SURF Product Privacy Policy
Last updated July 30, 2026
This Product Privacy Policy explains what data the SURF Zero Trust Browser and the SURF browser extension (together, the "Product") collect, how that data is handled, where it is stored, how long it is kept, and who it is shared with.
This policy covers the Product only. Information about visitors to our website, and about our sales and marketing activities, is covered by our separate Website Privacy Policy. Where the two documents differ in relation to the Product, this Product Privacy Policy governs.
1. Who we are
The Product is provided by Surf Security Inc, a Delaware corporation ("SURF", "we", "us"). Our contact details are in section 14.
2. The Product is enterprise software, and our role is that of a processor
The Product is licensed only to organisations. It is deployed and configured by an organisation (the "Customer") for its own workforce or contractors, under a written agreement between SURF and that Customer. It is not offered to, or intended for, individual consumers, and it requires a Customer tenant in order to function.
Because of this, SURF acts as a data processor in respect of all end user data handled by the Product. The Customer is the data controller. The Customer decides which policies are enabled, and therefore which data is collected, how long it is retained, and who inside the Customer's organisation can view it. SURF processes that data only on the Customer's documented instructions, under the data processing terms of the applicable agreement.
If you are an end user and want to know what your organisation has enabled, or wish to exercise rights over your data, please contact your organisation's IT, security, or privacy team. See section 12.
3. What data the Product collects
3.1 Collected by default
In its default configuration, the only end user data the Product transmits from the device to SURF is:
- Web browsing activity: the URLs of pages visited, together with the timestamp of the visit. This supports the Product's core purpose, which is to give the deploying organisation visibility of and control over corporate web and SaaS activity, and to enforce that organisation's security policies. The URL history is presented back to the organisation's administrators in the SURF management console.
- Account and identity data needed to associate activity with a user and to authenticate them: user identifier, email address or user principal name, and group or tenant membership supplied by the organisation's identity provider during single sign-on.
- Device and technical data needed for the Product to function and to be supported: operating system, Product version, browser or extension build, device identifier, and diagnostic and crash logs.
3.2 Collected only when an administrator enables it
All other data collection is off unless the Customer's administrator turns on a specific policy. Depending on which policies the Customer chooses to enable, the Product may additionally process:
- Page content or page elements, where required to enforce a content or data loss prevention policy
- Data entered into web forms, including prompts submitted to generative AI services, where required to enforce a data loss prevention or AI usage policy
- Records of copy and paste actions, where required to enforce copy and paste restrictions. The Product blocks or replaces the copied content in order to enforce the policy; it does not read, transmit, or store the contents of your clipboard.
- File name and file extension type, where required to enforce file upload and download policies. The Product does not read, transmit, or store the contents of the files themselves.
- Screen capture or watermarking data, where required to enforce screenshot or screen sharing restrictions
- Records of policy events, such as a blocked site, a blocked upload, or a policy exception
Where a policy of this kind is enabled, the deploying organisation is responsible for informing its users, and for having a lawful basis to do so. SURF makes the applicable policy state visible in the Product interface and in the management console.
3.3 What the Product does not do
- We do not collect data for advertising, profiling, or marketing purposes.
- We do not sell end user data, and we do not share it with advertising networks, data brokers, or information resellers.
- We do not use end user data to train machine learning or artificial intelligence models.
- We do not use end user data to assess creditworthiness or for lending purposes.
- We do not read, transmit, or store the contents of your clipboard.
- We do not read, transmit, or store the contents of files you upload or download.
- We do not collect data from a device for any purpose unrelated to the security functions described above.
4. How the data is used
Data collected by the Product is used only to:
- Deliver the Product's security functions: applying the Customer's policies, blocking or allowing activity, and recording policy events
- Present activity, alerts, and reports to the Customer's administrators in the management console
- Detect and prevent malware, phishing, fraud, and abuse
- Maintain, secure, troubleshoot, and measure the reliability and performance of the Product
- Comply with legal obligations
SURF personnel do not access Customer data for SURF's own purposes. SURF personnel access Customer data only where the Customer requests support and that access is necessary to resolve the issue, where it is necessary to investigate a security incident or abuse, or where required by law. Such access is limited to authorised personnel, is role based, and is logged.
5. Legal bases (EEA and UK)
As processor, SURF does not determine the legal basis for the processing. Each Customer, as controller, is responsible for identifying its lawful basis for the collection and use it configures, and for meeting its own transparency obligations to its users.
