The products and services of Contrast Security, Inc. ("Contrast") represent a revolutionary approach to continuously protecting applications, just as the European Economic Area’s General Data Protection Regulation and, as of January 1, 2020, the California Consumer Privacy Act, represent revolutionary approaches to affording individuals control over their personal information. Contrast has a deep commitment to ensuring maximum Privacy and Information Security standards as evidenced by our product offerings and our internal compliance environment.
Accountability, Integrity, Transparency, Privacy by Design, our Security Standards, following best-in-class standards such as NIST and OWASP, inform virtually all decisions at Contrast.
You will share information with us when you visit our Website and use our services. We want to be up front with you regarding the information we collect, how we use it, how we share it, and the controls we give you to access, update, and delete your information.
We also want to provide it in a way that is easy to understand. Legal and regulatory requirements are important, but our goal is to minimize any “legalese” that may be confusing. You are also welcome to contact firstname.lastname@example.org at any time.
We do not collect Personally Identifiable Information (“PII”) or Personal Information ("PI") on our Website unless you provide it voluntarily. PII or PI is information that we can use to identify you as an individual and may include your name, address, company email, personal email, telephone number and any other information that relates to you personally.
If you are ever asked to provide PII, PI or other confidential information such as a Social Security number, My Number or National ID to someone claiming to represent Contrast, please notify email@example.com. If you believe you have discovered a security vulnerability at Contrast or with one of our products or services, please click here: Vulnerability Disclosure and/or email firstname.lastname@example.org.
We are committed to safeguarding the information in our custody and under our control. Our Operational Risk program is dynamic and proactive allowing us to stay abreast of the latest changes and enhancements to the ever-evolving global compliance landscape. We have implemented practical and sound administrative, technical and physical safeguards to protect against unauthorized access, use, modification and disclosure of this information. This is a responsibility that we take seriously, and we have strong internal controls around change management and employee accountability.
A co-founder of Contrast was a founder of The Open Web Application Security Project (“OWASP”), where he served as the Chair of the OWASP Board for 8 years. Both of our co-founders are major contributors to and created the OWASP Top 10, OWASP Enterprise Security API, OWASP Application Security Verification Standard, XSS Prevention Cheat Sheet, and many other widely adopted free and open projects. OWASP is a global not-for-profit charitable organization focused on improving the security of software. They provide impartial, practical information about AppSec to individuals, corporations, and other organizations worldwide. To further demonstrate the priority that Contrast gives to our compliance environment, we have a dedicated Director of Data Privacy as well as a Data Privacy Officer with over 33 years’ combined experience. Our Data Privacy Officer serves as our designated Data Protection Officer for the GDPR.
Our hosted product environment resides with Amazon Web Services (“AWS”) and they adhere to the strictest compliance standards. They are CSA, GDPR, ISO, PCI and SOC-compliant and were the first Cloud Service Provider to adopt the new PCI DSS 3.2 assessment in advance of the mandatory February 1, 2018, deadline. While we do not accept any online payments or otherwise collect payment information, we believe this proactive compliance indicates the strength of our hosting provider’s information security framework. AWS is FedRamp certified; meets all of the requirements for FERPA, HIPAA and the EU Data Protection Directive and are fully compliant with the GDPR; more information can be found here: AWS/ GDPR Compliance.
Contrast has entered into a Data Processing Addendum with AWS relative to the GDPR and CCPA. AWS allows for alignment with FISMA and adheres to the NIST framework. For a full list of their Assurance Programs, including information regarding Japan's Act on the Protection of Personal Information ("APPI") please click here. We welcome any questions you may have about the steps we take to ensure the most robust and best-in-class standards and practices at Contrast.
Contrast complies with Japanese laws and regulations, including the APPI. Contrast is primarily responsible for the management of the PI that is jointly used with our affiliates or third parties. We do not provide your information to third parties for marketing purposes without your prior consent.
As mentioned above, Contrast does not collect PII or PI on our Website unless you provide it voluntarily. Contrast does not use any information provided by the Japan My Number system.
As mentioned above, Contrast products represent a revolutionary approach to continuously protecting applications. The GDPR represents a revolutionary approach to affording individuals control over their PI.
As of January 31, 2017, Contrast is SOC2 Type II compliant and, as of October 31, 2017, we began maintaining a rolling, annual SOC2 schedule. Our most recent SOC2 Type II Report was issued December 6, 2019. We are audited for Availability, Confidentiality, Privacy and Security and the audit maps to HITRUST.
