Legal
Privacy Policy
How SECSQUAD collects, uses, and protects personal information when you use the SecScope website and client portal.
Last updated: June 2026Scope
This policy applies to the SecScope marketing website and the SecScope client portal (together, the “Services”). It does not cover the conduct of a penetration-testing engagement itself, which is governed by the separate agreement between you and SECSQUAD.
Information we collect
Information you provide
- Enquiries and demo requests — your name, work email, company, and any details you include when you contact us.
- Client portal account — account and profile details, the team members you invite, and the engagements associated with your organisation.
- Communications — messages you send us, including questions raised on findings within the portal.
Information collected automatically
- Usage data — pages viewed and actions taken, used to operate and improve the Services.
- Device and connection data — IP address, browser, and device information, collected for security and reliability.
- Cookies — see “Cookies” below.
How we use information
- To respond to your enquiries and provide requested demos.
- To operate, maintain, and secure the client portal and your account.
- To deliver engagement results, alerts, reports, and remediation tracking.
- To improve the Services and develop new features.
- To meet legal, regulatory, and contractual obligations.
- To send service communications, and — only with your consent — marketing.
Legal bases for processing
Where applicable data-protection law (such as the GDPR) applies, we process personal data on the basis of: performance of a contract; our legitimate interests in operating and securing the Services; your consent; and compliance with legal obligations.
Data retention
We retain personal information for as long as needed to provide the Services, comply with our legal obligations, resolve disputes, and enforce our agreements. Engagement data is retained in line with the terms of your engagement and your account settings.
Security
We apply organisational and technical measures appropriate to the sensitivity of the data we handle. No method of transmission or storage is completely secure, but protecting your data is central to how we operate.
International transfers
Where personal data is transferred across borders, we rely on appropriate safeguards (such as standard contractual clauses) as required by applicable law.
Your rights
Depending on your location, you may have the right to access, correct, delete, restrict, or object to processing of your personal data, to data portability, and to withdraw consent. You may also have the right to lodge a complaint with a supervisory authority. To exercise any of these rights, contact us at the address below.
Children
The Services are intended for businesses and are not directed at children.
Changes to this policy
We may update this policy from time to time. Material changes will be reflected by the “Last updated” date above.
Contact us
Questions about privacy or your data? Contact us at [email protected].
