Wiseep Privacy Policy

1. Introduction

Wiseep ("Wiseep", "we", "us", or "our") provides online cybersecurity and vulnerability assessment services designed to help organizations identify, understand, and remediate security vulnerabilities affecting their digital assets.

Our Services may include, depending on the Service selected:

  • Red Team Scan

  • Wildcard Domain Scan

  • Single Domain Scan

  • Credentialed Scan

  • Mobile Application Scan

  • Desktop Application Scan

  • Static Code Scan / Code Review

  • Infrastructure Scan and

  • Other security assessment and related services made available by Wiseep.

This Privacy Policy explains how Wiseep collects, uses, stores, protects, and otherwise processes personal data in connection with our website, platform, Services, communications, and related activities.

Wiseep is committed to protecting personal data and processing it in accordance with applicable data protection laws, including the UK General Data Protection Regulation ("UK GDPR") and the Data Protection Act 2018, where applicable.

2. Data Controller

The entity responsible for the processing of personal data under this Privacy Policy is Wiseep, By Ebruu Tech Limited.

For privacy-related questions or requests: support@wiseep.com

Depending on the nature and purpose of a particular processing activity, Wiseep may act as either a data controller or a data processor.

Where Wiseep processes personal data on behalf of a customer as a processor, the relevant customer may remain the controller of that data. In such circumstances, Wiseep will process the relevant data in accordance with the customer's instructions, applicable contractual arrangements, and any applicable Data Processing Agreement.

3. Personal Data We Collect

Depending on how you interact with Wiseep and which Services you use, we may process the following categories of information.

3.1. Account and Contact Information

This may include:

  • Name

  • Business name

  • Job title

  • Email address

  • Telephone number

  • Business address

  • Account credentials

  • Account identifiers and

  • Other information provided when creating or managing an account.

3.2. Billing and Transaction Information

This may include:

  • Billing name

  • Billing address

  • Transaction information

  • Payment status

  • Purchase history

  • Invoice information and

  • Other information necessary to process payments.

Where payments are processed by a third-party payment provider, Wiseep may not receive or store complete payment card information. Payment providers may process payment information in accordance with their own privacy policies.

3.3. Security Assessment and Scan Data

When you use Wiseep's Services, we may process information associated with the assets being assessed, including:

  • Domains and subdomains

  • IP addresses

  • URLs

  • Ports and services

  • Application information

  • Network information

  • System information

  • Security configuration information

  • HTTP requests and responses

  • Cookies and session information

  • Authentication information

  • Vulnerability findings

  • Security evidence

  • Proof-of-concept information

  • Screenshots

  • Logs

  • Metadata

  • Security headers

  • Publicly exposed information and

  • Other information necessary to perform the requested security assessment.

Such information may contain personal data belonging to you, your employees, customers, users, or other individuals.

3.4. Source Code and Application Files

For Code Review, Mobile Application Scan, Desktop Application Scan, or similar Services, customers may provide:

  • Source code

  • Application packages

  • Executable files

  • Mobile application files

  • Configuration files

  • Dependencies

  • Libraries

  • Documentation

  • API definitions

  • Credentials or secrets

  • Logs and

  • Other technical materials.

Such materials may contain personal data or confidential information. Customers are responsible for ensuring that they are authorized to provide such information to Wiseep.

3.5. Credentials and Authentication Information

For credentialed assessments, Wiseep may process authentication information supplied by the Customer, including:

  • Usernames

  • Passwords

  • API keys

  • Authentication tokens

  • Session credentials

  • Certificates

  • Access keys and

  • Other authentication information.

Wiseep uses such information only as reasonably necessary to perform the applicable security assessment and related Services.

3.6. Red Team and Publicly Available Information

Certain Services, including Red Team Scan, may involve identifying publicly accessible assets associated with an organization.

Depending on the Service, Wiseep may collect or process publicly available information such as:

  • Public domains

  • Subdomains

  • IP addresses

  • DNS information

  • Publicly accessible services

  • Public websites

  • Public files

  • Publicly exposed credentials or secrets

  • Publicly available technical information

  • Public security information

  • OSINT information and

  • Other publicly available information relevant to the security assessment.

