Wiseep Privacy Policy
1. Introduction
Wiseep ("Wiseep", "we", "us", or "our") provides online cybersecurity and vulnerability assessment services designed to help organizations identify, understand, and remediate security vulnerabilities affecting their digital assets.
Our Services may include, depending on the Service selected:
Red Team Scan
Wildcard Domain Scan
Single Domain Scan
Credentialed Scan
Mobile Application Scan
Desktop Application Scan
Static Code Scan / Code Review
Infrastructure Scan and
Other security assessment and related services made available by Wiseep.
This Privacy Policy explains how Wiseep collects, uses, stores, protects, and otherwise processes personal data in connection with our website, platform, Services, communications, and related activities.
Wiseep is committed to protecting personal data and processing it in accordance with applicable data protection laws, including the UK General Data Protection Regulation ("UK GDPR") and the Data Protection Act 2018, where applicable.
2. Data Controller
The entity responsible for the processing of personal data under this Privacy Policy is Wiseep, By Ebruu Tech Limited.
For privacy-related questions or requests: support@wiseep.com
Depending on the nature and purpose of a particular processing activity, Wiseep may act as either a data controller or a data processor.
Where Wiseep processes personal data on behalf of a customer as a processor, the relevant customer may remain the controller of that data. In such circumstances, Wiseep will process the relevant data in accordance with the customer's instructions, applicable contractual arrangements, and any applicable Data Processing Agreement.
3. Personal Data We Collect
Depending on how you interact with Wiseep and which Services you use, we may process the following categories of information.
3.1. Account and Contact Information
This may include:
Name
Business name
Job title
Email address
Telephone number
Business address
Account credentials
Account identifiers and
Other information provided when creating or managing an account.
3.2. Billing and Transaction Information
This may include:
Billing name
Billing address
Transaction information
Payment status
Purchase history
Invoice information and
Other information necessary to process payments.
Where payments are processed by a third-party payment provider, Wiseep may not receive or store complete payment card information. Payment providers may process payment information in accordance with their own privacy policies.
3.3. Security Assessment and Scan Data
When you use Wiseep's Services, we may process information associated with the assets being assessed, including:
Domains and subdomains
IP addresses
URLs
Ports and services
Application information
Network information
System information
Security configuration information
HTTP requests and responses
Cookies and session information
Authentication information
Vulnerability findings
Security evidence
Proof-of-concept information
Screenshots
Logs
Metadata
Security headers
Publicly exposed information and
Other information necessary to perform the requested security assessment.
Such information may contain personal data belonging to you, your employees, customers, users, or other individuals.
3.4. Source Code and Application Files
For Code Review, Mobile Application Scan, Desktop Application Scan, or similar Services, customers may provide:
Source code
Application packages
Executable files
Mobile application files
Configuration files
Dependencies
Libraries
Documentation
API definitions
Credentials or secrets
Logs and
Other technical materials.
Such materials may contain personal data or confidential information. Customers are responsible for ensuring that they are authorized to provide such information to Wiseep.
3.5. Credentials and Authentication Information
For credentialed assessments, Wiseep may process authentication information supplied by the Customer, including:
Usernames
Passwords
API keys
Authentication tokens
Session credentials
Certificates
Access keys and
Other authentication information.
Wiseep uses such information only as reasonably necessary to perform the applicable security assessment and related Services.
3.6. Red Team and Publicly Available Information
Certain Services, including Red Team Scan, may involve identifying publicly accessible assets associated with an organization.
Depending on the Service, Wiseep may collect or process publicly available information such as:
Public domains
Subdomains
IP addresses
DNS information
Publicly accessible services
Public websites
Public files
Publicly exposed credentials or secrets
Publicly available technical information
Public security information
OSINT information and
Other publicly available information relevant to the security assessment.
Red Team Scan may involve discovering assets without the Customer providing a complete technical scope, subject to Wiseep's applicable authorization and assessment procedures.
3.7. Usage and Technical Data
We may collect:
IP address
Browser type
Device information
Operating system
Login information
Session information
Access times
Referrer information
Error information
Platform activity and
Security and audit logs.
3.8. Communications
We may retain information contained in communications with Wiseep, including:
Emails
Support requests
Chat communications
Feedback
Complaints
Technical enquiries and
Other correspondence.
4. How We Use Personal Data
We may use personal data for the following purposes:
4.1. Providing the Services
We process information to:
Create and manage accounts
Authenticate users
Process scan requests
Verify scope and authorization
Conduct security assessments
Process uploaded files and technical information
Generate vulnerability findings
Provide vulnerability reports
Provide access to paid vulnerability details
Perform retesting
Provide customer support and
Otherwise provide the requested Services.
4.2. Security and Abuse Prevention
We may process information to:
Protect Wiseep systems
Detect unauthorized access
Detect fraud
Detect misuse
Prevent unauthorized scanning
Investigate security incidents
Protect customers and third parties
Monitor platform security and
Enforce our Terms of Service.
