Maze AI Limited (trading as Maze)
Effective Date: 27 August 2026
Last Updated: 27 August 2026
Version: 2
INTRODUCTION
1. ABOUT THIS POLICY
1.1. This Website Privacy Policy (“Policy”) explains how Maze AI Limited, trading as Maze (“Maze”, “we”, “us”, “our”), collects, uses, shares and protects personal data when you visit our website at mazehq.com (the “Website”), engage with our marketing communications, or otherwise interact with us in connection with our products and services.
1.2. This Policy applies to personal data for which Maze acts as a data controller. Where we process personal data on behalf of our customers as a data processor (for example, personal data handled within our vulnerability management platform), that processing is governed by our Product Privacy Policy and the data processing terms agreed with the relevant customer, not by this Policy.
1.3. Please read this Policy carefully so that you understand your rights and our obligations in relation to your personal data.
2. PRIVACY NOTICE FOR PROSPECTIVE CUSTOMERS
2.1. You are reading this because we have contacted you, or are about to, without having met you first. We obtained your details from a source other than you. UK GDPR Article 14 requires us to tell you how we got your data and what we do with it. This section does that.
2.2. Who we are and how to reach us.
The controller of your data is Maze AI Limited, trading as Maze. We are registered in England and Wales under company number 15203461. Our registered office is at 5 New Street Square, London, EC4A 3TW, United Kingdom. For any privacy matter, email privacy@mazehq.com. You can also reach our privacy contact, Phil O’Hagan, at that address.
2.3. Why we hold your data.
We identify and contact the people responsible for buying and operating vulnerability management software. Our purpose is to introduce Maze to you and to sell our product to your organisation.
2.4. Our lawful basis.
We rely on legitimate interests under Article 6(1)(f) of the UK GDPR. Our legitimate interest is promoting and selling our vulnerability management software to organisations that are likely to need it. We have carried out a legitimate interests assessment that weighs our interest against your rights. We will send you a copy on request. Email privacy@mazehq.com.
2.5. What data we hold.
We hold the following categories of data about you: your name; your job title; your employer; your work email address; your work phone number; your LinkedIn profile URL; your employer’s sector and size; your employer’s technology stack; and engagement data, meaning the outcome of our outreach to you, such as whether you opened or replied to an email, and your attendance at our events.
2.6. Where we got your data.
We obtained your data from one or more of these sources: business contact data vendors, specifically Apollo, Clay and Lemlist; event organisers who supply us with attendee lists when we exhibit or have a stand; your public LinkedIn profile; and our own website and event forms.
2.7. Who we share it with.
We share your data with the providers that run our sales systems. These are HubSpot, our customer relationship management system, and Lemlist, our email outreach tool. They act on our instructions and use your data only to provide those services to us. We do not sell your data.
2.8. How long we keep it.
We keep your data for 24 months from the date we obtained it, or from your last engagement with us, whichever is later. After that we delete it.
2.9. Your right to object
You can tell us to stop at any time. You do not need to give a reason. If you object, we will stop using your data to contact you and we will not approach you again for this purpose. To object, email privacy@mazehq.com or use the unsubscribe link in any email we send you. This right to object is separate from, and additional to, unsubscribing and to the other rights set out below.
2.10. Your other rights.
You also have the right to ask for a copy of the data we hold about you (access); to ask us to correct data that is wrong (rectification); to ask us to delete your data (erasure); to ask us to restrict how we use your data (restriction); and to ask us to transfer your data to you or another organisation (portability). To exercise any of these rights, email privacy@mazehq.com.
You also have the right to complain to the Information Commissioner’s Office. Its details are: Information Commissioner’s Office, Wycliffe House, Water Lane, Wilmslow, Cheshire, SK9 5AF. Website: ico.org.uk. Helpline: 0303 123 1113.
