Privacy Policy
Last updated August 2026
On this page+
This policy covers personal data we hold as controller: your account, your use of the platform, our website and our marketing. For personal data we process on your behalf inside systems you instruct us to test, our Data Processing Agreement applies instead. Below: what we collect, the lawful basis for each purpose, who we share it with, how long we keep it, and how to exercise your rights.
1. Introduction and Scope
1.1 AIPTx, a company registered in England and Wales, whose registered office is at 167-169 Great Portland Street, Fifth Floor, London, W1W 5PF, United Kingdom ("AIPTx", "we", "us"), is the controller of the personal data described in this policy.
1.2 This policy explains how we collect and use personal data when you visit our website, create an account, use the AIPTx platform, or contact us.
1.3 Two different roles. For personal data relating to your account, your use of the platform and your interactions with us, we are the controller and this policy applies. For personal data contained within systems you instruct us to test (including data incidentally captured in request and response evidence), you are the controller and we are the processor, and our Data Processing Agreement applies instead.
1.4 We comply with the UK General Data Protection Regulation (UK GDPR), the Data Protection Act 2018, and where applicable the EU GDPR and the Privacy and Electronic Communications Regulations 2003 (PECR).
1.5 Accountability. In accordance with Article 5(2) of the UK GDPR, we are responsible for, and are able to demonstrate, compliance with the data protection principles set out in Article 5(1) of the UK GDPR. We maintain appropriate policies, procedures, records and technical and organisational measures to support our compliance obligations, and we regularly review our data-processing activities to ensure that personal data is processed lawfully, fairly, transparently and securely.
2. Summary
What we collect, why, on what basis and how long we keep it. This table summarises the clauses that follow and does not replace them. Where a retention period has not been settled it is shown as outstanding rather than estimated.
| What | Why | Legal basis | How long |
|---|---|---|---|
| Account and contact details | To provide the Services | Contract | Duration of your account, plus a further period after closure (period to be confirmed) |
| Billing information | To take payment and meet accounting duties | Contract; legal obligation | Six years (statutory) |
| Assessment data and findings | To deliver and retain testing results | Contract | Per plan, see clause 7.3 (maximum to be confirmed) |
| Usage and technical data | To secure, operate and improve the Services | Legitimate interests | To be confirmed |
| Support correspondence | To answer you | Contract; legitimate interests | To be confirmed |
| Marketing communications | To tell you about our products | Consent, or legitimate interests under the PECR soft opt-in | Until you object |
| Cookies and analytics | To measure and improve the site | Consent (non-essential) | See Cookie Policy |
3. Information We Collect
3.1 Information you give us
- Name, email address, telephone number, job title and employer
- Account credentials, stored in hashed form
- Billing name, address and payment details
- Targets you configure, including URLs, domains and IP ranges
- Credentials you supply for authenticated testing, stored encrypted
- Support enquiries and correspondence
3.2 Information we obtain indirectly
In some circumstances we may receive personal data about you from third parties or other sources rather than directly from you. This may include information provided by your employer, colleagues, authorised users, service providers, business partners, publicly available sources, or other third parties in connection with our services. Where required by Article 14 of the UK GDPR, we will provide you with information about the source of that personal data and about the purposes and legal basis for processing it.
3.3 Information we collect automatically
- IP address, browser type and version, operating system and device information
- Pages visited, features used, timestamps and referring URLs
- Log and diagnostic data
- Cookie data, as set out in the Cookie Policy
3.4 Information generated by the Services
- Assessment results, findings, evidence and reports
- Risk scores and prioritisation output
3.5 Special category data
We do not knowingly collect special category data as defined in Article 9 of the UK GDPR in the course of controller processing. Where such data may be incidentally encountered during testing, the Data Processing Agreement governs.
4. Children
4.1 The Services are not intended for anyone under 18, and we do not knowingly collect personal data from children. We design and operate our Services with regard to applicable UK data-protection requirements, including the Information Commissioner's Office (ICO) Age Appropriate Design Code (Children's Code) where applicable. If you believe a child has provided us with personal data, please contact [email protected] and we will take appropriate steps to investigate and, where appropriate, delete the personal data in accordance with applicable law.
5. How We Use Your Information and Our Legal Basis
5.1 Under Article 6 of the UK GDPR we must have a lawful basis for each purpose for which we process personal data. They are:
| Purpose | Lawful basis |
|---|---|
| Creating and administering your account | Contract: necessary to perform our agreement with you |
| Providing the Services, running assessments, producing reports | Contract |
| Taking payment and managing subscriptions | Contract |
| Keeping accounting and tax records | Legal obligation |
| Providing support | Contract, and legitimate interests in maintaining service quality |
| Securing the Services, preventing fraud and abuse, investigating unauthorised use | Legitimate interests: protecting our platform, our customers and third parties |
| Monitoring performance and improving the Services | Legitimate interests: operating and developing a product our customers rely on |
| Producing aggregated, anonymised statistics | Legitimate interests: this data does not identify anyone |
| Sending service and security notifications | Contract, and legal obligation where a breach notification is required |
| Marketing to existing customers about similar products | Legitimate interests, under the PECR soft opt-in where it applies; otherwise consent (to be confirmed) |
| Marketing to prospective customers | Consent (to be confirmed) |
| Responding to lawful requests from authorities | Legal obligation |
5.2 Where we rely on legitimate interests, we have carried out a balancing assessment to confirm that our interests are not overridden by your interests, rights and freedoms. You may request a summary of that assessment from [email protected], and you have the right to object under clause 10.6.
