Privacy Policy
Version 2026-07-24
1. Who we are
Threat Detective Ltd, a company incorporated in England and Wales, is the data controller for the personal data we collect about visitors and account holders. The Information Commissioner's Office (ICO) is our lead supervisory authority.
2. What we collect
- Account data: name, email address, organisation, hashed password (or federated identity for users who sign in with GitHub or Google).
- Usage data: request logs, audit-log entries, and pageview events captured for product analytics. Analytics uses PostHog (EU-hosted) in cookieless mode — nothing is stored on your device, there is no element-level autocapture, and no session recording.
- Customer content: SBOMs, component metadata, vulnerability triage notes uploaded by you. Where this contains personal data, we process it on your instructions as a processor under the Data Processing Agreement.
3. Lawful bases (UK GDPR Article 6)
- Contract: to provide the Service to you.
- Legitimate interests: to secure the Service, prevent fraud, and improve product features — including cookieless, first-party product analytics on authenticated business users (PostHog EU).
- Consent: for marketing communications.
4. How long we keep it
We keep personal data only for as long as we need it for the purposes set out in this policy or as required by law. The headline retention periods are:
| Category | Retention | Reason |
|---|---|---|
| Account data (name, email, hashed credentials, federated identity) | Life of the account, then 30 days | Service provision; account recovery window after deletion |
| Customer content (SBOMs, components, triage notes) | Life of the account, then up to 90 days | Service provision; export window after termination |
| Audit logs and security event logs | 7 years | Legitimate interest in security investigations and regulatory record-keeping |
| Web request logs and request metadata | 90 days | Service operation, abuse prevention, debugging |
| Backups | Up to 30 days, on a rolling basis | Disaster recovery |
| Product analytics events (PostHog EU, cookieless) | 12 months | Product improvement; legitimate interest |
| Marketing consent records | Until withdrawn, then 3 years | Demonstrating lawful basis under UK GDPR Article 7(1) |
| Billing and tax records | 7 years | UK statutory retention (Companies Act 2006; HMRC requirements) |
Where law requires us to keep records longer than the periods above (for example for tax, fraud or litigation purposes), we will do so.
5. Subprocessors and international transfers
We use the subprocessors listed at /subprocessors. Where personal data is transferred outside the United Kingdom, we rely on the UK International Data Transfer Agreement (UK IDTA) or the UK Addendum to the EU Standard Contractual Clauses, supplemented by appropriate technical and organisational safeguards.
6. Your rights
Under UK GDPR you have rights of access, rectification, erasure, restriction, portability and objection. Email [email protected] to exercise them. You may also lodge a complaint with the ICO at ico.org.uk.
7. Cookies
We set only strictly necessary cookies — see our Cookie Policy for the full list.
8. Contact
Questions about this policy: [email protected].