Last Updated: March 3, 2026
The data controller responsible for your personal information is:
Pentesys LtdIf you have any questions about this Privacy Policy or our data practices, please contact our Data Protection Officer at [email protected].
| Category | Examples |
|---|---|
| Account Information | Name, email address, company name, job title, phone number, password (hashed) |
| Billing Information | Payment card details (processed by Stripe), billing address, VAT number, invoice history |
| Organisation Information | Company name, industry, size, domains owned, team member details |
| Target Information | Domain names, IP addresses, URLs, network ranges submitted for testing |
| Communications | Support tickets, chat messages, emails, feedback, survey responses |
| Category | Examples |
|---|---|
| Usage Data | Pages visited, features used, actions taken, time spent, click patterns |
| Device Information | IP address, browser type, operating system, device identifiers, screen resolution |
| Log Data | Access times, error logs, referrer URLs, API calls, authentication events |
| Location Data | Country and city (derived from IP address), timezone |
When you use our security testing services, we may collect:
| Purpose | Description |
|---|---|
| Service Delivery | Providing attack surface monitoring, penetration testing, and security assessments |
| Account Management | Creating and managing your account, authenticating users, processing subscriptions |
| Billing & Payments | Processing payments, managing credits, sending invoices, handling refunds |
| Communication | Sending service notifications, security alerts, support responses, and (with consent) marketing |
| Platform Improvement | Analysing usage patterns, debugging issues, developing new features |
| Security | Detecting fraud, preventing abuse, protecting our systems and users |
| Legal Compliance | Meeting regulatory requirements, responding to legal requests, enforcing our Terms |
| Research & Analytics | Aggregated, anonymised analysis to improve security intelligence and industry benchmarks |
Under the General Data Protection Regulation (GDPR), we process your personal data on the following legal bases:
| Legal Basis | Processing Activities |
|---|---|
| Contract Performance Article 6(1)(b) |
|
| Legitimate Interests Article 6(1)(f) |
|
| Consent Article 6(1)(a) |
|
| Legal Obligation Article 6(1)(c) |
|
We share data with trusted service providers who assist in operating our Platform:
| Provider Category | Purpose | Data Shared |
|---|---|---|
| Cloud Infrastructure | Hosting and data storage | All platform data (encrypted) |
| Payment Processing (Stripe) | Handling payments | Billing information, transaction details |
| Email Services | Sending notifications | Email addresses, message content |
| Analytics | Platform improvement | Usage data (anonymised where possible) |
| Customer Support | Ticket management | Contact details, support history |
We may disclose your information in the following circumstances:
Your data may be transferred to and processed in countries outside the UK and European Economic Area (EEA). When we transfer data internationally, we ensure appropriate safeguards are in place:
You may request a copy of the safeguards we use by contacting [email protected].
We implement comprehensive security measures to protect your personal information:
The Platform uses a multi-tenant architecture with strict data isolation. Your data is logically separated from other customers and accessible only by your authorised users.
In the event of a personal data breach that poses a risk to your rights, we will:
We retain your personal data only for as long as necessary to fulfil the purposes for which it was collected:
| Data Type | Retention Period | Reason |
|---|---|---|
| Account Information | Duration of account + 2 years | Service delivery, re-activation |
| Security Scan Results | 12 months from scan date | Trend analysis, historical comparison |
| Penetration Test Reports | 7 years | Compliance, audit requirements |
| Billing Records | 7 years | Legal and tax requirements |
| Support Communications | 3 years | Service improvement, dispute resolution |
| Security Logs | 1 year | Security monitoring, incident investigation |
| Marketing Preferences | Until consent withdrawn | Respecting your preferences |
After the retention period, data is securely deleted or anonymised for statistical purposes.
Under data protection laws, you have the following rights:
Request a copy of the personal data we hold about you.
Request correction of inaccurate or incomplete data.
Request deletion of your personal data ("right to be forgotten").
Request limitation of how we use your data.
Receive your data in a structured, machine-readable format.
Object to processing based on legitimate interests or for marketing.
Not be subject to decisions based solely on automated processing.
Withdraw consent at any time (where processing is based on consent).
To exercise any of these rights, please contact us at [email protected]. We will respond within one month (extendable by two months for complex requests).
We may need to verify your identity before processing your request to protect your data from unauthorised access.
If you are unsatisfied with our response, you have the right to lodge a complaint with a supervisory authority. In the UK, this is the Information Commissioner's Office (ICO): ico.org.uk.
The Platform is not intended for individuals under 18 years of age. We do not knowingly collect personal information from children. If you believe we have collected data from a child, please contact us immediately at [email protected].
We may update this Privacy Policy from time to time. When we make material changes, we will:
We encourage you to review this Privacy Policy periodically.
If you have any questions, concerns, or requests regarding this Privacy Policy or our data practices, please contact us:
By using the Mirage platform, you acknowledge that you have read and understood this Privacy Policy.