Privacy Policy
Last updated: March 2026
1. Who We Are
Trace37 Ltd ("Trace37", "we", "us", "our") is a cybersecurity services company registered in England and Wales. We provide continuous offensive security testing through our Mastermind platform.
Contact: paul@trace37.com
2. What This Policy Covers
This policy explains how we collect, use, store, and protect personal data in connection with:
- Our website (mastermind.trace37.com and labs.trace37.com)
- Our security testing services (Mastermind)
- Business communications and marketing
3. Data We Collect
3.1 Data you provide to us
| Data | Purpose | Lawful basis |
|---|---|---|
| Name, email, phone number | Client onboarding, communication | Contract performance |
| Company name, role, address | Invoicing, service delivery | Contract performance |
| Scope information (domains, IPs) | Security testing | Contract performance |
| Correspondence | Support, queries | Legitimate interest |
3.2 Data collected automatically (website)
| Data | Purpose | Lawful basis |
|---|---|---|
| IP address, browser type, pages visited | Website analytics, security | Legitimate interest |
| Cookies (essential only) | Website functionality | Legitimate interest |
We do not use third-party tracking cookies, advertising pixels, or analytics platforms that share data with third parties.
3.3 Data encountered during security testing
During the course of security testing, we may encounter personal data within the Client's systems. This data:
- Is processed under the Client's instructions as Data Controller
- Is minimised to what is strictly necessary to evidence a vulnerability
- Is stored encrypted on the Client's Dedicated Instance (not our central systems)
- Is deleted within 30 days of the relevant finding being reported
- Is governed by a separate Data Processing Agreement with each Client
We do not use personal data encountered during testing for any purpose other than evidencing the security vulnerability.
4. How We Use Your Data
We use personal data only for:
- Delivering our services: Onboarding, testing, reporting, support
- Invoicing and accounts: Payment processing, VAT compliance
- Communication: Service updates, findings notifications, marketing (with consent)
- Legal compliance: Tax records, regulatory requirements
- Improving our services: Anonymised, aggregated insights (never individual client data)
5. Who We Share Data With
We do not sell personal data.
We may share data with:
| Recipient | Purpose | Safeguards |
|---|---|---|
| Cloud infrastructure providers (Hetzner) | Hosting Dedicated Instances | EU-based, DPA in place |
| Accounting / bookkeeping software | Invoicing, VAT returns | UK-based, encrypted |
| Legal advisors | Contract disputes, regulatory queries | Professional duty of confidence |
| Law enforcement | If required by law or court order | Only minimum required disclosure |
6. Data Retention
| Data type | Retention period |
|---|---|
| Client contact details | Duration of engagement + 2 years |
| Invoices and financial records | 6 years (HMRC requirement) |
| Security findings and reports | Duration of engagement + 30 days |
| Data encountered during testing | 30 days from finding report date |
| Website analytics | 12 months (rolling) |
| Marketing consent records | Until withdrawn + 1 year |
After the retention period, data is securely deleted or anonymised.
7. Data Security
We implement appropriate technical and organisational measures to protect personal data:
- Encryption at rest: All data stored on Dedicated Instances is encrypted
- Encryption in transit: All communications use TLS 1.2+
- Access control: Data access is limited to personnel who require it
- Isolated infrastructure: Each client's data is stored on a separate, isolated VPS
- Secure destruction: On offboarding, Dedicated Instances are securely wiped with certificate of destruction
8. International Transfers
We do not routinely transfer personal data outside the UK. Our infrastructure is hosted within the EU (Hetzner, Germany/Finland), which is recognised as providing adequate protection under UK GDPR.
If a transfer outside the UK/EU becomes necessary, we will ensure appropriate safeguards are in place (Standard Contractual Clauses or equivalent).
9. Your Rights
Under UK GDPR, you have the right to:
| Right | Description |
|---|---|
| Access | Request a copy of the personal data we hold about you |
| Rectification | Request correction of inaccurate data |
| Erasure | Request deletion of your data (subject to legal retention requirements) |
| Restriction | Request that we limit processing of your data |
| Portability | Receive your data in a structured, machine-readable format |
| Objection | Object to processing based on legitimate interest |
| Withdraw consent | Where processing is based on consent, withdraw it at any time |
To exercise any of these rights, contact us at paul@trace37.com. We will respond within 30 days.
10. Cookies
Our websites use only essential cookies required for functionality:
| Cookie | Purpose | Duration |
|---|---|---|
| Session cookie | Maintains user session | Session |
We do not use third-party tracking cookies, advertising cookies, or social media cookies.
11. Marketing
We may send marketing communications (e.g., research publications, service updates) if:
- You have given explicit consent; or
- You are an existing client and the communications relate to similar services (soft opt-in under PECR)
You can unsubscribe at any time by contacting paul@trace37.com or clicking the unsubscribe link in any email.
12. Changes to This Policy
We may update this policy from time to time. Material changes will be communicated to clients via email. The latest version will always be available at mastermind.trace37.com/privacy.
13. Complaints
If you are not satisfied with how we handle your data, you have the right to lodge a complaint with the Information Commissioner's Office (ICO):
- Website: ico.org.uk
- Phone: 0303 123 1113
- Post: Information Commissioner's Office, Wycliffe House, Water Lane, Wilmslow, Cheshire, SK9 5AF