"SURF enforces a strict Zero-Data Training policy. Your company's browser inputs, runtime sessions, and agentic workflows are never shared with or used to train third-party LLMs or external AI models."
— SURF Security Privacy Commitment
1. Information We Collect
SURF Security Ltd. ("SURF", "we", "us", or "our") collects the following categories of information when you use the SURF Enterprise AI Platform, SURF Browser, and SURF Browser Extension (collectively, the "Services"):
1.1 Telemetry Data
We collect anonymised telemetry data relating to platform performance, feature usage, error events, and session timing. Telemetry data does not contain the content of agent sessions, browsing activity, or user-generated data. Telemetry is used exclusively for platform reliability and product improvement purposes.
1.2 Device Posture Data
For enterprise deployments, SURF may collect device posture signals including operating system version, browser version, patch status, and device compliance state. This information is used to enforce access control policies defined by your enterprise administrator. Device posture data is processed within your tenant environment and is not accessible to SURF personnel without explicit authorisation.
1.3 Account and Identity Data
We collect account registration information (name, email address, company name) and identity verification data passed through your configured identity provider (Okta, Microsoft Entra ID, or SAML 2.0 provider). We do not store identity provider credentials.
1.4 Audit and Session Logs
Enterprise deployments generate audit logs capturing agent action metadata, policy decisions, and session events. The content and retention of these logs is controlled by your enterprise administrator in accordance with your organisation's data governance requirements.
2. How We Use Information
SURF uses the information we collect for the following purposes:
- Providing, operating, and maintaining the Services
- Enforcing enterprise access control policies configured by administrators
- Detecting, investigating, and preventing security incidents and policy violations
- Generating compliance reports and audit evidence for your organisation
- Improving platform reliability and performance through anonymised telemetry analysis
- Communicating with you about your account, service updates, and security notifications
- Fulfilling contractual obligations under your enterprise agreement
We do not sell, rent, or trade your personal information or enterprise data to third parties for commercial purposes.
4. Data Security & Retention
4.1 Security Measures
SURF implements enterprise-grade technical and organisational measures to protect data against unauthorised access, disclosure, alteration, or destruction. Key controls include AES-256-GCM encryption at rest, TLS 1.3 encryption in transit, role-based access controls, multi-factor authentication for all platform access, and comprehensive audit logging.
4.2 Retention Periods
- Account data: Retained for the duration of the enterprise agreement plus 30 days following termination.
- Audit logs: Default 12-month retention, configurable up to 7 years for regulated industries.
- Session recordings: Default 90-day retention, configurable by enterprise administrators.
- Telemetry data: Retained in anonymised form for up to 24 months.
- Security incident data: Retained for up to 3 years for legal and investigation purposes.
5. Your Rights
SURF is committed to respecting and facilitating data subject rights under the UK General Data Protection Regulation (UK GDPR), the UK Data Protection Act 2018, and the EU General Data Protection Regulation (EU GDPR). Individuals in the EEA, UK, and other applicable jurisdictions have the following rights:
Right of Access
Request a copy of the personal data we hold about you.
Right to Rectification
Request correction of inaccurate or incomplete personal data.
Right to Erasure
Request deletion of your personal data in applicable circumstances.
Right to Restriction
Request that we restrict processing of your personal data.
Right to Portability
Receive your personal data in a structured, machine-readable format.
Right to Object
Object to processing based on legitimate interests or for direct marketing.
To exercise any of these rights, contact our Data Protection team at privacy@surf.security. We will respond within 30 days.
This Privacy Policy is subject to change. We will notify enterprise customers of material changes via email and in-platform notification at least 30 days before changes take effect. Continued use of the Services after that period constitutes acceptance of the updated policy.