Bitdefender outsourcing announcement to US company Constella Inc.
Maybe somebody also received this email enclosed. In the first moment looks like coming from Bitdefender. Was in german language.
Hi,
The email address is legitimate. For any breach of your data, Bitdefender Digital Identity Protection will alert you of the findings and you will be advised on the steps to take to reduce the risks of account take-over and new account fraud. As stated in Bitdefender's Privacy Policy here, the company provides this service to customers by using Constella as data processor who processes data such as name, e-mail address and phone number on behalf of Bitdefender in accordance with Bitdefender's instructions and for the sole purpose of providing users Digital Identity Protection services. The information that is provided via Bitdefender Digital Identity Protection is collected as Data Controller by Constella Inc, and as such, users can exercise their rights regarding this at privacy@constellaintelligence.com.
I hope this brings peace of mind.
Regards
Hello,
Thank you for your previous reply confirming that Constella Inc. acts as data processor (for the name, e-mail address and phone number provided by Bitdefender) and as independent data controller (for the breach database used within Digital Identity Protection).
As a data subject located in the European Union, I would like to formally request the following information regarding the international transfer of my personal data to Constella Inc. in the United States:
I would appreciate a written response confirming these points.
Thank you for your attention to this matter.
For the above questions and for exercising any privacy rights, you may send a written request to Bitdefender via email at privacy@bitdefender.com.
Thank you!
Thank you for the reply, but I have to be honest: I find this answer quite unsatisfying.
I do not feel comfortable entrusting personal, confidential information to a company based in the United States, given the current administration and the ongoing political and legal uncertainty around it. At this point, I don't think it is reasonable to assume that this data will remain safe from government access at any given moment.
What genuinely surprises me is that Bitdefender, as a European company, is apparently not able to handle a service like this entirely within Europe, and instead relies on a US-based provider (Constella Inc.) to process and control this kind of data. For a company that markets itself as a cybersecurity and privacy leader, this choice seems inconsistent with the level of trust it asks from its European customers.
I would appreciate it if Bitdefender could clarify whether there are any plans to offer this service using EU-based processing, or at least a way to opt out of the international transfer while keeping the rest of the protection features active.
Thank you for your time.
I'm sorry to hear that you're not satisfied with the answer, but keep in mind that you've reached the Bitdefender forum, where we mostly rely on peer-to-peer support and guidance, so this type of questions should be directed to the Bitdefender team responsible for this area.
As such, in the event the Privacy Policy available on the Bitdefender website is not satisfactory, you can send any questions you may have to the competent department that possesses the necessary knowledge and expertise to respond. In the event you are still unsatisfied with the outcome, you can always opt out from Bitdefender services and data processing by exercising your right to be forgotten, of course. But I'm sure the Privacy Team together with the DPO available at dpo@bitdefender.com can address any concerns that you may have.
For the record, Bitdefender is in complete adherence to all GDPR and data privacy regulations, as well as other data protection requirements in any of the jurisdictions where the company operates.