Skip to main content

KASPERSKY – PRODUCTS AND SERVICES PRIVACY POLICY

Introduction

AO Kaspersky Lab, located at bldg. 3, 39A, Leningradskoe Shosse, Moscow, 125212, Russian Federation and all companies belonging to the group "Kaspersky" respect your privacy. Our representative in the EU for data protection is: Kaspersky Labs GmbH, Schloßlände 26, 85049, Ingolstadt, Germany, +49 (0) 841 98 18 90, according to Article 27 (1) of Regulation (EU) 2016/679 (General Data Protection Regulation, "GDPR"). Our Data Protection Officer in the EU, according to Article 37 (1) of GDPR, as well as for the other countries, may be contacted via dpo@kaspersky.com.

This Products and Services Privacy Policy (Privacy Policy) describes how we use the information you provide when you use our products and services, and the choices you can make about our use of the information. We also describe the measures we take to protect the information and how you can contact us about our privacy practices.

In connection with specific products or services offered by Kaspersky you are provided with the agreements, terms of use, and statements that supplement this policy relating to data handling.

This policy may be changed because of changes in legislation, the requirements of the authorities or to reflect changes in our practices concerning the processing of personal data. The revised policy will be posted on our website and will be effective immediately upon being posted. You can read at any time the policy currently in effect on our website: https://sciencebreakthrough.info/products-and-services-privacy-policy%3C/a%3E.%3C/p%3E%3Cp%3EThis version of the policy is effective as of February 28, 2022.

The Sources of Information

Kaspersky may obtain information about you from various sources, namely:

If you provide us with any information or material relating to another individual, you should make sure that this sharing with us and our further use as described to you from time to time are in line with applicable laws; thus, for example, you should duly inform that individual about the processing of her/his personal data and obtain her/his consent, as may be necessary under applicable laws.

You may also choose to consent to third parties disclosing information about you to us that those third parties have received.

Information Provided by Users and How We Use Information

Personal data processing by Kaspersky is always carried out in a legal and fair manner.

You will always know what kind of information you provide to Kaspersky before you start to use the products and services. The data which you provide depends on the services, products, and features you use. For more information about data you provide, please refer to End User License Agreement, Kaspersky Security Network Statement and other documentation of product and services that you use, especially:

FOR HOME USERS (B2C):

FOR BUSINESS USERS (B2B):

The data obtained for processing depends on the product or service, and it is recommended that users carefully read the agreements and related statements accepted during installation or usage of software or service.

Some data are non-personal, according to laws of certain countries. Regardless of the type of data and territory where data was received or processed, we use the highest standards of data protection and apply various legal, organizational, and technical measures in order to protect user data, guarantee safety and confidentiality, as well as ensure users' rights guaranteed under applicable law.

The data depends on the products and services you use, and could include the following:

It is processed in order to recognize legitimate users. This data is needed to maintain communication between the product and Kaspersky services – sending and receiving product databases, updates, etc.

Data on the product's operation and its interaction with the user is also analyzed. For example, how long does threat scanning take? Which features are used more often than others? Answers to these and other questions help developers to improve products, making them faster and easier to use.

Data such as device type, operating system, etc. may be needed so the user doesn't have to buy a new license for the security product after reinstalling the operating system. This information also helps us to analyze cyberthreats, because it shows how many devices are affected by any specific threat.

If a threat (new or known) is found on a device, information about that threat is sent to Kaspersky. This enables us to analyze threats, their sources, principles of infection, etc., resulting in a higher quality of protection for every user.

This information helps to create lists of harmless applications and prevents security products from mistakenly identifying such applications as malicious. This data is also used to update and extend program categories for features like Parental Control and Application Startup Control. In addition, this information helps us to offer users security solutions that best match their needs.

URLs can be sent to be checked whether they are malicious. This information also helps to create lists of harmless websites and prevents security products from mistakenly identifying such websites as malicious. This data is also used to update and extend website categories for solutions like Kaspersky Safe Kids and provide better protection for financial transactions in such products as Kaspersky Fraud Prevention. In addition, this information helps us to offer users security solutions that best match their needs. Information about logins and passwords, if contained in the initial browser request from the user, is removed from the visited URL addresses up to the hostname or IP address. In any case, it is not Kaspersky's purpose to process user logins and passwords, and Kaspersky takes all reasonable and sufficient measures to avoid processing these data.

New malware can often be identified only by its suspicious behavior. Because of this, the product analyzes data on processes running on the device. This makes it possible to identify early on processes that indicate malicious activity and to prevent any damaging consequences, such as the destruction of user data.

If an (as yet) unknown file, exhibiting suspicious behavior is detected on a device, it can be automatically sent for a more thorough analysis by machine learning-based technologies and, in rare cases, by a malware analyst. The 'suspicious' category includes mainly executable files (.exe). For the purpose of reducing the likelihood of false positives, executable and non-executable harmless files or their parts may be sent.

This information is analyzed in order to warn users of insecure (i.e., poorly protected) Wi-Fi access points, helping to prevent personal data from being inadvertently intercepted.

