This notice covers bonsaisecurity.com. It describes what the site collects when you apply to become a partner, and what happens to it afterwards.
Who we are
Bonsai Security provides white-label managed firewall operations to managed service providers. We are channel-only: we contract with MSPs, never with their end customers. For anything submitted through this site, we are the data controller.
What we collect
The partner application form asks for a work email address, your company name and the number of firewalls you manage. Those three are required. Your platform mix, the coverage model and hours you are interested in, your name and any free-text notes are optional.
The form also carries a hidden field that people never see. Anything submitted in it is treated as automated spam and the submission is discarded rather than stored.
With each submission we store the address of the page it was sent from and the browser user-agent string your browser supplies. Both are technical details rather than anything you type, and we keep them to tell a genuine enquiry from an automated one.
Separately, our host processes the technical details of every request, including your IP address, in order to serve and protect the site. We record the country an application was submitted from, taken from the country header our host adds. We do not store your IP address ourselves.
The spam check on the forms
Both forms are protected by Cloudflare Turnstile. When you submit, your browser loads a
check from challenges.cloudflare.com and Cloudflare tells us whether the
submission came from a person. Most visitors see nothing and are never asked to do
anything.
Cloudflare receives your IP address, your user-agent and technical signals about your browser as part of that check, and acts as our processor for it. Cloudflare states that Turnstile is not used to build advertising profiles. We store only the outcome, which is whether the check passed.
The check requires JavaScript. With JavaScript turned off the forms cannot be submitted, so email partners@bonsaisecurity.com instead and we will pick it up from there.
Why we process it
To assess your application, reply to it, and scope commercial terms with you. A firewall engineer reviews each one; we do not run it through an automated qualification sequence. We also process the technical request data to keep the site available and to block automated abuse of the form.
Where it goes
Each application is written to our host's log service as a structured record. That record deliberately leaves out your email address, your name and your notes. It carries only an application id and reference, your company, fleet size, platform mix, coverage model, coverage hours and country.
The complete application, including your email address, is delivered to the notification endpoint we use to pick up new partner enquiries, so that an engineer sees it.
We also keep the complete application in a database hosted by our edge provider, so that we can find an enquiry again weeks later and answer questions about what we hold. That record contains everything you submitted, along with the country, the page you submitted from, your user-agent and the spam-check outcome.
The parties that process data on our behalf are our hosting and edge provider, which also provides the database and the spam check, and the service behind that notification endpoint. This site also loads its typeface from Google Fonts, which means your browser requests those font files directly from Google and Google receives your IP address as part of that request.
Analytics
This site uses Google Analytics 4 to count visits and see which pages get read. It loads with Google Consent Mode set to denied for every storage category, which means no analytics cookie is written and no identifier is stored on your device unless you later consent. Google receives a cookieless signal that a page was viewed and estimates the rest.
What that signal carries: the page URL, the referring page, approximate location derived from a truncated IP address, and general device and browser characteristics. If your browser sends a Do Not Track signal, the tag does not load at all.
Google Analytics also records a small set of interaction events, which it calls enhanced measurement. On this site those are:
- Page views, including the page title and address.
- Scroll depth, recorded once when you reach the bottom of a page. This tells us whether an article gets read or abandoned.
- Outbound clicks, meaning the address of a link you follow to another site.
- File downloads, meaning the name of a document opened from this site.
- Form starts and submissions, meaning the fact that a form on this site was begun or sent.
The last of those is worth stating plainly. Google is told that a form was started and that a form was submitted. Google is never sent what you typed into it. Your email address, company name, fleet size and any notes go to us alone, by the route described under Where it goes. Advertising storage and personalization are denied for every visitor, so none of this feeds ad targeting.
Google acts as our processor for this and may process the data outside your country.
Their handling is covered by
Google's
own notice on how it uses data from sites that use its services. You can opt out
across all sites with Google's browser add-on, or block the domains
googletagmanager.com and google-analytics.com. Blocking them
changes nothing else about how this site works.
What we do not do
Beyond the analytics described above, this site sets no cookies of its own and runs no advertising tags. We do not sell or share application data for anyone else's marketing, and we never approach your customers.
Stored in your browser
The multi-step application at /apply/ saves a draft of your answers
in your browser's local storage, under the key bonsai:apply-draft, so that
"Save and finish later" works. That draft never leaves your device and is cleared when you
submit. The hidden anti-spam field is never written to it.
Immediately after you submit, your reference is passed to the confirmation page through
session storage under bonsai:apply-result, and removed once that page has
read it. Clearing your browser storage removes both.
How long we keep it
Structured application records live in our host's log service and expire according to the retention window of the plan we are on. The full application persists in the system behind our notification endpoint under that system's own retention policy.
The database copy is kept for 30 days from the date you submit it, then deleted automatically. A scheduled job runs daily and removes anything past that point, so the period is enforced by the system rather than by someone remembering. Ask us sooner and we will delete the row before then.
Deleting the database copy does not reach the notification endpoint, which keeps its own copy under the retention policy described above. Ask us to remove that too and we will.
Your rights
You can ask us what we hold about you, ask for it to be corrected or deleted, or object to us processing it. Email us and we will action it. If your application was unsuccessful and you would rather we did not keep the record, say so and we will remove it.
Questions about this page, your data or a security disclosure: partners@bonsaisecurity.com.