When you visit our Website at https://www.contrastsecurity.com (the “Website”), we collect your Internet Protocol (“IP”) address as well as other related information such as page requests, browser type, referring and exit pages, the files viewed on our site (for example, HTML pages, graphics, or other), operating system and average time spent on our Website. We use this information to help us understand our Website activity, and to monitor and improve our Website.
Our Website uses a technology called "cookies". For more information about cookies, please click here: Cookies. Cookies are small, often encrypted text files, located in browser directories. They are used by web developers to help users navigate their websites efficiently and perform certain functions. You may set your browser to notify you when you receive a cookie or to not accept certain cookies. However, if you decide not to accept cookies from our Website, certain features may not function as designed. You may also remove cookies. To learn how to do so, please click here: Clear Cookies
There are different ways you can prevent tracking of your online activity. One of them is setting a preference in your browser that alerts websites you visit that you do not want them to collect certain information about you. This is referred to as a Do-Not-Track (“DNT”) signal.
Contrast’s Website may not recognize or react in response to DNT signals from web browsers as, currently, there is no universally accepted standard for what a company should do when a DNT signal is detected. At such time as a standard is established, we will assess how to best respond to the signals. For more information, please click here: DNT Signals
Links to our Website may be featured or referenced on other websites that are not under our control and therefore we have no responsibility or liability for the manner in which they operate their sites. Be sure to understand the privacy policies and terms of service of any site you visit. If you believe another entity has posted a link to Contrast that is misleading or that compromises the integrity of Contrast, please contact email@example.com. Such notifications will be kept in strict confidence.
We encourage you to carefully read the privacy statement of any website you visit whether visiting https://www.contrastsecurity.com or another.
When you provide us with Data, it is primarily used to respond to requests or to allow us to provide better service to you. Once you become a customer of Contrast, we may send you a welcome e-mail, administrative e-mail notifications such as security or support and maintenance advisories; promotional communications, requests to participate in a survey, send upgrades and special offers related to our Service and for other Contrast-specific purposes. We may contact you by telephone for the purpose of verifying information, reviewing potential vulnerabilities or to solicit feedback.
As we provide web application security services and products, our software is embedded into our clients’ web applications to monitor for vulnerabilities and prevent attacks. For the purposes of performing the web application security services on behalf of our clients, we may collect and use Data through our clients’ web applications. We do not collect or use PI through your web applications for any purpose other than to provide the Service to which you have subscribed; this includes providing support and answering questions that you may have about the Service.
“Application Data” means data about the performance of your application, system data (such as version data, names of plug-ins, etc.) about the environment in which your application is operating, data about transactions in your application (“Transaction Data”), stack traces and extracts of source code for certain classes of errors, and other similar data related to your application.
Any Application Data we collect is used to notify you of vulnerabilities and attacks and to share application performance information with you. We may also aggregate Application Data across multiple accounts and use this data to create and publish industry benchmarks or comparative application performance metrics. By default, we obfuscate any Individual Transaction Data that we collect. You have the option of changing the configuration of our products so that individual Transaction Data is not obfuscated. You can also disable certain vulnerability rules and/ or the collection of certain types of Application Data collected through our Service. Information as to how to do so can be found here.
We may collect telemetry and diagnostic data about how our products and services are working to provide improvements and enhancements. This will enable us to not only give you a better user experience, but also enhance our products and services for your benefit. You expressly consent to the sharing of your Application Data as described in this Policy.
When we delete account information, it will be deleted from the active database but may remain in our archives. We will otherwise retain your information for as long as your account is active or as needed to provide you with the Service to which you have subscribed. It will also be retained as is necessary to comply with our legal obligations, resolve disputes, and enforce our agreements.
We will not disclose, sell or otherwise transfer PI without your prior consent except as otherwise set out herein or, if applicable, in your Agreement or Contract for Service with us.
We may transfer or disclose PI as follows:
Where a disclosure of your information is required under such circumstances, we will promptly notify you, whenever possible, prior to complying with such requirements (to the extent we are not prohibited from doing so). To this end, it is important that you maintain current information with us at all times.
Contrast will never intentionally collect data from children who are 13 years of age or younger. If a parent, guardian or other individual suspects that a child 13 or younger has provided data to Contrast, that individual should immediately report such information to firstname.lastname@example.org. Contrast will only retain the data for as long as it is necessary to delete the information using every reasonable measure to protect against its unauthorized access or use or to comply with legal or regulatory requirements.
