Privacy Policy
Last updated: May 16, 2026
Threatstealth Ltd ("Threatstealth", "we", "us", "our") is committed to protecting your personal data. This Privacy Policy explains how we collect, use, share, and protect information about visitors to our website (threatstealth.com) and customers of the Threatstealth cybersecurity platform ("Platform").
1. Who we are
Threatstealth is the data controller for personal data collected via the website and from account administrators. For Platform customer data, we act as a data processor — our customers are the data controllers. This distinction is set out in our Data Processing Agreement.
2. Data we collect
2.1 Account and contact data
- Name, work email address, job title, company name
- Authentication credentials (passwords stored as bcrypt hashes; we never store plaintext passwords)
- MFA settings (TOTP secrets, encrypted at rest with AES-256-GCM)
- Contact form submissions (name, email, company, message)
2.2 Usage and telemetry data
- Log data: IP address, user-agent, request path, HTTP method, response code, and timestamp for all API requests
- Session tokens (HttpOnly, Secure cookies; never stored in localStorage)
- Platform usage metrics: module access, feature usage, alert interaction
2.3 Customer security data (as processor)
When organisations use the Platform, they may submit security-sensitive data including alerts, threat intelligence, endpoint telemetry, compliance evidence, and employee information for phishing simulation. This data is processed under their instructions and under our DPA.
3. Legal basis for processing (GDPR Article 6)
- Contract performance — processing necessary to provide the Platform services to our customers
- Legitimate interests — security monitoring, fraud prevention, product improvement, and marketing to business users
- Consent — marketing emails (you may withdraw at any time)
- Legal obligation — compliance with applicable laws
4. How we use your data
- Provisioning and operating your Threatstealth account
- Authenticating your identity and enforcing multi-factor authentication
- Providing customer support and responding to enquiries
- Sending transactional emails (account alerts, security notices, renewal reminders)
- Sending marketing communications (with your consent; unsubscribe any time)
- Improving the Platform through aggregated, anonymised usage analytics
- Detecting and preventing fraud, abuse, and security incidents
- Complying with legal obligations and enforcing our Terms of Service
5. Data sharing and subprocessors
We do not sell personal data. We share data only with subprocessors required to deliver the service. A current list is available at /legal/subprocessors. Key subprocessors include cloud infrastructure (AWS), email delivery, and payment processing.
We may disclose data to law enforcement or regulatory authorities when required by applicable law, with appropriate safeguards.
6. International transfers
Customer data is stored in the EU (AWS eu-west-1) by default. For customers requiring data residency in other regions (US, APAC), this is configurable under an Enterprise plan. Cross-border transfers to non-EEA countries are governed by Standard Contractual Clauses (SCCs) under EU GDPR Article 46(2)(c).
7. Data retention
- Account data: retained for the duration of your subscription plus 30 days for recovery, then deleted
- Audit logs: retained for the period specified in your plan (90 days for Startup; 1 year for Professional; custom for Enterprise)
- Contact enquiries: 2 years from submission
- Marketing contact data: until you withdraw consent or request deletion
8. Your rights (GDPR / CCPA)
Depending on your jurisdiction, you may have the following rights:
- Access — request a copy of the personal data we hold about you
- Rectification — correct inaccurate personal data
- Erasure — request deletion of your personal data ("right to be forgotten")
- Portability — receive your data in a structured, machine-readable format
- Restriction — request that we limit processing of your data
- Objection — object to processing based on legitimate interests or for direct marketing
- CCPA opt-out — California residents may opt out of the sale of personal information (we do not sell data)
To exercise any right, email privacy@threatstealth.com or use the data deletion request form at /data-deletion-requests. We will respond within 30 days.
9. Security
We implement AES-256-GCM encryption at rest, TLS 1.3 in transit, MFA, RBAC, immutable audit logging, annual third-party penetration testing, and continuous SAST/DAST scanning. See our Trust & Security page for full details.
10. Cookies
We use strictly necessary cookies for authentication (HttpOnly, Secure, SameSite=Strict). We do not use advertising or tracking cookies. No third-party analytics scripts are loaded without consent.
11. Changes to this policy
We will notify customers of material changes to this Privacy Policy by email and by posting the updated policy with a new "Last updated" date at least 30 days before changes take effect.
12. Contact
Privacy enquiries: privacy@threatstealth.com
Data deletion requests: threatstealth.com/data-deletion-requests
Security concerns: security@threatstealth.com
