Skip to main content

Privacy Policy

Last updated August 2026

On this page
  1. 01Introduction and Scope
  2. 02Summary
  3. 03Information We Collect
  4. 04Children
  5. 05How We Use Your Data
  6. 06Sharing Your Information
  7. 07How Long We Keep It
  8. 08Automated Processing
  9. 09Data Security
  10. 10Your Rights
  11. 11International Transfers
  12. 12Cookies
  13. 13Changes to This Policy
  14. 14Contact Us
  15. 15Version History

This policy covers personal data we hold as controller: your account, your use of the platform, our website and our marketing. For personal data we process on your behalf inside systems you instruct us to test, our Data Processing Agreement applies instead. Below: what we collect, the lawful basis for each purpose, who we share it with, how long we keep it, and how to exercise your rights.

1. Introduction and Scope

1.1 AIPTx, a company registered in England and Wales, whose registered office is at 167-169 Great Portland Street, Fifth Floor, London, W1W 5PF, United Kingdom ("AIPTx", "we", "us"), is the controller of the personal data described in this policy.

1.2 This policy explains how we collect and use personal data when you visit our website, create an account, use the AIPTx platform, or contact us.

1.3 Two different roles. For personal data relating to your account, your use of the platform and your interactions with us, we are the controller and this policy applies. For personal data contained within systems you instruct us to test (including data incidentally captured in request and response evidence), you are the controller and we are the processor, and our Data Processing Agreement applies instead.

1.4 We comply with the UK General Data Protection Regulation (UK GDPR), the Data Protection Act 2018, and where applicable the EU GDPR and the Privacy and Electronic Communications Regulations 2003 (PECR).

1.5 Accountability. In accordance with Article 5(2) of the UK GDPR, we are responsible for, and are able to demonstrate, compliance with the data protection principles set out in Article 5(1) of the UK GDPR. We maintain appropriate policies, procedures, records and technical and organisational measures to support our compliance obligations, and we regularly review our data-processing activities to ensure that personal data is processed lawfully, fairly, transparently and securely.

2. Summary

What we collect, why, on what basis and how long we keep it. This table summarises the clauses that follow and does not replace them. Where a retention period has not been settled it is shown as outstanding rather than estimated.

WhatWhyLegal basisHow long
Account and contact detailsTo provide the ServicesContractDuration of your account, plus a further period after closure (period to be confirmed)
Billing informationTo take payment and meet accounting dutiesContract; legal obligationSix years (statutory)
Assessment data and findingsTo deliver and retain testing resultsContractPer plan, see clause 7.3 (maximum to be confirmed)
Usage and technical dataTo secure, operate and improve the ServicesLegitimate interestsTo be confirmed
Support correspondenceTo answer youContract; legitimate interestsTo be confirmed
Marketing communicationsTo tell you about our productsConsent, or legitimate interests under the PECR soft opt-inUntil you object
Cookies and analyticsTo measure and improve the siteConsent (non-essential)See Cookie Policy

3. Information We Collect

3.1 Information you give us

  • Name, email address, telephone number, job title and employer
  • Account credentials, stored in hashed form
  • Billing name, address and payment details
  • Targets you configure, including URLs, domains and IP ranges
  • Credentials you supply for authenticated testing, stored encrypted
  • Support enquiries and correspondence

3.2 Information we obtain indirectly

In some circumstances we may receive personal data about you from third parties or other sources rather than directly from you. This may include information provided by your employer, colleagues, authorised users, service providers, business partners, publicly available sources, or other third parties in connection with our services. Where required by Article 14 of the UK GDPR, we will provide you with information about the source of that personal data and about the purposes and legal basis for processing it.

3.3 Information we collect automatically

  • IP address, browser type and version, operating system and device information
  • Pages visited, features used, timestamps and referring URLs
  • Log and diagnostic data
  • Cookie data, as set out in the Cookie Policy

3.4 Information generated by the Services

  • Assessment results, findings, evidence and reports
  • Risk scores and prioritisation output

3.5 Special category data

We do not knowingly collect special category data as defined in Article 9 of the UK GDPR in the course of controller processing. Where such data may be incidentally encountered during testing, the Data Processing Agreement governs.

4. Children

4.1 The Services are not intended for anyone under 18, and we do not knowingly collect personal data from children. We design and operate our Services with regard to applicable UK data-protection requirements, including the Information Commissioner's Office (ICO) Age Appropriate Design Code (Children's Code) where applicable. If you believe a child has provided us with personal data, please contact [email protected] and we will take appropriate steps to investigate and, where appropriate, delete the personal data in accordance with applicable law.

