Skip to content
PRICINGBLOG
Continuous reconExploit chainingProof of impactIntegrations
02 Pricing03 Blog

CAPABILITIES

FOR TEAMS

LEGAL · PRIVACY

Privacy Policy

Last updated: 6 October 2026

Hog3 is the security services brand operated by Donely, Inc. This Privacy Policy explains how we collect, use, share, retain, and protect personal data when you visit hog3.com, contact us, book a meeting, receive marketing from us, work with us as a client or vendor, or interact with us in connection with an authorized security engagement.

For questions or privacy rights requests, contact us at privacy@hog3.com.

1. Our roles

Hog3 acts in two main roles:

  • Controller for our own business data. We decide how and why we process personal data about website visitors, prospects, client contacts, vendor contacts, job applicants, employees, contractors, and people who communicate with us.
  • Processor or service provider for client engagement data. During an authorized penetration test, red-team exercise, or security assessment, we may access personal data in a client's systems only as instructed by that client and only within the agreed scope. In that situation, the client is normally the controller or business that decides how the data is handled.

If your request concerns personal data inside a client's system, please contact that client first. If you contact us directly about engagement-scoped data, we will direct or forward the request to the client controller as appropriate.

2. Personal data we collect

We collect personal data in the following ways.

Information you provide to us

This may include:

  • Name, business email, phone number, job title, company, and related business contact details.
  • Inquiry, demo, meeting, support, and scheduling information.
  • Contract, authorization, scope, billing, and procurement records.
  • Communications with us, including emails, meeting notes, and feedback.
  • Vendor contact information and contract records.
  • Job applicant, employee, contractor, and workforce information, where relevant to recruitment or workforce administration.

Payment card processing, when used, is handled by a payment provider. Hog3 does not need to store full payment card numbers.

Website and device information

When you use hog3.com, we may collect:

  • IP address, device and browser information, approximate location derived from network data, pages viewed, referring page, timestamps, and similar log data.
  • Cookie and consent choices.
  • Analytics and marketing interaction data, if you consent where consent is required.

Our Cookie Policy explains the cookies and similar technologies used on hog3.com: https://hog3.com/cookie-policy.

Security engagement information

When a client authorizes us to test an in-scope system, we may incidentally encounter personal data, credentials, secrets, logs, screenshots, record counts, field names, regulated data, or other sensitive information while proving exploitability or validating risk. We do not collect this data for its own sake. We minimize access and use redacted proof wherever possible. Our policy requires sensitive engagement working copies to be minimized and securely deleted at engagement close-out, subject to documented contractual retention requirements, legal holds and incident-preservation obligations.

Information from other sources

We may receive business contact information from your employer, colleagues, referrals, public business sources, event interactions, vendors, clients, or service providers. During a client engagement, the client may provide information needed to perform the authorized assessment.

3. How we use personal data

We use personal data for these purposes:

How we use personal data and the legal basis where GDPR applies
PurposeExamplesLegal basis where GDPR applies
Provide and manage servicesClient intake, engagement scoping, authorization records, deliverables, account management, billing, and supportContract; legitimate interests; legal obligation
Perform authorized security workTesting in-scope systems, validating findings, preparing reports, and maintaining engagement recordsClient instructions as processor; contract; legitimate interests
Run and secure our website and business systemsSite delivery, security logging, abuse prevention, troubleshooting, access control, and incident responseLegitimate interests; legal obligation
Communicate with youResponding to inquiries, scheduling meetings, sending service updates, and managing relationshipsContract; legitimate interests
Sales and marketingB2B outreach, lead management, events, and non-essential marketing cookies where usedLegitimate interests; consent where required
Vendor and procurement managementVendor due diligence, contracts, invoicing, and operational communicationsContract; legitimate interests; legal obligation
Recruitment and workforce administrationCandidate review, hiring, employment, contractor management, payroll, access management, and complianceContract or steps before contract; legitimate interests; legal obligation
Legal and complianceRecords retention, rights requests, audits, regulatory obligations, dispute handling, and enforcement of agreementsLegal obligation; legitimate interests

Where we rely on legitimate interests, we balance our interests against your rights and expectations. Our legitimate interests include operating and securing a security services business, communicating with business contacts, proving authorization for testing, preventing misuse, keeping appropriate records, and improving our services.

Where we rely on consent, you may withdraw consent at any time. Withdrawing consent does not affect processing that happened before withdrawal.

4. Security engagement data

Hog3 performs only authorized security testing. No testing begins unless valid authorization is in place, such as a signed authorization and scope agreement, a published vulnerability disclosure program that covers the target, or a bug bounty program whose rules cover the target.

For engagement data:

  • We access client systems only within the authorized scope.
  • We use the minimum evidence needed to prove and explain a finding.
  • We treat credentials, secrets, reports, source code, customer data, personal data, cardholder data, and health information as confidential or restricted.
  • We do not intentionally send regulated client data, such as ePHI, PII, or cardholder data, to unapproved AI providers, transcripts, logs, or backups.
  • If regulated data is unexpectedly encountered, we stop further access where appropriate, escalate internally, and confirm the correct authorization and data-handling route before continuing.
  • Our policy requires sensitive engagement working copies to be securely deleted at engagement close-out, subject to documented contractual retention requirements, legal holds and incident-preservation obligations.
  • Final reports retain redacted proof and engagement paperwork rather than raw client data.

5. Cookies and analytics

Hog3 uses cookies and similar technologies to operate the website, remember consent choices, understand site usage, and support marketing where enabled. Some cookies are necessary for the site to work. Non-essential analytics and marketing cookies are used only where permitted by your choices and applicable law.

