DARKSIDE
ServicesHow it worksCredentialsPricing
Book a call

Legal

Privacy Policy

Last updated: 7 September 2026

This Privacy Policy explains how DARKSIDE SECURITY LIMITED (“Darkside”, “we”, “us”) collects, uses and protects personal data when you visit darkside-sec.com, contact us, or use our services. We are the data controller for the personal data described here.

DARKSIDE SECURITY LIMITED is a private limited by shares registered in England and Wales under company number 17419798, with its registered office at 43 St Johns Hill, London, SW11 1TT, United Kingdom. Our ICO registration reference will be published here once issued.

1 Who this applies to

This policy covers visitors to our website and prospective and current clients who contact us or engage our services. Where we perform penetration testing under a Master Services Agreement, the handling of personal data within a client’s systems is governed by the data-processing terms of that agreement, under which we act as a processor.

2 The data we collect

  • Contact and enquiry data - when you complete our “Book a call” form or email us: your name, work email, company name, job role, and anything you include in your message.
  • Client relationship data - for clients: billing contacts, engagement contacts, and correspondence.
  • Lead source data - when you submit an enquiry, we record the page, referrer, campaign parameters, and cookie consent state connected with that enquiry.
  • Outreach display observations - eligible non-UK business outreach emails may include a signed first-party image. If the image is requested, we record a pseudonymous prospect reference, campaign, email step, timestamp, and whether the request appears to come from an image proxy or automated security scanner. We do not retain the recipient’s email address, raw IP address, or raw browser user agent in this observation record. An image request does not prove that a person read the email.
  • Technical and visitor-attribution data - basic server logs and, if you consent, a pseudonymous first-party browser identifier, pages visited, approximate visible time and scroll depth, coarse counts of trusted pointer, touch, keyboard and scroll interactions, total pointer travel (not coordinates or keystrokes), selected link, download and form-submission events (never form-field contents), referrer and campaign parameters, browser, operating system, device category, viewport, language, time zone, coarse IP-derived location and reverse-DNS network metadata. We use the coarse interaction counts to distinguish deliberate engagement from automated email-security browsing. We also use Lusha’s tracking pixel to match IP and session signals to company records and receive company-level visit and engagement information; this feature does not identify the individual visitor. When you arrive through a tagged Darkside outreach link, our own system may connect that browser journey to the company and business contact already held in our outreach records. Where separate company-level evidence matches an outreach account, our system may also rank one or more business contacts at that company as possible associated contacts.

We do not intentionally collect special category data through our website, and we ask that you do not include sensitive personal information in free-text form fields.

3 How we use your data, and our lawful basis

PurposeLawful basis (UK GDPR)
Responding to your enquiry and arranging a callLegitimate interests / steps prior to entering a contract
Providing and administering our servicesPerformance of a contract
Sending service-related communicationsPerformance of a contract / legitimate interests
Understanding which campaigns and pages generate enquiriesConsent for non-essential cookies and pixels; legitimate interests for source data submitted with an enquiry
Measuring delivery engagement for eligible non-UK business outreach, without treating an image request as proof of readershipLegitimate interests, subject to regional law and our documented necessity and balancing assessment
Ranking possible business contacts for sales follow-up from consenting visitor journeys and company-level evidenceConsent for visitor tracking; legitimate interests for proportionate business-to-business prospecting and human-reviewed sales prioritisation
Meeting legal, tax and accounting obligationsLegal obligation
Securing our site and preventing misuseLegitimate interests

We do not sell your personal data, and we do not use it for automated decision-making that has legal or similarly significant effects. If you consent to analytics or advertising pixels, our advertising partners may use pseudonymous identifiers to measure campaign performance and build advertising audiences.

Our contact-ranking feature is advisory and reviewed by a person. It requires company-level evidence, such as a matching organisation network hostname, company domain or external referrer, before a named business contact can appear. Campaign region and recent email timing can only support an existing company match and cannot create one. We do not use browser type, operating system, language, viewport or location to identify a named person. An evidence score describes the strength of the company match; it is not a probability that the suggested contact used the browser and is not treated as proof of identity or employment.

Email display observations are advisory too. Image proxies and security scanners can request an image without a person reading the message, so these events remain separate from clicks, do not create a hot lead, and do not trigger an automated follow-up. We exclude UK cold outreach from this observation feature by default.

4 Sharing your data

We share personal data only with service providers who help us operate, under contracts that require them to protect it:

  • Supabase - database and authentication for our client portal.
  • Vercel - website and application hosting.
  • Cal.com - appointment scheduling.
  • Brevo - transactional and enquiry email delivery.
  • Anthropic - AI-assisted analysis of penetration-test reports within the portal.
  • Google, Meta, and LinkedIn - analytics, advertising pixels, and conversion measurement where you have consented.
  • Lusha - consented company-level website visitor identification and engagement insights.

We may also disclose data where required by law, to professional advisers, or in connection with a business transfer. Some providers may process data outside the UK; where they do, we rely on appropriate safeguards such as UK adequacy regulations or the International Data Transfer Agreement.

5 How long we keep it

We keep enquiry data for up to 24 months after last contact unless you become a client. Client and financial records are kept for the duration of the relationship and for at least six years afterwards to meet legal and accounting requirements. Penetration-testing engagement data and evidence are retained for 90 days after report delivery and then securely destroyed, unless a longer period is agreed in writing.

6 Your rights

Under UK data protection law you have the right to access, correct, erase, restrict, or object to the processing of your personal data, including an objection to direct-marketing profiling, and the right to data portability. To exercise any of these, email [email protected]. You also have the right to complain to the ICO at ico.org.uk, though we’d appreciate the chance to resolve any concern first.

7 Cookies

Our site uses essential storage required for it to function, including remembering your cookie preference. If you choose “Accept cookies”, we may also load analytics and advertising pixels from Google, Meta, LinkedIn, and Lusha to understand site usage, measure ad performance, and identify visiting companies. We also use a first-party pseudonymous visitor identifier to understand consenting visitors' page journeys, engagement events and return visits. If a browser uses a tagged Darkside outreach link, we connect that journey to the company already present in our outreach records. The identifier and its outreach attribution expire after 90 days. We may use the request IP transiently to derive coarse location and reverse-DNS network information, but we do not write the raw IP address to our visitor-intelligence records and network information is not treated as proof of a person's employer. Strong company-level evidence may be compared with the business contact records already in our outreach system to produce an advisory candidate ranking, as explained above. Our first-party matching does not use device fingerprinting. Lusha separately provides company-level visitor insights and does not identify the individual visitor from their browsing behaviour. These non-essential tools are not used unless you consent.

The Lusha Website Visitors Tracking Pixel is an analytics and marketing tool. It uses session-based tracking and processes the visitor IP address for company matching, pages visited, visit timestamps, and the referrer source. You can prevent it from loading by rejecting non-essential cookies.

If you choose “Reject cookies”, we do not load those pixels and we do not store visitor or outreach attribution data for marketing purposes. You can clear your browser storage to reset your choice.

8 Security

We apply appropriate technical and organisational measures to protect personal data, including encryption in transit and at rest, access controls, and the security practices you would expect of a firm whose business is security. No system is perfectly secure, but we take this seriously.

9 Changes and contact

We may update this policy from time to time; the “last updated” date above shows when. For any privacy question, contact [email protected].

DARKSIDE
How it worksPricingSample reportsResourcesIndustriesPrivacyTerms
© 2026 DARKSIDE SECURITY LIMITED · Registered in England & Wales · Company no. 17419798