Cloud Platform
Cloud platform apps

See Resources

Qualys Privacy Statement

Version 2.8 – Effective January 15, 2018

Validate TRUSTe privacy certification


Qualys®, Inc. (Qualys) is committed to providing you with excellent service for its Qualys services (“Services”). Because we respect your right to privacy and your desire to control your personal data that you share with us, we have developed this Privacy Statement to inform you about our privacy practices for This Privacy Statement describes how Qualys collects, uses, shares and secures the personal information you provide. It also describes your choices regarding use, access and correction of your personal information. This Privacy Statement is not applicable to any of our other privacy practices, including without limitation, data collected from other Qualys sites or offline. Qualys services may be hosted or provided via partner sites on behalf of Qualys, and if this Qualys Privacy Statement is listed on that site, then it will also apply.

Websites Covered

This Privacy Statement applies to Qualys Websites that link to this Privacy Statement:;;;;;;;;;;;;;;;
(collectively referred to as “Qualys Websites”).

Qualys Websites may contain links to other websites. Qualys is not responsible for the information practices or the content of such other websites. Qualys encourages you to review the privacy statements of other websites to understand their information practices.

Information We Gather from You – Personal Information

There are three ways in which you may explicitly and intentionally provide us with and consent to our collection of certain personal information:

  • E-mail Request for Information or Registrations for Guides or Seminars – We use links throughout our site to provide you with the opportunity to contact us via e-mail to ask questions, request information and materials, register or sign up for guides, seminars, training classes or provide comments and suggestions. You may also be offered the opportunity to have one of our representatives contact you personally to provide additional information about our services. To do so, we may request additional personal information from you, such as your name, telephone number and other address information, to help us satisfy your request.
  • Service Enrollment – If you choose to enroll for one of our Services, we will request certain information from you. Depending on the type of service that you request, you may be asked to provide different personal information. For enrollment in our Services, we may require your name, address (including country, city and state), telephone number, e-mail address, credit card number, bank account information, IP address, IP range, domain name(s), or web application URL(s). Other services may require different or supplemental information from you in order to register. For a detailed listing of the type of personal information requested for our various products, please refer to the enrollment page for the particular service.
  • Recruitment and Employment – You may choose to provide us with information about yourself, such a resume or other employment related information in connection with a job application or inquiry whether advertised on the Qualys site or as otherwise provided by Qualys. Qualys may use this information throughout Qualys and its related entities for the purpose of employment consideration or as you inquire.

Under no circumstances do we collect any personal data revealing racial or ethnic origin, political opinions, religious or philosophical beliefs, trade union membership, health, or sex life.

Statistical Information About Your Visit

When you visit Qualys Websites, our systems collect personal information (in the manner described above) and statistical or non-personally identifiable information about your visit to our sites (e.g. IP address, pages visited, origin of visitor domains, and types of browsers used). However, unless you actively submit personal information, we do not typically identify you via the non-personally identifiable information. Notwithstanding the foregoing, to the extent permitted by applicable law, we reserve the right to combine non-personally information with personal information that you have actively submitted.

Use of Cookies

We use “cookies” as described in this section. A “cookie” is a piece of information that Qualys Websites send to your browser, which then stores this information on your system. If a cookie is used, we will be able to “remember” information about you and your preferences either until you exit your current browser window (if the cookie is temporary) or until you disable or delete the cookie. Many users prefer to use cookies in order to help them navigate a website as seamlessly as possible. You should be aware that cookies contain no more information than you volunteer, and they are not able to “invade” your hard drive and return to the sender personal or other information from your computer. If you do not want Qualys to deploy cookies in your browser, you can set your browser to reject cookies or to notify you when a website tries to put a cookie in your browser software. Rejecting cookies may affect your ability to use some of our products and/or services.

Our uses of “cookies” are limited to the following specific situations. The first situation is with respect to temporary cookies. There are two instances in which we use temporary cookies. First, if you are accessing our services through one of our online applications our web server may automatically send your browser a temporary cookie, which is used to help your browser navigate our site. The only information contained in these temporary cookies is a direction value that lets our system determine which page to show when you hit the back button in your browser. This bit of information is erased when you close your current browser window. If you come to our site from one of our business or advertising partners, our web server may also send your browser a temporary cookie that reflects an “origination code” for that partner. We use this information for statistical and marketing purposes.

