Privacy Notice
This notice explains how Sylure processes personal data when you use our marketing website and, where relevant, when your organisation uses the Sylure service.
Last updated: 7 February 2026
Roles
Controller + Processor
Controller for website; Processor for uploads.
Retention
Customer-controlled
Raw bundles: 1d auto-expiry. Derived data: until you delete. Deleted on demand.
Evidence handling
Masked by default
Minimisation in UI and exports.
Indexing
Hash-first
Using HMAC-SHA256.
Who we are
"Sylure", "we", "us" and "our" refers to Sylure Ltd, a company registered in England and Wales, operating the Sylure platform and this website. If you are using Sylure through your employer or another organisation, that organisation may be the data controller for personal data in customer uploads and DSAR workflows.
Scope of this notice
This notice covers: (a) visitors to our marketing website, (b) people who contact us for a demo or commercial discussions and (c) users of the Sylure service (account holders). Where the Sylure service processes personal data contained in your organisation's uploaded bundles, Sylure typically acts as a processor on behalf of the customer (the controller).
Personal data we collect
Marketing website
- Contact requests: name, organisation, work email address and message content.
- Basic technical data: IP address, user agent, page requested, timestamp and standard web server logs.
Sylure service (account data)
- Account details: name, work email, role (ADMIN / ANALYST / VIEWER), authentication and security events.
- Operational metadata: workspace settings, audit log entries and export activity.
- Support communications related to your account and workspace.
Customer uploads (customer-controlled content)
Customer uploads may contain personal data about data subjects (for example: identity, contact, financial or government identifiers), depending on what your organisation uploads. Sylure is designed to minimise handling of raw identifiers by using normalised, hash-first indexing for matching and masked evidence previews by default. Exact configuration and outputs depend on your workspace settings and your organisation's instructions.
Cookies and similar technologies
We use a small number of cookies that are strictly necessary for the site to function. We do not currently use any analytics, advertising or tracking cookies.
| Cookie | Purpose | Duration | Type |
|---|---|---|---|
| sylure_session | Authentication session | Session | Essential (HttpOnly) |
| sylure_consent | Records your cookie preference | 1 year | Essential |
How we use personal data
- To provide and operate the Sylure service: upload intake, scanning, exposure mapping, DSAR workflows, reporting and audit exports.
- To respond to demo requests, enquiries and support tickets.
- To secure the platform and website, prevent misuse and investigate incidents.
- To improve reliability and performance. Where we analyse usage, we aim to use aggregate-only data and avoid unnecessary access to customer content.
Legal bases (UK GDPR)
- Website enquiries and demos: legitimate interests and/or steps taken at your request prior to entering into a contract.
- Service account data: performance of a contract and legitimate interests (security and fraud prevention).
- Customer upload processing: performance of a contract with the customer and processing on the customer's documented instructions.
Sharing and sub-processors
We share personal data with service providers who help us operate the website and platform (for example, hosting and storage providers), strictly on a need-to-know basis and subject to contractual safeguards including data processing terms.
A current list of sub-processors is available on request. Contact us if you require this for procurement or compliance review.
International transfers
We aim to host and process data in the UK or EEA where possible. If personal data is transferred outside the UK, we use appropriate safeguards such as the UK International Data Transfer Agreement (IDTA) and/or the UK Addendum to the EU Standard Contractual Clauses.
Retention and deletion
We retain personal data only for as long as necessary for the purposes described above, subject to legal and operational requirements.
Website enquiries
Retained for as long as needed to respond and manage commercial discussions, then deleted or anonymised.
Prepared uploads
Unscanned uploads expire after about 24 hours to reduce stale intake risk.
Customer data
Raw bundles auto-expire after 1 days. Derived data persists until you delete it.
When a customer deletes an upload bundle, we remove the underlying stored bundle and associated derived outputs in line with the retention and purge logic. Limited records may remain for audit and integrity purposes (for example, a deletion event), without the underlying content.
Security
We implement technical and organisational measures designed to protect personal data against unauthorised access, alteration, disclosure or destruction. These include access controls and role-based permissions, audit logging, transport encryption and evidence minimisation (masked by default) with hash-first indexing for matching.
Your rights
Under UK GDPR you may have rights to access, rectify, erase, restrict or object to processing of your personal data and the right to lodge a complaint with the Information Commissioner's Office (ICO).
If your personal data is contained in a customer upload processed by Sylure on behalf of an organisation, please contact that organisation (the controller) to exercise your rights.
Contact
For privacy questions or to exercise rights relating to website or account data, email us at sylure@sylure.com or use the contact form. If you require a data processing addendum (DPA) or sub-processor information for procurement, please include that in your message.
Changes to this notice
We may update this notice from time to time to reflect changes in our services, legal requirements or operational practices. We will post the updated version on this page with a revised "Last updated" date.