Legal
Privacy Policy
Last updated: 16 June 2026 · Version 1.0
1. Who we are
BreakMesh ("we", "us", "our") operates the BreakMesh authorized website security scanning platform. We are the data controller for personal data processed through the platform.
For data protection queries or to exercise your rights, contact us at: privacy@breakmesh.io
2. What personal data we collect
| Category | Examples | Source |
|---|---|---|
| Identity & contact | Name, email address | You provide at registration |
| Account credentials | Hashed password, MFA secret (encrypted) | You provide at registration / MFA setup |
| Organisation data | Organisation name, plan tier, billing status | You provide; Stripe provides billing status |
| Target & scan data | Domain names, scan results, finding details | You add targets; our scanner generates findings |
| Technical data | IP address (in consent records & audit logs), user-agent string | Automatically collected on pentest consent & login |
| Usage data | Pages visited, features used, scan history | Automatically collected |
| Payment data | Billing name, email, card last 4 digits | Stripe collects on our behalf |
| Communications | Support email content | You provide |
3. Lawful basis for processing
| Processing activity | Lawful basis |
|---|---|
| Providing the SaaS service (scans, reports, targets) | Contract — Art. 6(1)(b) GDPR |
| Billing and subscription management | Contract — Art. 6(1)(b) |
| Security audit logging | Legitimate interests — Art. 6(1)(f) (detecting fraud and misuse) |
| Pentest consent records | Legal obligation / Consent — Art. 6(1)(a) & (c) |
| Marketing communications | Consent — Art. 6(1)(a) (separate opt-in) |
| Regulatory / tax record-keeping | Legal obligation — Art. 6(1)(c) |
4. How we use your data
- To create and manage your account and organisation.
- To run authorized security scans and deliver results.
- To process billing and manage your subscription via Stripe.
- To maintain an audit trail of security-relevant actions (fraud prevention and legal accountability).
- To comply with our Rules of Engagement for penetration testing engagements.
- To send you product updates and security alerts related to your account (transactional emails).
- To send marketing emails if you have separately opted in.
5. Sub-processors
We share personal data with the following third-party processors where necessary to deliver the service:
| Sub-processor | Purpose | Location | Transfer mechanism |
|---|---|---|---|
| Stripe, Inc. | Payment processing & billing | USA | Standard Contractual Clauses (SCCs) |
| Atlassian (Jira) | Issue tracking (optional integration) | Australia / USA | SCCs |
| Slack Technologies | Notifications (optional integration) | USA | SCCs |
| GitHub, Inc. | PR status checks (optional integration) | USA | SCCs |
| OpenAI / Anthropic | AI-generated remediation suggestions (optional, requires explicit org opt-in) | USA | SCCs |
| Cloud infrastructure provider | Hosting, database, storage | EU / EEA (where available) | Adequacy decision / SCCs |
We will give 30 days' notice before adding any new sub-processors that process personal data.
Customers acting as data controller may also review our Data Processing Agreement, which sets out our obligations as processor and is available to enter into alongside your subscription.
6. International data transfers
Some sub-processors listed above are located outside the European Economic Area (EEA). For transfers to the USA, we rely on Standard Contractual Clauses (SCCs) approved by the European Commission, supplementary measures where required, and the Data Processing Agreements we have in place with each provider.
7. Data retention
| Data category | Retention period |
|---|---|
| Active user accounts | Duration of contract + 30 days after cancellation |
| Scan records & findings | 2 years from scan date |
| Pentest consent records | 5 years from engagement end (legal obligation) |
| Security audit logs | 3 years |
| Proof-of-concept (PoC) artifact files | 90 days (per Rules of Engagement) |
| Billing records | 7 years (tax / legal obligation) |
| Session tokens | 30 days or until logout |
8. Your rights
Under GDPR, you have the following rights regarding your personal data:
- Right of access (Art. 15) — request a copy of all data we hold about you via your account settings or by emailing privacy@breakmesh.io.
- Right to rectification (Art. 16) — correct inaccurate data in your account settings.
- Right to erasure (Art. 17) — request deletion of your account and data. Use the "Delete account" option in Settings or email us.
- Right to restrict processing (Art. 18) — request that we pause processing of your data while a dispute is pending.
- Right to data portability (Art. 20) — download a machine-readable JSON export of your data via Settings.
- Right to object (Art. 21) — object to processing based on legitimate interests, including direct marketing.
- Right to withdraw consent — withdraw marketing consent at any time via account settings.
We will respond to all rights requests within 30 days. To exercise any right, contact privacy@breakmesh.io.
If you believe your rights have not been respected, you may lodge a complaint with your national data protection supervisory authority. In the UK, this is the Information Commissioner's Office (ICO).
9. Cookies
We use only strictly necessary cookies for authentication. See our Cookie Policy for full details.
10. Security
We implement appropriate technical and organisational measures including:
- Passwords hashed with PBKDF2-SHA256 (210,000 iterations).
- API keys stored as HMAC-SHA256 hashes — raw keys are never persisted.
- Session cookies set with
HttpOnly,Secure, andSameSite=Strictflags. - HSTS enforced on all production endpoints.
- All personal data transmitted over TLS.
- Authentication credentials used for security scans are stored only in ephemeral memory and never written to the database.
11. Children
The BreakMesh platform is not intended for use by individuals under the age of 18. We do not knowingly collect personal data from children.
12. Changes to this policy
We will notify registered users by email at least 14 days before any material changes take effect. The current version and effective date are shown at the top of this page. Continued use after the effective date constitutes acceptance.
13. Contact
Data controller: BreakMesh
Email: privacy@breakmesh.io