Privacy and data protection
Privacy Notice
Last updated: 22 July 2026
This notice explains what information the anydefect service processes, why we process it, how long we keep it and the choices available to you.
1. Who to contact
Privacy enquiries and rights requests can be sent to privacy@anydefect.com. The contracting entity and its registered contact details are identified in your order form or subscription record.
2. What we process and why
| Category | Examples | Purpose | Lawful basis |
|---|---|---|---|
| Account and identity | Name, business email, role, authentication provider and profile settings. | Create and secure your account, provide the service and communicate about it. | Contract; legitimate interests in operating and securing the service. |
| Security and activity | IP address, device and session information, audit events and security telemetry. | Authenticate users, investigate abuse, maintain auditability and protect customers. | Contract; legitimate interests; legal obligation where applicable. |
| Customer workspace content | Asset identifiers, configuration metadata, scan results, findings, ownership and evidence records. | Perform customer-instructed security analysis, reporting and remediation workflows. | Processed on the customer controller's instructions under our DPA. |
| Commercial and support | Company, billing references, enquiries, support messages and procurement correspondence. | Manage subscriptions, respond to requests and maintain business records. | Contract; legitimate interests; legal obligation for financial records. |
| Optional browser telemetry | Error details and limited technical context when monitoring is configured. | Diagnose reliability and security defects. | Consent, where the optional telemetry category is enabled. |
We receive information from you, your organisation, connected systems you authorise, identity providers you select and service providers involved in delivering the platform. We do not sell personal information.
3. Sharing and subprocessors
We disclose information only as needed to operate the service, follow customer instructions, comply with law, protect legal rights or complete a corporate transaction. Recipients may include infrastructure, database, email, payment, monitoring and professional-service providers. Customer-enabled integrations receive only the data needed for the action the customer requests. Production subprocessor commitments are set out in the DPA and applicable order form.
4. Retention and deletion
- Access sessions expire after 15 minutes; refresh and anti-forgery records normally expire after 7 days, or 30 days when “remember me” is selected.
- Expired invitations and refresh-token records are automatically removed by database expiry controls.
- Audit-event retention is plan-based. The application currently supports 14, 60, 180 and 365-day schedules.
- An account-deletion request has a 30-day recovery period, after which direct account identifiers are deleted or anonymised by a scheduled process.
- Customer workspace findings, scans and evidence are controlled separately from an individual account. Deleting a user account does not delete records the customer must retain for security, contractual or legal purposes.
- Support, commercial and legal records are retained for the period needed to resolve the matter and meet applicable contractual or legal duties.
5. International transfers and data location
Hosting region and support arrangements are deployment-specific and should be recorded in the customer order form. Where a restricted transfer is required, we use an applicable adequacy decision or contractual safeguard, such as the EU Standard Contractual Clauses and, for UK transfers, the UK IDTA or Addendum, together with the required transfer assessment. Contact us to request the safeguards that apply to your deployment.
6. Your rights
Depending on the law and context, you may have rights of access, correction, erasure, restriction, objection and portability. You can withdraw consent at any time without affecting earlier lawful processing. Settings provides a self-service account-data snapshot and account-deletion workflow; contact the privacy address for a complete rights request or a request concerning customer workspace content. You can also use our privacy request and complaint form. We may verify identity and may need to preserve information where law permits or requires it.
Right to object: you may object to processing based on legitimate interests. We will stop unless we have compelling legitimate grounds or need the data for legal claims.
You may also complain to your local supervisory authority. In the United Kingdom, this is the Information Commissioner's Office.
7. Cookies, security and automated analysis
Our Cookie Policy identifies the technologies in use and how to change consent. We use access controls, audit logging, tenant scoping and other safeguards designed to protect information. Security scores, prioritisation and remediation suggestions support human decisions; anydefect does not use them to make solely automated decisions about people that have legal or similarly significant effects.
8. Children and policy changes
anydefect is a business security service and is not directed to children. We will publish material changes here and, where appropriate, notify account administrators before they take effect.