Maze AI Limited (trading as Maze)
Effective Date: 27 August 2026
Last Updated: 27 August 2026
Version: 2.0

1. INTRODUCTION

1.1. This Product Privacy Policy (“Policy”) explains how Maze AI Limited, trading as Maze (“Maze”, “we”, “us”, “our”), handles personal data when you use our vulnerability management triage and remediation platform and related applications, including our application available on the Atlassian Marketplace (together, the “Product”).

1.2. This Policy is intended to be concise. It sits alongside, and is supplemented by, our Master Services Agreement (the “MSA”) and Data Processing Addendum (the “DPA”) agreed with each customer. In the event of any conflict between this Policy and the MSA or DPA, the MSA and DPA prevail in respect of the processing of customer personal data.

1.3. This Policy does not cover personal data we process as a controller in connection with our website and marketing activities, which is addressed in our separate Website Privacy Policy.

2. WHO WE ARE

2.1. Maze is a cybersecurity software company headquartered in the United Kingdom, providing vulnerability management solutions to IT and security teams in medium and large enterprises.

2.2. The Maze contracting entity is Maze AI Limited (trading as Maze), a company registered in England and Wales with company number 15203461, whose registered office is at 5 New Street Square, London, EC4A 3TW, United Kingdom.

3. OUR ROLE

3.1. In relation to personal data processed within the Product on behalf of our customers, Maze acts as a data processor. Our customers are the data controllers and determine the purposes and means of that processing. We process such personal data only in accordance with the customer’s documented instructions and the DPA.

3.2. Maze acts as a data controller only in limited respects, such as the account, authentication and billing data we use to administer the Product and manage our customer relationship.

4. PERSONAL DATA WE PROCESS

4.1. When you install and use the Product, including via the Atlassian Marketplace, we process personal data on behalf of the customer that may include:

(a) user account identifiers and profile information, such as name, email address and account ID;

(b) issue and ticket data drawn from the customer’s connected environment (for example, Jira issues), which may contain personal data included by the customer or its users;

(c) authentication and access data used to secure and manage access to the Product; and

(d) usage and log data generated through use of the Product, including IP address and device information.

4.2. Maze does not require or intend the Product to process special categories of personal data, and customers should not input such data into free-text fields.

5. HOW WE USE PERSONAL DATA

5.1. As a processor, we process personal data solely to provide, maintain, secure and support the Product in accordance with our customers’ instructions and the DPA, including to:

(a) create and administer user accounts and authenticate users;

(b) provide access to and operate the Product’s triage and remediation functionality;

(c) associate issues and tickets with the relevant users; and

(d) provide technical support and respond to enquiries.

6. SUB-PROCESSORS

6.1. We engage a limited number of sub-processors to help provide the Product, each of which is bound by contractual obligations consistent with the DPA. These currently include:

(a) Amazon Web Services (AWS), for hosting and infrastructure;

(b) Google, for infrastructure and related services;

(c) Auth0, for authentication and identity management; and

(d) Plain, for support ticketing.

6.2. We maintain an up-to-date list of sub-processors and notify customers of intended changes in accordance with the DPA.

7. INTERNATIONAL TRANSFERS

7.1. Personal data processed within the Product is hosted on servers within the European Union. Where personal data is transferred to a country that has not received an adequacy decision, we implement appropriate safeguards, which may include the European Commission’s Standard Contractual Clauses and the UK International Data Transfer Agreement or UK Addendum, together with any required transfer risk assessment.

8. SECURITY

8.1. We implement appropriate technical and organisational measures to protect personal data, including hosting with appropriate security controls, encryption at rest and in transit, SOC 2 compliance, access controls and authentication, regular security assessments, and staff training on data protection and security. Further detail is set out in the DPA.

9. RETENTION

9.1. We retain personal data processed within the Product for the duration of the customer’s contract and thereafter only as required to comply with our legal obligations or as otherwise set out in the MSA and DPA. On termination, we return or delete customer personal data in accordance with the DPA.

10. DATA SUBJECT REQUESTS AND YOUR RIGHTS

10.1. Individuals whose personal data is processed within the Product should direct requests to exercise their rights (including access, rectification, erasure, restriction, portability and objection) to the relevant customer as data controller. Where we receive such a request directly, we will, unless legally required to act, refer it to the customer and assist the customer in responding as required by the DPA.

11. CONTACT US

11.1. If you have any questions about this Policy or our privacy practices, or if you are a customer requiring a copy of the MSA or DPA, please contact:
Data Protection Officer: Phil O’Hagan, VP Operations
Email: dataprotection@mazehq.com
Postal address: 45 Crescent Lane, Ground Floor Flat, London, SW4 9PT, United Kingdom.

12. CHANGES TO THIS POLICY

12.1. We may update this Policy from time to time to reflect changes in legal, technical or business developments. You can see when this Policy was last updated by checking the “Last Updated” date at the top of this Policy.