5.3 Where we rely on consent, you may withdraw it at any time. Withdrawal does not affect the lawfulness of processing carried out before withdrawal.
6. Sharing Your Information
6.1 We do not sell personal data.
6.2 We share personal data with the following recipients:
- Cloud infrastructure and hosting providers
- Payment processing providers
- Customer support and communications providers
- Website and product analytics providers
- Professional advisers, including our auditors, accountants and lawyers
The providers that set cookies on our website, or that receive analytics and advertising data from it, are named in our Cookie Policy. The named register of every recipient, the service it provides and the country in which it processes is maintained by us and provided on written request to [email protected]. It is not yet published at a public URL.
6.3 We may disclose personal data where required by law, court order or a lawful request from a competent authority, and where necessary to establish, exercise or defend legal claims.
6.4 In the event of a merger, acquisition or sale of assets, personal data may be transferred, subject to this policy continuing to apply.
6.5 Each processor we engage is bound by a written contract meeting the requirements of Article 28 of the UK GDPR.
6.6 Processors and onward engagement. Where we engage another organisation to process personal data on our behalf, we comply with the requirements of Article 28 of the UK GDPR. Where authorisation is required for the appointment, we obtain it, and we ensure that each such organisation is bound by a written agreement imposing data-protection obligations no less protective than those applicable to us. We remain responsible for the performance of those organisations to the extent required by applicable data-protection law. Where AIPTx acts as processor rather than controller, the corresponding obligations for the organisations engaged in that role are set out in clause 8 of the Data Processing Agreement.
7. How Long We Keep It
7.1 We keep personal data no longer than is necessary for the purposes set out in clause 5.
7.2 Account data is retained for the life of your account and for a further period after closure, to handle queries and disputes. The length of that period is to be confirmed.
7.3 Assessment data and findings. Your plan determines how long historical assessment results remain available to you in the platform. This is a feature of the product, not a measure of how long we consider it necessary to hold your data:
| Plan | Historical assessment data available for |
|---|---|
| Starter | 30 days |
| Professional | 12 months |
| Enterprise | Configurable, subject to a maximum (to be confirmed) |
Assessment data is deleted after the applicable period regardless of plan, and a maximum applies beyond which it is deleted in every case, whatever the plan provides. You may delete assessment data at any time.
7.4 Billing and accounting records are retained for six years from the end of the relevant financial year, as required by UK law.
7.5 Security and audit logs are retained for a defined period recorded in our retention schedule. The period is to be confirmed.
7.6 Backups are retained for 30 days, after which deleted data is removed from backup media in the ordinary rotation.
8. Automated Processing and the AI Risk Engine
8.1 We are transparent about where automated processing takes place.
8.2 What is automated. The Services use automated analysis to discover assets, test for vulnerabilities, validate findings by attempting exploitation, and rank findings by risk. Ranking uses weighted factors (exploitability, impact, asset value and exposure), and the weights are published on our AI Risk Engine page, so the arithmetic behind a finding's position can be followed rather than taken on trust.
8.2(a) Data Protection Impact Assessments. Where required by Article 35 of the UK GDPR, we will carry out a Data Protection Impact Assessment before undertaking processing that is likely to result in a high risk to individuals' rights and freedoms. The assessment will consider the necessity and proportionality of the processing, the risks to individuals, and the measures we intend to implement to address and mitigate those risks. Where required, we will also consult the Information Commissioner's Office in accordance with Article 36 of the UK GDPR.
8.3 What these decisions are about. These are assessments of security findings in systems, not of people. The output ranks vulnerabilities; it does not evaluate, score or make decisions about individuals.
8.4 Article 22. We do not make decisions producing legal effects concerning you, or similarly significantly affecting you, based solely on automated processing.
8.5 Automated abuse prevention. We use automated checks to detect unauthorised scanning, abuse and fraud. Where such a check results in restricted access, you may request human review by contacting [email protected], and you have the right to contest the outcome.
8.6 We do not use customer data to train machine learning models, whether our own or those of a third party.
9. Data Security
9.1 We implement appropriate technical and organisational measures under Article 32 of the UK GDPR, including encryption of data at rest using AES-256 and in transit using TLS 1.3, multi-factor authentication, role-based access control, logging and monitoring, and secure development practices. Full detail is in our Security Policy.
9.2 No system can be guaranteed completely secure. We maintain incident response procedures and, where required under Article 33 of the UK GDPR, will notify the Information Commissioner's Office of a personal data breach without undue delay and, where feasible, within 72 hours of becoming aware of it. Where the breach is likely to result in a high risk to your rights and freedoms, we will also notify you without undue delay, in accordance with Article 34 of the UK GDPR.