Red Team Scan may involve discovering assets without the Customer providing a complete technical scope, subject to Wiseep's applicable authorization and assessment procedures.

3.7. Usage and Technical Data

We may collect:

  • IP address

  • Browser type

  • Device information

  • Operating system

  • Login information

  • Session information

  • Access times

  • Referrer information

  • Error information

  • Platform activity and

  • Security and audit logs.

3.8. Communications

We may retain information contained in communications with Wiseep, including:

  • Emails

  • Support requests

  • Chat communications

  • Feedback

  • Complaints

  • Technical enquiries and

  • Other correspondence.

4. How We Use Personal Data

We may use personal data for the following purposes:

4.1. Providing the Services

We process information to:

  • Create and manage accounts

  • Authenticate users

  • Process scan requests

  • Verify scope and authorization

  • Conduct security assessments

  • Process uploaded files and technical information

  • Generate vulnerability findings

  • Provide vulnerability reports

  • Provide access to paid vulnerability details

  • Perform retesting

  • Provide customer support and

  • Otherwise provide the requested Services.

4.2. Security and Abuse Prevention

We may process information to:

  • Protect Wiseep systems

  • Detect unauthorized access

  • Detect fraud

  • Detect misuse

  • Prevent unauthorized scanning

  • Investigate security incidents

  • Protect customers and third parties

  • Monitor platform security and

  • Enforce our Terms of Service.

4.3. Security Risk Communication and Escalation

Where Wiseep reasonably determines that a security vulnerability presents a material, critical, or otherwise significant risk, we may process and use relevant information to communicate or escalate that risk to appropriate representatives of the Customer organization.

Depending on the circumstances, this may include contacting:

  • Information Security personnel

  • CISO

  • CIO

  • CTO

  • Security Manager

  • Risk Management

  • Compliance

  • Legal

  • Executive Management or

  • Other responsible representatives.

This may occur where Wiseep reasonably believes that a significant security vulnerability is being intentionally ignored, suppressed, concealed, improperly dismissed, or prevented from reaching personnel with appropriate responsibility or authority.

This right may apply even where an account holder or other individual acting on behalf of the Customer has requested that a finding be deleted, suppressed, ignored, or not purchased.

Wiseep will seek to limit such communications to information reasonably necessary to communicate and assess the relevant security risk.

This processing is separate from any decision to publicly disclose vulnerability information.

4.4. Service Improvement

We may use appropriately aggregated, anonymized, or otherwise lawfully processed information to:

  • Improve our scanning technologies

  • Improve vulnerability detection

  • Develop security methodologies

  • Analyze service performance

  • Improve reliability

  • Develop new features and

  • Improve the overall quality of our Services.

Where information is anonymized so that individuals are no longer identifiable, it is no longer treated as personal data to the extent permitted by applicable law.

4.5. Legal and Regulatory Compliance

We may process personal data where necessary to:

  • Comply with legal obligations

  • Respond to lawful requests

  • Establish, exercise, or defend legal claims

  • Cooperate with regulators

  • Prevent fraud

  • Protect rights and property or

  • Protect the safety and security of our users and systems.

5. Lawful Bases for Processing

Where required by applicable law, Wiseep relies on one or more lawful bases for processing personal data.

Depending on the circumstances, these may include:

5.1. Contract

Where processing is necessary to provide Services requested by you or to take steps before entering into a contract.

5.2. Legitimate Interests

Where processing is necessary for Wiseep's legitimate interests, including:

  • Platform security

  • Fraud prevention

  • Service improvement

  • Network and information security

  • Protecting our systems

  • Enforcing contractual rights

  • Defending legal claims and

  • Communicating material security risks.

Where we rely on legitimate interests, we consider the interests and fundamental rights of affected individuals and will not rely on this basis where those interests are overridden by those rights, unless otherwise permitted by law.

5.3. Legal Obligation

Where processing is necessary to comply with a legal obligation applicable to Wiseep.

5.4. Consent

Where consent is required by applicable law, Wiseep will seek consent before carrying out the relevant processing.

