This policy explains what personal data attackless.com collects, why, on what legal basis, how long we keep it, who receives it, and the rights you have under the EU General Data Protection Regulation (RGPD / GDPR) and Spanish law. It is written to be read, so please do.
1. Basic information at a glance
This is the short version, in the layered format Spanish law recommends (Article 11 of Organic Law 3/2018). The rest of this page gives the full detail.
| Controller | Octagon Plus Holding Ltd, operating attackless.com |
|---|---|
| Purpose | To assess and reply to your “Check if you qualify” request, to keep proof of your consent, and to keep the website secure. |
| Legal basis | Your consent (Art. 6(1)(a) RGPD) and steps taken at your request before a contract (Art. 6(1)(b)); our legitimate interest in security (Art. 6(1)(f)); legal obligations (Art. 6(1)(c)). |
| Recipients | Cloudflare, Inc. as our hosting and database provider. No one else, unless the law requires it. |
| Transfers | Some processing by Cloudflare may take place outside the EEA, under Standard Contractual Clauses and, where applicable, the EU–US Data Privacy Framework. |
| Your rights | Access, rectification, erasure, restriction, objection, portability, and withdrawal of consent. You can also complain to the AEPD. |
| More information | The sections below. |
2. Who is responsible for your data
The controller of your personal data (responsable del tratamiento) is:
| Name | Octagon Plus Holding Ltd, trading as attackless.com |
|---|---|
| Legal form | Private limited company |
| Company number | 16613975, registered in England and Wales |
| Registered office | Office 13605, 182-184 High Street North, East Ham, London, E6 2JA, United Kingdom |
| Website | attackless.com |
| support@attackless.com |
We are established in the United Kingdom. Because we offer services to businesses in Spain, the RGPD applies to our processing of your data under its Article 3(2), and we also comply with UK data protection law (the UK GDPR and the Data Protection Act 2018).
We have not appointed a Data Protection Officer, because our activities do not require one under Article 37 RGPD. We will review this if our activities change. Every privacy question or request goes to support@attackless.com.
3. What this policy covers
This policy applies to personal data we handle through the website attackless.com, including the “Check if you qualify” form and any email or other communication that follows from it. It also explains, in section 14, how we treat personal data when we deliver services to clients, which is governed by a different legal arrangement.
In this policy, “personal data” means any information about an identified or identifiable person, and “processing” means anything we do with it, such as collecting, storing, using, sharing or deleting it. “RGPD” is the EU General Data Protection Regulation, Regulation (EU) 2016/679, also known as the GDPR.
4. The data we collect
Data you give us
When you complete the “Check if you qualify” form we collect:
- your name, work email address and company name;
- your industry (healthcare, legal, industrial, tech or SaaS, e-commerce, financial services, or other) and company size, chosen from a range;
- what you need most: an assessment, compliance, fixing problems, ongoing protection, or not sure yet;
- the service you were looking at, if you reached the form by clicking on one;
- the time you agreed to this policy and the version of the consent wording you accepted.
If you write to us or reply to us by email, we also keep that correspondence and whatever information you choose to put in it.
Please do not send us sensitive information through the form or by email. This includes health data, criminal records, passwords, access credentials, and confidential technical details of a security incident. If you need to report an incident, tell us that you have one, and we will agree a safe way to share the details.
Data we receive automatically
When you submit the form we also store the country the request came from (reported by our hosting provider), the page you submitted from, the referring page if there was one, and your browser’s user-agent text. We use these to keep the site secure and to understand where requests come from. We do not store your IP address in our database.
As with any website, the servers that deliver these pages, operated by Cloudflare (see section 8), necessarily receive your IP address and basic request details in order to send you the page and to defend it against attacks. We do not use this to identify or profile you.
Data we do not collect
- No analytics, advertising or tracking tools of any kind.
- No cookies, local storage or tracking pixels (see section 15).
- No third-party content embedded in the pages: the fonts, images and scripts are all served from our own domain, so your browser contacts no other company’s servers when you visit.
- No special categories of personal data (Article 9 RGPD), and no data about minors.
- No data bought or received from third parties or data brokers.
Where the data comes from
Almost all of it comes directly from you. The only other source is the technical information your browser sends automatically when it requests a page or submits the form.
