Back to sign in

Infrawatch Services Privacy Notice

Services and Business Interactions

On this page

1. About this Notice

We are Infrawatch Limited (“Infrawatch”, “we”, “us” or “our”), a company registered in England and Wales under company number 16347462. Our registered office is 128 City Road, London, EC1V 2NX, United Kingdom. Infrawatch is registered with the UK Information Commissioner’s Office under reference ZC054546.

If you have any questions about this notice, or would like to contact us to complain or exercise your legal rights, please contact us at [email protected]. Postal correspondence may be sent to our registered office above.

This notice was last updated on 2 October 2026.

This Privacy Notice explains how we collect, use, share and protect personal information in connection with individuals’ use of the Infrawatch Platform, our software-as-a-service product web interface, and individuals' use of our corporate website at infrawatch.com (the "Website").

For the personal information described in this Notice, Infrawatch generally acts as the controller under UK and European data-protection law and as the business or equivalent regulated organisation under applicable US privacy law.

2. 2. Scope and defined terms

This Notice applies to personal information we process about:

  • individuals who create or use the Infrawatch platform, either through a free-tier account or through access provided by an Organisation's subscription or evaluation agreement with Infrawatch (each, a "User");
  • individuals who use the Infrawatch platform, portal, authorised APIs or related interfaces (the “Platform”);
  • individuals who contact us for support, demonstrations, evaluations, research access or other service-related purposes; and
  • individuals who visit our Website or subscribe to our newsletter.

“Organisation” means the entity, if any, whose subscription or evaluation agreement with Infrawatch provides a User's access.

“Organisation Agreement” means a separate order form, subscription agreement, master services agreement or other written agreement between Infrawatch and an Organisation.

The Platform analyses internet infrastructure at scale, including IP addresses, network ranges, domains, certificates and related technical identifiers. Some of that information may, in limited circumstances, relate to an identifiable individual. Section 4.1 explains this processing separately from User account and activity data.

3. Personal information we collect and use – Authorised user

This section describes the information we collect, how we use it and the legal bases we rely on.

3.1 Account and professional information

When you create and log into your account, we may collect your name, business email address and organisation name. We use this information to provide account services, authenticate users, manage permissions, administer evaluations and provide support, in performance of our contract with you. We also rely on our legitimate interest in preventing fraud and misuse, including by maintaining access records, preventing account sharing, identifying multiple-account evasion, enforcing query and export limits, investigating suspicious activity, maintaining audit logs and responding to incidents.

3.2 Authentication, device and security information

As part of account authentication, we may collect login and account-recovery records, SSO and account identifiers, API key or token identifiers, device and browser details, IP address, failed login attempts, security alerts and indicators of suspected compromise or abuse. We us this information to secure the Platform and prevent abuse: detect compromise, prevent account sharing, identify multiple-account evasion, enforce query and export limits, investigate suspicious activity, maintain audit logs, respond to incidents. We rely on our legitimate interest in platform security to use this information to detect compromise, enforce usage limits, investigate suspicious activity and enforce our terms.

3.3 Platform activity and User Inputs

When you interact with the Platform, we may collect information about your activity, including searches and queries, records or features used, investigation activity, rules, alerts, exports, downloads, API activity, usage volumes, timestamps, performance, support activity, audit events and suspected policy violations.

User Inputs may include IP addresses, domains, URLs and other observables, search-query text, rule content, notes, tags, labels, API request parameters, support messages and feedback entered through the Platform or an authorised API. The Platform does not currently permit Users to upload documents or files. We rely on our legitimate interest in improving the Platform and detecting fraud or misuse to use this data, including by understanding workflows, monitoring performance, managing capacity, improving usability and developing new features.

We also use this information to monitor performance, troubleshoot, understand workflows, develop features, manage capacity, improve usability and create aggregated or de-identified statistics.

Query content and technical identifiers may sometimes constitute personal information. You should not submit sensitive personal information, credentials, payment-card data, health information, children’s data, government identifiers, classified information or confidential information you are not authorised to disclose unless Infrawatch has expressly agreed appropriate safeguards.

3.4 Platform support and account communications

When you contact us for in-app support tied to your Platform account, we may collect the information you provide, including support tickets, messages, attachments and related correspondence. We use this information to respond to enquiries, administer evaluations, understand requirements, prepare proposals, manage prospect, customer and partner relationships and support conversion to an enterprise subscription. We rely on our legitimate interest in responding to your communications and maintaining our relationship with you.

When you leave us feedback, we may use it to improve our website, communications and services, relying on our legitimate interest in making those improvements.