2.11. International transfers.
Our US affiliate, Maze AI Inc, and its personnel access the same systems we use. Your data is therefore transferred to and accessed from the United States. We make that transfer under an intra-group data sharing agreement between Maze AI Limited and Maze AI Inc. That agreement incorporates the European Commission’s Standard Contractual Clauses together with the UK International Data Transfer Addendum issued by the Information Commissioner. These are the safeguards approved under UK data protection law for this kind of transfer. You can ask us for a copy of the safeguards we rely on. Email privacy@mazehq.com.
3. WHO WE ARE
3.1. Maze is a cybersecurity software company headquartered in the United Kingdom. We provide vulnerability management solutions to IT and security teams in medium and large enterprises.
3.2. For the purposes of the UK GDPR, the EU GDPR and other applicable data protection laws, the data controller in respect of personal data processed under this Policy is:
Maze AI Limited (trading as Maze), a company registered in England and Wales with company number 15203461, whose registered office is at 5 New Street Square, London, EC4A 3TW, United Kingdom.
4. PRIVACY CONTACT
4.1. We have appointed a person responsible for overseeing questions in relation to this Policy. If you have any questions about this Policy, or wish to exercise any of your legal rights, please contact:
Privacy Contact: Phil O’Hagan, VP Operations
Email: dataprotection@mazehq.com
Postal address: 5 New Street Square, London, EC4A 3TW, United Kingdom.
5. APPLICABLE LAW
5.1. This Policy is designed to comply with:
(a) the UK General Data Protection Regulation (“UK GDPR”) and the Data Protection Act 2018, as amended by the Data (Use and Access) Act 2025;
(b) the EU General Data Protection Regulation (Regulation (EU) 2016/679) (“EU GDPR”), where applicable to individuals in the European Economic Area; and
(c) the California Consumer Privacy Act, as amended by the California Privacy Rights Act (together, the “CCPA”), to the extent applicable, as set out in clause 12.
PERSONAL DATA WE COLLECT
6. INFORMATION YOU PROVIDE TO US
6.1. We collect personal data that you voluntarily provide to us when you:
(a) complete forms on the Website, including contact and demonstration-request forms;
(b) subscribe to our newsletters or other marketing communications;
(c) register for an event or webinar;
(d) request customer support or otherwise correspond with us; or
(e) interact with us on social media or other platforms.
6.2. This may include your name, email address, telephone number, employer and company information, job title, and any information contained in your communications with us.
7. INFORMATION WE COLLECT AUTOMATICALLY
7.1. When you use the Website, we may automatically collect certain information, including:
(a) your IP address;
(b) device information, browser type and version, and operating system;
(c) time zone setting and location;
(d) browser plug-in types and versions; and
(e) information about your visit, including the referral source, length of visit, page views and navigation paths.
7.2. We collect this information using cookies and similar technologies, as described in clause 5.
8. INFORMATION WE RECEIVE FROM OTHER SOURCES
8.1. We may receive personal data about you from third parties, including business partners, analytics providers, advertising platforms and providers of publicly available business information.
HOW WE USE YOUR PERSONAL DATA
9. PURPOSES OF PROCESSING
9.1. We use your personal data for the following purposes:
(a) to operate, maintain, analyse and improve the Website;
(b) to respond to enquiries and requests submitted through the Website or otherwise;
(c) to provide information about our products and services, including newsletters, updates, and invitations to events and webinars;
(d) to manage our relationship with you and with prospective customers;
(e) to measure and understand the effectiveness of our marketing;
(f) to ensure the security and integrity of the Website; and
(g) to comply with our legal obligations.
10. LEGAL BASES FOR PROCESSING
10.1. When processing your personal data as a data controller, we rely on one or more of the following legal bases:
(a) Consent: where you have given consent, for example to receive marketing communications or to the use of non-essential cookies. You may withdraw your consent at any time;
(b) Legitimate interests: where we need to process your data for our legitimate interests, and those interests do not override your interests or fundamental rights and freedoms. Our legitimate interests include providing and improving the Website, understanding how it is used, marketing to business contacts, and ensuring security;
(c) Contractual necessity: where we need to process your data to take steps you ask for before entering into a contract, or to perform a contract with you or your employer; and
(d) Legal obligation: where we need to process your data to comply with our legal obligations.
