Effective date: 1 January 2026. PHALANX is committed to protecting personal data in alignment with GDPR, DPDP, and global privacy standards.
PHALANX collects organizational security telemetry, platform usage analytics, and account information. We do not collect personal employee data beyond what is necessary for platform authentication and audit trail purposes.
All telemetry is processed within the customer's designated data region. Cross-region transfer only occurs where explicitly configured by the customer administrator. PHALANX acts as a data processor under GDPR Article 28.
Security telemetry is retained for 90 days in hot storage and up to 7 years in cold storage, subject to customer configuration. Personal data is deleted within 30 days of account termination upon written request.
Data subjects have the right to access, rectify, erase, restrict processing, and port their personal data. Requests are fulfilled within 30 days. Contact dpo@phalanx.io for all data subject requests.
Personal data is transferred outside the EEA only where Standard Contractual Clauses or equivalent safeguards are in place. PHALANX maintains SCCs with all sub-processors. Full list available at phalanx.io/trust.
PHALANX engages sub-processors for cloud infrastructure, payment processing, and customer support. All sub-processors are contractually bound to equivalent data protection standards. Current list published in Trust Center.
PHALANX uses essential cookies for platform authentication and security. Analytics cookies are only set with explicit consent. Cookie preferences can be managed from the consent banner or account settings.
Data Protection Officer: dpo@phalanx.io. PHALANX Systems Inc., 100 Mission Street, San Francisco CA 94105. EU Representative: PHALANX Europe BV, Amsterdam, Netherlands.