6. Where the data is stored
Product data is stored in the SURF cloud, which is hosted on Amazon Web Services. The regions in use are US East (Northern Virginia), Europe (London), and Europe (Ireland). Customers on eligible plans may select a hosting region. Data is encrypted in transit using TLS 1.2 or above and encrypted at rest using AES-256.
Certain Product functions, including local policy enforcement, are performed on the device itself and do not transmit data to SURF.
7. How long the data is kept
Product data is retained for 90 days by default, after which it is deleted. Customers may configure a shorter or longer retention period within the limits of their agreement, in which case the Customer's configured period applies. Account and configuration records are retained for the duration of the Customer's agreement and are then deleted or anonymised. Backups are deleted on a rolling cycle. On termination, Customer data is deleted in accordance with the applicable agreement.
8. Who the data is shared with
We share Product data only in the following circumstances:
- With the deploying organisation. Data collected from a deployment is made available to that organisation's authorised administrators. Where the Customer directs it, data may also be forwarded to the Customer's own systems, such as a SIEM or logging platform. The Customer's own privacy notice governs what it then does with that data.
- With sub-processors that provide infrastructure or support functions on our behalf, under written contracts that restrict them to processing on our instructions and require appropriate security measures. Our primary infrastructure sub-processor is Amazon Web Services, which provides the cloud hosting described in section 6. A current and complete list of sub-processors is available to Customers on request.
- Where required by law, or to establish, exercise, or defend legal claims.
- To protect against malware, spam, phishing, or other fraud or abuse.
- In connection with a merger, acquisition, or sale of assets, in which case we will comply with the notice and consent requirements of applicable law and of the Chrome Web Store User Data Policy.
No other transfer, use, or sale of end user data takes place.
9. Chrome Web Store Limited Use disclosure
SURF's use of information received from the SURF browser extension, and from any Google APIs used by it, adheres to the Chrome Web Store User Data Policy, including the Limited Use requirements. Specifically:
- Data is collected, used, and transmitted only where necessary for the extension's disclosed single purpose of enforcing the deploying organisation's security policies in the browser, and for related operational purposes such as maintaining, securing, and measuring the reliability of those features.
- Web browsing activity is collected only to the extent required for the user facing visibility and policy enforcement features described on the extension's Chrome Web Store listing and in the extension's own interface.
- Data is not transferred to third parties except as set out in section 8 above.
- Humans do not read end user data except with explicit consent, where necessary for support at the Customer's request, where necessary for security purposes, or to comply with applicable law.
- Data is not transferred, used, or sold for personalised advertising, to advertising platforms, data brokers, or information resellers, or to determine creditworthiness or for lending purposes.
10. Security
We maintain technical and organisational security measures appropriate to the data we process, including encryption in transit and at rest, role based access control, least privilege access for personnel, audit logging, network segregation, vulnerability management, and personnel security training. SURF maintains a SOC 2 attestation; a copy of the current report is available to Customers and prospective Customers under NDA. No system can be guaranteed to be completely secure.
11. International transfers
Product data may be transferred to and processed in the United States and in other countries where we or our sub-processors operate. Where personal data is transferred out of the EEA, the United Kingdom, or Switzerland, we rely on the European Commission's Standard Contractual Clauses, the UK International Data Transfer Addendum, or another lawful transfer mechanism, together with supplementary measures where required. Copies of the relevant clauses are available on request.
12. Your rights
Depending on where you live, you may have rights to access, correct, delete, restrict, or object to the processing of your personal data, and to receive a copy of it.
Because the Product is deployed by your employer or another organisation, that organisation controls your data and is the right place to send your request. Please contact its IT, security, or privacy team. SURF will assist that organisation in responding, as our agreement with it requires. If you contact us directly at the address in section 14, we will refer your request to that organisation rather than acting on it ourselves.
You also have the right to complain to your local data protection authority.
13. Children
The Product is enterprise software intended for use by organisations and their workforce. It is not offered to, marketed to, or intended for anyone under 18 years of age, and we do not knowingly collect personal data from anyone under 18.
14. Contact us
Surf Security Inc
447 Broadway, 2nd Floor Suite #1365
New York, NY 10013
United States
Privacy enquiries: info@surf.security
EEA and Switzerland representative: Frederic Benichou, contactable at info@surf.security.
United Kingdom representative: Moty Jacob, contactable at info@surf.security or by post at 71-75 Shelton Street, London WC2H 9JQ, England.
15. Changes to this policy
We may update this policy from time to time. The date at the top of the page shows when it was last revised. Where changes are material, we will notify Customers in accordance with their agreement, and will post a notice on this page.