Home / Privacy Policy
Legal
Privacy Statement
This page describes how Attack Vector collects, uses, and protects personal data when you visit our website or contact us about our services. Separate statements are provided for the United Kingdom and the European Economic Area.
This page contains separate privacy statements for visitors in the United Kingdom and the European Economic Area (EEA).
This Privacy Statement was last updated on 11 July 2026 and applies to visitors and prospective clients in the United Kingdom.
1. Introduction
Attack Vector Ltd ("Attack Vector", "we", "us" or "our") respects your privacy and is committed to protecting your personal data. This statement explains how we collect, use, and store personal data when you visit https://attackvector.uk, use our contact forms or instant quote calculator, or otherwise interact with us about our cybersecurity services.
This statement should be read together with our Cookies Policy, which explains how we use cookies and similar technologies.
2. Who we are
Data controller: Attack Vector Ltd
Registered address: 86-90 Paul Street, London, EC2A 4NE, United Kingdom
Company number: 14996130
Contact email: consultancy@attackvector.uk
If you have questions about this statement or how we handle your personal data, please contact us using the details above.
3. Personal data we collect
Depending on how you use our website, we may collect the following categories of personal data:
- Identity and contact data — such as your first name, last name, email address, telephone number, and company name.
- Enquiry and quote data — information you provide when contacting us or using our penetration testing quote calculator, including project scope details, infrastructure descriptions, and messages you send us.
- Technical and usage data — such as IP address, browser type, device information, referring pages, and timestamps, collected through server logs.
- Cookie and consent data — your cookie preferences and related consent records managed through our cookie banner.
We do not intentionally collect special category data (such as health information) through this website. Please do not submit sensitive personal data unless we have asked you to do so for a specific engagement.
4. How we collect personal data
We collect personal data when you:
- submit a contact form on our website;
- complete our instant quote calculator;
- email us or otherwise communicate with us;
- browse our website, including through cookies and server logs;
- manage your cookie preferences through our consent banner.
5. How and why we use personal data
We use personal data for the following purposes and on the following legal bases under UK GDPR:
| Purpose | Legal basis |
|---|---|
| Responding to enquiries and contact form submissions | Legitimate interests and/or steps prior to entering a contract |
| Providing quotes and assessing project scope | Steps prior to entering a contract and legitimate interests |
| Operating, securing, and improving our website | Legitimate interests |
| Preventing spam, abuse, and fraudulent submissions | Legitimate interests |
| Complying with legal and regulatory obligations | Legal obligation |
| Using non-essential cookies and similar technologies | Consent |
6. Data sharing
We do not sell, rent, or share your personal data with third-party services. Personal data you provide through this website is processed solely by Attack Vector Ltd for the purposes described in this statement.
We may disclose personal data only where we are legally required to do so, for example in response to a court order or a request from a regulator or law enforcement authority.
7. Cookies
We use cookies and similar technologies on our website. Some cookies are strictly necessary; others require your consent. For full details, including how to manage your preferences, see our Cookies Policy.
8. Data retention
We keep personal data only for as long as necessary for the purposes described in this statement, including to meet legal, accounting, or reporting requirements. In general:
- Contact and quote enquiries — retained for up to 24 months after our last meaningful contact, unless a longer period is needed for an active or prospective engagement.
- Server and security logs — typically retained for up to 90 days.
- Cookie consent records — retained in line with our cookie compliance configuration and applicable requirements.
We may retain data for longer where required by law or to establish, exercise, or defend legal claims.
9. Security
As a cybersecurity consultancy, we take appropriate technical and organisational measures to protect personal data against unauthorised access, loss, misuse, or alteration. No method of transmission over the internet is completely secure, and we cannot guarantee absolute security.
10. Your rights
Under UK data protection law, you have rights in relation to your personal data, including the right to:
- request access to the personal data we hold about you;
- request correction of inaccurate or incomplete data;
- request erasure of your personal data in certain circumstances;
- object to processing based on legitimate interests;
- request restriction of processing in certain circumstances;
- request data portability where applicable;
- withdraw consent at any time where processing is based on consent.
To exercise your rights, contact us at consultancy@attackvector.uk. We may need to verify your identity before responding.
You also have the right to lodge a complaint with the UK Information Commissioner's Office (ICO):
Website: ico.org.uk
Telephone: 0303 123 1113
11. Children
Our website and services are intended for business users and are not directed at children under 18. We do not knowingly collect personal data from children.
12. Changes to this statement
We may update this statement from time to time. The "last updated" date at the top of this document shows when it was most recently revised. We encourage you to review this page periodically.
