Privacy

Privacy Policy

How SurfaceLoop processes and protects personal data, and the rights you have under UK GDPR.

Last updated: 2 July 2026

This is a template. This policy is provided as a starting point and has not been reviewed by a qualified solicitor or data protection specialist. Have it reviewed before launch to ensure it accurately reflects your processing and meets UK GDPR obligations.

1. Who we are (data controller)

SurfaceLoop ("we", "us") provides an External Attack Surface Management platform. For the personal data described in this policy, SurfaceLoop is the data controller. You can contact our data protection point of contact at [email protected] (placeholder contact).

2. Personal data we process

We practise data minimisation and collect only what the Service needs. The personal data we process falls into two categories:

  • Account data — the email address and identity information you provide when you create an account, plus authentication metadata and billing information for paid plans.
  • Scan-discovered data — data our scanners observe about assets in your verified inventory, which may include IP addresses, domain names and subdomains, and email addresses (for example in DNS, certificate, or WHOIS records). Where these relate to identifiable individuals they are personal data.

We do not permanently store raw scanner output. Only the normalised exposure records needed to report findings to you are persisted; intermediate scanner payloads are discarded after processing.

3. How we use personal data and our lawful basis

  • • To provide the Service (create your account, run scans on your authorised assets, report exposures) — performance of a contract with you.
  • • To secure, maintain, and improve the Service, and to detect misuse — legitimate interests in operating a reliable and safe platform.
  • • To send service and alert emails — performance of a contract and legitimate interests.
  • • To meet legal and accountability obligations (for example audit logging of scan initiations) — legal obligation and legitimate interests.

4. Data residency

All scan result data, asset records, and account data are stored in the United Kingdom, in the AWS eu-west-2 (London) region. We do not replicate this data to regions outside the UK/EEA without review. Some sub-processors listed below may process limited data (for example diagnostic or analytics events) under appropriate safeguards; see section 8.

5. Data retention

We keep account data for as long as your account is active. Scan results and exposure records are retained for the configured retention period so you can track changes over time, after which resolved exposures older than that period are purgeable. Container logs are retained on a short rolling window (14 days). When you close your account or exercise your right to erasure, associated records are deleted as described below.

6. Your rights under UK GDPR

Subject to the conditions in UK GDPR, you have the right to:

  • • access the personal data we hold about you;
  • • request rectification of inaccurate data;
  • • request erasure (the "right to be forgotten");
  • • restrict or object to certain processing;
  • • data portability; and
  • • withdraw consent where processing is based on consent.

Right to erasure. We support right-to-erasure through cascade deletes implemented in our database: deleting an asset or account removes the dependent scan jobs and exposure records that reference it. One category is retained: the results of past scans, including the scanned hostname, are kept after an asset is removed so historical scan records and any reports you have shared stay accurate. On request, we erase the identifying values from that history while keeping its dates and findings. To exercise any right, contact us at the address in section 1. We aim to respond within one month.

7. How we protect data

We enforce tenant isolation through database row-level security, encrypt secrets at rest, verify authentication on every request, and avoid logging personal data (such as IP addresses, domain names, and email addresses) at diagnostic levels. Access to production data is restricted and audited.

8. Sub-processors

We use the following sub-processors and external services to operate the Service. The enrichment services are part of our reviewed external API allowlist and receive only the data needed for their stated purpose.

ServicePurpose
ClerkAuthentication and account identity
SupabaseDatabase and application data storage
Amazon Web Services (AWS)Hosting and infrastructure (eu-west-2, London)
ResendTransactional and alert emails
SentryError monitoring and diagnostics
PostHogProduct analytics
ShodanIP address enrichment
WhoisXMLWHOIS / domain registration enrichment
Certificate Transparency (crt.sh)Subdomain enumeration from public CT logs

9. Cookies and analytics

We use strictly necessary cookies to keep you signed in and to operate the Service. We use PostHog for product analytics to understand how the Service is used and to improve it. Where required, we will seek your consent for non-essential analytics.

10. Children

The Service is not directed at children and is intended for business use only. We do not knowingly collect personal data from anyone under 18.

11. Complaints to the ICO

If you are unhappy with how we have handled your personal data, we would like the chance to put it right — please contact us first. You also have the right to lodge a complaint with the UK Information Commissioner's Office (ICO) at ico.org.uk or by calling their helpline.

12. Changes to this policy

We may update this Privacy Policy from time to time. If we make material changes we will provide reasonable notice. The date at the top of this page shows when it was last updated. See also our Terms of Service and Acceptable Use Policy.