logo

Privacy Policy

Personal and Technical Data Privacy Policies for SkySiege Penetration Testing Services

SkySiege Customer Privacy Notice

This privacy notice tells you what to expect us to do with your personal and technical information.

Our contact details

You can contact our sales team at sales@skysiege.net

Customers can contact us at accounts@skysiege.net

SkySiege Personal Data Policy

What personal information we collect, use, and why

We collect or use the following information to provide services and goods, operation of customer accounts, management of guarantees and legal purposes:

We will not share your commercial data with any external party except in the following circumstances:

Payment and Financial Data

We do not hold, access or process any payment data. All payment data and transactions are handled by our payments partner Stripe Payments UK Ltd. Additionally, your payment data may be processed by payment intermediaries such as banks and financial institutions.

We are not privy to this information however Stripe’s privacy policy has further information and is available at this location.

Should you not wish to utilise our payments partner we would be happy to provide you with details for a direct transfer. This payment method is likely to delay the start of your services. Please contact us on accounts@skysiege.net to discuss your preferred arrangement.

Lawful bases

Our lawful bases for collecting or using personal information to provide services, operation of customer accounts, management of guarantees and legal purpose include:

We only get information with consent from authoritative parties that represent our business customers

How long we keep information (Commercial Documents)

We keep a copy of all receipts, quotes and proof of purchase indefinitely for taxation and book keeping purposes. We consider these documents to be Commercial Documents. This information includes:

Your data protection rights

Under data protection law, you have rights including:

How to complain

If you have any concerns about our use of your personal data, you can make a complaint to us using the contact details at the top of this privacy notice.

If you remain unhappy with how we’ve used your data after raising a complaint with us, you can also complain to the ICO.

The ICO’s address:

Information Commissioner’s Office
Wycliffe House
Water Lane
Wilmslow
Cheshire
SK9 5AF
Helpline number: 0303 123 1113
Website: https://www.ico.org.uk/make-a-complaint

SkySiege Technical Data Policy

What technical information we collect

During our work we collect and utilise the following information under the following definitions:

Access Data

Analysis Data

Report Data

How we use this data and why

We keep the above technical information along the following schedules:

Access Data

Access Data is data that describes the access route to perform scanning on the intended account(s). We consider Access Data to be sensitive but low risk, ie, we will keep Access Data confidential but does not pose a major security concern as the data alone does not allow access nor indicate vulnerabilities. Access Data originates:

We keep access data along the following schedules depending on where it is present:

Analysis Data

Analysis Data is data that is generated and inferred during scanning and testing. We consider Analysis Data to be both sensitive and high risk. Analysis Data includes the following

To handle this we perform the following:

During the 30 days following submission of the Report we retain a copy of the Report and our logs should there be any queries or issues. After 30 days from delivery of the Report we delete all Analysis Data including the generated Report.

Critically Private Data

We never access, record or analyse critically private data.

What we access (Analysis Data)

During scanning and testing we access resource specific information provided by the AWS APIs. This information contains resource specific technical details that vary depending on the resource. For example, an AWS EC2 Instance (virtual server) includes information such as:

This information is utilised for our scanning and testing to provide the functionality required for providing the services.

Information that we cannot access (Critically Private Data)

By default we have no capacity or functionality that can access the sensitive information in the following list, preventing any access at all to the following information:

Controlling access

Our access to your technical information is wholly controlled by the permissions that you grant when allowing us access. If there are services that you do not wish us to scan you can remove those permissions and disallow access. Our scanner may attempt access and will gracefully fail if permission is denied.

We’re happy to provide guidance on how to achieve this.