10.2. Where we rely on legitimate interests, you have the right to object to that processing, as described in clause 10.
COOKIES AND SIMILAR TECHNOLOGIES
11. WHAT COOKIES ARE
11.1. Cookies are small text files placed on your device when you visit a website. They allow the website to recognise your device and store information about your preferences or past actions. We also use similar technologies such as pixels and tags.
12. HOW WE USE COOKIES
12.1. We use cookies and similar technologies to:
(a) ensure the proper functioning of the Website;
(b) remember your preferences;
(c) analyse how visitors interact with the Website;
(d) deliver and measure marketing and advertising; and
(e) measure the effectiveness of our marketing campaigns.
13. TYPES OF COOKIES WE USE
13.1. We use the following categories of cookies:
(a) strictly necessary cookies, required for the operation of the Website;
(b) analytical or performance cookies, which allow us to recognise and count visitors and see how they move around the Website;
(c) functionality cookies, which recognise you when you return to the Website; and
(d) targeting and advertising cookies, which record your visit, the pages you have visited and the links you have followed.
14. CONSENT AND MANAGING COOKIES
14.1. We use CookieYes as our consent management platform. When you first visit the Website, you will be presented with a cookie banner allowing you to accept or reject non-essential cookies. Strictly necessary cookies do not require consent.
14.2. You may change or withdraw your cookie preferences at any time via the CookieYes preference centre on the Website. You can also control cookies through your browser settings. Removing or blocking cookies may impact your experience and parts of the Website may become inaccessible.
MARKETING AND YOUR CHOICES
15. MARKETING COMMUNICATIONS
15.1. We may send you marketing communications about our products and services where you have consented, or where we are otherwise permitted to do so by law.
15.2. You may opt out of marketing communications at any time by using the unsubscribe link in any marketing email, or by contacting us at dataprotection@mazehq.com. Opting out of marketing will not affect any non-marketing communications relating to our products or services.
16. MARKETING AND ADVERTISING TOOLS
16.1. We use third-party marketing, analytics and advertising tools to operate our Website and marketing activities, which may collect or receive personal data. These currently include Google Analytics, Google Ads, the LinkedIn Insight Tag and advertising services, Lemlist, OpenAI advertising services, and HubSpot. These providers process personal data in accordance with their own privacy notices.
HOW WE SHARE YOUR PERSONAL DATA
17. CATEGORIES OF RECIPIENTS
17.1. We may share your personal data with:
(a) service providers and processors who support our Website, marketing, analytics, advertising and communications, including the providers listed in clause 5.2;
(b) professional advisers, including lawyers, auditors and insurers;
(c) public authorities, regulators or law enforcement, where required to do so by law or in response to a valid request; and
(d) a purchaser or successor in the event of a merger, acquisition, reorganisation or sale of all or part of our business or assets, in which case we will notify you of any change in control of your personal data.
17.2. We require our service providers to protect your personal data and to use it only for the purposes we specify.
INTERNATIONAL TRANSFERS
18. TRANSFERS OUTSIDE THE UK AND EEA
18.1. Some of our service providers are located outside the United Kingdom and the European Economic Area, including in the United States. Where we transfer personal data to a country that has not received an adequacy decision, we implement appropriate safeguards, which may include:
(a) the European Commission’s Standard Contractual Clauses;
(b) the UK International Data Transfer Agreement or the UK Addendum to the Standard Contractual Clauses; and/or
(c) reliance on the EU-US Data Privacy Framework and the UK Extension to that Framework, where the recipient is certified.
18.2. You may request further information about the safeguards we apply, and a copy of the relevant mechanism, by contacting us at dataprotection@mazehq.com.