Contrast respects the intellectual property rights of others and expects its users to do the same. In accordance with the Digital Millennium Copyright Act of 1998 (the “DMCA”), the text of which may be found on the U.S. Copyright Office website at http://www.copyright.gov/legislation/dmca.pdf, Contrast will promptly respond to claims of copyright infringement using our Service or Website. Such claims must be reported to Contrast’s Designated Copyright Agent identified below.
If you are a copyright owner, authorized to act on behalf of a copyright owner, or are authorized to act under any exclusive right under copyright, please report alleged copyright infringements by completing the DMCA Notice of Alleged Infringement and delivering it to Contrast’s Designated Copyright Agent. Upon receipt of Notice as described below, Contrast will take whatever action it deems appropriate, including removal of the challenged content from the Website.
Identify the copyrighted work that you claim has been infringed or, if multiple copyrighted works are covered by this Notice, you may provide a representative list of the copyrighted works that you claim have been infringed.
Where our Services are made available to you through an organization (e.g. your employer), that organization is the administrator of the Services and is responsible for the accounts and/or Service sites over which it has control. If this is the case, please direct your data privacy questions to your administrator, as your use of the Services is subject to your organization's policies. We are not responsible for the privacy or security practices of an administrator's organization, which may be different than this policy.
Administrators are able to:
In some cases, administrators can also:
Even if the Services are not currently administered to you by an organization, if you use an email address provided by an organization (such as your work email address) to access the Services, then the owner of the domain associated with your email address (e.g. your employer) may assert administrative control over your account and use of the Services at a later date.
Please contact your organization or refer to your administrator’s organizational policies for more information.
We may post client endorsements on our web site which may contain PI. All client endorsements require the voluntary consent of the client to provide the endorsement and for us to publicly post it. Should you provide an endorsement and later want it removed, please contact email@example.com.
Alternatively, you may write to us, anonymously or otherwise, at:
Contrast Security, Inc.
Attn: Privacy (or Compliance) accordingly
240 3rd Street
Los Altos, CA 94022
The California Consumer Privacy Act of 2018 ("CCPA") became enforceable on January 1, 2020. The law is meant to enhance privacy rights and consumer protection of residents of California. CCPA is the first law of its kind to impact the U.S. and has some similarities to GDPR.
Contrast has put processes in place to ensure CCPA compliance and to meet our obligations to our customers and consumers. As such, we have reviewed our policies and procedures, including collection methods, to make sure they align with the requirements of CCPA.
Contrast falls under the definition of both a "Business" and a "Service Provider" per CCPA and we will assist our customers/ consumers with exercising their rights under CCPA. This includes ensuring any requests from you, or if applicable, your employees in the case of opt-out, for example, are handled promptly. We will work with third parties who may be involved to make sure requests are honored as soon as possible.
Contrast currently has three areas of activity that are related to the CCPA:
Regardless of which area of activity applies to you, Contrast does not sell your information.
To be clear, we have not sold, rented, released, disclosed, disseminated, made available, transferred, or otherwise communicated a consumer's PI to another business or third party for monetary or other valuable consideration since the CCPA legislation was passed.
Further, when we provide the services to our customers, we do not:
Your rights under the CCPA include the right to request a copy of the specific PI collected about you in the 12 months prior to the request, and our data collection practices (including categories of information collected, how the information is used, and to whom it is disclosed). We will generally refer to these as "access requests".
In addition, with some exceptions, you can request deletion of the PI that is collected about you. We will generally refer to these as "deletion requests".
With respect to the personal data of consumers collected in Contrast's marketing efforts, we are responsible for fulfilling access and deletion requests.
Pursuant to California Civil Code Section 1798.83, residents of the State of California have the right to request certain information relating to third parties to which Contrast may have disclosed certain categories of PI during the preceding year for the third parties’ direct marketing purposes. Contrast does not sell consumer data to any third parties. If you have any questions regarding your rights, please email CCPA@contrastsecurity.com.
GDPR addresses the technological changes in the global business environment over the past two decades and seeks to harmonize the approach to data protection across the EEA by establishing a single set of rules and associated penalties for non-compliance. The regulation was adopted on 27 April 2016 and became enforceable on 25 May 2018. The GDPR replaced the Data Protection Directive, a 20-year old law with similar requirements to the GDPR, but varying interpretation and application among member states of the EEA, and a lack of enforcement powers. GDPR has a global reach, however, as it even applies to companies who are outside the area that control or process the data of EEA subjects, making the GDPR the first global privacy standard.
