Privacy Policy
Trust begins with how identity and data are handled. This policy explains what personal data Fortanixor collects across its identity security platform (FortAuth, FortVoice, and FortAgent) and this website, why we process it, who we share it with, how long we keep it, how we protect it, and the rights and choices you have.
Last updated: August 9, 2026
Scope of this policy
This Privacy Policy describes how Fortanixor (“Fortanixor,” “we,” “us,” or “our”) processes personal data when it acts as a controller. That includes when you visit our website, request a demo, sign up for an account, attend an event, apply for a job, or otherwise interact with us. It covers our own practices across the FortAuth, FortVoice, and FortAgent products and this website (together, the “Services”).
It does not govern personal data that our enterprise customers submit to, or route through, the platform to serve their own end users (“Customer Data”). For Customer Data, the customer is the controller and determines how it is used; Fortanixor acts only as a processor under a data processing agreement and processes that data on the customer’s documented instructions. If you are an end user of a business that uses Fortanixor and have questions about how your data is handled, please contact that business and refer to its privacy policy.
This policy is provided in layers: the sections below can be read in full, and region-specific rights are summarized under “Your privacy rights.” If there is a conflict between this policy and a written agreement you have with us, that agreement controls for the data it covers.
Personal data we collect
We practice data minimization and collect only what is needed to provide, secure, and improve the Services. We collect personal data in three ways: information you provide, information collected automatically, and information we receive from third parties.
Information you provide to us
- Account and profile data: name, work email, phone number, organization, job title, and login identifiers created when you register or are provisioned by an administrator.
- Communications: the contents of demo requests, sales inquiries, support tickets, survey responses, and any messages you send us.
- Event and marketing data: details you share when you register for a webinar or event or subscribe to updates.
- Recruitment data: information in job applications, such as your CV, work history, and correspondence, where you apply to work with us.
Information we collect automatically
- Authentication and security data: passkey public keys, device and platform attestations, and sign-in event metadata such as timestamps, results, IP address, and risk signals. FortAuth is phishing-resistant by design: private keys and biometrics are bound to the user’s device and are never transmitted to or stored by Fortanixor.
- Device and connection data: IP address, browser type and settings, operating system, device identifiers, language, and referring URLs.
- Usage and telemetry: pages and features viewed, actions taken, dates and times of access, performance metrics, and diagnostic logs used to keep the Services reliable and secure.
- Cookies and similar technologies: as described in the “Cookies” section and our Cookie Policy.
Information from third parties
- Identity and SSO providers: limited profile information when you or your organization sign in through a connected identity provider or single sign-on.
- Business and marketing partners: contact and firmographic data from partners and publicly available sources, used to qualify and improve outreach.
- Integrations you connect: data from the CRM, telephony, or other tools your organization chooses to connect to the platform.
We do not intentionally collect special categories of personal data through the Services, and we ask that you not submit such data except where strictly necessary and lawful.
How we use personal data
We use personal data for the following purposes:
- To provide the Services: to create and manage accounts, authenticate users, deliver features, and provide customer support.
- To secure the Services: to authenticate identities, enforce access, monitor for and prevent fraud, bots, abuse, and identity threats, and to investigate incidents.
- To operate and improve: to understand how the Services are used, debug and improve performance, and develop new features.
- To communicate: to send administrative messages, respond to your requests, and, where permitted, send marketing communications you can opt out of at any time.
- To comply with law: to meet our legal, regulatory, tax, and contractual obligations, and to establish, exercise, or defend legal claims.
- With your consent: for any other purpose disclosed to you at the time we collect the data or for which you later provide consent.
We do not sell personal data. We do not use Customer Data to train foundation models, and we do not use personal data for cross-context behavioral advertising. Where we de-identify or aggregate data, we maintain it in a form that cannot reasonably be used to re-identify you and do not attempt to re-identify it.
How we disclose personal data
We disclose personal data only in the following circumstances:
- Service providers and subprocessors: vendors that host, support, or help us operate the Services under contract, such as cloud infrastructure, analytics, customer support, and email delivery providers. They may process personal data only on our instructions and are bound to confidentiality and security obligations no less protective than those in this policy.
- Affiliates: entities within the Fortanixor group, for the purposes described in this policy.
- Professional advisors: auditors, lawyers, bankers, and insurers where necessary to obtain their services or protect our rights.
- Legal and safety: authorities, regulators, or other parties where we believe disclosure is required by law or necessary to protect the rights, property, or safety of Fortanixor, our customers, or others.