3.5 Marketing information

Where you have signed up to a newsletter or previously expressed an interest in our products or services (and not opted-out of marketing), we will use your name and email address to send you updates relying on our legitimate interest in updating you about our product and in promoting our other products and services we think may interest you. For our Website newsletter specifically, we rely on your consent, which you may withdraw at any time as described below.

Where you are a new customer and have opted in via our website to receive updates on our products and services including offers, promotions and new options, we will process your personal data to provide you these updates in line with the preferences you have provided and will only use your personal data in this way with your consent.

You can withdraw your consent to marketing at any time by contacting us at [email protected] or by following the unsubscribe link in any marketing communication.

3.6 Website visitors and automatically collected data

When you visit our Website, our servers (and service providers we use to run the Website) may automatically process:

  • Log and device data: including IP address, data/time of access, pages requested, browser type/version, operating system, device type, referrer URL, and similar technical data; and
  • Usage analytics (where enabled): information about how visitors use our site (e.g., pages viewed, time on page, general location at a city/region level).

When using personal data we rely on legitimate interests to

  • Operate and secure our website: including debugging, preventing abuse and maintaining availability; ad
  • Understand and improve the website: including measuring performance and engagement.

Where any element of this processing requires consent (for example, non-essential analytical cookies), we rely on your consent instead, as described in section 3.7 below.

We do not intentionally collect special category (sensitive) personal data through our Website (for example, health, religion or political opinions). Please do not send us sensitive information.

3.7 Cookies

When you use our website and, where required, consent to our use of cookies we will collect information about how you use our website. We may use your personal data contained within this information to improve our website and to better understand how people use it. More details are set out in our Cookie Policy.

Some cookies on our Website are essential for it to function and cannot be switched off through a consent banner. Where we use non-essential cookies (including analytics cookies), we will request your consent before placing them, and you can accept or reject non-essential cookies via our cookie banner (where shown) and change or withdraw consent at any time via your browser settings and our cookie settings link. You can also block cookies in your browser, but parts of the Website may not function as intended.

4. Personal information we collect and use – Infrastructure Intelligence and other data

4.1 Infrastructure intelligence data

The Platform observes and analyses internet infrastructure data, such as IP addresses, network ranges, domain-registration information, certificates and host information, including infrastructure associated with suspected malicious activity, fraud or network abuse. This data generally relates to technical infrastructure rather than identified individuals, and Infrawatch does not process it for the purpose of identifying a specific individual.

Infrastructure data may occasionally constitute personal information (for example, where this includes IP addresses). Where it does and Infrawatch determines the purposes and means of processing, we generally rely on legitimate interests in cybersecurity, fraud prevention, network-abuse prevention and related security research, subject to appropriate balancing and safeguards.

4.2 Information from other sources

We may receive information from your Organisation, an administrator, reseller or partner, event organiser, referral source, identity or security provider, and fraud, abuse or sanctions-screening service. We rely on our legitimate interest in fraud prevention and security to use this information.

5. How we share your personal information

Your Organisation: Where your account is associated with an Organisation, authorised administrators may receive identity and account status, assigned permissions, usage volumes, security events, support information and compliance information. We do not routinely disclose detailed investigation content unless necessary for administration, security, compliance or an Organisation Agreement.

Service providers: We may use providers for cloud hosting, authentication, infrastructure, security, communications, support, analytics, email delivery, identity verification and professional services. They are subject to contractual and access restrictions. Authentication is provided through our identity provider, using single sign-on or username and password. Infrawatch does not collect or store User passwords or multi-factor authentication credentials; these are handled by our identity provider.

Professional advisers and transaction counterparties: We may share information with lawyers, auditors, insurers, accountants, investors, lenders, prospective purchasers and advisers where reasonably necessary and subject to confidentiality protections.

Authorities and legal recipients: We may disclose information to comply with law or valid legal process, investigate fraud or security threats, protect rights or safety, enforce agreements or establish and defend legal claims. Affiliates and at your direction: We may share information with Infrawatch affiliates for the purposes described in this Notice or with another party where you direct or authorise us to do so.

6. Prospective buyers of our business under our legitimate interest to ensure our business can be continued by the buyer. Sale, sharing and targeted advertising

Infrawatch does not sell or share personal information for cross-context behavioural advertising and has not done so during the preceding 12 months.

Infrawatch does not knowingly sell or share personal information of persons under 16 and does not use Platform investigation activity for advertising.