List of Temporary Cookies:

Name Function
leadsource, referer, link Indicates the origination code.
kw Indicates the keyword, similar to the origination code.
JSESSIONID, DWRSESSIONID, BIGipServersj08web_mch_http, BIGipServersj08web_mch_https Used by Qualys Community, SSL Labs and/or marketing automation systems for session tracking.
QualysSession, quickstart, QualysSession_notification_div Used by Qualys for session tracking and management., jive.user.loggedin Used by Qualys Community to remember whether logged in and into which back-end server.

The second situation in which we may use cookies is with respect to permanent cookies. This type of cookie remains on your system, although you can always delete or disable it through your browser preferences. There are two instances in which we use a permanent cookie. First, when you visit a Qualys Website and request documentation or a response from us. When you are filling out a form you may be given the option of having the Qualys Website deliver a cookie to your local hard drive. You might choose to receive this type of cookie in order to save time in filling out forms and/or revisiting the Qualys Website. We only send this type of cookie to your browser when you have checked a checkbox on the form with the caption “Please remember my profile information on this computer” when submitting information or communicating with us. The second instance where we use a permanent cookie is where we track traffic patterns on our site. Analysis of the collected information by our tracking technologies allows us to improve Qualys Websites and the user experience. In both instances of a persistent cookie, if you choose not to accept the cookie, you will still be able to use the Qualys Website. Even if you choose to receive this type of cookie, you can always set your browser to notify you when you receive any cookie, giving you the chance to decide whether to accept it in each situation in which one is sent.

List of Permanent Cookies:

Name Function
_mkto_trk For visitor tracking across Qualys Websites.
_utma, _utmb, _utmc, _utmv, _utmz For Google Analytics across Qualys Websites.
jive.recentHistory, jive_wysiwygtext_height Used by Qualys Community to remember user preferences.
sua_name, uid, page_visit_cnt Used by Qualys BrowserCheck for functionality.
PRUM_EPISODES Pingdom Realtime User Monitoring, to track page response time.

Some Qualys pages use cookies that permit select third party partners, including Google and Marketo, to provide you Qualys related content, including Qualys advertisements, on their sites or elsewhere on the Internet. This is based on your prior visits to the Qualys site.

Additionally, third parties may use cookies to allow you to link to social networking sites like Facebook and LinkedIn. As noted above, you can set your browser to notify you when you receive a cookie, giving you the chance to decide whether to accept it. You can control whether or not these cookies are used, but preventing them may stop us from offering you some services. Alternatively you may use the third parties’ own tools to prevent these cookies. You may also opt out of Google’s use of cookies by visiting

List of Third Party Cookies: Various third-party cookies are set by the following entities and used for statistical and marketing purposes: LivePerson ( and Adroll (

Web Beacons

Qualys uses web beacons alone or in conjunction with cookies to compile information about Customers and site visitors’ usage of the site and interaction with emails from Qualys. Web beacons are clear electronic images that can recognize certain types of information on your computer, such as cookies, when you viewed a particular website tied to the web beacon, and a description of a website tied to the web beacon. For example, Qualys may place web beacons in marketing emails that collect information when you click on a link in the email that directs you to Qualys’ site. We use web beacons to operate and improve Qualys’ site and email communications. Qualys may use information from web beacons in combination with data about Qualys to provide you with information about Qualys and the Qualys Services.

Information Sharing

We will share your personal information with third parties only in the ways that are described in this privacy statement. We do not sell your personal information to third parties. In some cases Qualys uses suppliers to collect, use, analyze and otherwise process information on its behalf. It is Qualys’ practice to require such suppliers and other service providers to handle information in a manner consistent with Qualys’ policies and to use your personal information only as necessary to provide these services to us.

We may also disclose your personal information as required by law, such as to comply with a subpoena, or similar legal process when we believe in good faith that disclosure is necessary to protect our rights, protect your safety or the safety of others, investigate fraud, or respond to a government request. We may also disclose your personal information if Qualys, Inc. is involved in a merger, acquisition, or sale of all or a portion of its assets. You will be notified via email and/or a prominent notice on the Qualys Website of any change in ownership or uses of your personal information, as well as any choices you may have regarding your personal information.

Qualys Supported Blogs and Forums

If you use a blog, forum, or other chat tool on a Qualys Website, you should be aware that any personal information you submit there can be read, collected, or used by other users of these forums, and could be used to send you unsolicited messages. Qualys is not responsible for the personal information you choose to submit in these forums. You are also responsible for using these forums in a manner consistent with the applicable Terms of Use or other terms and conditions set forth on the relevant forum site. To request removal of your personal information from our blog or community forum, please contact Qualys as described below. In some cases, we may not be able to remove your personal information, in which case we will let you know if we are unable to do so and why.