- Business transfers: in connection with a merger, acquisition, financing, or sale of assets, in which case personal data may be transferred subject to confidentiality and the terms of this policy.
- With your direction or consent: when you ask us to share your data or otherwise consent.
A current list of subprocessors is available on request, and we provide advance notice of material changes so customers can review them under their agreements.
Legal bases for processing
Where required (for example, under the GDPR or the UAE PDPL), we rely on one or more of the following legal bases when we process personal data as a controller:
- Contract: to provide the Services and perform our agreement with you.
- Legitimate interests: to operate, secure, and improve the Services and to communicate about them, balanced against your rights.
- Legal obligation: to comply with laws that apply to us.
- Consent: for optional activities such as certain marketing and cookies, which you can withdraw at any time.
For enterprise deployments, the customer determines the legal basis for Customer Data as the controller.
How long we keep data
We retain personal data only for as long as necessary to fulfill the purposes described in this policy:to provide the Services, comply with our legal obligations, resolve disputes, and enforce our agreements. After that we delete or irreversibly anonymize it. The retention period depends on the type of data and the context; for example, security and audit logs are kept for a defined period to support investigations. Enterprise customers can configure retention windows for logs and event data and can request export or deletion of Customer Data at the end of their term.
Marketing communications and your choices
Where permitted, we may send you marketing communications about our products and events. You can opt out at any time by using the unsubscribe link in our emails or by contacting us. This will not affect administrative or security messages related to your account. You can also manage cookie and tracking preferences as described above.
Your privacy rights
Depending on where you live, you may have some or all of the following rights over your personal data:
- Access: to know what personal data we hold about you and receive a copy.
- Correction: to correct inaccurate data or complete incomplete data.
- Deletion: to request that we delete your personal data, subject to legal exceptions.
- Restriction and objection: to restrict or object to certain processing, including direct marketing.
- Portability: to receive certain data in a structured, machine-readable format.
- Withdraw consent: where processing relies on consent, to withdraw it at any time.
- Opt out of sale or sharing: we do not sell or “share” personal data for cross-context behavioral advertising, but you retain this right where it applies.
- Non-discrimination: to not be discriminated against for exercising your rights.
EEA, UK, and Switzerland. If you are in these regions, the GDPR (and UK/Swiss equivalents) applies, and you may lodge a complaint with your local supervisory authority. United Arab Emirates. The UAE Personal Data Protection Law (PDPL) applies to processing in our home region. United States. Residents of certain states may have rights under applicable state privacy laws.
To exercise your rights, contact privacy@fortanixor.com. We may need to verify your identity before responding, and you may use an authorized agent where the law allows. Where Fortanixor acts as a processor, we will refer your request to the relevant controller. If we decline a request, you may have the right to appeal.
Security of your information
We protect personal data with a Zero Trust, defense-in-depth security program that includes encryption in transit and at rest, least-privilege access, continuous monitoring, and independent testing. While no method of transmission or storage is completely secure, we maintain an incident-response plan and will notify affected parties and regulators as required by law. For more detail, see our Security page.
International transfers and residency
Fortanixor is headquartered in the United Arab Emirates and operates across multiple regions, so your personal data may be processed in countries other than your own, including countries whose laws differ from those where you live. Where personal data is transferred across borders, we implement appropriate safeguards, such as standard contractual clauses or equivalent mechanisms, and enterprise customers can pin Customer Data to a specific region to meet data residency and sovereignty requirements.
Third-party links and services
Our website and communications may link to third-party sites and services that we do not control. This policy does not apply to those third parties, and we are not responsible for their content or privacy practices. We encourage you to review the privacy policies of any third-party services you use.
Children's data
Our Services are intended for organizations and their authorized users, not for children. We do not knowingly collect personal data from anyone under 16. If you believe a child has provided us personal data, contact us and we will delete it.
Changes to this policy
We may update this policy as our Services, technology, and legal obligations evolve. We will post the revised version here with a new “last updated” date and, where changes are material, provide additional notice. Your continued use of the Services after an update takes effect constitutes acceptance of the revised policy.
Contact us
If you have questions about this policy or wish to exercise your rights, contact us at privacy@fortanixor.com, or write to us at our headquarters in the United Arab Emirates. If you are in the EEA, UK, or Switzerland and are not satisfied with our response, you may also complain to your local data protection supervisory authority.