1. About This Privacy Policy
This Privacy Policy explains how ValueMentor Infosec Limited ("ValueMentor", "we", "us" or "our") collects, uses, shares and protects personal information when you visit Secusy.ai, create or use a Secusy account, purchase or use our services, communicate with us, or otherwise interact with the Secusy platform.
Secusy.ai ("Secusy") is the digital platform through which ValueMentor offers and delivers selected cybersecurity, compliance, assurance, testing, consulting, managed security and software-enabled services.
ValueMentor Infosec LimitedCompany number: 13545355Pepper HousePepper RoadHazel GroveStockportSK7 5DPUnited KingdomPrivacy enquiries: privacy@valuementor.com2. Our Role Under Data Protection Law
Depending on the circumstances, ValueMentor may act as either a controller or a processor of personal information.
When we act as a controller
We generally act as a controller when we determine why and how personal information is used, including information relating to:
- website visitors;
- Secusy account users;
- prospective and existing customers;
- purchasing and billing;
- customer relationship management;
- support enquiries;
- marketing;
- website and Platform security;
- analytics and service improvement; and
- our own legal and business administration.
This Privacy Policy primarily describes these controller activities.
When we act as a processor
Certain Services require us to process personal information contained within systems, documents, evidence, logs, security telemetry or other information supplied by a Customer.
Where we process such information solely on the Customer's documented instructions, the Customer generally acts as controller and ValueMentor acts as processor.
Those processing activities are governed by our applicable Data Processing Agreement ("DPA") and the Customer's own privacy obligations.
3. Information We Collect
The information we collect depends upon how you interact with Secusy and which Services you use.
Account and identity information
This may include:
- name;
- business email address;
- telephone number;
- job title;
- employer or organisation;
- username;
- account identifiers;
- authentication information; and
- account preferences.
Organisation information
This may include:
- company name;
- business address;
- industry;
- company size;
- country or region;
- technical contacts;
- billing contacts; and
- information relevant to determining Service requirements.
Transaction and billing information
This may include:
- Services purchased;
- subscription information;
- transaction amounts;
- billing address;
- invoice details;
- payment status;
- tax information; and
- transaction identifiers.
Where payments are processed through a third-party payment provider, payment card information may be collected and processed directly by that provider. We do not necessarily receive or store complete payment card details.
Service and onboarding information
Depending on the Service purchased, we may collect information such as:
- domains;
- IP addresses;
- application URLs;
- API information;
- cloud environments;
- technology information;
- asset information;
- authorised testing scope;
- security contacts;
- compliance requirements;
- questionnaires;
- supporting documentation;
- audit evidence;
- policies and procedures;
- security configurations;
- assessment responses; and
- information necessary to deliver the relevant Service.
Cybersecurity and assessment information
When delivering cybersecurity Services, information may include:
- vulnerability information;
- security findings;
- scan results;
- penetration-testing results;
- application or infrastructure information;
- logs and security events;
- endpoint or network information;
- attack-surface information;
- security configurations;
- screenshots;
- evidence;
- remediation information; and
- assessment and testing reports.
Some of this information may be commercially sensitive or confidential even where it does not constitute personal information.
Credentials and access information
Where necessary to provide a Service, Customers may provide temporary credentials, access tokens, API keys or other authentication information.
Customers should provide such information only where required for the relevant Service and should use appropriately restricted or temporary credentials wherever practicable.
Communications
We may collect information contained in:
- emails;
- support requests;
- chat communications;
- meeting communications;
- feedback;
- questionnaires; and
- other communications with us.
Technical and usage information
When you use Secusy, we may collect information such as:
- IP address;
- browser type;
- device information;
- operating system;
- pages viewed;
- timestamps;
- referring pages;
- session information;
- Platform activity;
- security events;
- diagnostic information; and
- cookie or similar technology identifiers.
4. How We Use Personal Information
We may use personal information to:
Provide and administer the Services
Including to:
- create and manage accounts;
- process Orders;
- onboard Customers;
- provide purchased Services;
- conduct assessments and testing;
- manage subscriptions;
- generate reports and deliverables;
- provide customer support; and
- communicate about Service delivery.