We display personal testimonials of satisfied customers on our site in addition to other endorsements. With your consent we may post your testimonial along with your name. If you wish to update or delete your testimonial, you can contact Qualys as described below.


From time-to-time we may request information from customers via surveys. Participation in these surveys is completely voluntary and the user therefore has a choice whether or not to disclose this information. Survey information will be used for improving our customer service and service offerings. The feedback and data we collect from these surveys is aggregated and we do not single-out individual responses unless the respondent chooses to be identified.

Social Media Widgets

Qualys Websites include social media features. These features may collect your IP address, which page you are visiting on our site, and may set a cookie to enable the feature to function properly. Social media features are either hosted by a third party or hosted directly on Qualys Websites. Your interactions with these features are governed by the privacy statement of the company providing it.

Public Profiles

The profile you create on a Qualys Website will be publically accessible unless otherwise indicated. You may change the privacy settings of your profile through your account portal.

Your Ability to Opt-Out of Further Notifications

From time to time, we notify visitors to Qualys Websites of new products, announcements, upgrades and updates unless you have opted out of these notices. If you would like to opt-out of being notified, please contact us at the address given at the end of this Privacy Statement.

If you would like to change your preferences online, please visit Please be aware that you may not opt out of receiving information regarding the security, initial use, expiration, product enhancement or migration of our products or services.

Access or Update Personal Information

If your personal information changes, if you no longer desire our service, or if you wish to know whether we hold any of your personal information, you may correct, update, amend, delete or deactivate it by making the change on your member information page or by emailing our Customer Support at the contact information listed below. We will respond to your request for access to personal information within 30 days.

We will retain your information for as long as your account is active or as needed to provide you services. We will retain and use your information as necessary to comply with our legal obligations, resolve disputes, and enforce our agreements.

Our Security Procedures

We consider the protection of all personal information we receive from Qualys Website visitors and customers as critical. Please be assured that we have security measures in place to protect against the loss, misuse, and alteration of any personal information we receive from you. As with any transmission over the Internet, however, there is always some element of risk involved in sending personal information. In order to try to minimize this risk, we encrypt all information that you submit in ordering our services using the Secure Sockets Layer (SSL) protocol. Our security procedures are also subject to an annual SSAE 16 and SOC1 industry standard audit by an internationally-recognized accounting firm. If you have questions about security, please contact us at the information provided below.

Qualys collects information under the direction of its customers, and has no direct relationship with the individuals whose personal data it processes. If you are a client of one of our customers and would no longer like to be contacted by such customer, please contact the customer that you interact with directly.

  • Service Provider, Sub-Processors/Onward Transfer – Qualys may transfer personal information to companies that help us provide our service. Transfers to subsequent third parties are covered by the provisions in this statement regarding notice and choice and the service agreements with our customers.
  • Access to Data Controlled by our Customers – An individual who seeks access to, or who seeks to correct, amend, or delete inaccurate data should direct their query to Qualys’ customer (the data controller). If requested to remove data, we will respond to your request within a reasonable timeframe.
  • Data Retention – Qualys will retain personal data we process on behalf of our clients for as long as needed to provide services to our client. Qualys will retain and use this personal information as necessary to comply with our legal obligations, resolve disputes, and enforce our agreements.

Qualys Privacy Shield Notice

Qualys, Inc. recognizes that the European Community has established a data protection regime pursuant to Directive 95/46/EC, which applies to the European Economic Area (“EEA”) and restricts companies in the EEA in transferring personal data about individuals in the EEA to the United States, unless there is “adequate protection” for such personal data when it is received in the United States.

EU-U.S. Privacy Shield
Qualys participates in and has certified its compliance with the EU-U.S. Privacy Shield Framework. Qualys is committed to subjecting all personal data received from European Union (EU) member countries, in reliance on the Privacy Shield Framework, to the Framework’s applicable Principles. To learn more about the Privacy Shield Framework, visit the U.S. Department of Commerce’s Privacy Shield List at

Qualys complies with the Privacy Shield Principles for all onward transfers of personal data from the EU, including the onward transfer liability provisions. Under those provisions and under certain circumstances Qualys is responsible for the processing of personal data it receives under the Privacy Shield Framework and subsequently transfers to a third party acting as an agent on its behalf.

