Privacy Notice
Last updated: 24 August 2026
This notice explains how Disruptors Cyber, trading as Disruptors ASM, handles personal data. Disruptors Cyber is the data controller for the personal data described here.
1. Who we are
Disruptors Cyber (Disruptors ASM, disruptorsasm.com) is the data controller. For any privacy question or request, contact lewis.denton-burke@disruptorscyber.com.
2. What we collect and why
- Account data (name, work email, phone number, company name, hashed login credentials) — to create and secure your account and provide the service. Legal basis: performance of a contract.
- Workspace and scan data (domains you submit, scan results, findings, notes, reports) — to deliver the service you purchased. Legal basis: performance of a contract.
- Support and correspondence (messages, enquiry forms, meeting requests) — to respond to you. Legal basis: legitimate interests / contract.
- Usage and telemetry (pages viewed, feature usage, device and browser information, IP address, error logs) — for security, abuse prevention and improving the product. Legal basis: legitimate interests.
- Marketing communications — only where you have opted in or where a soft opt-in applies. Legal basis: consent / legitimate interests.
Scan results may incidentally contain personal data that is already publicly available (for example company officer names from Companies House, or an email address appearing in a public breach dataset). Candidate email addresses generated during exposure checks are never stored or logged.
3. Who we share it with
- Service providers and subprocessors — hosting, database, email delivery, analytics and support tooling, acting on our instructions.
- Paddle.com, our Merchant of Record, for the sale of the product, subscription management, payments, tax compliance and invoicing.
- Professional advisers (legal, accounting) where necessary.
- Authorities or regulators where required by law.
We do not sell personal data.
4. International transfers
Some providers process data outside the UK/EEA. Where that happens we rely on an adequacy decision or on UK/EU Standard Contractual Clauses together with appropriate additional safeguards.
5. Retention
We keep account and scan data for as long as your account is active, and for up to 12 months after closure to allow reactivation and to meet legal obligations (billing records are kept for 6 years where tax law requires). After that, data is deleted or anonymised.
6. Security
We apply appropriate technical and organisational measures, including encryption in transit and at rest, row-level access controls, least-privilege access to production systems and server-side-only handling of all third-party API credentials.
7. Your rights
Under UK/EU GDPR you have the right to access, rectification, erasure, restriction, portability, and objection, and the right to withdraw consent at any time. Contact us at lewis.denton-burke@disruptorscyber.com and we will respond within one month. You also have the right to complain to the UK Information Commissioner's Office (ico.org.uk) or your local supervisory authority.
8. Cookies
We use essential cookies and local storage to keep you signed in and to remember session preferences — these are required for the service to function. We also use limited analytics to understand product usage. We do not use advertising or cross-site tracking cookies. You can clear or block cookies in your browser settings, though essential cookies are needed to sign in.