Contrast has put processes in place to ensure GDPR compliance and to meet our obligations to our customers and employees. We have appointed a Data Protection Officer to oversee compliance, conducted a full Data Protection Impact Assessment (DPIA), and tuned our current incident response and breach notification policy and process to align with the requirements of the GDPR. We have also implemented business processes to deal with privacy-related requests outside the Contrast platform and to ensure any requests from your employees directed to us, are made known to you in a timely manner, if applicable and permissible.
The GDPR defines 6 lawful bases for processing:
Contrast collects limited Corporate and Personal Data. The data we collect can be categorized as:
For business to business marketing efforts, we do not currently collect Personal Data (i.e. names, phone number, corporate email addresses) for the purpose of marketing our services. Rather, we only maintain contacts that have expressed interest in our services. If you have expressed interest in our services, we may contact you about updates or product offerings that may be of interest to you. If these communications are no longer of use, we invite you to unsubscribe at any time. Contrast believes we have a legitimate interest in offering business more information about our services and have controls in place to ensure the way in which we store and handle such data is subject to our Information Security Program.
We believe a very important piece of our continued compliance with privacy best practices, as well as compliance with the GDPR, is to ensure that we hold our vendors and sub-processors accountable for their security and privacy commitments. Contrast has a robust Third-Party Vendor Management program, and we frequently assess all third parties for continued compliance with their security, privacy and confidentiality commitments.
Do-Not-Track: There are different ways you can prevent tracking of your online activity. One of them is setting a preference in your browser that alerts websites you visit that you do not want them to collect certain information about you. This is referred to as a Do-Not-Track (“DNT”) signal.
Contrast’s Website may not recognize or react in response to DNT signals from Web browsers as, currently, there is no universally accepted standard for what a company should do when a DNT signal is detected. At such time as a standard is established, we will assess how to best respond to the signals. For more information, please click here: DNT Signals.
Contrast informs individuals about:
In addition, Contrast is subject to the investigatory and enforcement powers of the U.S. Federal Trade Commission ("FTC") regarding personal data received or transferred pursuant to the Privacy Shield Framework.
Under Privacy Shield, an individual has the option, under certain conditions, to invoke binding arbitration for complaints regarding Privacy Shield compliance not resolved by any of the other Privacy Shield mechanisms. Under Privacy Shield, Contrast must respond to individual complaints within 45 days. For additional information, visit: Privacy Shield / Complaints.
In the context of an onward transfer, Contrast has responsibility for the processing of the PI it receives under the Privacy Shield and subsequently transfers to a third party acting as an agent on its behalf. Contrast shall remain liable under the Principles if its agent processes such PI in a manner inconsistent with the Principles, unless the organization proves that it is not responsible for the event giving rise to the damage.
In compliance with the Principles, Contrast commits to resolve complaints about our collection or use of your PI. EU, UK or Swiss individuals with inquiries or complaints regarding our Privacy Shield policy should first contact Contrast at: firstname.lastname@example.org.
Contrast has further committed to cooperate with the panel established by the EU data protection authorities ("DPA"s) with regard to unresolved Privacy Shield complaints concerning Human Resources data transferred from the EU or the UK in the context of the employment relationship. Contrast also agrees to cooperate with the Swiss Federal Data Protection and Information Commissioner (“FDPIC”) and comply with the advice given by such authorities with regard to Human Resources data transferred from Switzerland in the context of the employment relationship. Finally, Contrast agrees to cooperate with the DPAs and/ or the FDPIC and to comply with the advice given by such authorities with regard to non-Human Resources data transferred from the EU to Switzerland.
Contrast self-certifies with Privacy Shield. A self-assessment is signed by a company officer or other authorized representative of the organization at least once a year and can be made available upon request by individuals or in the context of an investigation or a complaint related to non-compliance. Contrast is required to respond promptly to individual inquiries, and other requests for information from the Department of Commerce relating to its adherence to the Principles.
If you reside in the EEA and are interested in employment with Contrast, you will need to provide certain information (cover letter, resume, references, eligibility, or other employment-related information). We use this information for the purpose of processing and responding to your application for current and future career opportunities. In this respect, you would be considered a Data Subject and the information you provide to us would represent Personal Data.