5. Why we use your data, and the legal basis
We may only process personal data if we have a legal basis under Article 6 RGPD. For each purpose, this table shows the data involved and the basis we rely on.
| Purpose | Data | Legal basis (RGPD) |
|---|---|---|
| Assess your request, decide whether we can help, and reply to you | Name, email, company, industry, company size, need, service, your correspondence | Your consent, Art. 6(1)(a). Also steps taken at your request before entering a contract, Art. 6(1)(b). |
| Prove that you gave consent and which wording you accepted | Consent time and wording version | Legal obligation to be able to demonstrate consent, Art. 7(1) with Art. 6(1)(c). Also our legitimate interest in defending legal claims, Art. 6(1)(f). |
| Keep the website and form secure, and limit abuse such as repeated automated submissions | Country, user agent, source page, referrer, count of submissions per email address | Our legitimate interest in the security and integrity of our services, Art. 6(1)(f). |
| Deliver the website to you and protect it against attacks | IP address and request details, processed by our hosting provider | Our legitimate interest in operating a secure website, Art. 6(1)(f). |
| Handle your privacy requests and complaints | Identity details, the content of your request, our reply | Legal obligation, Art. 6(1)(c), to respond to the exercise of your rights. |
| Meet accounting, tax and other legal duties if you later become a client | Contract and invoicing data | Legal obligation, Art. 6(1)(c) (under UK and EU law). |
| Establish, exercise or defend legal claims | Any of the above, where relevant | Our legitimate interest, Art. 6(1)(f). |
Consent
The form has an unticked box that you must tick before you can send it. Ticking it is your consent. It is freely given, specific to handling your request, and you can withdraw it at any time as described in section 11. Withdrawing does not affect anything we did before you withdrew.
Legitimate interest
Where we rely on legitimate interest, we have weighed it against your interests, rights and freedoms. Keeping a website secure is something you would reasonably expect us to do, the data involved is minimal, and it is not used for any other purpose. You may object to it at any time (section 10).
What providing the data means
Filling in the form is voluntary. However, the name, email, company, size and interest are needed for us to assess and answer your request. Without them we cannot process it.
Other uses
We do not sell your data. We do not use it for advertising. We do not send you newsletters or marketing you did not ask for. If we ever want to use your data for a new purpose, we will tell you first and, where the law requires, ask for your consent.
6. How we contact you
We use your email address to reply to your request and to continue the conversation you started. We do not send unsolicited commercial communications, and we comply with Article 21 of Law 34/2002 (LSSI-CE), which prohibits them unless you have given consent or already have a relationship with us for similar products or services.
If we introduce a newsletter or similar mailing in the future, it will use a separate, clearly worded opt-in, and you will be able to unsubscribe in every message.
7. How long we keep your data
We keep personal data only as long as it is needed for the purpose it was collected for, and then delete it or anonymise it. The periods below are the ones we apply.
| Type of data | How long |
|---|---|
| Qualification requests that do not lead to a contract | Up to 12 months after our last contact with you, then deleted. |
| Client records, if you become a client | For the length of the relationship, then for the periods the law requires. For example, accounting and tax records are generally kept for six years under UK law. |
| Proof of consent | For as long as we hold your data, then for the limitation periods for legal claims. |
| Records of privacy requests | For as long as needed to show that we handled them lawfully. |
| Technical logs at our hosting provider | For the short periods set by that provider. |
| Backups | For the limited period set by our database provider, after which deleted data disappears from backups too. |
Once a retention period ends we delete the data. Where the law obliges us to keep some data longer, we restrict access to it and use it only for that legal purpose. You can ask us to delete your data sooner (see section 10).
8. Who receives your data
Only the people at attackless.com who need your data to handle your request can access it. We also use service providers that process data on our behalf (encargados del tratamiento). Each is bound by a data processing agreement that meets Article 28 RGPD: it may act only on our instructions, must keep the data confidential and secure, and must delete or return it at the end.
| Provider | What it does | Location |
|---|---|---|
| Cloudflare, Inc. | Hosts the website, delivers it through its network, protects it against attacks, and stores form submissions in its database service. | United States, with operations in the EU |
| Our email service provider | Provides the mailbox we use to read and reply to your request. | As set out in its data processing agreement; the safeguards in section 9 apply. |
The source code of this website is stored with a code hosting provider. It contains no visitor data.