Our lawful basis will generally be that processing is necessary to perform a contract or take steps at your request before entering into a contract, or our legitimate interests in delivering and administering Services to business customers.
Process payments and transactions
We use relevant information to process payments, issue invoices, maintain transaction records and manage subscriptions.
Our lawful bases may include performance of a contract, compliance with legal obligations and our legitimate interests in administering our business.
Secure Secusy and our Services
We may process information to:
- authenticate users;
- detect suspicious activity;
- prevent fraud and abuse;
- investigate security incidents;
- protect accounts;
- maintain logs;
- enforce our Terms and Conditions; and
- protect our infrastructure, Customers and users.
We generally rely on our legitimate interests in protecting our business, systems, Customers and users and, where applicable, compliance with legal obligations.
Communicate with you
We may send operational communications concerning accounts, purchases, security, subscriptions, assessments, Service delivery and changes affecting Services.
These are generally necessary to provide the relevant Service or pursue our legitimate interests in administering our relationship with you.
Improve Secusy and our Services
We may analyse how our Platform and Services are used to improve:
- functionality;
- usability;
- performance;
- service delivery;
- cybersecurity capabilities;
- assessment methodologies; and
- customer experience.
Where personal information is involved, we generally rely on our legitimate interests where appropriate. Where consent is legally required, we will obtain consent.
Meet legal and regulatory obligations
We may process information where necessary to:
- maintain legally required records;
- respond to lawful requests;
- establish or defend legal claims;
- comply with tax and accounting obligations;
- investigate unlawful activity; or
- comply with applicable legal or regulatory requirements.
The applicable lawful basis may be compliance with a legal obligation or, where appropriate, our legitimate interests.
5. AI, Machine Learning and Service Improvement
Secusy may use artificial intelligence and machine-learning technologies to support Platform functionality and cybersecurity or compliance Services.
Depending on the relevant feature, these technologies may assist with activities such as analysis, classification, recommendations, workflow automation, security analysis, mapping, summarisation or generation of Service-related outputs.
We may also use aggregated or effectively anonymised information derived from use of our Services for:
- statistical analysis;
- cybersecurity research;
- benchmarking;
- improving detection or assessment capabilities;
- improving Secusy; and
- developing or improving machine-learning and AI models.
Where information is treated as anonymised for these purposes, we take steps designed to ensure that it no longer identifies an individual or Customer.
We do not treat merely pseudonymised personal information as anonymous information where it remains capable of being associated with an identifiable person.
We will not use Customer Content containing identifiable personal information, credentials, identifiable confidential documents or identifiable Customer-specific security findings to train general-purpose AI models unless separately agreed with the Customer.
Where third-party AI providers process personal information on our behalf, we assess the relevant data-protection arrangements and apply appropriate contractual and security safeguards.
6. Marketing
We may send business customers and business contacts information about Secusy, ValueMentor and relevant cybersecurity Services where permitted by applicable law.
Depending upon the circumstances, we may rely on consent or legitimate interests.
You can opt out of marketing communications at any time using the unsubscribe mechanism provided in the communication or by contacting us.
Opting out of marketing will not prevent us from sending necessary Service, security, transaction or account communications.
9. International Data Transfers
ValueMentor operates internationally and some of our service providers, personnel or technology infrastructure may be located outside the United Kingdom.
As a result, personal information may be transferred to or accessed from other countries.
Where UK data-protection law treats a transfer as a restricted international transfer, we use an appropriate transfer mechanism where required.
Depending on the destination and circumstances, this may include:
- UK adequacy regulations;
- the UK International Data Transfer Agreement;
- the UK Addendum to approved EU Standard Contractual Clauses; or
- another lawful transfer mechanism.
Where required, we also assess whether additional safeguards are appropriate.
You may contact privacy@valuementor.com for further information about safeguards applicable to relevant international transfers.