9.3 Records of Processing Activities. We maintain records of our processing activities where required by Article 30 of the UK GDPR. These records contain the information required by law, including, where applicable, the purposes of processing, the categories of personal data and of individuals concerned, the categories of recipients, details of international transfers, applicable retention periods, and a general description of the technical and organisational security measures implemented. We will make these records available to the Information Commissioner's Office where required by law. The separate record we maintain as processor, under Article 30(2), is described in the Data Processing Agreement. Both records are required and neither replaces the other.
10. Your Rights
You have the following rights in relation to the personal data we hold about you as controller.
10.1 Access: a copy of the personal data we hold about you.
10.2 Rectification: correction of inaccurate or incomplete data.
10.3 Erasure: deletion, where one of the grounds in Article 17 applies.
10.4 Restriction: to limit how we use your data in certain circumstances.
10.5 Portability: to receive data you provided in a structured, commonly used, machine-readable format, and to have it transmitted to another controller where technically feasible.
10.6 Objection: to processing based on legitimate interests, and at any time to direct marketing.
10.7 Withdraw consent: where processing is based on consent.
10.8 Rights relating to automated decision-making: as described in clause 8.
10.9 To complain to the ICO. You have the right to lodge a complaint with the Information Commissioner's Office, the UK supervisory authority. Contact details are in clause 14. You may complain to the ICO without contacting us first, although we would welcome the opportunity to resolve the matter directly. You also have the right to an effective judicial remedy in accordance with Articles 78 and 79 of the UK GDPR, including the right to bring proceedings where you consider that your rights under the UK GDPR have been infringed.
10.10 Right to compensation. You have the right to receive compensation for any material or non-material damage you suffer as a result of an infringement of the UK GDPR. This right is set out in Article 82 of the UK GDPR. Where applicable, you may seek compensation from us, or from another controller or processor responsible for the damage, subject to the conditions and limitations set out in the UK GDPR.
10.11 To exercise any right, contact [email protected]. We respond within one month, extendable by two further months for complex requests, in which case we will tell you within the first month. There is no charge unless a request is manifestly unfounded or excessive.
10.12 We may need to verify your identity before acting on a request.
11. International Transfers
11.1 We process personal data in the countries in which we and our hosting and service providers operate. The specific countries and regions are being confirmed and will be recorded here; you may request the current position at any time from [email protected]. Where personal data is processed outside the United Kingdom, clause 11.2 applies.
11.2 Transfers out of the UK. Where personal data subject to UK GDPR is transferred to a country not covered by UK adequacy regulations, we use:
- (a) the UK International Data Transfer Agreement (IDTA); or
- (b) the EU Standard Contractual Clauses with the UK Addendum issued by the Information Commissioner under section 119A(1) of the Data Protection Act 2018,
supported by a transfer risk assessment and any additional safeguards it identifies.
11.3 EU Standard Contractual Clauses alone are not a valid mechanism for transfers of UK personal data.
11.4 Transfers out of the EEA. Where EU GDPR applies, transfers to countries without an adequacy decision are made under the EU Standard Contractual Clauses.
11.5 You may request a copy of the safeguards in place by contacting [email protected].
12. Cookies
12.1 We use cookies and similar technologies. Non-essential cookies are set only with your consent, as required by PECR. See our Cookie Policy for full detail and to change your preferences.
13. Changes to This Policy
13.1 We may update this policy. Material changes will be notified by email and by notice on this page at least 30 days before they take effect.
13.2 Previous versions and their effective dates are recorded in clause 15.
14. Contact Us
Data protection enquiries and rights requests
- Data protection contact: [email protected]
- General privacy enquiries: [email protected]
- Security: [email protected]
- Legal: [email protected]
Registered office
- 167-169 Great Portland Street
- Fifth Floor
- London, W1W 5PF
- United Kingdom
Registered in England and Wales.
Representative in the European Economic Area
Where we are required to designate a representative in the European Economic Area under Article 27 of the EU GDPR, the details will be published here.
Complaints to the supervisory authority
You have the right to lodge a complaint with the Information Commissioner's Office, the UK supervisory authority for data protection, as set out in clause 10.9.
- Information Commissioner's Office
- Wycliffe House, Water Lane, Wilmslow, Cheshire, SK9 5AF
- Telephone: 0303 123 1113
- ico.org.uk
15. Version History
| Version | Effective date | Summary |
|---|---|---|
| 2.1 | To be confirmed | UK GDPR alignment; Article 6 lawful basis disclosed per purpose; controller and processor roles separated; summary table; ICO complaint right, judicial remedy under Articles 78 and 79 and right to compensation under Article 82; UK transfer mechanisms under the IDTA or UK Addendum; automated processing and AI Risk Engine disclosure; accountability under Article 5(2); information obtained indirectly under Article 14; the Children's Code; processor engagement under Article 28; DPIAs under Article 35; breach notification under Articles 33 and 34; Records of Processing Activities under Article 30; plan-tier retention reframed; UK registered office |
| 1.0 | 29 December 2025 | Initial version |