DATA SECURITY AND RETENTION
19. SECURITY
19.1. We implement appropriate technical and organisational measures to protect your personal data against accidental or unlawful destruction, loss, alteration, and unauthorised disclosure or access. These include hosting with appropriate security controls, encryption at rest and in transit, SOC 2 compliance, access controls and authentication, regular security assessments, and staff training on data protection and security.
20. DATA BREACHES
20.1. We have procedures in place to deal with any suspected personal data breach. Where a breach poses a risk to your rights and freedoms, we will notify you and any applicable regulator as required by law.
21. RETENTION
21.1. We retain your personal data only for as long as necessary to fulfil the purposes for which it was collected, including to satisfy any legal, accounting or reporting requirements. When determining the appropriate retention period, we consider the amount, nature and sensitivity of the personal data, the potential risk of harm from unauthorised use or disclosure, the purposes for which we process it, and applicable legal requirements.
YOUR RIGHTS
22. RIGHTS UNDER UK AND EU DATA PROTECTION LAW
22.1. Subject to applicable law and certain conditions, you have the following rights:
(a) the right to be informed about how we use your personal data;
(b) the right to access your personal data;
(c) the right to request rectification of inaccurate personal data;
(d) the right to request erasure of your personal data;
(e) the right to request restriction of processing;
(f) the right to data portability;
(g) the right to object to processing, including for direct marketing; and
(h) rights in relation to automated decision-making and profiling. We do not currently engage in automated decision-making that produces legal or similarly significant effects.
22.2. Where our processing is based on consent, you have the right to withdraw that consent at any time. This does not affect the lawfulness of processing carried out before withdrawal.
23. EXERCISING YOUR RIGHTS
23.1. To exercise any of these rights, please contact us at dataprotection@mazehq.com. We will respond within one month, although we may extend this period where permitted by law. There is no fee for exercising your rights, but we may charge a reasonable fee, or refuse to comply, where a request is manifestly unfounded, repetitive or excessive.
24. COMPLAINTS
25. HOW TO COMPLAIN
25.1. If you have a complaint about our use of your personal data, please contact us in the first instance at dataprotection@mazehq.com. You also have the right to lodge a complaint with the UK Information Commissioner’s Office (ICO) at ico.org.uk, or with the relevant supervisory authority in your jurisdiction, particularly in the country where you live or work, or where you believe a breach has occurred.
26. CALIFORNIA PRIVACY RIGHTS
27. APPLICATION
27.1. This clause applies only to the extent that the CCPA applies to Maze and to our processing of the personal information of California residents. We do not currently sell or share personal information for cross-context behavioural advertising within the meaning of the CCPA, and accordingly we do not offer a “Do Not Sell or Share My Personal Information” mechanism.
27.2. Where the CCPA applies, California residents may have the right to know what personal information we collect and how we use and disclose it, the right to request access to and deletion of their personal information, the right to correct inaccurate personal information, and the right not to be discriminated against for exercising these rights. To exercise any applicable right, please contact us at dataprotection@mazehq.com. We will verify your request before responding.
THIRD-PARTY LINKS
28. EXTERNAL WEBSITES
28.1. The Website may contain links to third-party websites, plug-ins and applications. Clicking on those links or enabling those connections may allow third parties to collect or share data about you. We do not control these third-party websites and are not responsible for their privacy practices. We encourage you to read the privacy notice of every website you visit.
CHANGES TO THIS POLICY
29. UPDATES
29.1. We may update this Policy from time to time in response to changing legal, technical or business developments. When we update this Policy, we will take appropriate measures to inform you, consistent with the significance of the changes. You can see when this Policy was last updated by checking the “Last Updated” date at the top of this Policy.
CONTACT US
30. HOW TO CONTACT US
30.1. If you have any questions about this Policy or our privacy practices, please contact:
Privacy Contact: Phil O’Hagan, VP Operations
Email: dataprotection@mazehq.com
Postal address: 5 New Street Square, London, EC4A 3TW, United Kingdom.