the following rights:
In the above-mentioned cases, or if you have questions or complaints, please write to or e-mail us at the below address. You also have a right to lodge a complaint with a data protection supervisory authority. The data protection supervisory authority located in the state in which you live or where the data controller is domiciled has jurisdiction.
b) United States – California Consumer Privacy Act and Other State Laws
If you are a resident of California, you have certain rights under the California Consumer Privacy Act (CCPA) listed below. However, these rights are not absolute and in certain cases we may decline your request as permitted by law.
c) United States – Other State Laws
Depending on the state in which you reside, you may have the following privacy rights, subject to statutory limitations. However, these rights are not absolute and in certain cases we may decline your request as permitted by law.
d) Canada – Personal Information Protection and Electronic Documents Act
If you are located in Canada, your personal data is protected by the Personal Information Protection and Electronic Documents Act (PIPEDA). Under PIPEDA, you have the following rights:
e) Australia – Privacy Act 1988
If you are located in Australia, your personal data is protected by the Privacy Act 1988. Under the Privacy Act, you have the following rights:
f) Other Jurisdictions
If you are located in a jurisdiction not mentioned above, please note that we will comply with any applicable local data protection laws and regulations and will take all necessary steps to ensure your privacy rights are respected.
For certain requests, we require that you provide the following information:
The information that you provide will be analyzed to determine whether we can reasonably verify your identity. We may need to obtain additional information from you to process your request. For example, if we determine that the information provided is not sufficient for verification, you may be prompted to answer a few questions.
There may be circumstances where we may not completely fulfill your request, as permitted under applicable law. For example, if you submit a request to delete your personal information, we may need to retain certain personal information to complete a transaction, detect fraud, or comply with our legal obligations.
If you are an authorized agent acting on behalf of a California resident, or acting on behalf of resident of a state with a similar legal requirement, please send your request to our Data Protection Officer and include the following information about you and the person on whose behalf you are submitting the request: full name, mailing address, e-mail address, and phone number. You should also provide proof of your authorization to act on the other person’s behalf. We will contact you for additional information once your request has been received. Note that we may require the consumer to verify their identity and confirm your authority as the agent.
3) DATA RETENTION
We store your personal data for as long as it is necessary to perform a service that you have requested or for which you have granted your permission, providing that no legal requirements exist to the contrary such as in case of retention periods required by trade or tax regulations.
4) DATA PROCESSING WHEN VISITING OUR WEBSITE
When you visit our web pages, the following data is recorded during an ongoing connection for communication between your Internet browser and our web server:
We collect the listed data to ensure a smooth connection of the website and to enable a comfortable use of our website by the users. Legal basis for this type of processing is our legitimate interests pursuant Art. 6(1)(f) GDPR.
With the exception of your IP address, personal data is only stored if you choose to submit it to us, (e.g., when contacting us via our contact form, during registration, in a survey, in a competition or in order to enable performance of an agreement).
Your personal data remains only with our company, our affiliates, and our providers and may be made available to third parties. For third party services we use at our website please see information below.
Our website may contain links to third-party websites. If you click on one of those links, you will be taken to websites we do not control. This Privacy Policy does not apply to the information practices of those websites. You should read the privacy policies of other websites carefully. We are not responsible for third-party websites.
5) JOB APPLICANTS
When applying for a job posting you will be required to provide us with information on your personal, professional, and academic background, including:
Your data is encrypted during electronic transmission.
The primary legal basis for this is:
Internally, your application data will only be processed by the relevant contact persons of the Human Resources Department and the department to which your application is directed. In case you are applying for a position at VMRay Inc., your application will be forwarded to the responsible USA-employee only. All our employees are contractually obliged to treat personal data strictly confidential.
In case your application has been successful, your data may be used for administrative purposes within the framework of your future employment and the applicable legal requirements. In that case, your data will be stored in accordance with the retentions periods applicable by law.