4.3. Security Risk Communication and Escalation
Where Wiseep reasonably determines that a security vulnerability presents a material, critical, or otherwise significant risk, we may process and use relevant information to communicate or escalate that risk to appropriate representatives of the Customer organization.
Depending on the circumstances, this may include contacting:
Information Security personnel
CISO
CIO
CTO
Security Manager
Risk Management
Compliance
Legal
Executive Management or
Other responsible representatives.
This may occur where Wiseep reasonably believes that a significant security vulnerability is being intentionally ignored, suppressed, concealed, improperly dismissed, or prevented from reaching personnel with appropriate responsibility or authority.
This right may apply even where an account holder or other individual acting on behalf of the Customer has requested that a finding be deleted, suppressed, ignored, or not purchased.
Wiseep will seek to limit such communications to information reasonably necessary to communicate and assess the relevant security risk.
This processing is separate from any decision to publicly disclose vulnerability information.
4.4. Service Improvement
We may use appropriately aggregated, anonymized, or otherwise lawfully processed information to:
Improve our scanning technologies
Improve vulnerability detection
Develop security methodologies
Analyze service performance
Improve reliability
Develop new features and
Improve the overall quality of our Services.
Where information is anonymized so that individuals are no longer identifiable, it is no longer treated as personal data to the extent permitted by applicable law.
4.5. Legal and Regulatory Compliance
We may process personal data where necessary to:
Comply with legal obligations
Respond to lawful requests
Establish, exercise, or defend legal claims
Cooperate with regulators
Prevent fraud
Protect rights and property or
Protect the safety and security of our users and systems.
5. Lawful Bases for Processing
Where required by applicable law, Wiseep relies on one or more lawful bases for processing personal data.
Depending on the circumstances, these may include:
5.1. Contract
Where processing is necessary to provide Services requested by you or to take steps before entering into a contract.
5.2. Legitimate Interests
Where processing is necessary for Wiseep's legitimate interests, including:
Platform security
Fraud prevention
Service improvement
Network and information security
Protecting our systems
Enforcing contractual rights
Defending legal claims and
Communicating material security risks.
Where we rely on legitimate interests, we consider the interests and fundamental rights of affected individuals and will not rely on this basis where those interests are overridden by those rights, unless otherwise permitted by law.
5.3. Legal Obligation
Where processing is necessary to comply with a legal obligation applicable to Wiseep.
5.4. Consent
Where consent is required by applicable law, Wiseep will seek consent before carrying out the relevant processing.
You may withdraw consent at any time where processing is based on consent.
Withdrawal of consent does not affect the lawfulness of processing carried out before withdrawal.
6. Cookies and Similar Technologies
Wiseep may use cookies and similar technologies to:
Operate the website
Maintain sessions
Remember preferences
Understand website usage
Improve performance
Protect against abuse
Support analytics or marketing where permitted.
Where required by applicable law, Wiseep will obtain consent before placing non-essential cookies or similar technologies.
Further information may be provided through Wiseep's Cookie Notice or cookie settings.
7. Data Sharing and Recipients
Wiseep does not sell personal data.
We may share personal data where reasonably necessary with the following categories of recipients:
7.1. Service Providers
These may include providers of:
Cloud infrastructure
Hosting
Payment processing
Email
Customer support
Authentication
Analytics
Security monitoring
Backup
Communications
Technical infrastructure and
Other services necessary to operate Wiseep.
Such providers may process information only as necessary to provide their services and subject to appropriate contractual or legal safeguards where required.
7.2. Customer Representatives
Where necessary for security risk escalation under this Privacy Policy and our Terms of Service, Wiseep may communicate relevant security information to appropriate representatives of the Customer organization.
7.3. Legal and Regulatory Authorities
Wiseep may disclose information where:
Required by law
Required by a court or competent authority
Necessary to comply with a lawful request
Necessary to establish, exercise, or defend legal claims or
Otherwise permitted or required under applicable law.
7.4. Corporate Transactions
Wiseep may disclose relevant information as part of:
A merger
Acquisition
Sale of assets
Corporate restructuring
Financing transaction or
Similar corporate transaction.
subject to applicable confidentiality and data protection requirements.
8. International Data Transfers
Wiseep may use service providers or infrastructure located outside the United Kingdom.
Where personal data is transferred outside the UK, Wiseep will implement appropriate safeguards where required by applicable data protection law.
Depending on the destination and circumstances, safeguards may include:
UK adequacy regulations
International Data Transfer Agreements
UK GDPR Addendum
Standard Contractual Clauses where applicable
Appropriate contractual protections or
Other legally recognized transfer mechanisms.
9. Data Security
Wiseep implements appropriate technical and organizational measures designed to protect personal data against unauthorized access, loss, misuse, alteration, disclosure, or destruction.
Measures may include:
Access controls
Authentication controls
Encryption in transit
Encryption at rest where appropriate
Logging and monitoring
Network security controls
Segmentation and isolation
Secure development practices
Vulnerability management
Backup and recovery controls and
Personnel security and awareness measures.
No method of transmission, storage, or processing can be guaranteed to be completely secure.
Wiseep therefore cannot guarantee absolute security of personal data.