7. International transfers

Infrawatch and its service providers may process personal information outside the country where you live, including in connection with the use of our Platform and our Website. Where UK or EEA law applies, we use an appropriate transfer mechanism, such as an adequacy regulation or decision, the European Commission Standard Contractual Clauses, the UK International Data Transfer Agreement, the UK Addendum to the Standard Contractual Clauses or another lawful safeguard. We may also use supplementary technical and organisational measures where appropriate.

You may contact us for further information about safeguards relevant to your information.

8. Retention

We retain personal information only for as long as reasonably necessary for the purposes described in this Notice, including security, audit, legal and dispute requirements. The following periods apply:

InformationRetention period or criterion
Account and profile informationFor the life of the account and normally 90 days after closure or expiry, unless the account converts to organisation-sponsored access or longer retention is required for security, legal or contractual reasons.
Authentication, security, query and usage logsNormally 12 months, then deleted or anonymised, unless a longer period is required to investigate security incidents, abuse or legal claims.
Evaluation and free-access administration recordsNormally 12 months after access ends, unless converted to an enterprise relationship or required for legal, security or audit purposes.
Support records24 months after resolution of the support request.
Terms acceptance and contract recordsFor the applicable relationship and then for the relevant statutory limitation period, normally up to 7 years.
Infrastructure intelligence dataFor as long as it remains relevant to cybersecurity, fraud-prevention, network-abuse and historical-analysis purposes, subject to our data-retention controls and periodic review.
Newsletter subscription data (Website)Retained until you unsubscribe (and then suppressed as needed to respect your opt-out and maintain compliance).
Website logsRetained for a limited period for security and operational purposes (typically days to months depending on system needs), then deleted or anonymised.
Website analytics dataRetained for a limited period set by our analytics configuration and used primarily in aggregate to understand trends.

When information is no longer required, we delete, anonymise or securely isolate it. Backup copies may remain for a limited period before deletion through normal backup cycles.

Where we anonymise your personal data so that it can no longer be associated with you, we may use this anonymised information indefinitely without notifying you. We use this anonymised information to improve our operations and services.

9. Security

We use technical and organisational measures designed to protect personal information, including encryption in transit and at rest where appropriate (including HTTPS encryption for our Website), access controls, least-privilege practices, multi-factor authentication enforced through our identity provider, monitoring and security hardening appropriate to our risk profile, secure development, vulnerability management, incident-response procedures, vendor assessment and employee confidentiality obligations.

No service is completely secure. Users are responsible for protecting credentials and promptly reporting suspected compromise. A summary of relevant security measures may be made available to customers on request.

10. Cookies and similar technologies

We use cookies, local storage and similar technologies within the Platform to recognise your browser or device, authenticate and secure sessions, maintain preferences and, where used, understand Platform usage and measure performance. These technologies are essential or functional to operating the Platform; where any non-essential technology is used, we obtain consent as required by law.

You can manage any non-essential technologies through your Platform account settings or browser controls. Disabling essential cookies may prevent parts of the Platform from working.

For more information, please see our separate Cookie Policy.

11. Automated security decisions

We may use automated systems to identify suspicious logins, account compromise, abusive querying, limit evasion, fraud, malware and other security risks. These systems may result in temporary restriction or referral for human review.

Infrawatch does not currently make solely automated decisions about Users that produce legal or similarly significant effects within the meaning of UK or EEA data-protection law. If that changes, we will provide the information and rights required by applicable law.

12. Your privacy rights

Depending on your location and applicable law, you may have rights to access, correct, delete or obtain a portable copy of personal information; restrict or object to processing; withdraw consent; opt out of certain sale, sharing, targeted advertising or profiling; appeal a denied request; and complain to a regulator. The jurisdiction-specific sections below provide further detail.

To submit a request, email [email protected]. We may verify your identity and authority. Where your account is administered by an Organisation, some requests may need to be coordinated with that Organisation. We will not discriminate against you for exercising an applicable privacy right. We normally respond to requests governed by UK or EEA data-protection law within one month after receiving a valid request and completing any necessary identity verification. We may extend this period where applicable law permits, and will notify you if an extension is required.

13. UK and EEA additional information

If UK or EEA data-protection law applies, you may have rights of access, rectification, erasure, restriction, objection, portability, withdrawal of consent and rights concerning solely automated decisions, subject to legal conditions and exceptions.

You may object at any time to direct marketing. You may also object to processing based on legitimate interests; we will stop unless we demonstrate compelling legitimate grounds or need the information for legal claims.

UK residents may complain to the Information Commissioner’s Office. EEA residents may complain to the supervisory authority in the country where they live, work or believe an infringement occurred. We encourage you to contact us first.

