Last updated · June 25, 2026[cite: 1]
1. Introduction
Welcome to VaultStrike ("we," "our," or "us").[cite: 1] We operate the cybersecurity platform, products, and the website located at https://www.vaultstrike.com/.[cite: 1] We are committed to protecting and respecting the privacy of our corporate clients, website visitors, and users.[cite: 1] This Privacy Policy outlines how we collect, use, disclose, and safeguard personal data under the UK General Data Protection Regulation (UK GDPR) and the Data Protection Act 2018.[cite: 1]
Our Role Under UK GDPR
- Data Controller: We act as a Data Controller for personal data collected through our website, for marketing activities, and for managing customer account billing and relationship administration.[cite: 1]
- Data Processor: When providing our cybersecurity suite—including vulnerability scanning, defacement monitoring, vulnerability management, incident response, and attack surface monitoring—we process data solely on behalf of and according to the instructions of our enterprise/organization clients (who act as the Data Controllers).[cite: 1]
A. Information You Provide to Us (As Controller)
- Account and Contact Data: Name, corporate email address, business telephone number, job title, and organization name when you sign up for our services or request a demo.[cite: 1]
- Billing Information: Corporate payment details and invoicing addresses (processed securely via our payment gateways).[cite: 1]
B. Technical Data Collected via Our Products (As Processor)
To provide our core automated defense services, our platform ingests, scans, and analyzes technical data from your designated public attack surfaces and environments.[cite: 1] This may include:
- Target domain names, URLs, and IP addresses.[cite: 1]
- Public-facing asset configurations and SSL/TLS certificate metadata.[cite: 1]
- System logs, application integrity snapshots, and file metadata (for file integrity and malware monitoring).[cite: 1]
- Content changes on monitored web assets (used exclusively to detect web defacement incidents).[cite: 1]
- Technical diagnostic data, user profile login trails, and audit logs within the VaultStrike portal.[cite: 1]
C. Website Metadata (As Controller)
IP addresses, browser types, operating systems, and usage analytics collected via essential website cookies to ensure portal security and optimize performance.[cite: 1]
3. How and Why We Use Your Data (Lawful Bases)
Under the UK GDPR, we only process personal data where we have a valid legal framework.[cite: 1] We rely on the following bases:
- Performance of a Contract: To onboard your organization, provision access to the VaultStrike engine, manage user accounts, and provide agreed-upon customer support.[cite: 1]
- Legitimate Interests: For identifying system performance improvements, evaluating emerging web threats, ensuring the security and resilience of our own network infrastructure, and preventing unauthorized access or fraud.[cite: 1]
- Legal Obligation: To comply with applicable UK statutory, financial, regulatory, or law-enforcement requirements.[cite: 1]
4. Third-Party Hosting & Data Location
- Data Residency: All data collected and processed by our products is securely stored and hosted within the United Kingdom utilizing third-party enterprise cloud infrastructure provided by Namecheap Cloud.[cite: 1]
- No International Transfers: We do not routinely transfer personal data or customer scan telemetry outside the United Kingdom.[cite: 1] If a client explicitly requests a cross-border integration or third-party service routing, such transfers are governed strictly by the UK International Data Transfer Agreement (IDTA) or Standard Contractual Clauses (SCCs).[cite: 1]
5. Data Retention
We retain your personal data only for as long as necessary to fulfill the purposes for which it was collected:[cite: 1]
- Account & Billing Records: Retained for the duration of your active subscription and up to 6 years following contract termination to comply with UK tax laws.[cite: 1]
- Scan Telemetry and Security Logs: Vulnerability scans, defacement capture history, and audit logs are retained or purged in accordance with the data retention parameters set within your organization’s platform configurations or standard service SLAs.[cite: 1]
6. Information Security
As a cybersecurity vendor, information security is fundamental to our business.[cite: 1] We apply stringent technical and organizational measures to safeguard data against unauthorized access, alteration, disclosure, or destruction.[cite: 1] This includes end-to-end data encryption in transit and at rest, access control mechanisms, regular automated security audits, and continuous threat monitoring of our hosting environments.[cite: 1]
7. Your Data Protection Rights
Under UK data protection law, individuals whose data we hold as a Controller possess the following statutory rights:[cite: 1]
- Right of Access: You can request a copy of the personal information we hold about you.[cite: 1]
- Right to Rectification: You can request that we update or correct inaccurate or incomplete data.[cite: 1]
- Right to Erasure ("Right to be Forgotten"): You can request that we delete your personal information under certain legal criteria.[cite: 1]
- Right to Restriction or Objection: You have the right to object to or restrict our processing of your personal data under specific conditions.[cite: 1]
- Right to Data Portability: You can request a digital transfer of your provided data to another provider.[cite: 1]
Note on Client Data: If your data is processed by VaultStrike as part of a corporate client's automated scanning or incident logs (where we act as a Data Processor), please direct your inquiry or rights request to your organization's internal system administrator.[cite: 1]
To exercise your data protection rights, or if you have any questions regarding this Privacy Policy, please contact our privacy compliance team at:[cite: 1]
- Company Name: VaultStrike[cite: 1]
- Registered Address: 79 Chaplin Rd, Stoke-on-Trent ST3 4RH, United Kingdom[cite: 1]
- Contact Phone: +923323687232[cite: 1]
- Email Contact: [email protected][cite: 1]
Supervisory Authority
If you feel we have not handled an inquiry to your satisfaction, you have the right to file a complaint at any time with the UK supervisory authority:[cite: 1]
Information Commissioner’s Office (ICO)
Wycliffe House, Water Lane, Wilmslow, Cheshire, SK9 5AF
Website: https://ico.org.uk/[cite: 1]