Skip to content
TrailSight
  • Platform
  • Agent Security
  • How it works
  • Trust
  • Request a Demo

Legal

TrailSight Website Privacy Policy

On this page

  1. 1Introduction
  2. 2Policy at a Glance
  3. 3Data Collection
  4. 4Processing Purposes
  5. 5Third-Party Sharing
  6. 6Cookies
  7. 7Data Subject Rights
  8. 8Third-Party Links
  9. 9US State Rights
  10. 10Security
  11. 11Retention
  12. 12International Transfers
  13. 13Policy Changes

Welcome to Trailsight website. We respect your privacy, and this Privacy Policy outlines how we handle your personal information. Please read it carefully.

1. Introduction

We, at TrailSight Ltd. (the "Trailsight," "we," "us," "our"), respect the privacy and data protection rights of our users and business contacts.

This Privacy Policy (the "Policy") describes the personal information we collect and the policies and procedures we use regarding personal information in each of the following contexts:

  • The data practices on our website.
  • Our relationship with representatives of existing and prospective customers and vendors.

This website provides commercial information about TrailSight, a security platform for Salesforce, providing deep AI-agent visibility, runtime behavior, exploitable configuration risk, compliance evidence, and shift-left code/config analysis.

2. Policy at a Glance

We've summarized the key points of this privacy policy to make it easier to read. This summary does not replace the full policy set out below.

  • What it is. This policy applies to the website and explains what personal information we collect about you when you use it, and how we use it.
  • Providing information is voluntary. You are not legally required to give us personal information, but some of it is needed to use website; without it we may be unable to provide some features.
  • Information you give us. Some information is collected directly from you — for example when you request a demo or contact us — including details you choose to provide, such as your name, contact details, company name and Salesforce footprint.
  • Information collected automatically. When you use the website, some information is collected automatically, such as usage and activity data, device type, and IP address.
  • Information from third parties. We may receive information about you from external sources, such as our service providers.
  • How we use your information. We use your information to operate, maintain and improve website, to communicate with you, and to meet our legal obligations.
  • Who we share it with and why. We may share information with service providers acting on our behalf and with others where needed to operate website, as required by law or with your consent.
  • Cookies and digital tracking. We only use cookies and similar tracking technologies to operate website, remember your preferences and analyze how it is used.
  • Keeping your information and transfers abroad. We keep your information for 7 years or for as long as needed for the purposes it was collected, whichever is later, or as required by law.
  • Your rights. You can access the information we hold about you, ask us to correct or delete it, and exercise other rights available to you under law.
  • International data transfers. Some information may be stored or processed by providers outside your country, subject to appropriate safeguards.
  • Who we are and how to contact us. The website is operated by TrailSight Ltd. For any privacy question or request, you can contact us at contactus@trailsight.io.

Full Privacy Policy

3. Data Collection

We collect only the personal information that is necessary for the specific purposes described in this Policy and retain it only for as long as necessary to fulfill those purposes.

The website collects personal information directly from users, such as when contacting us or requesting a demo, in the form of full name, phone number, email address, company name, Salesforce footprint and data collected automatically such as operating system and browser information, and internet protocol addresses.

Providing information voluntarily

You are not required by law to provide us with the personal information described in this Policy. Providing it depends on your consent and discretion, but without providing it you will not be able to use some features of the website.

How We Collect Data

We collect personal information from several sources:

  • Directly from you when you provide it to us through email communications, demo request or online form, or subscribe to our service.
  • If another representative of your organization provides us with your information.

You do not have a legal duty to provide information to us. However, you will not be able to submit a demo request, access the website features, or be in contact with us without providing the above information.

The website collects personal information through automatic technical means, including IP address and operating system and browser information.

Consent for information about third parties

If you provide us with the personal information of other people, you must inform them that you are providing us with their details, and you confirm and declare that you have obtained their explicit consent to provide us with their personal information so that we may use it in accordance with this Policy.

The information we collect

When you use the website we may collect information about the way in which you use it — for example, which content you read, the pages you viewed, search queries you ran, the online services and sections that interested you, how frequently you used them, your computer's location and the internet-address (IP address) data from which you accessed the website, your type of operating system, the type of end device you hold, and more.

4. Processing Purposes

Providing you with the functionality of the website, sending service-related updates and operational communications, contacting you regarding administrative issues related to the website, responding to support requests or subscription quotes, maintaining and improving the website, enforcing the provisions of this Policy, the terms of use of the website and any other binding document, complying with the requirements of any law, regulation or other legislation, and to assisting competent authorities and any third party where we believe in good faith that we are required to do so.

Personal Information Used for Each Purpose

We use the categories of personal information we collect for the purposes described in this Notice. The categories of personal information used for each purpose are as follows:

  • Inquiries, Demos - In these cases, we rely on legitimate interests in developing potential leads and responding to business inquiries and demo requests.
  • Aggregated and anonymous information - We may use or share aggregated or anonymous information that does not personally identify you, for any purpose, including statistical analysis, research, marketing or business development, when visiting the website.
  • Administering the business relationship with customers and partners. In this case, we rely on our legitimate interests in managing our business and administering and performing the contractual obligations with customers and partners.
  • Administering the business relationship with vendors and service providers - We rely on our legitimate interests in administering contractual obligations with service providers and vendors.
  • Responding to, handling, and mitigating suspected violations of law in connection with our business - We rely on our legitimate interests in defending against and enforcing against violations and breaches that are harmful to our business.
  • Complying with a binding request from a competent authority - We rely on our legitimate interests in complying with mandatory legal requirements imposed on us.
  • For Enabling a structural change in the operation of the website and our business - we rely on our legitimate interests in our business continuity.

5. Third-Party Sharing

We will share your personal information with service providers who assist us with the internal operations of the Service. These companies are authorized to use your personal information in this context only as necessary to provide these services to us and not for their own promotional purposes.

  • Examples of third parties involved: data storage providers, infrastructure and platform providers, development and operations providers, data and analytics providers;
  • Purposes for sharing personal information: operating the website and managing our business operations.

Disclosure of information to third parties

We will disclose the personal information you provide us with, or that we collect while you use the website, to others only in the following cases:

  • if it is required for the proper provision of the website and our business. In this context, we may share personal information with third parties on our behalf who assist us in operating the website or in managing Trailsight's business. They, in turn, may use and process your personal information only to perform the services they provide to us and in accordance with our instructions, and they must protect and keep your personal information confidential;
  • if you breach the terms of use of the website, or if you perform through the website actions that we consider unlawful;
  • if we receive a judicial order, or a demand from an authority competent to make it, directing us to disclose your details or the personal information relating to you to a third party or to the relevant authority;
  • in any dispute, claim, suit, demand or legal proceedings, if any, between you and us or between you and a party related to us;
  • in any case in which we believe in good faith that disclosing the personal information is necessary to prevent serious harm to your person or property, or to the person or property of a third party;
  • if we reorganize Trailsight's activity, or the activity of any of the services on the website, within another framework, and also if we change our legal structure (for example, if we sell Trailsight's activity, or part of it, to a third party). In such cases we may transfer to the new entity a copy of your personal information, provided that this entity undertakes toward you the provisions of this Policy;
  • at your explicit request.

6. Cookies

We may use "cookies" on the website. Cookies are text files that your browser creates on command. Some cookies expire when you close your browser (Session Cookies), and others are stored on the hard drive of your computer or mobile device and are used when you return to visit the website (Persistent Cookies). Cookies may contain a variety of information, such as information about the pages you visited, how long you spent on the website, where you arrived at the website from, the information you request to view when entering the website, and more.

If you prefer not to store cookies locally, you can set this through the settings on your computer or mobile device.

7. Data Subject Rights

If you are in the EEA or the UK, you have the following rights under the GDPR:

Right of access, correction and deletion

The Privacy Protection Law (PPL) provides that every person is entitled to review the personal information about them held in a database. In addition, a person who has inspected the personal information about them and found that it is incorrect, incomplete, unclear or not up to date, may apply to the controller of the database with a request to correct or delete the personal information. If we refuse to correct the information, we must notify you of this in the manner and by the means prescribed in the regulations issued under the PPL. You will be entitled to appeal against the refusal in accordance with the law.

Right to Access

Right to Access and receive a copy of your personal information that we process.

Right to Rectify

Right to Rectify inaccurate personal information we have concerning you and to have incomplete personal information completed.

Right to Data Portability

Right to data portability, that is, to receive the personal information that you provided to us, in a structured, commonly used, and machine-readable format. You have the right to transmit this data to another person or entity. Where technically feasible, you have the right to have your personal information transmitted directly from us to the person or entity you designate

Right to Object

Right to object to our processing of your personal information based on our legitimate interest. However, we may override the objection if we demonstrate compelling legitimate grounds, or if we need to process such personal information for the establishment, exercise, or defense of legal claims.

Right to Restrict

Right to restrict us from processing your personal information (except for storing it): (a) if you contest the accuracy of the personal information (in which case the restriction applies only for a period enabling us to determine the accuracy of the personal information); (b) if the processing is unlawful and you prefer to restrict the processing of the personal information rather than requiring the deletion of such data by us; (c) if we no longer need the personal information for the purposes outlined in this Policy, but you require the personal information to establish, exercise or defend legal claims; or (d) if you object to our processing based on our legitimate interest (in which case the restriction applies only for the period enabling us to determine whether our legitimate grounds for processing override yours).

Right to be Forgotten

Right to be forgotten. Under certain circumstances, such as when you object to our processing of your personal information based on our legitimate interest and there are no overriding legitimate grounds for the processing, you have the right to ask us to erase your personal information. However, notwithstanding such a request, we may still process your personal information if it is necessary to comply with our legal obligations, or for the establishment, exercise, or defense of legal claims. If you wish to exercise any of these rights, please contact us through the channels listed in this Policy.

Subject to applicable law, you have the right to lodge a complaint with your local data protection authority. If you are in the EU, then according to Article 77 of the GDPR, you can lodge a complaint with the supervisory authority in the Member State of your residence, place of work, or place of alleged infringement of the GDPR. For a list of supervisory authorities in the EU, click here.

If you are in the UK, you can lodge a complaint with the Information Commissioner's Office (ICO) pursuant to the instructions provided here.

8. Third-Party Links

Our website may contain links to third-party websites or services. We are not responsible for the privacy practices of those third parties, and this Policy does not apply to them. We encourage you to review their privacy policies before providing any personal information.

9. US State Rights

Notice to U.S. Residents

If you are an individual residing in the United States, we provide you with the following information pursuant to state privacy laws.

We do not sell your personal information and have not done so in the past 12 months. We do not share your personal information for cross-context behavioral advertising. We also do not use or disclose sensitive personal information.

Right to Know

You have the right to know the following:

  • The categories of personal information we have collected about you.
  • The categories of sources from which the personal information is collected.
  • Our business or commercial purpose for collecting personal information.
  • The categories of third parties with whom we share personal information, if any.
  • The specific pieces of personal information we have collected about you.

Right to Deletion

Subject to certain exceptions set forth below, upon receipt of a verifiable request from you, we will:

  • Delete your personal information from our records; and
  • Direct any service providers to delete your personal information from their records.

Please note that we may not delete your personal information if it is necessary to:

  • Complete the transaction for which the personal information was collected, fulfill the terms of a written warranty or product recall conducted in accordance with federal law, provide a good or service requested by you, or reasonably anticipated within the context of our ongoing business relationship with you, or otherwise perform a contract between you and us.
  • Detect security incidents, protect against malicious, deceptive, fraudulent, or illegal activity, or prosecute those responsible for that activity.
  • Debug to identify and repair errors that impair existing intended functionality.
  • Exercise free speech, ensure the right of another consumer to exercise his or her right of free speech, or exercise another right provided for by law.
  • Comply with the California Electronic Communications Privacy Act.
  • Engage in public or peer-reviewed scientific, historical, or statistical research that conforms or adheres to all other applicable ethics and privacy laws, when our deletion of the information is likely to render impossible or seriously impair the ability to complete such research, provided we have obtained your informed consent.
  • Enable solely internal uses that are reasonably aligned with your expectations based on your relationship with us and compatible with the context in which you provided the information.

Or

  • Comply with an existing legal obligation.

We will also deny your request to delete if it proves impossible or involves disproportionate effort, or if another exception to the law applies. We will provide you with a detailed explanation that includes enough facts to give you a meaningful understanding as to why we cannot comply with the request to delete your information.

Right to Correct

If we receive a verifiable request from you to correct your information and we determine the accuracy of the corrected information you provide, we will correct inaccurate personal information that we maintain about you.

In determining the accuracy of the personal information that is the subject of your request to correct, we will consider the totality of the circumstances relating to the contested personal information.

We may also require that you provide documentation if we believe it is necessary to rebut our own documentation that the personal information is accurate.

We may deny your request to correct in the following cases:

  • We have a good-faith, reasonable, and documented belief that your request to correct is fraudulent or abusive.
  • We determine that the contested personal information is more likely than not accurate based on the totality of the circumstances.
  • Conflict with federal or state law.
  • Other exception under the law.
  • Inadequacy of the required documentation.
  • Compliance proves impossible or involves disproportionate effort.

We will provide you with a detailed explanation that includes enough facts to give you a meaningful understanding as to why we cannot comply with the request to correct your information.