For privacy questions or to exercise your rights, contact [email protected].

14. United States privacy disclosures

Residents of certain US states may have rights to confirm whether we process personal information, access, correct, delete or obtain a portable copy of it, and opt out of sale, targeted advertising or certain profiling. Some states also provide a right to appeal a denied request.

You may exercise applicable rights using the methods in section 12. To appeal, reply to our decision or email [email protected] with “Privacy Appeal” in the subject line. For requests governed by applicable US state privacy law, we normally respond within 45 days after receiving a valid request and completing any necessary identity verification. We may extend this period where permitted by law and will notify you of any extension.

Where legally required, Infrawatch recognises applicable universal opt-out mechanisms, including Global Privacy Control or another regulator-recognised signal, for sale, sharing or targeted-advertising opt-outs in California, Colorado, Connecticut and other jurisdictions that require recognition of such signals.

15. California Privacy Notice

This section supplements the rest of this Notice for California residents and is intended to address the California Consumer Privacy Act, as amended (“CCPA”), where it applies.

15.1 Categories, sources and purposes

CategoryExamplesSourcesPurposes
IdentifiersName, business email address, organisation name, IP address, account identifiersYou, Organisation, devices, providersAccounts, security, support, communications
Customer-record informationBusiness contact and account informationYou, OrganisationAccount and relationship management
Commercial informationEvaluation, subscription and interaction recordsYou, Organisation, systemsService administration and sales
Internet or electronic activityLogins, queries, downloads, browser and usage activityDevices and PlatformService delivery, security, analytics

15.2 Disclosures and sale or sharing

We may disclose the categories above to service providers, your Organisation, professional advisers, affiliates, transaction counterparties and authorities for the purposes described in this Notice. As stated in section 6, Infrawatch does not sell or share personal information for cross-context behavioural advertising and has not done so during the preceding 12 months.

15.3 California rights

Subject to applicable conditions and exceptions, California residents may request access to categories and specific pieces of personal information, correction, deletion, information about disclosure, opt-out of sale or sharing, limitation of certain uses of sensitive personal information, and non-discriminatory treatment.

An authorised agent may submit a request where permitted, subject to verification of the agent’s authority and the resident’s identity. At or before collection, Infrawatch will provide a notice identifying the categories collected, purposes, applicable retention information and whether personal information is sold or shared.

Infrawatch does not disclose personal information to third parties for their own direct-marketing purposes in the manner covered by California’s “Shine the Light” law.

Canadian residents may request access to and correction of personal information and may withdraw consent where processing is based on consent, subject to legal and contractual limitations. Information may be processed outside Canada, where it may be accessible to foreign courts, law-enforcement or regulatory authorities under local law.

16. Third-party links

Our Website may include links to third-party websites. We are not responsible for their privacy practices. Please review their policies before providing personal data.

17. Children

The Platform is intended for business, professional, governmental, academic and legitimate security-research use and is not directed to persons under 18. Our website is not intended for children under 18. We do not knowingly create accounts for children or knowingly collect personal data from children via our Website. If you believe a child has provided personal information, contact [email protected].

18. Communications and marketing choices

We may send Platform account communications, including security notices, maintenance updates, account messages and changes to legal documents. These are necessary to operate the Platform and are not marketing. We may also send product update messages tied to your Platform account, which you may opt out of separately.

You may opt out of optional product update messages using the unsubscribe link, your account settings or by contacting us. We may retain limited suppression-list information to honour your choice. You can withdraw your consent to Website marketing communications at any time by contacting us at [email protected] or by following the unsubscribe link in any marketing communication.

19. Changes to this Notice

We may update this Notice to reflect changes in our processing, services, vendors, law, security or business operations. We will publish the updated version and effective date. Where changes are material, we may notify you through the Platform or by email. Where consent is legally required for a new purpose, we will request it separately.

20. Contact and complaints

Infrawatch Limited, 128 City Road, London EC1V 2NX, United Kingdom. Email:

You have a right to make a complaint to us about how we handle your personal data. If you would like to make a complaint, please contact us at [email protected].

You also have the right to make a complaint to the Information Commissioner's Office (ICO), the UK supervisory authority for data protection issues (www.ico.org.co.uk). We would, however, appreciate the chance to deal with any complaints before the ICO is approached so please contact us using the contact details given above in the first instance.

If you are based in the EU, the ICO may not be the appropriate authority to direct your complaint to. You can find your relevant supervisory authority here. US residents may contact the regulator or authority applicable in their jurisdiction.