Privacy Policy
Last updated 1 September 2026
This Privacy Policy explains what personal data PenStrike (“PenStrike”, “we”, “us”) collects when you use this website or request access to our platform, how we use it, and the rights you have over it.
01Who we are
PenStrike operates this website and the PenStrike access program. For any privacy-related request you can reach us at [email protected]. Where required by law, PenStrike acts as the data controller for the personal data described below.
02Information we collect
We only collect what we need to evaluate access requests and respond to you:
- Information you provide. When you submit the access or contact form we collect your name, work email, company, role, team size and the use case you describe, together with your authorization attestation.
- Technical data. Our servers automatically record limited request metadata such as IP address, timestamp, user agent and referring page for security, abuse-prevention and diagnostic purposes.
- Preferences. The site stores a small local preference in your browser (for example, whether ambient sound is enabled). This never leaves your device.
03How we use your information
- Review, verify and respond to access requests and enquiries.
- Operate, secure and improve the website and the service.
- Detect, prevent and investigate abuse, fraud and security incidents.
- Comply with applicable legal obligations and enforce our agreements.
We do not sell your personal data, and we do not use it for third-party advertising.
04Legal bases
Where the GDPR or a similar framework applies, we rely on: your consent (which you may withdraw at any time), our legitimate interests in running and securing the service, the performance of a contract or steps taken at your request, and compliance with a legal obligation.
05Service providers
We share personal data only with vetted processors acting on our instructions:
- Email delivery. We use Resend to deliver transactional email related to your request.
- Hosting. Our website and services run on a dedicated server operated by our infrastructure provider.
These providers are bound by contract to protect your data and to process it only as necessary to provide their services to us.
06Retention
We keep access-request data for as long as needed to evaluate and follow up on your request, and for up to 24 months afterwards unless a longer period is required to comply with the law or resolve disputes. Technical logs are retained for a short rolling window and then deleted or anonymised.
07Security
Data is encrypted in transit (HTTPS). We apply access controls, data minimisation and least-privilege principles to the systems that store submissions. No method of transmission or storage is perfectly secure, but we work to protect your data using appropriate technical and organisational measures.
08Your rights
Depending on your location, you may have the right to access, correct, delete, restrict or object to the processing of your personal data, and to data portability. To exercise any of these rights, email [email protected]. You also have the right to lodge a complaint with your local data protection authority.
09International transfers
Your data may be processed in countries other than your own. Where it is transferred internationally, we rely on appropriate safeguards such as standard contractual clauses or an equivalent recognised mechanism.
10Cookies
This website does not use advertising or cross-site tracking cookies. We use only strictly necessary storage and a single local preference for the ambient-sound toggle.
11Children
The service is intended for security professionals and organisations. It is not directed to, and we do not knowingly collect data from, anyone under 18.
12Changes to this policy
We may update this policy from time to time. Material changes will be reflected by the “Last updated” date above, and where appropriate we will provide additional notice.
13Contact
Questions about this policy or your data? Email [email protected].