PrefixIT

Privacy Policy

Last updated: March 31, 2026

This Privacy Policy describes how PrefixIT (“we”, “us”, or “our”) collects, uses, stores, and protects information when you use the PrefixIT cloud service and related endpoint software (the “Service”). The Service is designed for organizations (such as MSPs, IT teams and Compliance officers) to Monitor, Control, Manage and inventory their devices.

1. Who this applies to

This policy applies to users of the PrefixIT web application (administrators and authorized staff), Agent utilizers (workstations) and to data processed on behalf of the organization that subscribes to the Service (“Customer”). If you use the Service on behalf of a company, that company is typically the data controller for employee or device data; we act as a processor when we host and process that data strictly to provide the Service.

2. Information we process

Depending on how the Customer configures agents and the PrefixIT web application, the Service may process categories such as:

The exact scope depends on Customer configuration and applicable contracts. Customers are responsible for ensuring collection is lawful for their workforce and for providing any required notices to end users.

3. How we use information

We use the information above to provide, operate, and improve the Service; authenticate users; enforce access controls; troubleshoot issues; comply with law; and protect the security and integrity of our systems and users.

4. Non-personal data, machine learning, and insights

In addition to supporting the subscribed features you explicitly use, PrefixIT may process information that does not constitute personal information or that does not reasonably identify any individual or specific Customer, for example aggregated or de-identified operational statistics, anomaly patterns measured across tenants only in generalized form, diagnostic signals stripped of linkage to identifiable users or workloads, or similar derivative data, for purposes including security monitoring, spam and abuse prevention, capacity planning, product improvement, and training or validating machine-learning models. We may derive insights or automated alerts from such analyses without disclosing identifiable Customer-specific data or content to unrelated third parties, except where necessary to operate the Service you have subscribed to or as required by law.

5. Legal bases (where applicable)

Where the GDPR, CCPA or similar laws apply, we rely on appropriate bases such as contract performance, legitimate interests (for example, securing the platform), and, where required, consent.
When processing personal data, we comply with the principles of transparency, purpose limitation, data minimization, accuracy, and security.
Customers who act as controllers remain responsible for their own legal basis for processing personal data about their users and devices.

6. Sharing and subprocessors

We do not sell your personal information. We may share data with subprocessors that help us host, secure, or operate the Service (for example, infrastructure or email providers), subject to confidentiality and data-protection terms. We may disclose information if required by law or to protect rights, safety, or the Service.

7. Retention

We retain information for as long as needed to provide the Service, meet legal obligations, resolve disputes, and enforce agreements. Retention periods may depend on Customer settings, backups, and operational requirements.

8. Security

We implement appropriate technical and organizational measures designed to protect data. No method of transmission or storage is completely secure; we encourage Customers to use strong credentials, least-privilege access, and HTTPS for agent and browser traffic.

9. International transfers

If data is processed in countries other than where you or the Customer are located, we use appropriate safeguards where required by law (such as standard contractual clauses).

10. Your rights

Depending on your jurisdiction, you may have rights to access, correct, delete, restrict, or object to certain processing, and to lodge a complaint with a supervisory authority. PrefixIT web application users should contact their organization’s administrator for many requests; individuals may also contact us using the details your organization provides for support.

11. Children

The Service is not directed at children, and we do not knowingly collect personal information from children for consumer purposes.

12. Changes

We may update this policy from time to time. We will post the revised version with an updated date. Material changes may be communicated through the Service or by other reasonable means.

13. Contact

For privacy questions related to PrefixIT, contact your account administrator or the support channel associated with your organization’s subscription.