6. Sharing Your Information

6.1 We do not sell personal data.

6.2 We share personal data with the following recipients:

  • Cloud infrastructure and hosting providers
  • Payment processing providers
  • Customer support and communications providers
  • Website and product analytics providers
  • Professional advisers, including our auditors, accountants and lawyers

The providers that set cookies on our website, or that receive analytics and advertising data from it, are named in our Cookie Policy. The named register of every recipient, the service it provides and the country in which it processes is maintained by us and provided on written request to [email protected]. It is not yet published at a public URL.

6.3 We may disclose personal data where required by law, court order or a lawful request from a competent authority, and where necessary to establish, exercise or defend legal claims.

6.4 In the event of a merger, acquisition or sale of assets, personal data may be transferred, subject to this policy continuing to apply.

6.5 Each processor we engage is bound by a written contract meeting the requirements of Article 28 of the UK GDPR.

6.6 Processors and onward engagement. Where we engage another organisation to process personal data on our behalf, we comply with the requirements of Article 28 of the UK GDPR. Where authorisation is required for the appointment, we obtain it, and we ensure that each such organisation is bound by a written agreement imposing data-protection obligations no less protective than those applicable to us. We remain responsible for the performance of those organisations to the extent required by applicable data-protection law. Where AIPTx acts as processor rather than controller, the corresponding obligations for the organisations engaged in that role are set out in clause 8 of the Data Processing Agreement.

7. How Long We Keep It

7.1 We keep personal data no longer than is necessary for the purposes set out in clause 5.

7.2 Account data is retained for the life of your account and for a further period after closure, to handle queries and disputes. The length of that period is to be confirmed.

7.3 Assessment data and findings. Your plan determines how long historical assessment results remain available to you in the platform. This is a feature of the product, not a measure of how long we consider it necessary to hold your data:

PlanHistorical assessment data available for
Starter30 days
Professional12 months
EnterpriseConfigurable, subject to a maximum (to be confirmed)

Assessment data is deleted after the applicable period regardless of plan, and a maximum applies beyond which it is deleted in every case, whatever the plan provides. You may delete assessment data at any time.

7.4 Billing and accounting records are retained for six years from the end of the relevant financial year, as required by UK law.

7.5 Security and audit logs are retained for a defined period recorded in our retention schedule. The period is to be confirmed.

7.6 Backups are retained for 30 days, after which deleted data is removed from backup media in the ordinary rotation.

8. Automated Processing and the AI Risk Engine

8.1 We are transparent about where automated processing takes place.

8.2 What is automated. The Services use automated analysis to discover assets, test for vulnerabilities, validate findings by attempting exploitation, and rank findings by risk. Ranking uses weighted factors (exploitability, impact, asset value and exposure), and the weights are published on our AI Risk Engine page, so the arithmetic behind a finding's position can be followed rather than taken on trust.

8.2(a) Data Protection Impact Assessments. Where required by Article 35 of the UK GDPR, we will carry out a Data Protection Impact Assessment before undertaking processing that is likely to result in a high risk to individuals' rights and freedoms. The assessment will consider the necessity and proportionality of the processing, the risks to individuals, and the measures we intend to implement to address and mitigate those risks. Where required, we will also consult the Information Commissioner's Office in accordance with Article 36 of the UK GDPR.

8.3 What these decisions are about. These are assessments of security findings in systems, not of people. The output ranks vulnerabilities; it does not evaluate, score or make decisions about individuals.

8.4 Article 22. We do not make decisions producing legal effects concerning you, or similarly significantly affecting you, based solely on automated processing.

8.5 Automated abuse prevention. We use automated checks to detect unauthorised scanning, abuse and fraud. Where such a check results in restricted access, you may request human review by contacting [email protected], and you have the right to contest the outcome.

8.6 We do not use customer data to train machine learning models, whether our own or those of a third party.

9. Data Security

9.1 We implement appropriate technical and organisational measures under Article 32 of the UK GDPR, including encryption of data at rest using AES-256 and in transit using TLS 1.3, multi-factor authentication, role-based access control, logging and monitoring, and secure development practices. Full detail is in our Security Policy.

9.2 No system can be guaranteed completely secure. We maintain incident response procedures and, where required under Article 33 of the UK GDPR, will notify the Information Commissioner's Office of a personal data breach without undue delay and, where feasible, within 72 hours of becoming aware of it. Where the breach is likely to result in a high risk to your rights and freedoms, we will also notify you without undue delay, in accordance with Article 34 of the UK GDPR.

