How CylanceAVERT collects and uses data
CylanceAVERT
collects and uses dataFor complete information about this product, see the Cylance Endpoint Security docs.
Item | Data collection and use |
---|---|
Collection of admin user data | BlackBerry collects and processes the following information about administrators to authenticate authorized administrators and deliver application alerts:
|
Collection of user account data | BlackBerry collects and processes the following information about user accounts to provide application functionality and support service delivery:
|
Collection of endpoint data | BlackBerry collects and processes the following information about the configuration of a device endpoint to provide application functionality and support service delivery:
|
Collection of sensitive file inventory data | BlackBerry collects and processes the following information from the file inventory to identify sensitive documents and provide the risk assessment:
|
Collection of web browser exfiltration events | BlackBerry collects and processes the following information about web browser exfiltration events to mitigate potential data loss:
|
Collection of email message exfiltration events | BlackBerry collects and processes the following information about email message exfiltration events to mitigate potential data loss:
|
Collection of local file transfer exfiltration events | BlackBerry collects and processes the following information about local file transfer exfiltration events to mitigate potential data loss:
|
Collection of file snippets | BlackBerry collects samples of the specific text that triggers the information protection policy. Depending on the configuration of the customer’s information protection policies, the file snippet may contain sensitive information, including personal data.This feature is disabled by default. |
Collection of evidence files | BlackBerry collects the entire document which contains the text that triggered the customer’s information protection policy. Depending on the configuration of the customer’s information protection policies, the evidence file may contain sensitive information, including personal data.This feature is disabled by default. |
Collection of administrator login data | BlackBerry collects the login activity from the administrators or operators of customer tenant, including the following information:
|
Data sharing or forward processing | BlackBerry uses the identified information to facilitate the performance of the End User License Agreement under which BlackBerry services and products are offered. This data is only shared with necessary third-party services needed to fulfill the intended purpose of these services.BlackBerry will not sell, lease, or otherwise distribute this information beyond what is disclosed below. |
Cross-border data transfers | CylanceAVERT customers select the geographic location for their tenant, which is where the personal data that is used to manage the customer’s service and the collected endpoint data is stored. Data is not transferred from the chosen customer’s tenant location to any other geography without customer instruction. The data that is collected is stored in one of the following subprocessors:
|
Data retention
Personal data processed | Data retention period |
---|---|
Administrator and user account information | Data is stored for the duration of the contract. A customer administrator can remove an individual user’s personal data or initiate a service removal request in the administrative console. Data that is backed up is retained for 90 days after the conclusion of a service agreement. |
Endpoint data | Data is stored for as long as a registered device is active. |
Sensitive file inventory | Data about files is stored until the file is no longer detected within a customer’s environment, or for the duration of the contract. Data that is backed up is retained for 90 days after the conclusion of a service agreement. |
Detected exfiltration events: web browser, email, file operations | Data is stored for 30 days. |
File snippets | Data is stored for 30 days. |
Evidence files | A customer administrator can remove collected evidence files in the administrative console. Customers can configure a policy to store files for either 30, 60, or 90 days. By default, evidence files are stored for 30 days. |
Diagnostic information | Data is stored for 5 years. |
Customer administrative login activity | Data is stored for 1 year. |