Legal

Privacy Policy

Last updated: June 1, 2026 · Applies to surfbrowser.ai and all SURF Security Services

"SURF enforces a strict Zero-Data Training policy. Your company's browser inputs, runtime sessions, and agentic workflows are never shared with or used to train third-party LLMs or external AI models."

— SURF Security Privacy Commitment

1. Information We Collect

SURF Security Ltd. ("SURF", "we", "us", or "our") collects the following categories of information when you use the SURF Enterprise AI Platform, SURF Browser, and SURF Browser Extension (collectively, the "Services"):

1.1 Telemetry Data

We collect anonymised telemetry data relating to platform performance, feature usage, error events, and session timing. Telemetry data does not contain the content of agent sessions, browsing activity, or user-generated data. Telemetry is used exclusively for platform reliability and product improvement purposes.

1.2 Device Posture Data

For enterprise deployments, SURF may collect device posture signals including operating system version, browser version, patch status, and device compliance state. This information is used to enforce access control policies defined by your enterprise administrator. Device posture data is processed within your tenant environment and is not accessible to SURF personnel without explicit authorisation.

1.3 Account and Identity Data

We collect account registration information (name, email address, company name) and identity verification data passed through your configured identity provider (Okta, Microsoft Entra ID, or SAML 2.0 provider). We do not store identity provider credentials.

1.4 Audit and Session Logs

Enterprise deployments generate audit logs capturing agent action metadata, policy decisions, and session events. The content and retention of these logs is controlled by your enterprise administrator in accordance with your organisation's data governance requirements.

2. How We Use Information

SURF uses the information we collect for the following purposes:

  • Providing, operating, and maintaining the Services
  • Enforcing enterprise access control policies configured by administrators
  • Detecting, investigating, and preventing security incidents and policy violations
  • Generating compliance reports and audit evidence for your organisation
  • Improving platform reliability and performance through anonymised telemetry analysis
  • Communicating with you about your account, service updates, and security notifications
  • Fulfilling contractual obligations under your enterprise agreement

We do not sell, rent, or trade your personal information or enterprise data to third parties for commercial purposes.

3. Cookies and Tracking

The SURF web application and marketing website use the following categories of cookies and tracking technologies:

Strictly Necessary

Session authentication, CSRF protection, and platform functionality. These cannot be disabled without impairing service functionality.

Analytics

Anonymised usage analytics to understand how visitors interact with our website. No personal identifiers are attached to analytics data. You may opt out via our cookie preference centre.

Functional

Remembering user preferences, language settings, and UI configuration. These are optional and do not affect platform security functionality.

The SURF Browser Extension and SURF Browser do not use third-party advertising or tracking technologies within enterprise sessions.

4. Data Security & Retention

4.1 Security Measures

SURF implements enterprise-grade technical and organisational measures to protect data against unauthorised access, disclosure, alteration, or destruction. Key controls include AES-256-GCM encryption at rest, TLS 1.3 encryption in transit, role-based access controls, multi-factor authentication for all platform access, and comprehensive audit logging.

4.2 Retention Periods

  • Account data: Retained for the duration of the enterprise agreement plus 30 days following termination.
  • Audit logs: Default 12-month retention, configurable up to 7 years for regulated industries.
  • Session recordings: Default 90-day retention, configurable by enterprise administrators.
  • Telemetry data: Retained in anonymised form for up to 24 months.
  • Security incident data: Retained for up to 3 years for legal and investigation purposes.

5. Your Rights

SURF is committed to respecting and facilitating data subject rights under the UK General Data Protection Regulation (UK GDPR), the UK Data Protection Act 2018, and the EU General Data Protection Regulation (EU GDPR). Individuals in the EEA, UK, and other applicable jurisdictions have the following rights:

Right of Access

Request a copy of the personal data we hold about you.

Right to Rectification

Request correction of inaccurate or incomplete personal data.

Right to Erasure

Request deletion of your personal data in applicable circumstances.

Right to Restriction

Request that we restrict processing of your personal data.

Right to Portability

Receive your personal data in a structured, machine-readable format.

Right to Object

Object to processing based on legitimate interests or for direct marketing.

To exercise any of these rights, contact our Data Protection team at privacy@surf.security. We will respond within 30 days.

This Privacy Policy is subject to change. We will notify enterprise customers of material changes via email and in-platform notification at least 30 days before changes take effect. Continued use of the Services after that period constitutes acceptance of the updated policy.