We may also share data with:
- professional advisers, such as lawyers, accountants and auditors, bound by confidentiality;
- public authorities, courts and law enforcement, where the law obliges us to or where necessary to establish, exercise or defend legal claims;
- a buyer or successor if the business is ever sold or restructured, in which case this policy would continue to protect your data and we would tell you.
We do not share your data with anyone else, and we do not sell or rent it.
9. Transfers outside the European Economic Area
Transfers to the United Kingdom. We are established in the UK, so the data you send us is transferred from the EEA to the UK. The European Commission has recognised the UK as providing an adequate level of data protection through its adequacy decisions. If those decisions are ever not in force, we will rely on other safeguards under Chapter V RGPD, such as Standard Contractual Clauses.
Transfers to our providers. Our database is configured with a Western Europe location preference. That is a preference, not a guarantee. Cloudflare operates a global network, and Cloudflare, Inc. is a company based in the United States. Some processing of your data, such as delivering pages, handling technical requests or providing support, may therefore take place outside the EEA.
Where that happens, the transfer is protected by one or both of these safeguards under Chapter V RGPD:
- the Standard Contractual Clauses approved by the European Commission (Implementing Decision (EU) 2021/914), which form part of the provider’s data processing agreement; and
- where the provider is certified, the EU–US Data Privacy Framework, recognised by the European Commission’s adequacy decision of 10 July 2023.
The same principle applies to any other provider we use. You can ask us for a copy of the safeguards that apply to your data by writing to the privacy contact.
10. Your rights in detail
Under Articles 15 to 22 RGPD, and Articles 12 to 18 of Organic Law 3/2018, you have the following rights. They are free of charge.
| Right | What it means |
|---|---|
| Access | Ask whether we hold data about you, and receive a copy together with information about how we use it. |
| Rectification | Have inaccurate data corrected and incomplete data completed. |
| Erasure | Ask us to delete your data, for example when it is no longer needed, when you withdraw consent, or when you object and we have no overriding reason to keep it. We may keep data we are legally obliged or entitled to keep, such as for legal claims. |
| Restriction | Ask us to pause the use of your data while we check a correction or an objection, or when the processing is unlawful but you prefer restriction to deletion. |
| Objection | Object to processing based on our legitimate interest, on grounds relating to your situation. We will stop unless we show compelling legitimate grounds or the processing is needed for legal claims. |
| Portability | Receive the data you provided in a structured, commonly used, machine-readable format, and have it sent to another controller where technically feasible. This applies where we process it on the basis of consent or a contract, and by automated means. |
| Withdraw consent | Withdraw your consent at any time, as easily as you gave it. This does not affect earlier processing. |
| Not to be subject to automated decisions | See section 12: we do not make such decisions. |
How to exercise your rights
Write to support@attackless.com. Tell us which right you want to use and, ideally, the email address you used on the form so we can find your data. You do not need to use any special form.
What happens next
- We may ask you to confirm your identity, to be sure we do not give your data to someone else. We will ask only for what is needed.
- We answer within one month of receiving your request. If your request is complex or we receive many, we may extend this by up to two further months, and we will tell you within the first month and explain why.
- If we decide not to act on your request, we will tell you why, and about your right to complain to the supervisory authority and to seek a judicial remedy.
- If your requests are manifestly unfounded or excessive, especially if they are repetitive, we may charge a reasonable fee or refuse them, as Article 12(5) RGPD allows. We will explain our reasons.
11. Withdrawing your consent
You can withdraw consent at any time by writing to support@attackless.com with the subject “Withdraw consent”. It is as easy to withdraw as to give. After you withdraw, we stop using your data for the purpose you consented to and delete it unless another legal basis, such as a legal obligation, lets us keep it. Withdrawing consent does not make the earlier processing unlawful.
12. Automated decisions and profiling
We do not take decisions about you based solely on automated processing, including profiling, that would have legal effects on you or similarly significantly affect you (Article 22 RGPD). Requests sent through “Check if you qualify” are reviewed by people on our team. The simple checks the form performs, such as confirming that an email address looks valid, or limiting repeated submissions, are technical safeguards and do not evaluate you.
13. How we protect your data
We apply technical and organisational measures appropriate to the risk, as Article 32 RGPD requires. They include:
- encrypted connections (HTTPS) for all traffic between your browser and the website;
- a strict Content-Security-Policy and other security headers, which stop the website from loading anything from outside our own domain;
- access to the database limited to authorised people, using the provider’s access controls;
- server-side validation of everything submitted through the form, protection against automated abuse, and limits on repeated submissions;
- collecting only the data we need, and not storing IP addresses in our database;
- deleting data when the retention period ends;
- confidentiality obligations for people who can access personal data.