9.3 Records of Processing Activities. We maintain records of our processing activities where required by Article 30 of the UK GDPR. These records contain the information required by law, including, where applicable, the purposes of processing, the categories of personal data and of individuals concerned, the categories of recipients, details of international transfers, applicable retention periods, and a general description of the technical and organisational security measures implemented. We will make these records available to the Information Commissioner's Office where required by law. The separate record we maintain as processor, under Article 30(2), is described in the Data Processing Agreement. Both records are required and neither replaces the other.

10. Your Rights

You have the following rights in relation to the personal data we hold about you as controller.

10.1 Access: a copy of the personal data we hold about you.

10.2 Rectification: correction of inaccurate or incomplete data.

10.3 Erasure: deletion, where one of the grounds in Article 17 applies.

10.4 Restriction: to limit how we use your data in certain circumstances.

10.5 Portability: to receive data you provided in a structured, commonly used, machine-readable format, and to have it transmitted to another controller where technically feasible.

10.6 Objection: to processing based on legitimate interests, and at any time to direct marketing.

10.7 Withdraw consent: where processing is based on consent.

10.8 Rights relating to automated decision-making: as described in clause 8.

10.9 To complain to the ICO. You have the right to lodge a complaint with the Information Commissioner's Office, the UK supervisory authority. Contact details are in clause 14. You may complain to the ICO without contacting us first, although we would welcome the opportunity to resolve the matter directly. You also have the right to an effective judicial remedy in accordance with Articles 78 and 79 of the UK GDPR, including the right to bring proceedings where you consider that your rights under the UK GDPR have been infringed.

10.10 Right to compensation. You have the right to receive compensation for any material or non-material damage you suffer as a result of an infringement of the UK GDPR. This right is set out in Article 82 of the UK GDPR. Where applicable, you may seek compensation from us, or from another controller or processor responsible for the damage, subject to the conditions and limitations set out in the UK GDPR.

10.11 To exercise any right, contact [email protected]. We respond within one month, extendable by two further months for complex requests, in which case we will tell you within the first month. There is no charge unless a request is manifestly unfounded or excessive.

10.12 We may need to verify your identity before acting on a request.

11. International Transfers

11.1 We process personal data in the countries in which we and our hosting and service providers operate. The specific countries and regions are being confirmed and will be recorded here; you may request the current position at any time from [email protected]. Where personal data is processed outside the United Kingdom, clause 11.2 applies.

11.2 Transfers out of the UK. Where personal data subject to UK GDPR is transferred to a country not covered by UK adequacy regulations, we use:

  • (a) the UK International Data Transfer Agreement (IDTA); or
  • (b) the EU Standard Contractual Clauses with the UK Addendum issued by the Information Commissioner under section 119A(1) of the Data Protection Act 2018,

supported by a transfer risk assessment and any additional safeguards it identifies.

11.3 EU Standard Contractual Clauses alone are not a valid mechanism for transfers of UK personal data.

11.4 Transfers out of the EEA. Where EU GDPR applies, transfers to countries without an adequacy decision are made under the EU Standard Contractual Clauses.

11.5 You may request a copy of the safeguards in place by contacting [email protected].

12. Cookies

12.1 We use cookies and similar technologies. Non-essential cookies are set only with your consent, as required by PECR. See our Cookie Policy for full detail and to change your preferences.

13. Changes to This Policy

13.1 We may update this policy. Material changes will be notified by email and by notice on this page at least 30 days before they take effect.

13.2 Previous versions and their effective dates are recorded in clause 15.

14. Contact Us

Data protection enquiries and rights requests

Registered office

  • 167-169 Great Portland Street
  • Fifth Floor
  • London, W1W 5PF
  • United Kingdom

Registered in England and Wales.

Representative in the European Economic Area

Where we are required to designate a representative in the European Economic Area under Article 27 of the EU GDPR, the details will be published here.

Complaints to the supervisory authority

You have the right to lodge a complaint with the Information Commissioner's Office, the UK supervisory authority for data protection, as set out in clause 10.9.

  • Information Commissioner's Office
  • Wycliffe House, Water Lane, Wilmslow, Cheshire, SK9 5AF
  • Telephone: 0303 123 1113
  • ico.org.uk

15. Version History

VersionEffective dateSummary
2.1To be confirmedUK GDPR alignment; Article 6 lawful basis disclosed per purpose; controller and processor roles separated; summary table; ICO complaint right, judicial remedy under Articles 78 and 79 and right to compensation under Article 82; UK transfer mechanisms under the IDTA or UK Addendum; automated processing and AI Risk Engine disclosure; accountability under Article 5(2); information obtained indirectly under Article 14; the Children's Code; processor engagement under Article 28; DPIAs under Article 35; breach notification under Articles 33 and 34; Records of Processing Activities under Article 30; plan-tier retention reframed; UK registered office
1.029 December 2025Initial version