You may withdraw consent at any time where processing is based on consent.

Withdrawal of consent does not affect the lawfulness of processing carried out before withdrawal.

6. Cookies and Similar Technologies

Wiseep may use cookies and similar technologies to:

  • Operate the website

  • Maintain sessions

  • Remember preferences

  • Understand website usage

  • Improve performance

  • Protect against abuse

  • Support analytics or marketing where permitted.

Where required by applicable law, Wiseep will obtain consent before placing non-essential cookies or similar technologies.

Further information may be provided through Wiseep's Cookie Notice or cookie settings.

7. Data Sharing and Recipients

Wiseep does not sell personal data.

We may share personal data where reasonably necessary with the following categories of recipients:

7.1. Service Providers

These may include providers of:

  • Cloud infrastructure

  • Hosting

  • Payment processing

  • Email

  • Customer support

  • Authentication

  • Analytics

  • Security monitoring

  • Backup

  • Communications

  • Technical infrastructure and

  • Other services necessary to operate Wiseep.

Such providers may process information only as necessary to provide their services and subject to appropriate contractual or legal safeguards where required.

7.2. Customer Representatives

Where necessary for security risk escalation under this Privacy Policy and our Terms of Service, Wiseep may communicate relevant security information to appropriate representatives of the Customer organization.

7.3. Legal and Regulatory Authorities

Wiseep may disclose information where:

  • Required by law

  • Required by a court or competent authority

  • Necessary to comply with a lawful request

  • Necessary to establish, exercise, or defend legal claims or

  • Otherwise permitted or required under applicable law.

7.4. Corporate Transactions

Wiseep may disclose relevant information as part of:

  • A merger

  • Acquisition

  • Sale of assets

  • Corporate restructuring

  • Financing transaction or

  • Similar corporate transaction.

subject to applicable confidentiality and data protection requirements.

8. International Data Transfers

Wiseep may use service providers or infrastructure located outside the United Kingdom.

Where personal data is transferred outside the UK, Wiseep will implement appropriate safeguards where required by applicable data protection law.

Depending on the destination and circumstances, safeguards may include:

  • UK adequacy regulations

  • International Data Transfer Agreements

  • UK GDPR Addendum

  • Standard Contractual Clauses where applicable

  • Appropriate contractual protections or

  • Other legally recognized transfer mechanisms.

9. Data Security

Wiseep implements appropriate technical and organizational measures designed to protect personal data against unauthorized access, loss, misuse, alteration, disclosure, or destruction.

Measures may include:

  • Access controls

  • Authentication controls

  • Encryption in transit

  • Encryption at rest where appropriate

  • Logging and monitoring

  • Network security controls

  • Segmentation and isolation

  • Secure development practices

  • Vulnerability management

  • Backup and recovery controls and

  • Personnel security and awareness measures.

No method of transmission, storage, or processing can be guaranteed to be completely secure.

Wiseep therefore cannot guarantee absolute security of personal data.

10. Data Retention

Wiseep retains personal data only for as long as reasonably necessary for the purposes described in this Privacy Policy, unless a longer period is required or permitted by law.

Retention periods may vary depending on the type and purpose of the information.

For example, Wiseep may retain:

  • Account information while an account remains active

  • Billing and transaction records for periods required by applicable tax and accounting requirements

  • Security and audit logs for periods reasonably necessary for security, fraud prevention, investigation, and operational purposes

  • Scan results and vulnerability information for periods reasonably necessary to provide Services, maintain records, investigate disputes, preserve evidence, enforce contractual rights, or protect Wiseep and its customers

  • Customer-submitted technical materials only for as long as reasonably necessary for the applicable Service and related purposes and

  • Backup copies until they are overwritten or securely deleted in accordance with applicable backup and retention processes.

Where a customer requests deletion, Wiseep will assess the request in accordance with applicable law.

Deletion may be refused or delayed where Wiseep has a lawful basis or legal obligation to retain the information, including where necessary to:

  • Comply with legal obligations

  • Establish, exercise, or defend legal claims

  • Prevent fraud or abuse

  • Investigate security incidents

  • Protect Wiseep or others or

  • Maintain necessary business or security records.

