Legal

Privacy Policy

Last updated: March 11, 2026

M-Theory Group ("we," "us," "our") provides Managed Security Services ("Services") to our clients. This Privacy Policy explains how we collect, use, disclose, and protect personal information when you visit our website, interact with us, or use our Services.

1. Introduction

M-Theory Group ("we," "us," "our") provides Managed Security Services ("Services") to our clients. This Privacy Policy explains how we collect, use, disclose, and protect personal information when you visit our website, interact with us, or use our Services.

By using our website or Services, you acknowledge that you have read and understood this Privacy Policy. If you do not agree, please discontinue use of our website and Services.

2. Scope

This Privacy Policy applies to:

  • Visitors to our website
  • Prospective, current, and former clients and their personnel
  • Individuals whose data may be processed in connection with our security monitoring, incident response, and related Services (e.g., client employees, contractors, or end users)

This Policy does not override any specific data protection clauses in a Master Service Agreement (MSA), Data Processing Agreement (DPA), or Business Associate Agreement (BAA). Where there is a conflict, those contracts will control.

3. Definitions

  • Personal information: Any information that identifies or can reasonably be linked to an individual
  • Client data: Data (including logs, alerts, and telemetry) that our clients provide or make available to us via our Services. Client data may include personal information
  • Processing: Any operation performed on data, such as collection, storage, use, disclosure, or deletion

4. Information We Collect

4.1 Information you provide directly

  • Contact details: name, email address, phone number, job title, company name
  • Account details: login credentials, authentication identifiers
  • Support information: messages, tickets, and related artifacts you provide when you request support
  • Contract and billing details: billing contact information, invoicing details, and payment-related identifiers (handled via our payment providers)

4.2 Information we collect automatically

When you visit our website or use our portals:

  • Technical data: IP address, browser type and version, operating system, device identifiers
  • Usage data: pages viewed, features used, session duration, timestamps, referring URLs
  • Security telemetry: access logs, authentication events, error logs, and similar data for security monitoring and fraud prevention

4.3 Information processed on behalf of clients

In providing MSSP services, we may process:

  • Network, endpoint, and cloud logs containing user identifiers, email addresses, hostnames, or related metadata
  • Security events and alerts related to user accounts, devices, or applications
  • Incidental content in security artifacts (e.g., email headers, suspicious attachments, URLs)

We process this data under our agreement with the client and only for the purposes described in that agreement.

5. How We Use Personal Information

We use personal information for the following purposes:

  • To provide and maintain our Services, including security monitoring, incident detection, triage, and response
  • To authenticate users and manage access to our platforms and portals
  • To provide customer support and respond to inquiries
  • To operate, maintain, and improve our website, products, and Services
  • To analyze usage trends, capacity, and performance to enhance security and reliability
  • To send administrative communications, such as service announcements, billing notifications, and policy updates
  • To comply with legal obligations, enforce our agreements, and protect our rights, our clients, and other users
  • To conduct security, compliance, and audit activities in line with recognized frameworks such as SOC 2

We do not sell personal information.

6. Legal Bases for Processing (where applicable)

Where required by law (e.g., in the EEA/UK), we process personal information on one or more of the following legal bases:

  • Performance of a contract (e.g., providing our Services under an MSA)
  • Legitimate interests (e.g., securing our systems, improving our Services, preventing fraud)
  • Compliance with legal obligations
  • Consent, where we rely on it (e.g., certain marketing activities or optional cookies)

7. Data Sharing and Disclosure

We may disclose personal information in the following circumstances:

  • Service providers: To trusted vendors who perform services on our behalf (e.g., cloud hosting, email delivery, analytics, customer support tools), under written agreements with confidentiality and security obligations
  • Clients: When we act as a service provider/processor, we may provide logs, reports, and security findings back to the client
  • Legal and regulatory: When required to comply with applicable law, regulation, legal process, or governmental request, or to protect the safety, rights, or property of us, our clients, or others
  • Business transfers: In connection with a merger, acquisition, reorganization, or sale of all or part of our business, subject to appropriate protections

We do not allow third parties to use personal information we share with them for their own marketing or unrelated purposes.

8. International Transfers

We may process and store personal information in countries other than the one in which it was collected. When we transfer personal information internationally, we use appropriate safeguards, such as contractual data protection clauses and security controls consistent with recognized standards.

9. Data Retention

We retain personal information for as long as necessary to:

  • Provide the Services and fulfill the purposes described in this Policy
  • Comply with legal, regulatory, and contractual obligations
  • Resolve disputes and enforce our agreements

Retention periods for security logs and client data are typically defined in our client contracts. When data is no longer required, we securely delete or anonymize it in accordance with our data retention and disposal procedures.

10. Security Measures

We implement administrative, technical, and physical controls designed to protect personal information, including:

  • Access control, least-privilege, and role-based access mechanisms
  • Encryption in transit and at rest (where appropriate)
  • Network and endpoint security controls
  • Security monitoring, logging, and alerting
  • Vulnerability management and patching
  • Employee security awareness and confidentiality obligations

No security controls can guarantee absolute protection, but we continuously work to maintain a robust security posture.

11. Your Rights and Choices

Depending on your jurisdiction, you may have rights such as:

  • Access: Request confirmation of whether we process your personal information and obtain a copy
  • Correction: Request that we correct inaccurate or incomplete information
  • Deletion: Request deletion of certain personal information, subject to our legal and contractual obligations
  • Restriction or objection: Object to or request limitation of certain processing activities
  • Portability: Request a copy of certain information in a structured, commonly used format

You may exercise these rights (where applicable) by contacting us at compliance@m-theorygrp.com. We may need to verify your identity before fulfilling your request and may be unable to fully comply where a request conflicts with security, legal, or contractual requirements.

You may also opt out of marketing communications at any time by following the unsubscribe instructions in our emails or contacting us directly.

12. Children’s Privacy

Our website and Services are intended for business use and are not directed to children under 16. We do not knowingly collect personal information from children under 16. If you believe we have collected such information, contact us so we can take appropriate action.

13. Changes to This Policy

We may update this Privacy Policy from time to time. When we do, we will revise the "Last Updated" date below and post the updated policy on this page. Material changes may be communicated through additional notices.

14. Contact Us

If you have questions or concerns about this Privacy Policy or our privacy practices, please contact us at compliance@m-theorygrp.com.