Legal

Privacy notice

This notice explains how Sylure processes personal data when you use our marketing website and, where relevant, when your organisation uses the Sylure service.

Last updated: 7 January 2026

Roles

Controller + Processor

Controller for website; Processor for uploads.

Retention (default)

90 days

+ 7-day grace window.

Evidence handling

Masked by default

Minimisation in UI and exports.

Indexing

Hash-first

Using HMAC-SHA256.

1.

Who we are

"Sylure", "we", "us" and "our" refers to the entity operating the Sylure platform and this website (the "Company"). If you are using Sylure through your employer or another organisation, that organisation may be the data controller for personal data in customer uploads and DSAR workflows.

2.

Scope of this notice

This notice covers: (a) visitors to our marketing website, (b) people who contact us for a demo or commercial discussions, and (c) users of the Sylure service (account holders). Where the Sylure service processes personal data contained in your organisation's uploaded bundles, Sylure typically acts as a processor on behalf of the customer (the controller).

3.

Personal data we collect

Marketing website

  • Contact requests: name, organisation, work email address and message content.
  • Basic technical data: IP address, user agent, page requested, timestamp and standard web server logs.

Sylure service (account data)

  • Account details: name, work email, role (ADMIN / ANALYST / VIEWER), authentication and security events.
  • Operational metadata: workspace settings, audit log entries, and export activity.
  • Support communications related to your account and workspace.

Customer uploads (customer-controlled content)

Customer uploads may contain personal data about data subjects (for example: identity, contact, financial or government identifiers), depending on what your organisation uploads. Sylure is designed to minimise handling of raw identifiers by using normalised, hash-first indexing for matching, and masked evidence previews by default. Exact configuration and outputs depend on your workspace settings and your organisation's instructions.

4.

How we use personal data

  • To provide and operate the Sylure service: upload intake, scanning, exposure mapping, DSAR workflows, reporting and audit exports.
  • To respond to demo requests, enquiries and support tickets.
  • To secure the platform and website, prevent misuse, and investigate incidents.
  • To improve reliability and performance. Where we analyse usage, we aim to use aggregate-only data and avoid unnecessary access to customer content.
5.

Legal bases (UK GDPR)

  • Website enquiries and demos: legitimate interests and/or steps taken at your request prior to entering into a contract.
  • Service account data: performance of a contract and legitimate interests (security and fraud prevention).
  • Customer upload processing: performance of a contract with the customer and processing on the customer's documented instructions.
6.

Sharing and sub-processors

We share personal data with service providers who help us run the website and platform (for example, hosting and storage providers), strictly on a need-to-know basis and subject to contractual safeguards. For the Sylure service, uploads are stored in object storage and processed by our backend systems to generate results for your workspace.

7.

International transfers

We aim to host and process data in the UK or EEA where possible. If personal data is transferred outside the UK, we use appropriate safeguards such as the UK International Data Transfer Agreement (IDTA) and/or the UK Addendum to the EU Standard Contractual Clauses.

8.

Retention and deletion

We retain personal data only for as long as necessary for the purposes described above, subject to legal and operational requirements.

Website enquiries

Retained for as long as needed to respond and manage commercial discussions, then deleted or anonymised.

Prepared uploads

Unscanned uploads expire after about 24 hours to reduce stale intake risk.

Customer bundles

Default retention is 90 days with a 7-day grace window. Customers can delete bundles earlier via the product.

When a customer deletes an upload bundle, we remove the underlying stored bundle and associated derived outputs in line with the retention and purge logic. Limited records may remain for audit and integrity purposes (for example, a deletion event), without the underlying content.

9.

Security

We implement technical and organisational measures designed to protect personal data against unauthorised access, alteration, disclosure or destruction. These include access controls and role-based permissions, audit logging, transport encryption, and evidence minimisation (masked by default) with hash-first indexing for matching.

10.

Your rights

Under UK GDPR you may have rights to access, rectify, erase, restrict or object to processing of your personal data, and the right to lodge a complaint with the Information Commissioner's Office (ICO).

If your personal data is contained in a customer upload processed by Sylure on behalf of an organisation, please contact that organisation (the controller) to exercise your rights.

11.

Contact

For privacy questions or to exercise rights relating to website or account data, use the contact form on this site. If you require a data processing addendum (DPA) or sub-processor information for procurement, please include that in your message.

12.

Changes to this notice

We may update this notice from time to time to reflect changes in our services, legal requirements or operational practices. We will post the updated version on this page with a revised "Last updated" date.