10. Data Retention
Wiseep retains personal data only for as long as reasonably necessary for the purposes described in this Privacy Policy, unless a longer period is required or permitted by law.
Retention periods may vary depending on the type and purpose of the information.
For example, Wiseep may retain:
Account information while an account remains active
Billing and transaction records for periods required by applicable tax and accounting requirements
Security and audit logs for periods reasonably necessary for security, fraud prevention, investigation, and operational purposes
Scan results and vulnerability information for periods reasonably necessary to provide Services, maintain records, investigate disputes, preserve evidence, enforce contractual rights, or protect Wiseep and its customers
Customer-submitted technical materials only for as long as reasonably necessary for the applicable Service and related purposes and
Backup copies until they are overwritten or securely deleted in accordance with applicable backup and retention processes.
Where a customer requests deletion, Wiseep will assess the request in accordance with applicable law.
Deletion may be refused or delayed where Wiseep has a lawful basis or legal obligation to retain the information, including where necessary to:
Comply with legal obligations
Establish, exercise, or defend legal claims
Prevent fraud or abuse
Investigate security incidents
Protect Wiseep or others or
Maintain necessary business or security records.
11. Your Data Protection Rights
Subject to applicable law and relevant exemptions, you may have the following rights:
11.1. Right of Access
You may request access to personal data held about you.
11.2. Right to Rectification
You may request correction of inaccurate or incomplete personal data.
11.3. Right to Erasure
You may request deletion of personal data in certain circumstances.
11.4. Right to Restriction
You may request restriction of processing in certain circumstances.
11.5. Right to Object
You may object to certain processing, including processing based on legitimate interests.
11.6. Right to Data Portability
Where applicable, you may request your personal data in a structured, commonly used, and machine-readable format.
11.7. Right to Withdraw Consent
Where processing is based on consent, you may withdraw your consent.
These rights are not absolute and may be subject to legal exceptions and limitations.
12. Marketing Communications
Wiseep may send service-related communications that are necessary to operate your account or provide Services.
Where permitted by law, Wiseep may also send promotional communications about:
Wiseep Services
New features
Security services
Offers and
Other relevant products or services.
Where consent is required, Wiseep will obtain it before sending applicable marketing communications.
You may unsubscribe from marketing communications at any time using the unsubscribe mechanism included in the communication or by contacting Wiseep.
13. Automated Processing and AI-Assisted Technologies
Wiseep may use automated, machine-learning, AI-assisted, and other technical processes to support security assessments, vulnerability detection, classification, prioritization, analysis, and service improvement.
Such technologies may process technical information, scan data, application information, source code, logs, and other information submitted or generated during the Services.
Where applicable data protection law grants individuals specific rights regarding solely automated decision-making or profiling, Wiseep will comply with those requirements.
Wiseep's security findings should not be interpreted as decisions about an individual's legal status, employment, creditworthiness, or other similarly significant matters.
14. Children's Data
Wiseep's Services are intended for businesses and organizations and are not directed toward children.
Wiseep does not knowingly seek to collect personal data from children for the purpose of providing the Services.
If you believe that a child has provided personal data to Wiseep without appropriate authorization, please contact us.
15. Data Breach and Security Incidents
If Wiseep becomes aware of a personal data breach affecting information for which Wiseep has notification obligations under applicable law or contract, Wiseep will take reasonable steps to investigate, contain, mitigate, and address the incident.
Where legally required, Wiseep will notify the appropriate authority and/or affected parties within the applicable legal timeframe.
Where Wiseep processes personal data on behalf of a Customer as a processor, notification and cooperation obligations will be governed by the applicable Data Processing Agreement and applicable law.
16. Customer Responsibilities
Customers are responsible for ensuring that information submitted to Wiseep is provided lawfully and that they have appropriate authority to submit such information.
Customers should avoid submitting personal data that is unnecessary for the requested security assessment.
Customers are responsible for ensuring that they have an appropriate legal basis for providing personal data belonging to their employees, customers, users, contractors, or other individuals to Wiseep.
Customers must not intentionally submit information to Wiseep that they are legally prohibited from disclosing or processing.
17. Confidential and Sensitive Information
Security assessment data may contain highly confidential or sensitive information, including credentials, source code, personal data, security configurations, vulnerability evidence, and information concerning individuals.
Wiseep will process such information only as reasonably necessary for the purposes described in this Privacy Policy, applicable contractual arrangements, and applicable law.
Customers should not provide Wiseep with special category personal data unless it is necessary for the requested Service and the Customer has an appropriate legal basis and other required conditions for processing.
Special category data receives additional protection under applicable data protection laws.
18. Data Protection Agreements
Where Wiseep processes personal data on behalf of a Customer and applicable law requires a controller-processor agreement, Wiseep may enter into a separate Data Processing Agreement ("DPA") with the Customer.
Where there is a conflict between this Privacy Policy and a separately executed DPA concerning processor activities, the DPA will govern to the extent of that conflict.
19. Complaints
If you have concerns about Wiseep's handling of your personal data, you should first contact us: support@wiseep.com

