CloudGuard WAF Privacy Data Sheet

CloudGuard WAF

This Privacy Data Sheet explains how Check Point’s CloudGuard Web Application Firewall ("WAF") processes personal data.

About CloudGuard WAF

CloudGuard WAF leverages artificial Intelligence (AI) to provide web application firewall and API Protection. By integrating AI with IPS signatures, it offers protection against both known threats and zero-day exploits. The AI engine continuously adapts to your application's behavior, monitoring adjustments across the application's lifecycle. This results in a low rate of false positives and reduces the need for frequent rule adjustments following each application update.

How Does Check Point Comply With Applicable Data Protection Regulations?

At Check Point, ensuring customer privacy and security remains our foremost concern, with the trust our customers place in our services being one of our most valued assets.

What Types Of Personal Data Does CloudGuard WAF Process?

Important clarification: CloudGuard WAF inspects logs to detect security events. However, you have the option to configure local logging, ensuring that data remains within your infrastructure and is not shared with Check Point.

Why Does CloudGuard WAF Process Data?

CloudGuard WAF processes personal data to enhance the security and performance of web applications by:

For more information on the purposes for which we process personal data, please visit our Privacy Policy.

What is the Duration and Frequency of Processing?

Data is shared with CloudGuard WAF throughout the subscription term.

What are the Retention Periods?

DATA TYPE RETENTION PERIOD
Identifiers used to identify users' interactions with CloudGuard WAF 7 days
Personal data extracted from logs concerning detected security events 1 year*

*After your subscription ends, your data is retained for 30 days, during which you can retrieve it. After this period, the data will be deleted.

Where Is Personal Data Stored?

Personal data is stored on AWS Cloud Hosting Service. The hosting locations available are: United States, Europe, Australia, India, Canada, and Singapore. The location is selected per your choice during the onboarding process.

Sub-Processors

Check Point engages third-party Sub-processors in connection with the provision of Check Point's products and services. The list of Sub-processors is available at our Sub-Processors Page.

Privacy Options

We provide the following tools, empowering our customers to select their data and privacy preferences:

Authorized Access To Personal Data

Customer Access Access to data is controlled by customer’s selected administrators. Only users authorized by the administrators can access data. All access and any action taken by administrators or by their authorized users are fully logged.

Check Point Access Data contained within the customer’s CloudGuard WAF environment may be accessed by Check Point’s support and R&D teams for troubleshooting and security purposes. Such access is granted only to those authorized representatives for which the access is necessary to perform their intended functions. Any access to specific customer data by Check Point personnel requires prior approval.

Information contained in this data sheet is for awareness only, may be modified, and does not constitute legal or professional advice or warranty of fitness for a particular purpose. This Privacy Data Sheet is a supplement to Check Point’s Privacy Policy. Please visit it for more information on how Check Point collects and uses personal data.