In case your application has not been successful, we will keep your application for 6 months to answer any questions you may have in connection with your application. For longer periods of time, your data will only be stored in case of a legal requirement to do so or for the purpose of providing legal evidence. In that case, your data will be deleted after the ground for storage ceases to exist. The legal basis for storage is our legitimate interest to provide evidence in case of legal claims by the applicant within the meaning of Art. 6(1)(f) GDPR and § 24(1) no. 2 BDSG. Our legitimate interest lies in legal defense and enforcement. At any time, you may exercise your data protection rights as described in this policy (see below).
6) CONTACT FORM
We offer multiple general contact forms on our site. Before contacting us, the user has to consent to this Privacy Policy. If a user contacts us, the data entered will be transmitted to us and stored. This data includes your first name (second name optional), e-mail address, company name, country as well as date and time of your message. The transmission of data via the web form is encrypted. We will use this data only to process your request. The legal basis for this type of processing is our legitimate interest in answering your request in accordance with Art. 6(1)(f) GDPR. If your request serves the conclusion of a contract with us, further legal basis for the processing is Art. 6(1)(b) GDPR. The data will be deleted after your request has been processed. If we are legally obliged to store data for a longer period of time, the data will be deleted after expiry of the corresponding period. In the case of Art. 6(1)(f) GDPR, you can object to the processing of your personal data at any time.
7) REQUEST A TRIAL
We provide a contact form to request a 30-day trial period for our product. If a user contacts us, the data entered will be transmitted to us and stored. This data includes your first name (second name optional), e-mail address, job title, company name, country, IP-address as well as date and time of your message.
We will use this data only to process your request. Legal basis for this type of processing is the execution of pre-contractual measures in accordance with Art. 6(1)(b) GDPR or your consent granted to us in accordance with Art. 6(1)(a) GDPR.
Your personal data will be deleted as soon as they are no longer required for the purpose of their collection.
8) COOKIES
a) In General
Cookies are small text files that are used to store small pieces of information. They are stored on your device when the website is loaded on your Internet browser. These cookies help us make the website function properly, make it more secure, provide better user experience, and understand how the website performs and to analyze what works and where it needs improvement.
How do we use cookies? Our website uses first-party and third-party cookies for several purposes. First-party cookies are mostly necessary for the website to function the right way, and they do not collect any of your personally identifiable data.
The third-party cookies used on our website are mainly for understanding how the website performs, how you interact with our website, keeping our services secure, providing advertisements that are relevant to you, and all in all providing you with a better and improved user experience and help speed up your future interactions with our website.
b) Types of Cookies Used
c) Managing Cookie Preferences
You can review all the Cookies we use and change your cookie preferences by clicking “Customize” at the bottom of our GDPR compliant Cookie bar on our website. This will let you revisit the cookie consent banner and change your preferences or withdraw your consent right away.
If you are using any other Internet browser, please visit your Internet browser’s official support documents.
9) SERVICES USED
We use various third-party services to enhance our website functionality, improve user experience, and support our business operations. Below, we provide details on the third-party services we use, their purposes, and how they process your personal data.
Some of these services involve the transfer of personal data to the USA. In such cases, we implement additional protective measures to ensure compliance with the Art. 46(2)(c) GDPR and to maintain an adequate level of data protection.
a) Google Services
We use several services provided by Google LLC and its European subsidiary, Google Ireland Limited (Gordon House, Barrow Street, Dublin 4, Ireland) (Google). These services may process your personal data, include IP addresses and online identifiers.
The legal basis for this processing is your consent (Art. 6(1)(a) GDPR). In case of data collection processes that are not consolidated in your Google Account (e.g., because you do not have a Google Account or have objected to the consolidation), the data collection is based on our legitimate interests within the meaning of Art. 6(1)(f) GDPR. The legitimate interest arises from our legitimate interest in the anonymized analysis of website visitors for advertising purposes.