Security is our profession, and we apply to our own systems the standards we recommend to clients. No system is completely secure, however, and we cannot guarantee absolute security.
If something goes wrong
If a personal data breach is likely to put your rights and freedoms at risk, we will notify the competent supervisory authorities within 72 hours of becoming aware of it (Article 33 RGPD). Because we have no establishment in the EU, that includes the Agencia Española de Protección de Datos where people in Spain are affected, and the UK Information Commissioner’s Office (ICO). If the breach is likely to result in a high risk to you, we will also tell you without undue delay (Article 34), explaining what happened, what data is affected and what you can do.
14. Data we handle when delivering services
This website is separate from the services we deliver. When a company becomes our client and we test, monitor or secure systems for it, we may come into contact with personal data that belongs to the client, its staff or its customers. In that situation:
- the client is normally the controller of that data and we act as its processor (encargado del tratamiento);
- we process the data only on the client’s documented instructions, under a data processing agreement that meets Article 28 RGPD;
- the client’s contract, not this website policy, sets the rules for that data, including confidentiality, security, sub-processors, retention and return or deletion;
- we minimise our access to personal data during security work and handle any we encounter in line with the contract.
This is also the position for data of business contacts (professionals who act on behalf of a company). Where we handle such contact data for business purposes, we take account of Article 19 of Organic Law 3/2018.
15. Cookies and similar technologies
This website does not set cookies and does not use similar technologies, such as local storage, fingerprinting or tracking pixels, to identify or follow you. For that reason we show no cookie banner.
Our hosting provider may use strictly necessary technical security mechanisms to protect the site against attacks. These are exempt from the consent requirement of Article 22(2) of Law 34/2002 (LSSI-CE) and of the ePrivacy Directive (2002/58/EC), because they are strictly necessary to provide the service you request.
If we ever add analytics or any other non-essential technology, we will first ask for your consent, offer an easy way to refuse, and update this policy.
16. Links to other websites
The website may link to other websites, for example to the Spanish Data Protection Agency. We do not control them and are not responsible for their privacy practices. Read their policies before giving them personal data.
17. Minors
This website and our services are intended for businesses and professionals. We do not knowingly collect data from people under 14, the age below which parental or guardian consent is required for data processing in Spain (Article 7, Organic Law 3/2018). If you believe a minor has sent us data, tell us and we will delete it promptly.
18. Keeping your data accurate
Please give us accurate information and tell us if it changes. You can ask us at any time to correct or update it.
19. How we show we comply
Article 5(2) RGPD makes us responsible for being able to show that we comply. We do this by keeping a record of our processing activities (Article 30), recording the consent you give and the wording version you accepted, applying data protection by design and by default (Article 25), keeping our processors under written agreements, and reviewing this policy when we change what we do with data.
20. Complaints and remedies
If you think we have not handled your data properly, please contact us first so that we can put it right. You also have the right to lodge a complaint with a supervisory authority, and to seek a judicial remedy (Articles 77 and 79 RGPD).
In Spain the authority is the Agencia Española de Protección de Datos (AEPD), C/ Jorge Juan, 6, 28001 Madrid, www.aepd.es. You may instead complain to the authority of the EU member state where you live, work, or where you believe an infringement took place. As we are established in the United Kingdom, you may also complain to the UK Information Commissioner’s Office (ICO), ico.org.uk.
21. Changes to this policy
We may update this policy, for example if we add a tool, change a provider, or change how we use your data. The date at the top shows when it was last updated, and earlier versions are available from us on request. If a change is significant, we will make it clearly visible on the website and, where the law requires, ask for your consent again. The consent version recorded with each request lets us show which wording you accepted.
22. Contact
For anything about your personal data, write to support@attackless.com, or by post to Octagon Plus Holding Ltd, Office 13605, 182-184 High Street North, East Ham, London, E6 2JA, United Kingdom.
Legal framework: Regulation (EU) 2016/679 (RGPD/GDPR) · UK GDPR and Data Protection Act 2018 · Organic Law 3/2018 on data protection (LOPDGDD) · Law 34/2002 on information society services (LSSI-CE) · Directive 2002/58/EC (ePrivacy)