How Penthropic Security collects, uses, and protects personal data, and the rights you have under the UK General Data Protection Regulation (UK GDPR) and the Data Protection Act 2018.
Last updated: 2 July 2026
We collect only what we need to run our services and answer your enquiries, we never sell your data, we encrypt it and isolate it per tenant, and you can ask us to access or delete it at any time. The formal detail, who controls your data, our lawful bases, processors, retention, and your rights, follows below.
Penthropic Security is a trading name of Penthropic Ltd, a company registered in England & Wales. For the personal data described in this policy, Penthropic Ltd is the data controller. We are a boutique cyber-security consultancy based in London, United Kingdom.
If you have any question about this policy or how we handle your data, contact us at privacy@penthropic.ai.
We only collect personal data we genuinely need to operate our business and serve our clients. Depending on how you interact with us, this may include:
We do not seek to collect special-category personal data through our website, and we ask that you do not submit it through our contact forms.
Under UK GDPR we rely on the following lawful bases:
| Activity | Lawful basis |
|---|---|
| Responding to enquiries and discovery calls | Legitimate interests (responding to a request you initiated) and steps to enter a contract. |
| Delivering engagements and operating portal/platform accounts | Performance of a contract with you or your organisation. |
| Securing our website, logs, and platform | Legitimate interests (keeping our services and clients safe) and legal obligation. |
| Understanding how visitors find and use our website (first-party analytics) | Legitimate interests (measuring and improving our website), using privacy-friendly, cookie-free analytics. |
| Sending service or relationship updates | Legitimate interests, or consent where required. |
Where we rely on legitimate interests, we have balanced those interests against your rights and freedoms. You can object to this processing at any time, see section 9.
Our public website uses a small number of strictly necessary cookies and browser storage to function, for example, to remember whether you have dismissed a banner, and to register a service worker that caches static assets so the site loads quickly and reliably. These are essential to the operation of the site.
The client portal and platform use authentication and session storage that are necessary to keep you signed in securely. We do not use advertising cookies, and we do not sell or share your personal data with advertising networks.
To understand how our public website is used, which pages are popular, how visitors arrive, and roughly where in the world our audience is, we operate our own first-party, privacy-friendly analytics. When you load a page, our own server records a single page-view event containing:
This analytics is deliberately lightweight and respectful of your privacy:
Our lawful basis is legitimate interests, measuring and improving our website and understanding our audience, balanced against your rights. You can object to this processing at any time (see section 9), and analytics records are automatically deleted on the schedule set out in section 7.
We use a small set of trusted suppliers to provide our services. Each acts as a data processor on our behalf under a written data processing agreement, and processes personal data only on our instructions:
| Provider | Purpose | Region |
|---|---|---|
| Amazon Web Services (AWS) | Cloud hosting, storage, and infrastructure for our website, portal, and platform. | London (eu-west-2) |
| Anthropic | AI-assisted features (for example, the website assistant and platform investigation tooling). Inputs are processed to generate responses and are not used to train foundation models. | United States |
| Stripe | Payment and billing processing where you pay for a service. | UK / EU / US |
We keep this list current and review our processors' security and data-protection posture. We do not sell personal data, and we share it with these providers only to the extent needed to deliver our services to you.
When data is no longer needed for the purpose it was collected, we securely delete or anonymise it.
Our primary hosting region is the United Kingdom (AWS London, eu-west-2). Some processors, such as Anthropic and parts of Stripe, may process data outside the UK. Where personal data is transferred internationally, we rely on appropriate safeguards such as the UK International Data Transfer Agreement, the UK Addendum to the EU Standard Contractual Clauses, or an adequacy decision.
Under UK GDPR you have the right to:
To exercise any of these rights, email privacy@penthropic.ai. We will respond within one month. There is normally no charge.
We apply encryption in transit and at rest, least-privilege access, multi-factor authentication for our team, and tenant isolation within our platform. You can read more on our security statement.
For any data-protection request or question, contact us at privacy@penthropic.ai or write to Penthropic Ltd, London, United Kingdom.
If you are not satisfied with our response, you have the right to lodge a complaint with the UK Information Commissioner's Office (ICO) at ico.org.uk. We would, however, appreciate the chance to address your concerns first.