Skip to main content
Threatstealth
Login

Privacy Policy

Last updated: May 16, 2026

Threatstealth Ltd ("Threatstealth", "we", "us", "our") is committed to protecting your personal data. This Privacy Policy explains how we collect, use, share, and protect information about visitors to our website (threatstealth.com) and customers of the Threatstealth cybersecurity platform ("Platform").

1. Who we are

Threatstealth is the data controller for personal data collected via the website and from account administrators. For Platform customer data, we act as a data processor — our customers are the data controllers. This distinction is set out in our Data Processing Agreement.

2. Data we collect

2.1 Account and contact data

2.2 Usage and telemetry data

2.3 Customer security data (as processor)

When organisations use the Platform, they may submit security-sensitive data including alerts, threat intelligence, endpoint telemetry, compliance evidence, and employee information for phishing simulation. This data is processed under their instructions and under our DPA.

3. Legal basis for processing (GDPR Article 6)

4. How we use your data

5. Data sharing and subprocessors

We do not sell personal data. We share data only with subprocessors required to deliver the service. A current list is available at /legal/subprocessors. Key subprocessors include cloud infrastructure (AWS), email delivery, and payment processing.

We may disclose data to law enforcement or regulatory authorities when required by applicable law, with appropriate safeguards.

6. International transfers

Customer data is stored in the EU (AWS eu-west-1) by default. For customers requiring data residency in other regions (US, APAC), this is configurable under an Enterprise plan. Cross-border transfers to non-EEA countries are governed by Standard Contractual Clauses (SCCs) under EU GDPR Article 46(2)(c).

7. Data retention

8. Your rights (GDPR / CCPA)

Depending on your jurisdiction, you may have the following rights:

To exercise any right, email privacy@threatstealth.com or use the data deletion request form at /data-deletion-requests. We will respond within 30 days.

9. Security

We implement AES-256-GCM encryption at rest, TLS 1.3 in transit, MFA, RBAC, immutable audit logging, annual third-party penetration testing, and continuous SAST/DAST scanning. See our Trust & Security page for full details.

10. Cookies

We use strictly necessary cookies for authentication (HttpOnly, Secure, SameSite=Strict). We do not use advertising or tracking cookies. No third-party analytics scripts are loaded without consent.

11. Changes to this policy

We will notify customers of material changes to this Privacy Policy by email and by posting the updated policy with a new "Last updated" date at least 30 days before changes take effect.

12. Contact

Privacy enquiries: privacy@threatstealth.com
Data deletion requests: threatstealth.com/data-deletion-requests
Security concerns: security@threatstealth.com