.png)
Privacy Statement
This privacy statement (the “Privacy Statement”) is effective November 12, 2025.
Illumio, Inc. and its global subsidiaries (“Illumio,” “we,” “us,” or “our”) recognize the importance of protecting personal data entrusted to us by clients, partners, and other individuals. Illumio takes this trust seriously and is committed to comply with the laws of all countries in which it operates, including the General Data Protection Regulation and other applicable data protection laws around the globe.
This Privacy Statement describes Illumio’s practices regarding the collection, use and disclosure of personal information about an identified or identifiable natural person (“personal data”) that we collect when you use Illumio’s website at www.illumio.com (including, without limitation, portal.illumio.com, support.illumio.com, my.illumio.com, community.illumio.com, docs.illumio.com, status.illumio.com, and partners.illumio.com) and our training portal at Illumio.learnupon.com (collectively, the “Site”); interact with our social media platforms; sign up to attend or participate in an event or webinar; download a white paper or other materials; and inquire about our products and/or services (collectively, the “Services”). For purposes of this Privacy Statement, the terms “user,” “you” and “your” are meant to refer to the individuals about whom we may collect personal information.
This Privacy Statement does not apply to the information our customers upload or provide to us when they use our Services, which is governed by our customer agreements. This Privacy Statement also does not apply to any third-party websites, services or applications, even if they are accessible through our Site. We encourage you to review the privacy policies of any third-party websites or services you access through our Site, as their practices may differ from ours.
Personal Data We Collect
You may provide us with certain categories of personal data when you:
- complete and submit forms or chat on our websites
- log in to a Site feature or portal
- download white papers or other Illumio content
- subscribe to our newsletters or other Illumio content-related materials
- register for courses, training or education
- register and/or attend webcasts, seminars, tradeshows, conferences and other events sponsored by Illumio or a partner
- provide us with feedback or contact us by phone, virtual meeting, email, online, through social media or otherwise
- participate in a survey
- purchase Services from us
- visit our offices
We may also collect personal data from third-party sources where we have a lawful basis to do so, such as consent or legitimate interest. These sources may include partners, resellers, referral programs, and publicly available platforms.
Personal Information About California Consumers Subject to the California Consumer Protection Act (“CCPA”): In the preceding 12 months, Illumio has collected the following categories of personal information about California consumers. We may collect this personal information directly from you, from third parties and from your interactions with our Site and social media platforms. As defined by the CCPA, the personal information categories are:
- business contact information, including identifiers such as name, email address, address and phone number
- commercial information, such as records of Services purchased and other transactional data
- internet or other network or device activity details, such as technical data about your use of our Site or social media platforms
- geolocation data, such as your approximate location based on IP address
- audio, electronic or visual data, such as part of a photo or recording for an Illumio in-person or virtual event
How We Use Personal Data
We collect and use personal data that you provide in order to operate our business, provide our products and services, send marketing and other communications, and comply with applicable laws and regulations as further described below.
In the preceding 12 months and where applicable, we have disclosed each of these categories to our service providers, affiliates, partners, resellers and event sponsors, in line with the applicable purpose(s) described above. (Please note: Business contact details provided by customers for service-related notifications are used solely for those purposes. We do not share this information with third parties for marketing or advertising. Such information is handled in accordance with our customer agreements.)
How We Share Personal Data
We do not sell or otherwise disclose personal data about our website visitors or others that interact with Illumio or our products or services, except as described herein. We may share your personal data with authorized Illumio personnel in our subsidiaries with a need to know the information in order to process the personal data for the purpose we collected it. We also share personal data with third parties who are acting on our behalf in order to provide the products or services you request or to support our relationship with you. These third parties are not authorized by us to use or disclose the information except as necessary to perform services on our behalf pursuant to a contractual obligation or to comply with legal requirements. Illumio requires such third parties to comply with applicable data protection and privacy laws and agree to implement and maintain appropriate technical and organizational security measures to safeguard the personal data.
Our sharing may include:
- with any of our subsidiaries and trusted third party suppliers/partners in order to perform our services or support our legitimate business interests
- with event sponsors (in addition to this Privacy Statement, your personal information is subject to sponsors' privacy practices)
- with third-party social media networks, advertising networks, and websites, so Illumio can market and advertise on third-party platforms and websites
- with our professional advisors and insurers to run our business
- with competent legal authorities when required by applicable laws or regulations
- with law enforcement authorities or other government officials when we are required to do so by law or pursuant to legal process (including to meet national security or law enforcement requirements); when we believe disclosure is necessary or appropriate to prevent physical harm or financial loss or in connection with an investigation of suspected or actual fraud or illegal activity; or when we believe that disclosure is necessary to protect our rights, protect your safety or the safety of others
- with appropriate third parties in connection with the sale, transfer or financing of all or part of an Illumio business or its assets, including any such activities associated with a bankruptcy proceeding
- other third parties that you have given us consent to share it with
In the preceding 12 months, we have disclosed certain categories of personal information described above to third-party advertising partners, such as in connection with our use of tracking technologies for cross-context behavioral advertising or by providing lists of email addresses for potential customers so that we can reach you across the internet with advertisements for our Services. This may be considered “sharing” or a “sale” under the CCPA. (Please note: Business contact details provided by customers for SMS or email alerts related to our products are used solely for those communications. We do not share this information with third parties for marketing or advertising. Such information is managed in accordance with our customer agreements.)