Non-Discrimination

You have the right to not be discriminated against by us because you exercised any of your rights under applicable laws. If you exercise your rights, we cannot:

  • deny you services.
  • charge different prices or fees for services, including through discounts, benefits, or fines.
  • provide you a different level or quality of services.
  • propose that you receive different prices or tariffs for services.

Please note that we may charge a different fee or provide a different level or quality of services if the difference is reasonably related to the value we gain from your personal information.

Do Not Track

We do not currently respond to or take any action with respect to web browser "do not track" signals. We do allow third parties who provide us with analytics tools to collect personal data about a user's online activities when a user uses the website.

California Shine the Light

California Civil Code Section 1798.83 (and other similar state statutes) permits our customers who are California residents (or residents of states with similar legislation) to request certain information regarding our disclosure of Personal Data to third parties for their direct marketing purposes. To make such a request, please send an email to contactus@trailsight.io. Please note that we are only required to respond to one request per customer each year.

Verification & Agents

We will ask you for additional information to confirm your identity and for security purposes before disclosing the personal data requested to you, by using a two- or three-point data verification process, depending on the type of information you require and the nature of your request.

You may also designate an authorized agent to make a request on your behalf. To do so, you need to provide the authorized agent with written permission, and the agent will need to submit to us proof that they have been authorized by you. We will also require that you verify your own identity, as explained below.

Response Timeline

We will respond to your requests within 45 days (or within 90 days, where the law permits and we determine it necessary considering the complexity and number of the requests you have filed). If we take longer than 45 days, we will inform you of the extension within the initial 45-day response period, together with the reason for the extension.

We may deny your request in the following cases:

  • If we believe in good faith, based on reasons that are documented in writing, that your request is fraudulent or an abuse of your rights under applicable law.
  • If we conclude that the request is irrelevant, based on all the circumstances at issue (e.g., if you requested to correct your personal information, and we find that it is likely to be accurate).
  • If it is contrary to federal or state law.
  • Due to a discrepancy in the required documentation.
  • If the fulfillment of your request turns out to be impossible or involves disproportionate effort.

We will provide you with a detailed explanation, including sufficient facts, to enable you to meaningfully understand why we cannot fulfill your request.

10. Security

Information Security

We implement appropriate technical and organizational measures to secure your information against unauthorized access, alteration, disclosure, or destruction. These measures include encryption of data in transit and at rest, access controls, regular security assessments, staff training, and incident response procedures. While we maintain industry-standard security practices, no system can guarantee absolute security, and we continuously work to enhance our protective measures.

The controller has implemented technical security measures including Transport Layer Security (TLS) for encrypted data transmission over HTTPS, encryption at rest to protect stored data, and access controls to restrict data access to authorized personnel. These measures are designed to protect personal data from unauthorized access, disclosure, and alteration. The controller remains committed to maintaining and updating these security practices in accordance with applicable data protection requirements.

Information security

We treat the security of the information in our systems with utmost importance. In order to preserve and protect the information, we operate systems, applications and procedures for information security that are designed to minimize the risks of theft, damage, loss or unauthorized access to the information, including personal information. That said, there is no certainty that these measures absolutely guarantee that personal information will not be exposed or stolen from the databases. Therefore, we do not undertake that the services and information systems we use will be immune to unauthorized access to the information stored in them. By using the website, you are aware of, and agree to, these limitations.

11. Retention

Data Retention

We will retain your information for the duration needed to support our ordinary business activities, operating the website, and interacting with existing and potential customers, suppliers, and partners. Thereafter, we will still retain your personal information as necessary to comply with our legal obligations, resolve disputes, establish and defend legal claims, and enforce our agreements. The overall period of retention is approximately 7 years.

12. International Transfers

International data transfers

To facilitate processing your information with our service providers, we will transfer your information to countries outside your current location. For transfers to countries without adequacy decisions, we implement appropriate safeguards, including Standard Contractual Clauses approved by the European Commission (2021/914/EU) and the UK International Data Transfer Addendum, supplemented by additional technical and organizational measures where necessary to ensure equivalent protection.

13. Policy Changes

This Policy may be amended from time to time. We will post any changes to this Policy on our website a reasonable time in advance of the effective date of the change, and we will also make efforts to proactively notify you by email of the changes to the Policy if we have your email address.

Website Terms Trust & Security contactus@trailsight.io
TrailSight

Security Platform for Salesforce.

No trackers. No ad cookies.

Platform Agent Security How it works Findings Request a Demo
contactus@trailsight.io
Privacy Policy Website Terms Data Processing Addendum Trust & Security LinkedIn (opens in new tab)

© 2026 TrailSight. All rights reserved.