Privacy Policy

Your privacy is important to us. This policy explains how we collect, use, and protect your personal information.

Last updated: 9 December 2025

Privacy Policy

Who We Are

AutoSec is operated by &DEV Limited, with registered offices at Orwell House, Cowley Road, Cambridge, Cambridgeshire, CB4 0PP, United Kingdom. We are committed to protecting your privacy and ensuring your personal data is handled in accordance with UK data protection laws, including the UK General Data Protection Regulation (UK GDPR) and the Data Protection Act 2018.

For any privacy-related questions or concerns, please contact us at support@autosec.app.

What Information We Collect

Personal Information

We collect information you provide directly to us, including:

  • Name and contact details (email address, phone number)
  • Company information and job title
  • Account credentials and authentication data
  • Payment and billing information
  • Communications with our support team
  • Domain names and URLs submitted for security testing

Technical Information

We automatically collect certain technical information when you use our service:

  • IP addresses and device identifiers
  • Browser type, version, and operating system
  • Website usage data and analytics (via Fathom Analytics)
  • Log files and access patterns
  • Security scan results and vulnerability data
  • Performance metrics and system diagnostics

How We Use Your Information

We use your personal information for the following purposes:

  • Service Provision: To provide our automated security testing services and generate vulnerability reports
  • Account Management: To create and maintain your account, process payments, and provide customer support
  • Communication: To send you service-related notifications, security alerts, and respond to your inquiries
  • Improvement: To analyze usage patterns and improve our security testing algorithms and user experience
  • Legal Compliance: To comply with applicable laws, regulations, and legal processes
  • Security: To protect our systems, detect fraud, and ensure the security of our platform

Third-Party Services

Fathom Analytics

We use Fathom Analytics to understand how visitors interact with our website. Fathom is a privacy-focused analytics service that:

  • Does not use cookies or collect personal data
  • Does not track visitors across sites
  • Is fully GDPR, CCPA, and PECR compliant
  • Collects only aggregate, anonymized usage data (page views, referrers, device types)

No opt-out is required as Fathom does not track individual users.

Microsoft Azure

Our service is hosted on Microsoft Azure cloud infrastructure, including:

  • Azure compute and storage services
  • Azure Front Door CDN for content delivery
  • Azure security and monitoring services

Data processed through Azure remains within the UK and EU data centers, ensuring compliance with UK data protection requirements.

Data Storage and Security

Security Measures

We implement appropriate technical and organizational measures to protect your personal data:

  • End-to-end encryption for data transmission
  • Encrypted storage of sensitive data
  • Regular security audits and penetration testing
  • Access controls and authentication systems
  • Employee training on data protection

Data Retention

We retain your personal data only for as long as necessary:

  • Account data: Until account deletion or 7 years after last activity
  • Security scan results: 2 years for analysis and reporting
  • Communication records: 3 years for customer support purposes
  • Analytics data: Fathom Analytics retains anonymized, aggregate data only

Your Rights

Under UK data protection law, you have the following rights:

  • Access: Request a copy of your personal data
  • Rectification: Correct inaccurate or incomplete data
  • Erasure: Request deletion of your personal data
  • Portability: Receive your data in a structured format
  • Restriction: Limit how we process your data
  • Objection: Object to processing based on legitimate interests
  • Withdraw consent: Where processing is based on consent

To exercise these rights, please contact us at support@autosec.app. We will respond within one month.

Cookies

We use cookies and similar technologies to enhance your experience:

  • Essential cookies: Required for basic site functionality
  • Analytics: Fathom Analytics (cookie-free, privacy-focused)
  • Preference cookies: Remember your theme and language settings

You can manage cookie preferences through your browser settings. Disabling certain cookies may affect site functionality.

Contact and Complaints

For any privacy-related questions or to exercise your rights, contact us:

If you’re not satisfied with our response, you can lodge a complaint with the Information Commissioner’s Office (ICO) at ico.org.uk.

Changes to This Policy

We may update this privacy policy from time to time. When we do, we will:

  • Post the updated policy on this page
  • Update the “Last updated” date

We encourage you to review this policy periodically to stay informed about how we protect your privacy.