For more information on Google’s use of personal data, please visit https://policies.google.com/privacy.
b) Social Media Platforms
We integrate and interact with the following social media platforms:
The above social media platforms are able to establish a direct connection between your Internet browser and the applicable social media platform’s server with your IP address and/or your social media account. Such social media platform may also record and process the data and time of your visit to our website.
The legal basis for these types of processing is our legitimate business interest (Art. 6(1)(f) GDPR).
See individual privacy policies for further details:
c) CRM and Marketing
To manage customer relationships and marketing activities, we use:
See individual privacy policies for further details:
d) Cloud Storage and Collaboration
We use Nextcloud (Albrechtstraße 14b, 10117 Berlin, Germany) for secure cloud storage and collaboration. For users with a temporary account, the retention period for the data is 3 days. For users with a regular account, the retention period for the data is 30 days.
Please be aware that Nextcloud is not an archive for the submitted information. As soon as we decide that any information is no longer needed for the aforementioned purpose, we have the right to delete such information.
For more information, please visit https://nextcloud.com/privacy/.
e) Managing Your Preferences
You can control and restrict data collection by adjusting cookie settings on your Internet browser and by managing consent settings within each platform’s privacy controls.
10) NEWSLETTER
We send our newsletter for the purpose of advertising our product and informing about our company. For the registration to our newsletter, we use the double opt-in procedure. You may subscribe and consent to the receipt of our newsletter by providing us with your e-mail address via our contact form, explicitly ticking the opt-in box underneath and by clicking the link in the confirmation e-mail. By clicking on the corresponding link, we process the public IP address of the computer from which the link is accessed, together with the date and time of the click. We process this data to be able to provide proof that you have confirmed receipt of our e-mail newsletter. You may cancel the subscription by using the unsubscribe option provided in the newsletter. The data which we require as proof that you have agreed to receive the newsletter will be deleted after expiration of any legal obligation to provide this evidence. The legal basis for this type of processing is your consent according to Art. 6(1)(a) GDPR.
Our e-mail newsletter is sent via the technical service provider HubSpot Ireland Limited (see above) to whom we transfer the information you provide when you register for the newsletter. This disclosure is made in accordance with Art. 6(1)(f) GDPR and serves our legitimate interest in using an effective, secure and user-friendly newsletter system. HubSpot uses this information for the dispatch and statistical analysis of the newsletter on our behalf.
For evaluation purposes, the e-mails sent contain web beacons or tracking pixels, which are one-pixel image files stored on our website. The use of the web beacons and tracking pixels can determine whether a newsletter message has been opened and which links have been clicked on, if applicable. Conversion tracking can also be used to analyse whether a predefined action (e.g., purchase of a product on our website) was carried out after clicking on the link in the newsletter. Technical information is also recorded (e.g., time of access, IP address, Internet browser type, and operating system). The data is collected pseudonymously and is not linked to your other personal data. This data is used exclusively for statistical analysis of newsletter campaigns. The results of these analyses can be used to better adapt future newsletters to the interests of the recipients. If you wish to object to the data analysis for statistical purposes, you must cancel the newsletter subscription.
Since personal data may be transferred to the USA, further protective mechanisms are required to ensure the level of data protection under the GDPR. To ensure this, we have agreed to standard data protection clauses with the provider in accordance with Art. 46(2)(c) GDPR. These standard data protection clauses obligate the recipient of the data in the USA to process the data in accordance with the level of protection in Europe. In cases in which this cannot be guaranteed even by this contractual extension, we will endeavour to obtain additional regulations and commitments from the recipient in the USA.
11) WEBINARS
We use the GoToWebinar software solution from LogMeIn, Inc (320 Summer Street Boston, MA 02210, USA) to conduct regular seminars via the Internet. Pursuant to our arrangement with LogMeIn, LogMeIn is required to protect our customers’ information.
