AP (Affordable Pentesting) is committed to protecting the personal information entrusted to us. This Privacy Policy explains what we collect through affordablepentesting.com, how we use and share it, and the choices and rights available to you.
In this policy
1. Scope
This Policy applies to visitors to our website, people who request a quote or contact us, prospective and current customers, and other business contacts. It covers personal information processed by Affordable Pentesting in connection with our website, marketing, sales, and delivery of manual, AI-assisted, and compliance-focused penetration-testing services.
It does not govern third-party websites, platforms, or services that we do not control, even when linked or embedded on our website.
2. Information we collect
Information you provide
- Contact and business information, including name, business email, phone number, company, job title, and country.
- Quote and scoping information, including pentest type, target environment, asset count, compliance framework, desired timeline, and other details you submit.
- Communications, including messages, meeting requests, support questions, feedback, and correspondence.
- Commercial information, including services requested, engagement status, invoices, and payment-related records. A payment provider may collect payment card details directly.
- Engagement information, including authorized target details, access information, technical contacts, evidence, findings, and remediation communications needed to scope, perform, report, and retest an authorized assessment.
Please do not send secrets, production credentials, patient information, payment-card data, or other highly sensitive information through a general website form. We will provide an appropriate secure channel when sensitive engagement data is required.
Information collected automatically
When you use the website, we and our service providers may collect IP address, approximate location, device and browser information, operating system, referring page, pages viewed, links clicked, timestamps, session and conversion events, and campaign data such as UTM parameters. Some information is collected through cookies, pixels, tags, local storage, and similar technologies.
Information from other sources
We may receive business contact information from your employer or colleagues, referral partners, public business sources, advertising and analytics providers, and tools you use to interact with our services.
3. How we use information
We use personal information to:
- respond to inquiries, prepare quotes, scope engagements, and schedule calls;
- provide manual, AI-assisted, and compliance-focused penetration-testing services;
- authenticate users and deliver reports, remediation guidance, and retests;
- process transactions and manage customer relationships;
- improve our website, services, content, and customer experience;
- measure website performance and marketing effectiveness;
- send service communications and permitted marketing;
- detect and prevent fraud, misuse, security incidents, and unlawful activity; and
- comply with law, enforce agreements, and establish or defend legal claims.
Where applicable law requires a legal basis, we rely on performance of a contract or steps requested before entering one, our legitimate interests in operating and securing the business, consent, and compliance with legal obligations.
6. Security-assessment and customer data
Penetration testing can involve confidential technical information. We use engagement data only as reasonably necessary to scope and perform authorized testing, validate findings, prepare reports, support remediation and retesting, maintain engagement records, secure our services, and meet contractual or legal duties.
Customers are responsible for ensuring they have authority to provide target systems, personal information, and access details to us. We do not authorize testing outside the written scope of an engagement.
7. Data retention
We retain personal information for as long as reasonably necessary to provide services, maintain business and security records, meet contractual commitments, resolve disputes, and comply with tax, accounting, and legal requirements. Retention varies based on the type and sensitivity of information and applicable engagement terms. We may delete or de-identify information when it is no longer needed.
8. How we protect information
We use administrative, technical, and organizational safeguards designed to protect personal information against unauthorized access, loss, misuse, alteration, or disclosure. No internet transmission or storage system is completely secure, so we cannot guarantee absolute security.
9. International data transfers
Affordable Pentesting and its service providers may process information in the United States and other countries where privacy laws may differ from those in your location. Where required, we use appropriate safeguards for international transfers, such as contractual protections.
10. Your privacy rights
Depending on where you live, you may have rights to request access to, correction of, deletion of, or a copy of your information; restrict or object to certain processing; withdraw consent; opt out of targeted advertising, sale, or sharing; and appeal a denied request. You may also complain to a privacy or data-protection authority.
We may need to verify your identity and authority before completing a request. Authorized agents may submit requests where permitted by law. We will not discriminate against you for exercising a privacy right.
You can unsubscribe from marketing emails using the link in the message. We may still send non-promotional communications about a request, transaction, engagement, security matter, or legal notice.
11. Children’s privacy
Our website and services are intended for businesses and are not directed to children under 13. We do not knowingly collect personal information from children under 13.
12. Third-party services and links
Our website may contain links to, or embeds from, third-party services. Their privacy practices are governed by their own notices, not this Policy.
13. Changes to this Policy
We may update this Policy as our services, technology, or legal obligations change. We will post the revised version here and update the “Last updated” date. If a change is material, we may provide additional notice where appropriate.
14. Contact us
For privacy questions or requests, contact Affordable Pentesting through the contact or quote form on this website and include “Privacy Request” in your message so it can be routed appropriately.
Contact Affordable PentestingDraft for legal review before publication. Qualified counsel should confirm that this notice matches AP’s legal entity, vendors, retention schedule, locations served, and contractual obligations.