How We Protect Personal Data
We use reasonable security procedures and technical and organizational measures to protect against accidental or unlawful destruction, loss, disclosure or use of personal data we handle. Our network and systems used to provide services are governed by corporate Information security policies, which are based upon standards, including International Organization for Standardization (ISO) 27001 and National Institute of Standards and Technology (NIST). We limit access to and use of your personal data to authorized persons and trusted third parties who have a reasonable need to know the information in order to perform our services and business operations and who are bound by confidentiality obligations.
Illumio is subject to the investigatory and enforcement powers of the Federal Trade Commission. Illumio is responsible for and may be held liable in the event of onward transfers to third parties. Provided that an individual has invoked binding arbitration by delivering notice to Illumio organization and following the procedures and subject to conditions set forth in Annex I of Principles, Illumio is obligated to arbitrate claims and follow the terms as set forth in Annex I of the DPF Principles.
How Long We Retain Personal Data
We retain your personal data only for as long as is necessary to fulfill the purpose for which the data was collected from you and in consideration of and compliance with applicable legal or regulatory requirements to maintain the data for legitimate purposes. For example: (1) where required by law for audits or accounting requirements; or (2) to enforce our agreements or handle disputes. When personal data is no longer needed for the purpose it was collected or processed or to comply with a legal obligation, we securely destroy it.
How to Request Access to Personal Data
We rely on you to provide accurate, complete and current personal data to us. If you need to correct or update the personal data you provided to us, in many cases, you can edit your data from the location where you provided the personal data to us. If you are not able to access it yourself, we will respond in a timely manner to all reasonable requests to access, correct or delete your personal data. Requests and questions can be submitted to [email protected].
Reasons for Collection
The type of data we process under this Privacy Statement includes contact details such as name, company, email, phone, website preferences and other information collected for marketing or business operation purposes. We process such personal data using the following legal basis:
- to meet our legitimate business interests such as to develop and improve our solutions, support our sales and business operations, secure our systems, facilities and personnel
- to comply with applicable laws and regulations
- in order to perform or fulfill our obligations under an agreement with you or the entity with which you are affiliated
- based upon the provision of your consent, which you may withdraw at any time by contacting us at [email protected]
Your Privacy Rights
You may have certain rights relating to your personal information, subject to local data protection laws. Depending on the applicable laws these rights may include the right to:
- to obtain confirmation from us if we are processing your personal data
- to request that we correct inaccurate personal data and to have incomplete data completed
- to object to the processing of your personal data for compelling and legitimate reasons relating to your particular situation and we will comply except in cases where legal provisions expressly provide for that processing
- in circumstances when the processing is based on your consent or a contract and the processing is carried out by automated means, to receive your personal data that you have provided to us, in a structured, commonly used and machine-readable format
- to restrict processing of your personal data if (i) you contest the accuracy of the data; (ii) the processing is unlawful and you oppose the erasure of the data and request restriction instead; (iii) we no longer need the data, but you tell us you need the data to establish, exercise or defend a legal claim; or (iv) you object to processing based on public or legitimate interest
- to opt out of the processing of data if it is used for targeted advertising (or sharing as defined under California’s privacy law), the sale of personal data, or profiling in furtherance of decisions that produce legal or similarly significant effects ("profiling")
- to erase your personal data where there is no compelling reason for its continued processing
- to authorize another individual or entity to submit requests on your behalf (if you choose to exercise this right, we may require verification of the authorized agent’s identity and proof of your authorization before processing the request)
- not receive discriminatory treatment from Illumio for exercising your privacy rights
- to lodge a complaint with a supervisory authority (for example in the EU Member State of your residence, place of employment, or the location where the issue that is the subject of the complaint occurred)
Please note that in case we ask for your consent to processing, you are free to refuse to give consent and you can withdraw your consent at any time without any adverse or negative consequences. The lawfulness of any processing of your personal data that occurred prior to the withdrawal of your consent will not be affected.