Since personal data may be transferred to the USA, further protective mechanisms are required to ensure the level of data protection under the GDPR. To ensure this, we have agreed to standard data protection clauses with the provider in accordance with Art. 46(2)(c) GDPR. These standard data protection clauses obligate the recipient of the data in the USA to process the data in accordance with the level of protection in Europe. In cases in which this cannot be guaranteed even by this contractual extension, we will endeavor to obtain additional regulations and commitments from the recipient in the USA.
A connection will be established between you and the webinar organizer to conduct the webinar. We do not record the sound or image information transmitted during the webinar. With your participation you also confirm not to make any recordings or screen shots. You can end the session at any time by simply closing the Internet browser window or closing the program or application.
For LogMeIn’s privacy policy please see https://www.logmeininc.com/de/legal/privacy.
12) SECURITY
We take reasonable technical and organisational measures to ensure a level of protection appropriate to the risk, taking into account the state of the art, implementation costs and the nature, scope, circumstances and purposes of processing as well as the different probability of occurrence and severity of the risk to the rights and freedoms of natural persons, in accordance with Art. 32 GDPR. Such measures shall include ensuring the confidentiality, integrity, and availability of data by controlling physical access to the data, as well as the access, input, transmission, security of availability, and its separation.
13) DATA PROCESSING BY THIRD PARTIES
Your personal data may be transferred to and processed by third parties on our behalf for various business purposes, such data processing by third parties occurs under the following situations:
In addition, we use external service providers for our services, which we have carefully selected and commissioned in writing. If necessary, we have concluded Data Processing Agreements in accordance with Art. 28 GDPR.
14) TRANSFER TO THIRD COUNTRIES
Your personal information may be transferred to and processed in countries outside of your country of residence, including jurisdictions that may not have the same data protection laws as your home country. When we transfer your data to third countries, we take appropriate safeguards to ensure that your information remains protected in accordance with applicable laws.
Subject to legal or contractual permissions, we process the data in a third country only under the special requirements of Art. 44 ff. GDPR.
15) LEGAL OBLIGATIONS
The provision of personal data for the decision to conclude a contract, for the performance of a contract or for the implementation of pre-contractual measures is voluntary. However, we can only make the decision within the framework of contractual measures if you provide such personal data as are necessary for the conclusion of the contract, the fulfilment of the contract or pre-contractual measures.
16) AUTOMATED INDIVIDUAL DECISION-MAKING, INCLUDING PROFILING
No automated decision making or profiling pursuant to Art. 22 GDPR takes place.
17) SECURITY INCIDENT RESPONSE INTEGRATION
When applicable, our Security Incident Response Integration is developed to meet high standards of data protection and transparency. This section outlines the types of data we collect, how it is used, how it is protected, and your rights as a user.
a). Data Collection
We may collect the following categories of data:
b). Data Usage
We use the collected data solely for the following purposes:
c). Data Sharing
We only share data:
d). Data Security
We apply strong data protection measures:
e). Additional Terms
If any aspect of this section is not addressed, our general Privacy Policy will apply.
18) CHANGES TO THIS PRIVACY POLICY
The continuous development of the Internet makes it necessary for us to adjust our data protection rules from time to time. We reserve the right to implement appropriate changes at any time.
19) CONTACT
If you wish to exercise your data protection rights or if you have any comments, suggestions, questions, or complaints, please do not hesitate to send an e-mail to dataprotection@vmray.com.
Our Data Protection Officer, Patrick Grihn, can be contacted via:
DSBRuhr
c/o nextindex GmbH & CO. KG
Grabenstr. 12
44787 Bochum
tel.: 0049234 810 503 00
e-mail: grihn@dsb.ruhr
Date of Privacy Policy: April 2025
join VMRay for two powerhouse webinars designed to sharpen your threat detection and response capabilities — featuring a special joint session with Red Canary:
Live session's over. Watch the on-demand video to learn how VMRay and Red Canary combine forces to deliver faster, smarter threat detection!
Learn how to cut phishing triage time with automated detonation and deep analysis — quickly uncover threats while improving response accuracy!