Privacy Policy
Last updated: 5 October 2026
This policy explains what personal data TrustDyne collects, why, who we share it with and what your rights are. It applies to our website, the TrustDyne platform and our business communications.
1. Who we are
TrustDyne is operated by Khandaker Saifuzzaman, trading as TrustDyne, 50 Dale Road, Luton, LU1 1LJ, United Kingdom. We intend to transfer the business to a UK limited company. When we do, this policy will name that company and we will tell customers. Privacy contact: legal@trustdyne.com.
We act in two roles:
- Controller for account data, website visits, security researcher reports, billing records and our own sales and marketing contacts. We decide why and how that data is used.
- Processor for the content you give the platform to analyse: uploaded files, scan targets, scan results, reports and connected cloud account metadata. You decide why that data is processed and we follow your instructions under our Data Processing Addendum.
2. What we collect
| Data | Examples | Source |
|---|---|---|
| Account data | Email address, company domain, sign-in and multi-factor settings. Passwords are handled by our authentication provider (Amazon Cognito). We do not see or store them. | You |
| Platform content | Uploaded firmware, apps and code. Domains and cloud accounts you register. Scan results, findings, SBOMs and reports. Role ARNs and configuration data from cloud accounts you connect. | You and the scans you run |
| Usage and audit data | Scan IDs, timestamps, API calls, consent and report-access events, IP address and browser type. | Generated when you use the platform |
| Vulnerability reports | Name, email and details submitted by security researchers through our disclosure programme. | The researcher |
| Billing data | Plan, subscription status, invoices. Card details are collected and held by Stripe, not by us. | You and Stripe |
| Sales and marketing contacts | Business name, work email, job title and company of people at organisations we think might benefit from TrustDyne. | Publicly available business sources, or you |
| Website visit data | IP address and request details processed by our hosting provider to serve the site and protect it from abuse. | Your browser |
We do not knowingly collect special category data. Please do not include it in uploaded content or reports.
3. Why we use it, and our legal basis
| Purpose | Legal basis (UK GDPR Art. 6) |
|---|---|
| Provide the platform, run scans, produce reports, authenticate you and support you | Contract |
| Keep the platform secure, prevent abuse and fraud, keep audit logs | Legitimate interests (securing our service and our customers) |
| Take payment and keep financial records | Contract and legal obligation |
| Handle vulnerability reports and respond to researchers | Legitimate interests (improving security) |
| Send service messages such as scan-complete and account notices | Contract |
| Contact businesses about TrustDyne by email | Legitimate interests (promoting a relevant B2B service). Every message includes a way to opt out and we stop when you ask. We only email corporate addresses, as required by PECR. |
| Improve the product using aggregated, non-content usage information | Legitimate interests |
We do not sell personal data. We do not use your uploaded content, findings or reports to train AI models.
4. AI processing
Some features use large language models, which we reach through Amazon Bedrock in AWS. Content sent for analysis is used to produce your results. Under AWS's Bedrock terms, prompts and outputs are not shared with the model provider and are not used to train the underlying models. Findings and suggested fixes are decision support. We do not make decisions about individuals that have legal or similarly significant effects.
5. Who we share data with
We use a small set of service providers (sub-processors) listed on our Sub-processors page. We share data with other third parties only if the law requires it, to protect people or our rights, or as part of a business transfer such as moving the business into a limited company. Integrations such as Jira or GitHub only send data to those services when you connect them.
6. International transfers
Our infrastructure runs in the AWS US East (N. Virginia) region, so personal data is transferred from the UK and EEA to the United States. We rely on the UK Extension to the EU-US Data Privacy Framework (the UK-US data bridge) for providers that are certified under it, including AWS, and on appropriate safeguards required by UK GDPR for any other transfer. Contact us for details.
7. How long we keep it
| Data | Retention |
|---|---|
| Scan reports and derived findings | 12 months from creation, then deleted automatically |
| Uploaded files (firmware, apps, archives) | Deleted, including stored versions, once analysis finishes |
| Account data | While your account is open, then deleted or anonymised within 90 days of closure or on your request |
| Application audit events | 90 days |
| Cloud provider audit logs (AWS CloudTrail) | Kept long term for security and accountability. No fixed deletion date at present. |
| Backups | Database point-in-time recovery: 35 days. Recurring disaster-recovery snapshots: 90 days. Deleted data can persist in backups until they expire. |
| Vulnerability reports | As long as needed to handle the report and show how we responded |
| Sales and marketing contacts | While the contact is relevant. We remove it when you ask. |
| Billing records | As required by UK tax and accounting law |
8. Security
Customer data is encrypted at rest with AWS KMS keys and in transit with TLS. Access is limited to named roles. See our Security and Trust page for the controls we run.
9. Your rights
You can ask us to access, correct, delete, restrict or export your personal data, and you can object to processing based on legitimate interests or to direct marketing. Email legal@trustdyne.com. We will reply within one month. If you are a customer's user and your data is platform content that we hold as processor, we can pass your request to the customer.
You can complain to the UK Information Commissioner's Office at ico.org.uk or on 0303 123 1113. We would appreciate the chance to put things right first.
10. Cookies and similar technologies
See our Cookie Policy. We do not use advertising or analytics cookies.
11. Children
The platform is for businesses and is not directed at anyone under 18.
12. Changes
We will post changes here and update the date above. If a change is material we will tell account holders by email before it takes effect.
TrustDyne