With respect to personal data received or transferred pursuant to the Privacy Shield Framework, Qualys is subject to the regulatory enforcement powers of the U.S. Federal Trade Commission. In certain situations, Qualys may be required to disclose personal data in response to lawful requests by public authorities, including to meet national security or law enforcement requirements.

Under certain conditions, more fully described on the Privacy Shield website, you may be entitled to invoke binding arbitration when other dispute resolution procedures have been exhausted.

Scope of this Notice

This Notice does not apply to employees of Qualys; this Notice addresses other data subjects residing in the EEA (“EEA Persons”) whose data Qualys may receive from one of its subsidiaries, customers, suppliers or other businesses in the EEA, e.g., customers’ procurement managers, suppliers’ sales representatives, individual independent contractors, EEA residents who are mentioned or referred to in documents to be produced in pre-trial discovery proceedings, etc.

Categories of EEA Data

Qualys collects data processing and advisory services largely for businesses and rarely if ever for consumers. Thus, Qualys solely receives business-related information from the EEA. Occasionally, Qualys also receives contact information related to individual representatives of businesses with whom Qualys is dealing (including, without limitation, names, addresses, work phone numbers, work email addresses, etc.), and, in connection with our managed document review and advisory services, Qualys processes data that may be relating to EEA residents on behalf of, and in accordance with instructions from, customers (collectively “EEA Data”). Since EEA Data covered by this Notice is by definition sent to Qualys by another company in the EEA (e.g., a supplier to Qualys), the categories of data sent and the purposes of processing often depend on such other company, with whom the EEA Persons typically have a closer employment, business or other relationship (and which therefore, can provide additional information on categories of data shared with us).


Qualys collects and uses EEA Data for purposes of providing data processing and advisory services to its customers, communicating with corporate business partners about business matters, processing EEA Data on behalf of corporate customers, transmitting marketing emails and performing other marketing activities, and conducting related tasks for legitimate business purposes.


Qualys shares EEA Data with affiliates and contractors, which process EEA Data on behalf of Qualys. Qualys also shares EEA Data with other third parties for the purposes for which Qualys receives the EEA Data (e.g., performance of contractual obligations) and as required or permitted by law.

With respect to marketing emails, EEA Persons may opt-out of receiving further email marketing communications from Qualys by sending an email to, or by following opt-out instructions that are contained in each marketing email. EEA Persons may also send an email to this address to ask to opt-out of disclosures to third parties, but such a limitation on data sharing may make it difficult or impossible for Qualys to provide the requested services. Notwithstanding other statements in this Notice, Qualys may disclose EEA Data where it is legally required to disclose (e.g., under statutes, contracts or otherwise) or the disclosure is permitted by law and Qualys has a legitimate business interest in such disclosure.

Access and Review

EEA Persons whose EEA Data Qualys holds may request access to, and the opportunity to update, correct or delete some or all of the EEA Data that Qualys holds about them. To submit such requests or raise any other questions, please contact Qualys as described below. Qualys reserves the right to take appropriate steps to authenticate an applicant’s identity, charge an adequate fee before providing access and deny requests, except as required by the Privacy Shield Framework.

Qualys complies with the EU-U.S. Privacy Shield Framework and Swiss-U.S. Privacy Shield Framework as set forth by the U.S. Department of Commerce regarding the collection, use, and retention of personal information transferred from the European Union and Switzerland to the United States. Qualys has certified to the Department of Commerce that it adheres to the Privacy Shield Principles. If there is any conflict between the terms in this privacy policy and the Privacy Shield Principles, the Privacy Shield Principles shall govern. To learn more about the Privacy Shield program, and to view our certification, please visit

Changes To This Statement

We may update this privacy statement to reflect changes to our information practices. If we make any material changes we will notify you by email or by means of a notice on this site prior to the change becoming effective. We encourage you to periodically review this page for the latest information on our privacy practices.

Contact Information

If you have questions about Qualys’ Privacy Statement, please contact our Qualys Privacy Administrator at 919 E Hillsdale Blvd, 4th Floor, Foster City, CA 94404, USA, telephone: +1 650 801 6100, or fax: +1 650 801 6101; or email us at

If you have an unresolved privacy or data use concern that we have not addressed satisfactorily, please contact our U.S.-based third party dispute resolution provider (free of charge) at