Skip to main content

Privacy Policy

Effective Date: 01/01/2025

Who We Are

Assumed Breach (referred to as “we,” “our,” or “us”) is a cybersecurity consultation firm specializing in penetration testing, red team operations, vulnerability assessments, and other related services. Our website address is https://assumed-breach.com.

Personal Information Collection

We may collect personal identification information in various ways, including when users:

  • Fill out contact forms or request services.
  • Subscribe to newsletters or updates.
  • Engage in consultations or training sessions.
  • Interact with other activities, features, or resources we make available.

Visitors may browse our website anonymously, but personal identification information will only be collected if voluntarily provided.

Comments

When Visitors leave comments on our site, we collect the data provided in the comment form, the Visitor’s IP address, and browser user agent string to assist in spam detection.

Newsletter Signups

When you subscribe to our newsletter we store the name and email address you enter. We also record the IP address the signup came from, your browser’s user agent string, and the approximate location our hosting provider derives from that address.

We record this to keep the list honest. It lets us recognise automated submissions, notice one address signing up under many names, and understand what happened after a wave of spam. Our lawful basis is legitimate interests, specifically keeping a public form from being abused. We do not use it to build a profile of you, we do not use it for advertising, and we do not share it with anyone.

The location is approximate and we treat it as such. It reflects roughly where your connection reaches the internet rather than where you are, and it is frequently wrong for anyone on a VPN, a corporate network or a mobile connection.

We erase the IP address and user agent string 90 days after signup. Your subscription is unaffected by that: your name and email address are kept until you ask us to remove them. To unsubscribe, or to ask what we hold about you, email support@assumed-breach.com and we will action it within 30 days.

Media

If users upload images to our website, they should avoid embedding location data (EXIF GPS). Visitors can download and extract location data from uploaded images.

Analytics and Your Choice

We use Google Analytics to understand which pages people read. It is loaded only after you agree, and it is not loaded at all if you decline or ignore the banner. We set no advertising cookies, we do not use Google Signals, and we do not sell or share this data.

The data collected is limited to page addresses, page titles, referring pages, approximate location derived from a truncated IP address, and basic device and browser information. We do not send names, email addresses or the contents of any form to Google Analytics.

Our lawful basis is your consent, and you may withdraw it at any time using the control below. Withdrawing is as straightforward as giving it, and takes effect immediately.

Loading your current preference.

Cookies

  • Comments: When leaving a comment, users can opt-in to save their name, email, and website in cookies for convenience. These cookies last for one year.
  • Login: If you visit the login page, we set a temporary cookie to determine if your browser accepts cookies. These cookies contain no personal data and are discarded when you close your browser.
  • Logged-In Users: Login cookies are stored for two days, and display preference cookies are stored for one year. Selecting “Remember Me” extends login persistence to two weeks.

Embedded Content from Other Websites

Articles on our website may include embedded content (e.g., videos, images). Embedded content from other websites behaves as if the Visitor has accessed the external site, which may collect data, use cookies, and track interactions.

How We Use Collected Information

  • To Improve Customer Service: Information helps us respond to inquiries and support requests more effectively.
  • To Personalize User Experience: Aggregated information helps us understand how users interact with our services.
  • To Send Updates: Email addresses may be used to send information related to inquiries, services, or company updates.

Who We Share Your Data With

  • Service Providers: Trusted third parties for data storage, payment processing, and advertising.
  • Legal Compliance: To comply with legal obligations or protect our rights and the safety of users.
  • Change in Control: In case of mergers, acquisitions, or sale of assets.
  • With Your Consent: When directed or authorized by you.

How Long We Retain Your Data

  • Comments: Retained indefinitely, along with metadata, for moderation purposes.
  • Registered Users: Personal data provided in profiles is retained as long as the account is active. Users can view, edit, or delete their data, except for usernames. Administrators can also access this information.
  • Newsletter Subscribers: The IP address and browser user agent recorded at signup are erased after 90 days. Names and email addresses are retained until you ask us to remove them.

Legal Bases for Collecting and Using Information

For users in the EU, our legal grounds for processing your data include:

  • Fulfilling our commitments under terms of service or agreements.
  • Complying with legal obligations.
  • Protecting vital interests.
  • Pursuing legitimate interests, such as improving our services and ensuring security.
  • Obtaining user consent where required.

Your Rights Over Your Data

Users can request:

  • An export of personal data we hold.
  • Deletion of personal data, except for information retained for legal, administrative, or security purposes.

To exercise these rights, contact us at support@assumed-breach.com. We respond within 30 days.

Where We Send Your Data

Visitor comments may be checked through automated spam detection services.

Third-Party Websites

Our website may link to third-party services, advertisers, and content. We are not responsible for the privacy practices of external sites.

Changes to This Privacy Policy

Assumed Breach reserves the right to update this Privacy Policy at any time. Users are encouraged to review this page periodically. Continued use of our services signifies acceptance of any changes.

Exceptions

Requests for exceptions to this policy must be approved by the company’s management.

Violations & Enforcement

Violations of this policy should be reported to management. Violations may result in disciplinary action, including termination of services or employment.

Contact Information

For questions or concerns about this Privacy Policy, please contact us at: