Skip to main content

Policy

Privacy Policy

Last updated: June 2026

This Privacy Policy describes how Stealth Layer Security ("we", "us", "our") collects, uses, and protects personal information in connection with our website and the security services we provide. We take a GDPR-aligned approach to data protection and are committed to handling personal information responsibly and transparently.

Effective date: June 2026

1. Data Controller

The data controller responsible for your personal information is:

Stealth Layer Security
Website: stealthlayersecurity.com
Contact: security@stealthlayersecurity.com

For all data protection enquiries, please contact us at the email address above.

2. Information We Collect

We collect only the minimum information necessary to respond to enquiries, scope engagements, and deliver services. This typically includes:

  • Business contact details (name, email address, job title, organisation name)
  • Technical and environmental details required to define the scope of an engagement
  • Information you voluntarily provide through our contact form or by email

We do not collect sensitive personal data as defined under Article 9 GDPR unless this is strictly necessary and we have obtained your explicit consent.

3. Lawful Basis for Processing

We process your personal data only where we have a valid lawful basis under Article 6 GDPR. The bases we rely on are:

  • Contract performance (Article 6(1)(b)): Processing necessary to enter into or perform a contract for security services with you or your organisation.
  • Legitimate interests (Article 6(1)(f)): Processing necessary for our legitimate business interests, including responding to pre-contractual enquiries, maintaining engagement records, and improving our services — provided these interests are not overridden by your rights.
  • Compliance with a legal obligation (Article 6(1)(c)): Where we are required to retain or process data to comply with applicable law.

4. How We Use Your Information

We use the information we collect to:

  • Respond to your enquiry and scope proposed services
  • Deliver security engagements under written authorisation
  • Maintain records related to engagements for the agreed retention period
  • Comply with our legal and contractual obligations

We do not use your personal data for automated decision-making or profiling. We do not sell, rent, or share personal information with third parties for marketing purposes.

5. Cookies

We currently use no cookies, tracking scripts, advertising scripts, or third-party analytics on this website. No cookie consent is required at this time. Should we introduce cookies or tracking technologies in the future, we will update this policy and implement a compliant consent mechanism before doing so.

6. Data Retention

Engagement-related data is retained for the period agreed in the engagement contract — typically sufficient to support retesting — and then securely deleted from all working systems and associated backups in accordance with documented disposal procedures.

Where no engagement results, enquiry data is retained only for as long as is reasonably necessary to respond to your enquiry and is then deleted.

Retention periods may be shortened or extended by written agreement between the parties.

7. Data Security

We implement appropriate technical and organisational measures to protect personal data against unauthorised access, loss, or disclosure. Specific measures include:

  • Encryption of engagement artifacts in transit and at rest using current industry-standard mechanisms
  • Access controls limiting access to engagement data to personnel directly involved in delivery
  • Logging of internal access where appropriate
  • Secure deletion procedures applied at the end of the retention period

8. International Data Transfers

Where we use subprocessors or tools that involve the transfer of personal data outside the UK or European Economic Area (EEA), we ensure that adequate safeguards are in place, such as the use of Standard Contractual Clauses (SCCs) approved by the European Commission, or we rely on an adequacy decision where applicable.

Any subprocessors used to support an engagement are disclosed to clients during scoping and are bound by confidentiality obligations consistent with this policy and applicable data protection law.

9. Your Rights Under GDPR

Under GDPR, you have the following rights in relation to your personal data:

  • Right of access (Article 15): Request a copy of the personal data we hold about you.
  • Right to rectification (Article 16): Request correction of inaccurate or incomplete personal data.
  • Right to erasure (Article 17): Request deletion of your personal data where there is no compelling reason for us to continue processing it.
  • Right to restriction of processing (Article 18): Ask us to restrict processing of your data in certain circumstances.
  • Right to data portability (Article 20): Where processing is based on consent or contract and carried out by automated means, receive your data in a structured, commonly used, machine-readable format.
  • Right to object (Article 21): Object to processing based on legitimate interests. We will cease processing unless we can demonstrate compelling legitimate grounds that override your interests.
  • Rights related to automated decision-making (Article 22): We do not carry out automated decision-making or profiling, so this right is not currently applicable.

To exercise any of these rights, please contact us at security@stealthlayersecurity.com. We will respond within 30 days. We may ask you to verify your identity before processing your request.

10. Data Breach Notification

In the event of a personal data breach that is likely to result in a risk to your rights and freedoms, we will notify the relevant supervisory authority within 72 hours of becoming aware of the breach, in accordance with Article 33 GDPR.

Where the breach is likely to result in a high risk to your rights and freedoms, we will also notify you directly without undue delay, in accordance with Article 34 GDPR, except where we have implemented measures that render the risk unlikely to materialise.

Suspected incidents affecting client data are investigated promptly and reported to the affected client in line with the engagement contract.

11. Right to Lodge a Complaint

If you are located in the UK, you have the right to lodge a complaint with the Information Commissioner's Office (ICO):

Information Commissioner's Office
Website: ico.org.uk
Helpline: 0303 123 1113

If you are located in the EU, you have the right to lodge a complaint with your national data protection authority. A list of EU supervisory authorities is available at edpb.europa.eu/about-edpb/about-edpb/members_en.

We would, however, appreciate the opportunity to address your concerns before you contact a supervisory authority, so please contact us first at security@stealthlayersecurity.com.

12. Changes to This Policy

We may update this Privacy Policy from time to time to reflect changes in our practices or applicable law. The "Last updated" date at the top of this document will be revised accordingly. Material changes will be communicated to active clients by email.

We encourage you to review this policy periodically.

13. Contact

Questions, requests, or concerns about this Privacy Policy or our data handling practices can be directed to:

Stealth Layer Security
security@stealthlayersecurity.com