Privacy Policy

Last updated: 5 October 2026

This policy explains what personal data TrustDyne collects, why, who we share it with and what your rights are. It applies to our website, the TrustDyne platform and our business communications.

1. Who we are

TrustDyne is operated by Khandaker Saifuzzaman, trading as TrustDyne, 50 Dale Road, Luton, LU1 1LJ, United Kingdom. We intend to transfer the business to a UK limited company. When we do, this policy will name that company and we will tell customers. Privacy contact: legal@trustdyne.com.

We act in two roles:

  • Controller for account data, website visits, security researcher reports, billing records and our own sales and marketing contacts. We decide why and how that data is used.
  • Processor for the content you give the platform to analyse: uploaded files, scan targets, scan results, reports and connected cloud account metadata. You decide why that data is processed and we follow your instructions under our Data Processing Addendum.

2. What we collect

DataExamplesSource
Account dataEmail address, company domain, sign-in and multi-factor settings. Passwords are handled by our authentication provider (Amazon Cognito). We do not see or store them.You
Platform contentUploaded firmware, apps and code. Domains and cloud accounts you register. Scan results, findings, SBOMs and reports. Role ARNs and configuration data from cloud accounts you connect.You and the scans you run
Usage and audit dataScan IDs, timestamps, API calls, consent and report-access events, IP address and browser type.Generated when you use the platform
Vulnerability reportsName, email and details submitted by security researchers through our disclosure programme.The researcher
Billing dataPlan, subscription status, invoices. Card details are collected and held by Stripe, not by us.You and Stripe
Sales and marketing contactsBusiness name, work email, job title and company of people at organisations we think might benefit from TrustDyne.Publicly available business sources, or you
Website visit dataIP address and request details processed by our hosting provider to serve the site and protect it from abuse.Your browser

We do not knowingly collect special category data. Please do not include it in uploaded content or reports.

3. Why we use it, and our legal basis

PurposeLegal basis (UK GDPR Art. 6)
Provide the platform, run scans, produce reports, authenticate you and support youContract
Keep the platform secure, prevent abuse and fraud, keep audit logsLegitimate interests (securing our service and our customers)
Take payment and keep financial recordsContract and legal obligation
Handle vulnerability reports and respond to researchersLegitimate interests (improving security)
Send service messages such as scan-complete and account noticesContract
Contact businesses about TrustDyne by emailLegitimate interests (promoting a relevant B2B service). Every message includes a way to opt out and we stop when you ask. We only email corporate addresses, as required by PECR.
Improve the product using aggregated, non-content usage informationLegitimate interests

We do not sell personal data. We do not use your uploaded content, findings or reports to train AI models.

4. AI processing

Some features use large language models, which we reach through Amazon Bedrock in AWS. Content sent for analysis is used to produce your results. Under AWS's Bedrock terms, prompts and outputs are not shared with the model provider and are not used to train the underlying models. Findings and suggested fixes are decision support. We do not make decisions about individuals that have legal or similarly significant effects.

5. Who we share data with

We use a small set of service providers (sub-processors) listed on our Sub-processors page. We share data with other third parties only if the law requires it, to protect people or our rights, or as part of a business transfer such as moving the business into a limited company. Integrations such as Jira or GitHub only send data to those services when you connect them.

6. International transfers

Our infrastructure runs in the AWS US East (N. Virginia) region, so personal data is transferred from the UK and EEA to the United States. We rely on the UK Extension to the EU-US Data Privacy Framework (the UK-US data bridge) for providers that are certified under it, including AWS, and on appropriate safeguards required by UK GDPR for any other transfer. Contact us for details.

7. How long we keep it

DataRetention
Scan reports and derived findings12 months from creation, then deleted automatically
Uploaded files (firmware, apps, archives)Deleted, including stored versions, once analysis finishes
Account dataWhile your account is open, then deleted or anonymised within 90 days of closure or on your request
Application audit events90 days
Cloud provider audit logs (AWS CloudTrail)Kept long term for security and accountability. No fixed deletion date at present.
BackupsDatabase point-in-time recovery: 35 days. Recurring disaster-recovery snapshots: 90 days. Deleted data can persist in backups until they expire.
Vulnerability reportsAs long as needed to handle the report and show how we responded
Sales and marketing contactsWhile the contact is relevant. We remove it when you ask.
Billing recordsAs required by UK tax and accounting law

8. Security

Customer data is encrypted at rest with AWS KMS keys and in transit with TLS. Access is limited to named roles. See our Security and Trust page for the controls we run.

9. Your rights

You can ask us to access, correct, delete, restrict or export your personal data, and you can object to processing based on legitimate interests or to direct marketing. Email legal@trustdyne.com. We will reply within one month. If you are a customer's user and your data is platform content that we hold as processor, we can pass your request to the customer.

You can complain to the UK Information Commissioner's Office at ico.org.uk or on 0303 123 1113. We would appreciate the chance to put things right first.

10. Cookies and similar technologies

See our Cookie Policy. We do not use advertising or analytics cookies.

11. Children

The platform is for businesses and is not directed at anyone under 18.

12. Changes

We will post changes here and update the date above. If a change is material we will tell account holders by email before it takes effect.