Legal

Privacy Policy

Effective August 2026. This policy explains what personal information we collect through planckdefense.com, why we collect it, how long we keep it, who we share it with, and the rights you hold over it.

We are a security firm, and we treat visitor data the way we advise our clients to treat theirs: collect little, protect what you hold, and delete what you no longer need. The sections below describe our practice in full. There is no fine print beyond what you read here.

Who We Are

Planck Defense & Aerospace is a boutique cybersecurity consultancy providing penetration testing and offensive security, organization-specific threat intelligence, and dedicated IP VPN infrastructure to business clients. For the purposes of applicable data protection law, we act as the controller of personal information collected through this website.

This policy covers the website only. Data we handle inside a client engagement is governed by the contract for that engagement, which typically imposes stricter confidentiality and handling obligations than this policy does.

What We Collect

We run a deliberately quiet website. The categories below are the full extent of our collection.

  • Contact details you choose to send us: your name, work email address, company, and the content of your message when you write to one of our addresses or use the contact form.
  • Correspondence that follows: emails, documents, and scoping notes you share with us while we discuss or deliver work.
  • Standard server logs: the IP address of each request, the URL requested, a timestamp, the user agent string, and the referring page. We use these records for security monitoring and troubleshooting only.

This site sets no advertising trackers and no analytics cookies. The contact form composes an email in your own mail client rather than posting data to our servers, so nothing you type into it reaches us until you choose to send that email. We do not buy information about visitors from data brokers and we do not build marketing profiles.

How We Use Your Information

  • To answer your inquiry and carry on the conversation you started.
  • To scope, contract, and deliver the services you ask us for.
  • To protect this website and our infrastructure, including reviewing server logs for signs of abuse.
  • To meet legal obligations, such as accounting and tax record requirements.

We do not use your information for advertising and we do not sell it. We send no newsletters or marketing email unless you explicitly ask to receive updates, and you can withdraw that request at any time by replying to any message from us.

Legal Bases in Plain Language

Where the GDPR or a similar law applies, each use above rests on a recognized legal basis. In plain terms:

  • When you contact us, we process your details because you asked us to respond. Legally, this is consent or steps taken at your request before entering a contract.
  • When we deliver an engagement, processing is necessary to perform that contract.
  • Server logging and security monitoring rest on our legitimate interest in keeping our systems secure. We keep that interest narrow and weigh it against your privacy.
  • Some record keeping is a legal obligation, for example retaining invoices for tax purposes.

Retention

  • Inquiry correspondence is kept while the conversation is live and for up to 24 months afterward, so we have context if you return.
  • Engagement records are retained for the period set in the applicable contract, then destroyed or returned as that contract requires.
  • Server logs rotate automatically and are deleted within 90 days, unless a specific entry is needed for an active security investigation.

When a retention period ends, we delete the data or anonymize it irreversibly.

Sharing and Disclosure

We share personal information in two situations only.

  • Service providers under contract: the hosting and email infrastructure providers that run our systems process data on our documented instructions and are bound by confidentiality and security terms.
  • Legal obligations: where a law, regulation, or valid legal process compels disclosure. We review every demand and disclose the minimum the law requires.

We never sell personal information and we never share it with advertisers or data brokers.

International Transfers

Our service providers may store or process data outside the country where you live. Where personal information leaves the European Economic Area, the United Kingdom, or another jurisdiction with transfer rules, we rely on recognized safeguards such as adequacy decisions or standard contractual clauses, and we hold the receiving provider to the same confidentiality and security obligations described in this policy.

Your Rights

Depending on where you live, you may hold some or all of the following rights over your personal information.

  • Access: ask what we hold about you and receive a copy.
  • Correction: have inaccurate information corrected.
  • Deletion: have your information erased where no legal ground requires us to keep it.
  • Restriction and objection: limit or object to specific processing, including anything based on legitimate interest.
  • Portability: receive the information you provided in a structured, machine readable format.
  • Withdrawal of consent: where processing rests on consent, withdraw it at any time without affecting prior processing.
  • Complaint: raise the matter with the data protection authority in your jurisdiction.

To exercise any of these rights, email us at the address below. We may need to verify your identity before acting on a request, and we respond within the timelines the applicable law sets.

Security Measures

Security is our trade, and we apply to our own systems what we recommend to clients.

  • All site traffic is encrypted in transit over TLS.
  • Access to correspondence and engagement data is restricted to the practitioners who need it for their work.
  • Our infrastructure uses per-user credentials with prompt revocation when access is no longer required.
  • We collect minimally in the first place, which remains the strongest control of all.

No system is perfectly secure. If an incident ever affects your personal information, we will notify you and the relevant authorities as the law requires.

Contact for Privacy Matters

Questions, requests, or complaints about this policy go to info@planckdefense.com. We acknowledge privacy inquiries within one business day. If our answer does not satisfy you, you retain the right to complain to your local data protection authority.