trace37/ mastermind
  • home
  • pricing
  • research
  • get started
ABCDEFGH
document privacy policy rev march 2026
home / privacy policy

Privacy Policy

Last updated: March 2026

1. Who We Are

Trace37 Ltd ("Trace37", "we", "us", "our") is a cybersecurity services company registered in England and Wales. We provide continuous offensive security testing through our Mastermind platform.

Contact: paul@trace37.com

2. What This Policy Covers

This policy explains how we collect, use, store, and protect personal data in connection with:

  • Our website (mastermind.trace37.com and labs.trace37.com)
  • Our security testing services (Mastermind)
  • Business communications and marketing

3. Data We Collect

3.1 Data you provide to us

DataPurposeLawful basis
Name, email, phone numberClient onboarding, communicationContract performance
Company name, role, addressInvoicing, service deliveryContract performance
Scope information (domains, IPs)Security testingContract performance
CorrespondenceSupport, queriesLegitimate interest

3.2 Data collected automatically (website)

DataPurposeLawful basis
IP address, browser type, pages visitedWebsite analytics, securityLegitimate interest
Cookies (essential only)Website functionalityLegitimate interest

We do not use third-party tracking cookies, advertising pixels, or analytics platforms that share data with third parties.

3.3 Data encountered during security testing

During the course of security testing, we may encounter personal data within the Client's systems. This data:

  • Is processed under the Client's instructions as Data Controller
  • Is minimised to what is strictly necessary to evidence a vulnerability
  • Is stored encrypted on the Client's Dedicated Instance (not our central systems)
  • Is deleted within 30 days of the relevant finding being reported
  • Is governed by a separate Data Processing Agreement with each Client

We do not use personal data encountered during testing for any purpose other than evidencing the security vulnerability.

4. How We Use Your Data

We use personal data only for:

  • Delivering our services: Onboarding, testing, reporting, support
  • Invoicing and accounts: Payment processing, VAT compliance
  • Communication: Service updates, findings notifications, marketing (with consent)
  • Legal compliance: Tax records, regulatory requirements
  • Improving our services: Anonymised, aggregated insights (never individual client data)

5. Who We Share Data With

We do not sell personal data.

We may share data with:

RecipientPurposeSafeguards
Cloud infrastructure providers (Hetzner)Hosting Dedicated InstancesEU-based, DPA in place
Accounting / bookkeeping softwareInvoicing, VAT returnsUK-based, encrypted
Legal advisorsContract disputes, regulatory queriesProfessional duty of confidence
Law enforcementIf required by law or court orderOnly minimum required disclosure

6. Data Retention

Data typeRetention period
Client contact detailsDuration of engagement + 2 years
Invoices and financial records6 years (HMRC requirement)
Security findings and reportsDuration of engagement + 30 days
Data encountered during testing30 days from finding report date
Website analytics12 months (rolling)
Marketing consent recordsUntil withdrawn + 1 year

After the retention period, data is securely deleted or anonymised.

7. Data Security

We implement appropriate technical and organisational measures to protect personal data:

  • Encryption at rest: All data stored on Dedicated Instances is encrypted
  • Encryption in transit: All communications use TLS 1.2+
  • Access control: Data access is limited to personnel who require it
  • Isolated infrastructure: Each client's data is stored on a separate, isolated VPS
  • Secure destruction: On offboarding, Dedicated Instances are securely wiped with certificate of destruction

8. International Transfers

We do not routinely transfer personal data outside the UK. Our infrastructure is hosted within the EU (Hetzner, Germany/Finland), which is recognised as providing adequate protection under UK GDPR.

If a transfer outside the UK/EU becomes necessary, we will ensure appropriate safeguards are in place (Standard Contractual Clauses or equivalent).

9. Your Rights

Under UK GDPR, you have the right to:

RightDescription
AccessRequest a copy of the personal data we hold about you
RectificationRequest correction of inaccurate data
ErasureRequest deletion of your data (subject to legal retention requirements)
RestrictionRequest that we limit processing of your data
PortabilityReceive your data in a structured, machine-readable format
ObjectionObject to processing based on legitimate interest
Withdraw consentWhere processing is based on consent, withdraw it at any time

To exercise any of these rights, contact us at paul@trace37.com. We will respond within 30 days.

10. Cookies

Our websites use only essential cookies required for functionality:

CookiePurposeDuration
Session cookieMaintains user sessionSession

We do not use third-party tracking cookies, advertising cookies, or social media cookies.

11. Marketing

We may send marketing communications (e.g., research publications, service updates) if:

  • You have given explicit consent; or
  • You are an existing client and the communications relate to similar services (soft opt-in under PECR)

You can unsubscribe at any time by contacting paul@trace37.com or clicking the unsubscribe link in any email.

12. Changes to This Policy

We may update this policy from time to time. Material changes will be communicated to clients via email. The latest version will always be available at mastermind.trace37.com/privacy.

13. Complaints

If you are not satisfied with how we handle your data, you have the right to lodge a complaint with the Information Commissioner's Office (ICO):

  • Website: ico.org.uk
  • Phone: 0303 123 1113
  • Post: Information Commissioner's Office, Wycliffe House, Water Lane, Wilmslow, Cheshire, SK9 5AF
Trace37 Ltd
Registered in England and Wales
Contact: paul@trace37.com
documentprivacy policy
revisionmarch 2026
drawntrace37
checkedoffensive team
trace37 / mastermind drawing set — end of sheets
mastermind

continuous offensive security.
human-validated. always on.

@trace37_labs

product

  • home
  • pricing
  • research

company

  • contact
  • trace37 labs

legal

  • privacy
  • terms
© 2026 Trace37 Ltd. All rights reserved. paul@trace37.com