In the performance of Netskope’s cloud security services (“Services”) pursuant to an active master subscription agreement (“Agreement”) executed by Netskope and the end customer (“Customer”), Netskope supports the customer’s compliance for Processing covered by the California Consumer Privacy Act of 2018 (the “CCPA”), as amended by the California Privacy Rights Act of 2020 (the “CPRA”). To confirm applicable aspects of the CCPA and CPRA in connection with Customer’s use of the Services, Netskope is providing this Compliance Statement. Terms not defined below have the meanings given to them in the CCPA and CPRA.
Netskope operates as a service provider or processor to our customers. We process personal information solely on behalf of, and at the direction of, our customers. Netskope does not “sell” or “share” any personal information as defined by the CCPA and CPRA. Our processing activities are strictly limited to providing and improving the security services for which we have been engaged, as specified in our contractual agreements.
Netskope processes personal information that our customers provide to us as part of their use of our Services. The purpose for this processing is to provide cloud security services, which includes identifying and preventing threats, protecting data, and ensuring compliance with our customers’ policies. The information processed is determined by the customer’s specific deployment of our services and may include data from a variety of sources within their environment.
Deidentification and Aggregation. If the Services involve Processing Deidentified and/or Aggregated information, Netskope will do so only with Personal Information that has been Deidentified and/or Aggregated as those terms are defined below. For Deidentified information, Netskope will implement appropriate safeguards to prevent reidentification.
Data Retention. Netskope retains personal information as long as necessary to fulfill the purposes for which it was collected or as required by our contractual agreements with our customers. The retention periods are defined by the customer’s settings and policies within our platform. Upon the termination of an agreement, Netskope will, at the customer’s request and in accordance with the agreement, delete or return all personal information as required by law.
Consumer Requests. To the extent that Netskope stores Personal Information subject to the CCPA and CPRA, at Customer’s request, Netskope will assist Customer with Customer’s obligation to respond to consumers’ requests to exercise their rights under the CCPA and CPRA by securely deleting or destroying Personal Information pertaining to a consumer identified by Customer where such Personal Information is within possession or control of Netskope.
Information Security. Netskope maintains a written comprehensive data security program and maintains appropriate technical and organizational security procedures and practices designed to protect Personal Information against anticipated threats or hazards to its security, confidentiality or integrity. Netskope’s security program is regularly audited by independent third parties, and we have achieved the following certifications to demonstrate our commitment:
Security Breach. Netskope will notify Customer without undue delay if Netskope learns that there has been unauthorized access, use, modification, disclosure, loss, or damage to Personal Information in the possession or control of Netskope (“Security Breach”). Netskope will provide reasonable assistance and cooperation in the remediation or investigation of a Security Breach and/or the mitigation of potential damage.
Transparency and Resources. Netskope is committed to providing full transparency regarding our security and privacy practices. For a complete and up-to-date overview of our compliance frameworks, policies, and certifications, please visit the Netskope self-service compliance center. This centralized resource provides access to:
For purposes of the above, the following definitions apply: “Aggregated” information means information that relates to multiple Consumers that fall into the same group or category, from which individual Consumer identities have been removed, that is not linked or reasonably linkable to any Consumer or household, including via a device. “Consumer” means a natural person. “Deidentified” means information that cannot reasonably identify, relate to, describe, be capable of being associated with, or be linked, directly or indirectly, to a particular Consumer. “Personal Information” means any information provided to Netskope in connection with the Services, in any form, format or media (including paper, electronic and other records) that identifies an individual or relates to an identifiable individual and is subject to the CCPA. “Proceso” or “Processing” means any operation or set of operations performed on Personal Information or sets of Personal Information, whether or not by automated means. Processing includes the collection, recording, organization, structuring, alteration, use, access, disclosure, copying, transfer, storage, retention, deletion, combination, restriction, adaptation, retrieval, consultation, destruction, disposal, sale, sharing or other use of Personal Information.
For more information about the CCPA and CPRA, see California Attorney General’s website on the CCPA located at https://oag.ca.gov/privacy/ccpa and the California Privacy Protection Agency website at https://cppa.ca.gov.