You can manage cookie choices through the consent tools on hog3.com. For more detail, see our Cookie Policy: https://hog3.com/cookie-policy.

6. How we share personal data

We may share personal data with:

  • Service providers and processors that help us operate the website, cloud infrastructure, email, scheduling, customer relationship management, analytics, security, payment, collaboration, and support systems.
  • Clients where information is part of an authorized engagement, report, delivery record, or client instruction.
  • Professional advisers such as lawyers, accountants, auditors, insurers, and compliance advisers.
  • Authorities or third parties where required by law or where needed to protect rights, security, safety, or prevent misuse.
  • Business transaction parties if we evaluate or complete a merger, acquisition, financing, reorganization, sale of assets, or similar transaction.

We do not sell personal data for money. Some laws may treat certain advertising or analytics cookies as a "sale" or "sharing" of personal data. You can reject or withdraw consent for non-essential cookies through the cookie controls on hog3.com.

7. International transfers

Donely, Inc. operates Hog3 as a U.S. company, with team members and operational support in Asia-Pacific. Our default production infrastructure may use AWS in the United States and Cloudflare's global edge network. Some vendors and team members may process personal data outside your country.

Hosting locations and any agreed regional restrictions for client engagement data are specified in the applicable engagement documentation. Hosting location alone does not mean all support access or processing occurs within that region.

Where applicable law requires safeguards for an international transfer, the appropriate transfer arrangements must be established before that transfer takes place.

8. Retention

We keep personal data only as long as needed for the purposes described in this Privacy Policy, unless a longer period is required or permitted by law, contract, legal hold, incident preservation, or audit obligation.

Our current retention approach includes:

  • Website, inquiry, prospect, marketing, and business contact data is kept while needed for the relationship, request, opt-out, compliance record, or business purpose.
  • Client authorization, scope, DPA, BAA, responsibility agreement, final report with redacted proof, destruction log, and related engagement paperwork are generally kept for 6 years from engagement close-out or the last effective date of the relevant instrument.
  • Our policy requires sensitive engagement working copies to be minimized and securely deleted at engagement close-out, subject to documented contractual retention requirements, legal holds and incident-preservation obligations.
  • We retain security logs for periods determined by their security purpose, incident-investigation needs and applicable contractual or legal obligations. Records needed for an investigation or legal hold may be retained until that requirement ends.
  • HR and background-screening records are generally kept for 7 years from end of employment or screening date, or longer if required by law.
  • Cookie retention periods are described in the Cookie Policy.

When personal data is no longer needed, we delete it, de-identify it, or securely dispose of it.

9. Security

We use technical and organizational safeguards designed to protect personal data, including access controls intended to limit access to authorized personnel and services according to their responsibilities, encryption in transit, encryption at rest where provided by hosting and storage layers, security logging, scoped authorization for engagements, evidence redaction, and secure disposal practices.

No method of transmission or storage is perfectly secure. If we become aware of a security incident involving personal data, we will investigate and notify affected clients, individuals, regulators, or other parties where required by law or contract.

10. Your privacy rights

Depending on your location and the type of personal data involved, you may have the right to:

  • Request access to your personal data.
  • Request correction of inaccurate or incomplete personal data.
  • Request deletion of personal data.
  • Request restriction of processing.
  • Object to processing based on legitimate interests or direct marketing.
  • Request portability of personal data.
  • Withdraw consent where processing is based on consent.
  • Opt out of certain sales, sharing, targeted advertising, or marketing communications where applicable.
  • Appeal or complain if you are not satisfied with our response, including to a data protection authority where applicable.

To exercise your rights, contact privacy@hog3.com. We may need to verify your identity before acting on a request.

Where GDPR applies, we aim to respond within one month of receiving a request. If a request is complex or numerous, we may extend the response period by up to two additional months and will tell you within the first month if we need that extension.

We will not discriminate against you for exercising privacy rights.

11. Automated decisions

Hog3 does not use personal data from hog3.com to make solely automated decisions that produce legal or similarly significant effects about individuals.

During authorized security engagements, automated tools and agents may help test systems, analyze findings, or prepare evidence under human accountability and within the client's authorized scope. Those activities are used to assess systems and vulnerabilities, not to make legal or similarly significant decisions about individual people.

12. Children

Hog3 provides business-to-business security services. Our website and services are not directed to children, and we do not knowingly collect personal data from children. If you believe a child has provided personal data to us, contact privacy@hog3.com so we can review and delete it where appropriate.

13. Third-party links and services

Our website or communications may link to third-party websites, platforms, or services. Their privacy practices are governed by their own policies.

14. Changes to this Privacy Policy

We may update this Privacy Policy from time to time. The "Last updated" date shows when the policy was last changed. If changes are material, we will provide notice in a manner appropriate to the change.

15. Contact us

For privacy questions, rights requests, or complaints, contact:

Donely, Inc., operating the Hog3 security services brand

Email: privacy@hog3.com

A machine hand and a human hand reaching toward each other, rendered as a dot matrix.

Point HOG3 at your stack.

Continuous pentesting, tailored to your environment. Start with a demo, then discuss a subscription or a scoped free pentest.

AUTONOMOUS PENTESTING PLATFORM

EXPLORE

About Trust Center Pricing Offers Blog

FINDINGS BRIEF

What we broke this month, and how. One mail, no marketing.

COMPLIANCE
IN PROGRESS

SOC 2 Type IIONGOING
ISO 27001ONGOING
GDPRONGOING
HIPAAONGOING
© 2026 Donely Inc. ALL SYSTEMS OPERATIONALTerms of ServicePrivacy PolicyCookie Policy