Effective as of May 2026
Introduction
Affirm Logic Inc. (“Affirm Logic,” “we,” “us,” or “our”) is a cybersecurity and technology company providing solutions exclusively to enterprise organizations and government agencies.
Our Services are not intended for individual consumer use, and we do not knowingly collect personal data for consumer marketing purposes.
This Privacy Policy explains how we collect, use, disclose, and protect information in connection with our business-to-business (“B2B”) and business-to-government (“B2G”) Services, in alignment with ISO/IEC 27001 information security practices.
Scope of This Policy
This Privacy Policy applies to:
- Representatives of enterprise customers and government entities
- Authorized users of our platforms and solutions
- Business partners, vendors, and contractors
- Individuals interacting with us in a professional capacity
This policy does not apply to consumer-facing services, as Affirm Logic does not offer such services.
Information We Collect
a. Business Contact Information
We may collect limited professional information necessary to support business relationships, such as:
Name
- Business email address
- Business phone number
- Company/agency name
- Job title or role
b. Account and System Access Data
For authorized users of our Services:
- User credentials and authentication data
- Role-based access permissions
- Account activity logs
c. Technical and Usage Data
We collect operational and security-related data, including:
- IP address and device identifiers
- System logs and audit trails
- Network activity metadata
- Usage patterns within our platforms
This data is primarily used for security monitoring and system integrity.
d. Customer-Controlled Data
In many cases, Affirm Logic acts as a service provider/data processor on behalf of our customers.
- Customers (enterprise or government entities) determine what data is uploaded or processed within our systems
- We process such data only in accordance with contractual agreements and documented instructions
How We Use Information
a. Service Delivery
- Provide and maintain cybersecurity and technology solutions
- Manage access control and authentication
- Support customer operations and service functionality
b. Security and Threat Detection
A primary function of our Services includes:
- Monitoring systems for threats, vulnerabilities, and anomalies
- Detecting and preventing unauthorized access or malicious activity
- Supporting incident response, investigation, and remediation
These activities align with ISO/IEC 27001 controls, including logging, monitoring, and risk management.
c. Contractual and Operational Management
- Administer customer accounts and agreements
- Provide technical support and service communications
- Ensure service reliability and performance
d. Legal and Regulatory Compliance
- Meet applicable legal, regulatory, and contractual obligations
- Support audits, compliance reviews, and government requirements
Legal Basis for Processing
In the context of enterprise and government services, Affirm Logic processes information based on:
- Contractual necessity (to deliver Services)
- Legitimate business interests (e.g., security, operations)
- Legal and regulatory obligations
Consent is generally not relied upon, except where explicitly required.
Data Sharing and Disclosure
We do not sell personal information and do not engage in consumer data monetization.
We may share information only as necessary with:
a. Authorized Service Providers
- Infrastructure and cloud providers
- Security monitoring and analytics vendors
All providers are subject to strict contractual, confidentiality, and security requirements aligned with ISO 27001 vendor risk management.
b. Customer Organizations
Information is shared with the enterprise or government entity that controls the account, including administrators and authorized personnel.
Legal and Government Authorities
We may disclose information where required to:
- Comply with law, regulation, or legal process
- Support lawful investigations
- Protect systems, customers, or national security interests
Data Retention
We retain information in accordance with:
- Contractual obligations
- Customer requirements (including government retention schedules)
- Legal and regulatory mandates
- Security and audit needs
Retention is governed by formal data lifecycle controls consistent with ISO/IEC 27001.
Data Security
Affirm Logic maintains a comprehensive Information Security Management System (ISMS) aligned with ISO/IEC 27001, including:
- Encryption in transit (TLS/HTTPS) and at rest where applicable
- Role-based access controls and least privilege enforcement
- Continuous monitoring, logging, and alerting
- Vulnerability management and regular testing
- Incident response and breach management procedures
Customer Responsibilities
Enterprise and government customers are responsible for:
- Determining what data is uploaded into the Services
- Ensuring lawful collection and use of that data
- Managing user access within their organization
- Complying with applicable privacy and data protection laws
Affirm Logic acts as a service provider/processor, not a data controller, for customer-managed data unless otherwise specified.
Individual Rights
Because Affirm Logic does not operate consumer services, most personal data we process is controlled by our customers.
If you are an individual whose data is processed through a customer’s use of our Services, you should:
- Direct requests (e.g., access, correction, deletion) to the relevant enterprise or government entity
We will support our customers in fulfilling such requests as required.
International Data Transfers
Affirm Logic primarily operates within the United States. Where data is transferred internationally:
- Appropriate safeguards are implemented
- Transfers are conducted in accordance with contractual and regulatory requirements
Third-Party Links
Our Services may contain links to third-party systems or tools. We are not responsible for their privacy practices.
Updates to This Policy
We may update this Privacy Policy to reflect:
- Changes in legal or regulatory requirements
- Updates to security practices or certifications
- Modifications to our Services
Contact Information
For privacy or security inquiries, please contact:
Affirm Logic Inc.
1775 Greensboro Dr, Suite 230
McLean, VA 22102
888-825-0094