To the extent privacy laws applicable to you afford you with the rights referenced above, we will respect your rights and comply with such laws. You can exercise these rights by contacting us at [email protected]. Subject to legal and other permissible considerations, we will make every reasonable effort to honor your request promptly in accordance with applicable law or inform you if we require further information in order to fulfill your request. We ask that you please attempt to resolve any issues with us before you contact your local supervisory authority and/or relevant institution.
In compliance with the EU-U.S. DPF (as defined below) and the UK Extension to the EU-U.S. DPF and the Swiss-U.S. DPF (as defined below), Illumio commits to cooperate and comply respectively with the advice of the panel established by the EU data protection authorities (DPAs) and the UK Information Commissioner’s Office (ICO) and the Swiss Federal Data Protection and Information Commissioner (FDPIC) with regard to unresolved complaints concerning our handling of personal data received in reliance on the EU-U.S. DPF and the UK Extension to the EU-U.S. DPF and the Swiss-U.S. DPF.
Notice of Right to Opt Out of Sales of Personal Information and Sharing/Processing of Personal Information for Targeted Advertising Purposes.
Certain U.S. states provide residents with the ability to opt out of the "sale" of their Personal Information or the "sharing/processing" of their Personal Information for cross-context behavioral and advertising purposes. As discussed above in “How We Use Personal Data,” we may engage in certain online advertising activities through social media and by re-targeting advertising for our Services on other websites. We may use third-party ad networks to assist in these activities, which involves their collection of cookie and device identifier information to perform these activities. Under certain U.S. state laws you have the right to opt out of these activities.
If you would like to opt out of our online disclosure such as through cookie and pixel technology of your Personal Information for purposes that could be considered "sales" or "sharing" for purposes of cross-contextual behavioral advertising, please visit our homepage’s cookie banner and click on the ‘Do Not Sell or Share My Personal Information’ link. To learn more about online advertising and other tracking technologies and what choices you have regarding their use, please see our Cookie Notice.
You can also submit a request to opt out of our offline disclosures of personal information that are subject to applicable opt out rights (e.g. name, email collected via forms or events) by contacting us at [email protected].
Please note that we do not maintain or control any third party opt-out mechanisms and are not responsible for their operation.
How We Process and Transfer Personal Data Across International Borders
Illumio is a global enterprise based in the United States with operations in countries around the world. Authorized Illumio personnel and third parties acting on our behalf may access, use and process personal data collected from you in a country that is different from the country where you entered the personal data, which may have less stringent data protection laws. As a network security company, Illumio has implemented global privacy practices for processing personal data protected under various data protection laws. Illumio transfers personal data between the countries in which we operate in accordance with the standards and conditions of applicable data privacy laws, including standards and conditions related to security and processing and acceptable transfer mechanisms.
Illumio complies with the EU-U.S. Data Privacy Framework (EU-U.S. DPF) and the UK Extension to the EU-U.S. DPF, and the Swiss-U.S. Data Privacy Framework (Swiss-U.S. DPF) as set forth by the U.S. Department of Commerce. Illumio has certified to the U.S. Department of Commerce that it adheres to the EU-U.S. Data Privacy Framework Principles (EU-U.S. DPF Principles) with regard to the processing of personal data received from the European Union and the United Kingdom in reliance on the EU-U.S. DPF and the UK Extension to the EU-U.S. DPF. Illumio has certified to the U.S. Department of Commerce that it adheres to the Swiss-U.S. Data Privacy Framework Principles (Swiss-U.S. DPF Principles) with regard to the processing of personal data received from Switzerland in reliance on the Swiss-U.S. DPF. If there is any conflict between the terms in this privacy policy and the EU-U.S. DPF Principles and/or the Swiss-U.S. DPF Principles, the Principles shall govern. To learn more about the Data Privacy Framework (DPF) program, and to view our certification, please visit https://www.dataprivacyframework.gov.
Children
Our Services are not directed to individuals under the age of consent in their jurisdiction. We do not knowingly collect personal data from children. If we become aware that we have inadvertently collected such data, we will take steps to delete it promptly.
Changes to this Privacy Statement
Any personal data that we process is subject to the Privacy Statement in effect at the time such personal data is processed. We may, however, modify and revise this Privacy Statement from time to time. If we make any material changes to this Privacy Statement, we will notify you of such changes by posting the updated Privacy Statement on the Site or by sending you an email or other notification, and we will indicate when such changes will become effective.
EEA, UK, Swiss Representative
For individuals whose personal data we collect directly or instruct our trusted third party to collect on our behalf, Illumio, Inc. or one of our subsidiaries located in the EEA, UK, or Switzerland is a data controller under the General Data Protection Regulation.
Questions?
Please contact us at [email protected] if you have any questions about our Privacy Policy.