Email addresses are used for authorization on the Kaspersky web portals (My Kaspersky, Kaspersky CompanyAccount, Kaspersky Endpoint Security Cloud, etc.), which enables users to manage their protection remotely. Email addresses are used to send security messages to (e.g., containing important alerts) to users of Kaspersky products. Users can also choose to specify the names (or nicknames) by which they would like to be addressed on the My Kaspersky portal and in emails. Contact information is provided by users at their own discretion.

By checking the special box in the product settings, users can also share error reports with Kaspersky servers. This information helps (1) during analysis of errors that occurred in the product and to modify it accordingly so that it will function more effectively moving forward, and (2) in the investigation of infection of a user's computer in order to mitigate threats to a user's system.

During your use of the anti-spam functionality, Kaspersky scans emails and uses information about them to protect you from spam and fraud. When you indicate to Kaspersky that an email is spam or has been incorrectly identified by the software as spam, you help us analyze it and enable a higher quality of protection for users.

The Anti-theft feature provides certain remote access and control functions designed to protect data on your mobile phone in case of theft, as well allows you to receive information about the location of the stolen device. Anti-theft has to store data about your phone and approved users for these functions to work.

If a parent or holder of parental responsibility wants to use the child protection feature like Kaspersky Safe Kids, he or she can receive information about the child's device and information about the child's location. Additionally, the parent or holder of parental responsibility can configure parameters in order to block or permit specific websites and/or allow or prevent certain applications from running on the child's device. Kaspersky does not collect children's data beyond the framework of such feature.

This device identifier is generated on user device on Android 8 and higher, using the Advertising ID of the device. We do not process the Advertising ID in clear text; we process only its hash sum. In case user has reset the value of the Advertising ID, the new value of the unique identifier of the mobile device will be associated with the old value, which is necessary for the correct use of the device with services.

KASPERSKY WILL ONLY PROCESS PERSONAL DATA FOR PARTICULAR, PRE-DETERMINED PURPOSES THAT ARE LEGITIMATE WITH REGARD TO APPLICABLE LAW, AND THAT ARE RELEVANT TO KASPERSKY'S BUSINESS.

Threat Intelligence for Protection of Cyber Space

New generations of malware appear all the time, many using new, sophisticated techniques to bypass existing security solutions. In this constantly shifting environment, protection is only as effective as the ability to closely analyze the threat landscape and distill data into actionable intelligence for our users. To achieve this, security solutions must apply a cloud approach that combines the widest possible scope of threat data handling with the most intelligent data processing technologies.

Our infrastructure is designed to receive and process complex global cyberthreat data, transforming it into the actionable threat intelligence that powers our products. A key source of threat-related data comes from our users. By sharing their data and allowing it to be stored and analyzed by artificial intelligence and experts, they help us to ensure that users around the world are protected against the newest cyberthreats. In particular, KSN helps us to respond rapidly to emerging cyberthreats while delivering the highest possible effectiveness of protection and helping reduce the number of false positives.

The amount of data you allow our infrastructure to receive depends on the product used, its configuration settings and preferences.

This approach offers numerous benefits for users and cyber space overall, including:

Product Statistical Research

To better understand how we can improve the experience of current users, develop our products and services, determine potential markets, and pursue business opportunities, we perform research and conduct statistical analyses to acquire an aggregated overview of products for home users. Of course, we do so always for a legitimate reason and with a legal basis. In addition, we make sure to implement technical and organizational measures to ensure a high level of data protection. For example, when we conduct statistical analysis on data, they first undergo a de-identification process for that purpose. This is consistent with our privacy principles (see below for more details in the section "Privacy Principles").

Legal Bases for Data Processing

The legal basis we use depends on the purpose of processing personal data, which may be the following:

LIMITATION OR RESTRICTION DATA PROCESSING

IF YOU CHOOSE NOT TO PROVIDE DATA THAT IS NECESSARY IN ORDER FOR A PRODUCT OR FEATURE TO WORK, YOU MAY NOT BE ABLE TO USE THAT PRODUCT OR FEATURE. THIS OBLIGATORY DATA IS LISTED IN THE END USER LICENSE AGREEMENT. THE KASPERSKY SECURITY NETWORK STATEMENT OR MARKETING STATEMENT CONTAINS A LIST OF DATA THAT USERS CAN DECIDE TO PROVIDE TO US AT ANY TIME BY CHECKING THE CORRESPONDING BOX IN THE PRODUCT SETTINGS (THEY CAN ALSO REVERSE THIS DECISION WHENEVER THEY CHOOSE).

What we aren't going to process

Through its products and services, Kaspersky never process "sensitive" personal data such as religion, political views, sexual preference, or health, or other special categories of personal data. We do not wish to receive any such data and will not request it from you.

Kaspersky's products must be installed and used by an adult. Children may use the device where Kaspersky's product was installed only with permission from their parents or holder of parental responsibility. Except for "Data for child protection feature", we do not intend to process personal data of children, nor do we want to receive such personal information of children.

Provision of Information

We may only disclose the Information as follows: