1. Introduction

Terrabyte Group (“Terrabyte”, “we”, “us”, or “our”) is an enterprise cybersecurity value-added distributor (VAD). We support organizations in evaluating, procuring, and deploying cybersecurity technologies through our vendor and partner ecosystem.

This Privacy Policy explains how personal information is collected, used, disclosed, transferred, retained, and protected when you visit our websites, engage with events and webinars, download materials, or submit forms.

2. Scope

This Privacy Policy applies to personal information processed through:

This Privacy Policy does not apply to third-party websites not controlled by Terrabyte.

3. Definitions

4. Personal Information Collected

Based on website form structures currently deployed, Terrabyte may collect:

4.1 Identification and Contact Data

4.2 Professional and Organization Data

4.3 Inquiry and Engagement Data

4.4 Technical Submission Metadata

5. Information Collected Automatically

When users access the website, certain data may be collected automatically through scripts and tags, including:

6. Cookies

The website appears to use cookies and/or similar technologies in connection with analytics and traffic measurement tooling.

A consent status variable is referenced in page scripts. However, exact cookie categories, names, lifespans, and consent-banner implementation details cannot be fully verified from static source review alone.

7. Analytics

The website currently appears to deploy or reference:

Exact event taxonomy, retention windows, and IP anonymization settings require implementation confirmation.

8. Marketing Communications

Terrabyte may send business and marketing communications where permitted by law, including:

Recipients may opt out of non-essential marketing communications.

9. Legal Basis

Depending on applicable law and context, Terrabyte may process personal information based on:

For GDPR-governed processing, legal bases are applied per processing activity.

10. Purposes of Processing

Terrabyte processes personal information to:

11. Disclosure to Third Parties

Terrabyte may disclose personal information to:

Observed website integrations indicate third-party services such as Google tag services and HubSpot script references. A complete subprocessor inventory is not publicly confirmed from website artifacts.

12. International Data Transfers

Given regional operations and third-party tooling, personal information may be processed outside the originating jurisdiction.

Where required, Terrabyte will implement appropriate transfer safeguards.

13. Data Retention

Terrabyte retains personal information for as long as reasonably necessary to fulfill the purposes in this policy and to satisfy legal, tax, audit, dispute, and evidentiary requirements.

Specific retention schedules by data category are:

14. Information Security

Terrabyte implements reasonable technical, organizational, and administrative safeguards designed to protect personal information from unauthorized access, use, alteration, and disclosure.

No system is fully immune to risk; users should only submit information through official channels.

15. User Rights

Subject to applicable law, individuals may have rights to:

16. Singapore PDPA Rights

For personal data governed by the Singapore Personal Data Protection Act (PDPA), individuals may request:

Terrabyte may require identity verification and may apply statutory exceptions.

17. Indonesia PDP Rights

For personal data governed by Indonesia Law No. 27 of 2022 (PDP Law), rights may include:

Implementation details and designated channels are:

18. GDPR Rights (Where Applicable)

For EEA/UK data subjects where GDPR-equivalent rights apply, rights may include:

EU/UK representative details (if required):

19. Withdrawal of Consent

Where processing is consent-based, consent may be withdrawn at any time. Withdrawal does not affect prior lawful processing.

20. Access and Correction

Requests should be submitted using official contact channels below. Terrabyte may request identity verification and sufficient detail to process requests.

21. Complaint Process

Individuals may raise concerns with Terrabyte first. If unresolved, they may lodge complaints with relevant data protection regulators.

Regulatory references and contact details:

22. Children’s Privacy

Terrabyte’s website and services are intended for professional B2B audiences and are not directed to children. Terrabyte does not knowingly collect children’s personal information through its B2B channels.

23. Third-party Websites

The website may link to third-party websites and platforms. Terrabyte is not responsible for third-party privacy practices.

24. Updates

Terrabyte may revise this Privacy Policy from time to time. Updated versions will be posted on the website with revised dates.