Our Website includes a “Careers” link. All applications must originate from this Website. Any entity that processes data on behalf of Contrast will be fully GDPR compliant. You will need to provide your Consent for us to contact you as part of your application. You have the right not to provide Consent but we will be unable to process your application and consider you for employment if you do not provide it. While we will obtain your Consent, we process and manage your data based on legitimate interests.
A limited number of employees of Contrast will also have access to your data once you apply for a position. The recipients of your personal data will be select employees of Contrast such as Human Resources, your hiring leader, individuals with whom you will need to interview, etc. All information is shared according to the principle of least privilege and need-to-know. These employees have all undergone GDPR-related training. A limited number of third-party providers, under contract with Contrast, may also have access to your Personal Data. We ensure that any such provider has data protection levels equivalent to those set forth in this privacy notice, at a minimum. We have entered into Data Processing Addenda with all such vendors or ensure appropriate language is in our Agreements with them.
If you are selected as a final candidate for a position, we will enter into the appropriate contract, agreement, or other documentation as appropriate for your country of residence. All documentation and actions, including those requiring additional Consent, will reflect full compliance with GDPR.
As part of becoming an employee of Contrast you will be provided with a GDPR Employee Privacy Notice outlining your rights and remedies. At that time, you will also be provided with any and all documentation and information related to your status as both a Data Subject under the GDPR and an employee of Contrast.
A subject access request is a written request for PI/ Personal Data held about you by us. You have the right to see what PI we hold about you. You are entitled to be given a description of the information, what we use it for, who we might pass it on to, and any information we might have about the source of the information. However, this right is subject to certain exemptions or restrictions that are set out in the GDPR.
To make a Subject Access Request, email GDPR@contrastsecurity.com or write:
Sharron Reed Gavin, Data Protection Officer
Contrast Security, Inc.
240 3rd Street
Los Altos, CA 94022
The GDPR requires that we provide you with the following information:
Finally, you have the right to lodge a complaint with the Information Commissioners’ Office (“ICO”) if you believe that we have not complied with the requirements of the GDPR with regard to your personal data. The ICO encourages individuals to first report their concern to the organization controlling or processing your data. For more information, please refer to ICO/ Raising a Concern.
Keeping your data secure is critical to us at Contrast. We follow industry best practices in application, network, and product security to ensure that your data is safe. We envision a world where we can trust software with the most important activities of humanity. We love software, and it hurts us to see it misused to cause harm to others. As a security company, we not only protect our business, but yours as well. Contrast is committed to the highest standards of application and network security for our hosted products. At the core of our approach to security is a commitment to transparency – across our protections, processes, and even potential issues.
Contrast has successfully undergone third party Service Organization Control auditing (SOC 2 Type II). The SOC 2 report provides assurance that we have designed and implemented effective security controls as defined by the SOC 2 standards which are based on defined Trust Services Criteria. During the examination, the independent auditors evaluated and tested controls over the following:
With respect to Security, Availability, Confidentiality and, as of 2018, Privacy.
Contrast's security application services and data are currently hosted on servers in Amazon Web Services (AWS) ISO 27001 certified facilities in the United States. AWS is routinely audited and believes in transparent security. A few of AWS’ Assurance Programs are as follows: FedRAMP, ISO 27001, FIPS, SOC2/Type 2, FERPA, and HIPAA. As of March 26, 2018, AWS is fully compliant with the GDPR; more information can be found here: AWS/ GDPR Compliance. Contrast has entered into a Data Processing Addendum with AWS.
A full list of AWS certifications is available here: http://aws.amazon.com/compliance/.
In addition, Amazon Web Services has published the Shared Responsibility Model where they describe the division of responsibilities between AWS and the customer. In general, AWS is responsible for security of the cloud and the customer is responsible for security in the cloud. No Contrast employees have physical access to AWS Data Centers.
We store our data across multiple AWS availability zones and perform multiple database backups each day. These backups are stored in geographically distributed object storage. Backup integrity is automatically tested daily. Host logs are ingested into a log management platform for support and operational processes.
Operating Systems are hardened using Center for Internet Security standards and other industry best practices depending on the host's role. System configuration and patches occur through both scheduled and ad-hoc process that are driven by configuration management tools. The code is committed, tested, and peer reviewed before deployment.
Security patch management is an automated task for all hosts. Should a security patch be needed outside this process, we can apply patches in bulk to all hosts. If an urgent patch needs to be applied outside the regular schedule, we first verify that our infrastructure is vulnerable and then apply the patch.