This Privacy Statement was last updated on 11 July 2026 and applies to visitors and prospective clients in the European Economic Area (EEA).
1. Introduction
Attack Vector Ltd ("Attack Vector", "we", "us" or "our") respects your privacy and is committed to protecting your personal data in accordance with the EU General Data Protection Regulation (GDPR).
This statement explains how we collect, use, and store personal data when you visit https://attackvector.uk, use our contact forms or instant quote calculator, or otherwise interact with us about our cybersecurity services from within the EEA.
This statement should be read together with our Cookies Policy.
2. Who we are
Data controller: Attack Vector Ltd
Registered address: 86-90 Paul Street, London, EC2A 4NE, United Kingdom
Company number: 14996130
Contact email: consultancy@attackvector.uk
Attack Vector is established in the United Kingdom. Where EU GDPR applies to our processing of your personal data, you may contact us using the details above for any privacy-related request.
3. Personal data we collect
Depending on how you use our website, we may collect the following categories of personal data:
- Identity and contact data — such as your first name, last name, email address, telephone number, and company name.
- Enquiry and quote data — information you provide when contacting us or using our penetration testing quote calculator, including project scope details, infrastructure descriptions, and messages you send us.
- Technical and usage data — such as IP address, browser type, device information, referring pages, and timestamps.
- Cookie and consent data — your cookie preferences and related consent records.
We do not intentionally collect special category data through this website unless we have a lawful basis and have asked you to provide it for a specific engagement.
4. How we collect personal data
We collect personal data when you:
- submit a contact form on our website;
- complete our instant quote calculator;
- email us or otherwise communicate with us;
- browse our website, including through cookies and server logs;
- manage your cookie preferences through our consent banner.
5. How and why we use personal data
We process personal data for the following purposes and on the following legal bases under Article 6 GDPR:
| Purpose | Legal basis |
|---|---|
| Responding to enquiries and contact form submissions | Article 6(1)(b) contract / pre-contractual steps and Article 6(1)(f) legitimate interests |
| Providing quotes and assessing project scope | Article 6(1)(b) and Article 6(1)(f) |
| Operating, securing, and improving our website | Article 6(1)(f) legitimate interests |
| Preventing spam, abuse, and fraudulent submissions | Article 6(1)(f) legitimate interests |
| Complying with legal obligations | Article 6(1)(c) legal obligation |
| Using non-essential cookies and similar technologies | Article 6(1)(a) consent |
6. Data sharing
We do not sell, rent, or share your personal data with third-party services. Personal data you provide through this website is processed solely by Attack Vector Ltd for the purposes described in this statement.
We may disclose personal data only where we are legally required to do so, for example in response to a court order or a request from a regulator or law enforcement authority.
7. Cookies
We use cookies and similar technologies on our website. Some cookies are strictly necessary; others require your consent under the ePrivacy rules and GDPR. For details and preference controls, see our Cookies Policy.
8. Data retention
We retain personal data only for as long as necessary for the purposes described in this statement. In general:
- Contact and quote enquiries — up to 24 months after our last meaningful contact, unless a longer period is needed for an active or prospective engagement.
- Server and security logs — typically up to 90 days.
- Cookie consent records — retained in line with our cookie compliance configuration and applicable requirements.
We may retain data longer where required by law or to establish, exercise, or defend legal claims.
9. International transfers
Personal data is processed by Attack Vector Ltd in the United Kingdom. We do not share personal data with third-party services. If you access our website from the EEA, your personal data remains under our control and is processed in the UK in accordance with this statement.
10. Security
We implement appropriate technical and organisational measures to protect personal data against unauthorised access, loss, misuse, or alteration. No online transmission can be guaranteed to be completely secure.
11. Your rights
Under EU GDPR, you have the following rights in relation to your personal data:
- right of access;
- right to rectification;
- right to erasure ("right to be forgotten") in certain circumstances;
- right to restriction of processing;
- right to data portability;
- right to object to processing based on legitimate interests;
- right to withdraw consent at any time where processing is based on consent;
- right not to be subject to a decision based solely on automated processing where applicable.
To exercise your rights, contact us at consultancy@attackvector.uk. We will respond within one month, subject to permitted extensions for complex requests.
You also have the right to lodge a complaint with your local supervisory authority in the EEA. A list of EU data protection authorities is available from the European Data Protection Board.
12. Children
Our website and services are intended for business users and are not directed at children under 16. We do not knowingly collect personal data from children.
13. Changes to this statement
We may update this statement from time to time. The "last updated" date at the top of this document shows when it was most recently revised.