10. Data Security
We use appropriate technical and organisational measures designed to protect personal information against unauthorised or unlawful processing and against accidental loss, destruction, alteration or disclosure.
Measures may include, as appropriate:
- access controls;
- authentication controls;
- encryption;
- logging and monitoring;
- network and infrastructure security;
- vulnerability management;
- endpoint security;
- backups;
- security testing;
- personnel controls; and
- incident-management procedures.
No information system can be guaranteed to be completely secure.
Customers are responsible for protecting their own account credentials and for notifying us promptly of suspected unauthorised access.
11. Data Retention
We retain personal information only for as long as reasonably necessary for the purposes for which it was collected, including to provide Services and meet legal, accounting, security and reporting requirements.
Retention periods vary according to the type of information and Service involved.
When determining retention periods, we consider:
- the duration of the Customer relationship;
- contractual obligations;
- Service requirements;
- the sensitivity and security risk of the information;
- legal and regulatory requirements;
- limitation periods;
- accounting and tax requirements;
- dispute-resolution requirements; and
- whether continued retention is necessary for security or fraud prevention.
Certain Service-specific information, particularly credentials, evidence, testing information and security data, may have shorter retention periods determined by the applicable Service or Customer instructions.
Where ValueMentor acts as processor, deletion or return of Customer personal data is governed by the applicable DPA and Customer instructions.
When information is no longer required, we delete, anonymise or otherwise securely dispose of it in accordance with applicable requirements.
12. Your Data Protection Rights
Depending on applicable law and the circumstances of the processing, you may have rights including:
- the right to access your personal information;
- the right to correct inaccurate personal information;
- the right to request deletion;
- the right to restrict certain processing;
- the right to object to certain processing;
- the right to data portability where applicable;
- rights relating to certain automated decision-making; and
- the right to withdraw consent where processing is based on consent.
These rights are not absolute and may be subject to legal conditions or exemptions.
Your right to object
Where we process your personal information on the basis of legitimate interests, you may have the right to object to that processing.
You also have the right to object to the use of your personal information for direct marketing purposes at any time.
To exercise your rights, contact:
We may need to verify your identity before completing a request.
Where we process personal information solely as a processor for one of our Customers, requests concerning that information should generally be directed to the relevant Customer. We will assist the Customer as required under applicable law and our DPA.
13. Complaints
If you have concerns about how we handle your personal information, please contact us first at:
You also have the right to lodge a complaint with the UK Information Commissioner's Office (ICO) or, where applicable, another competent data-protection authority.
14. Automated Decision-Making
Secusy may use automated technologies and AI to assist with cybersecurity analysis, compliance workflows, prioritisation, recommendations and other Service functionality.
Unless expressly disclosed in relation to a particular Service, we do not use solely automated processing to make decisions about individuals that produce legal effects or similarly significant effects on them.
If this changes for a particular Service, we will provide appropriate information and safeguards as required by applicable law.
15. Information About Other People
Customers may provide information concerning employees, contractors, customers, suppliers or other individuals when using our Services.
The Customer is responsible for ensuring that it has an appropriate lawful basis and has provided any required privacy information before providing personal information to us.
Where we process such information solely on the Customer's behalf, the applicable DPA governs our processing.
16. Third-Party Websites and Services
Secusy may contain links to or integrations with third-party websites and services.
Those organisations may process personal information under their own privacy policies.
This Privacy Policy does not govern independent processing carried out by third parties acting as separate controllers.
17. Changes to This Privacy Policy
We may update this Privacy Policy to reflect changes to our Services, technology, business operations or legal requirements.
The current version will be published on Secusy.ai with the date it was last updated.
Where a change materially affects how we use personal information, we will take reasonable steps to provide additional notice where appropriate.
18. Contact Us
For privacy questions, requests or complaints, contact:
ValueMentor Infosec LimitedCompany number: 13545355Pepper HousePepper RoadHazel GroveStockportSK7 5DPUnited KingdomEmail: privacy@valuementor.comWebsite: Secusy.ai