11. Your Data Protection Rights

Subject to applicable law and relevant exemptions, you may have the following rights:

11.1. Right of Access

You may request access to personal data held about you.

11.2. Right to Rectification

You may request correction of inaccurate or incomplete personal data.

11.3. Right to Erasure

You may request deletion of personal data in certain circumstances.

11.4. Right to Restriction

You may request restriction of processing in certain circumstances.

11.5. Right to Object

You may object to certain processing, including processing based on legitimate interests.

11.6. Right to Data Portability

Where applicable, you may request your personal data in a structured, commonly used, and machine-readable format.

11.7. Right to Withdraw Consent

Where processing is based on consent, you may withdraw your consent.

These rights are not absolute and may be subject to legal exceptions and limitations.

12. Marketing Communications

Wiseep may send service-related communications that are necessary to operate your account or provide Services.

Where permitted by law, Wiseep may also send promotional communications about:

  • Wiseep Services

  • New features

  • Security services

  • Offers and

  • Other relevant products or services.

Where consent is required, Wiseep will obtain it before sending applicable marketing communications.

You may unsubscribe from marketing communications at any time using the unsubscribe mechanism included in the communication or by contacting Wiseep.

13. Automated Processing and AI-Assisted Technologies

Wiseep may use automated, machine-learning, AI-assisted, and other technical processes to support security assessments, vulnerability detection, classification, prioritization, analysis, and service improvement.

Such technologies may process technical information, scan data, application information, source code, logs, and other information submitted or generated during the Services.

Where applicable data protection law grants individuals specific rights regarding solely automated decision-making or profiling, Wiseep will comply with those requirements.

Wiseep's security findings should not be interpreted as decisions about an individual's legal status, employment, creditworthiness, or other similarly significant matters.

14. Children's Data

Wiseep's Services are intended for businesses and organizations and are not directed toward children.

Wiseep does not knowingly seek to collect personal data from children for the purpose of providing the Services.

If you believe that a child has provided personal data to Wiseep without appropriate authorization, please contact us.

15. Data Breach and Security Incidents

If Wiseep becomes aware of a personal data breach affecting information for which Wiseep has notification obligations under applicable law or contract, Wiseep will take reasonable steps to investigate, contain, mitigate, and address the incident.

Where legally required, Wiseep will notify the appropriate authority and/or affected parties within the applicable legal timeframe.

Where Wiseep processes personal data on behalf of a Customer as a processor, notification and cooperation obligations will be governed by the applicable Data Processing Agreement and applicable law.

16. Customer Responsibilities

Customers are responsible for ensuring that information submitted to Wiseep is provided lawfully and that they have appropriate authority to submit such information.

Customers should avoid submitting personal data that is unnecessary for the requested security assessment.

Customers are responsible for ensuring that they have an appropriate legal basis for providing personal data belonging to their employees, customers, users, contractors, or other individuals to Wiseep.

Customers must not intentionally submit information to Wiseep that they are legally prohibited from disclosing or processing.

17. Confidential and Sensitive Information

Security assessment data may contain highly confidential or sensitive information, including credentials, source code, personal data, security configurations, vulnerability evidence, and information concerning individuals.

Wiseep will process such information only as reasonably necessary for the purposes described in this Privacy Policy, applicable contractual arrangements, and applicable law.

Customers should not provide Wiseep with special category personal data unless it is necessary for the requested Service and the Customer has an appropriate legal basis and other required conditions for processing.

Special category data receives additional protection under applicable data protection laws.

18. Data Protection Agreements

Where Wiseep processes personal data on behalf of a Customer and applicable law requires a controller-processor agreement, Wiseep may enter into a separate Data Processing Agreement ("DPA") with the Customer.

Where there is a conflict between this Privacy Policy and a separately executed DPA concerning processor activities, the DPA will govern to the extent of that conflict.

19. Complaints

If you have concerns about Wiseep's handling of your personal data, you should first contact us: support@wiseep.com