Our network is engineered and designed to limit access by origin and port between hosts and services (AWS Security Groups). Where possible, separate private networks (AWS VPCs) are created and are completely separate from other networks. All network and firewall rules are checked into our source code repository and reviewed by staff via Pull Requests and only deployed once tested and reviewed. The network is designed with limited public facing systems.
In addition to our own product, we deploy several monitoring solutions to measure the health of our service.
Contrast only collects the data absolutely necessary to provide the analysis and metrics we offer. Our agents minimize the amount of data collected by reporting only confirmed vulnerabilities. Your source code and binaries never leave your servers. Contrast collects the following types of data:
Contrast encrypts all data at rest and sends and receives all data over HTTPS using TLS.
Our primary defenses keep out attackers and control access, but we also use strong encryption to ensure that all of the data we store is inaccessible to attackers. All Contrast data is stored on encrypted volumes or object storage. We extend the use of encryption to backups, logs, and any other data associated with the Contrast service.
Where possible, we utilize Amazon's Key Management Service to generate and rotate keys used across our services.
Amazon’s overall key management infrastructure uses Federal Information Processing Standards (FIPS) 140-2 approved cryptographic algorithms and is consistent with the National Institute of Standards and Technology (NIST) 800-57 recommendations.
Contrast uses strong encryption and mutual authentication on all connections. This protects against sniffing, spoofing, and other communications attacks. The connection from the Contrast Agents to the Contrast TeamServer uses a TLS socket connection that can be configured to use an outbound proxy. The Agents verify the Contrast TeamServer certificate and send the client authorization key to the TeamServer to establish mutual authentication. Back-end connections are also both encrypted and mutually authenticated. Any attempt to access our service over a non-SSL connection is redirected to use HTTPS.
We leverage multiple AWS services relating to encryption.
We enable administrator, manager, or individual contributor permission levels within the app to be set for your individual users. Permission levels determine the user’s ability to change settings, view information, and edit, delete, or export data. These are configurable by customer.
We believe that everything that happens within Contrast should be fully authenticated and traceable to a particular individual and we discourage the use of shared logins. We do not charge or limit the number of users within an organization. We check password strength and failed login lockouts to ensure that Contrast is not susceptible to brute force attacks. We allow organizations and users to configure our Two Step Verification process that leverages time-based one-time passwords ("TOTP").
Contrast was designed from the ground up to be resilient against injection attacks like SQL injection, cross-site scripting (XSS), LDAP injection, XML entity attacks, command injection, and other risks. Our software architecture requires strict input validation on all input before it can be used. We minimize the use of interpreters where possible and use parameterized interfaces, if available.
Contrast uses TeamServer to identify, track, and remediate vulnerabilities during the Software Development Life Cycle. Our agent runs in automated testing and manual verification environments.
Contrast performs regular vulnerability scanning using several tools. Contrast performs external infrastructure scans on a quarterly basis, at minimum. Also, Contrast uses Contrast Assess (IAST) and Contrast Protect (RASP) on the staging and production environments to detect vulnerabilities before they make it to production, and to protect against application security attacks in production.
Annually, at a minimum, Contrast contracts with respected third-party security experts to execute a penetration test on our source code and production infrastructure. Also, Contrast consistently performs internal penetration testing and code review of our SaaS application. Alongside the internal assessments, the application security team is also a part of approving code pull requests should security components be affected.
Contrast restricts access to our production environment on a need-to-know basis and maintains a comprehensive logging system to track access and events. Contrast closely monitors potential attacks both at a network and application security level with automated alerting to internal chat and paging systems.
Updated 28 February 2020
Changes made to this Policy on 2/28/20 include:
1. Updates to information regarding Japan's Act on the Protection of Personal Information ("APPI") and the My Number Act.
2. Clarification as to Contrast's notification to individuals about the key goals of Privacy Shield and onward transfer of data.
Updated 30 December 2019
Changes made to this Policy on 12/30/19 are related to the California Consumer Privacy Act.
Updated 21 November 2019
Updated 29 March 2019
Changes made to this Policy on 3/29/19 are related to data being sent to the UK from the EU (see Privacy Shield Information).
Updated 24 May 2018
Changes made to this Policy on 5/24/18 are related to the enforcement of the General Data Protection Regulation
Updated 1 February 2018
Updated 9 January 2018
Updated 29 September 2017
Originally published 1 September 2016