Legal

Privacy policy

Last updated: 26 April 2026 · We collect only what is necessary to deliver your report.

We do not sell your data. We do not use it for advertising. We collect only what is necessary to deliver your report and run our service.
1. Who we are

ProtectPatch ("we", "us", "our") is the data controller for personal data collected through this website. For privacy-related queries contact us here.


2. What data we collect

When you place an order we collect:

  • Your name and email address
  • Your company name (if provided)
  • Your billing address
  • The domain name you submit for scanning
  • Payment confirmation data from Stripe (we never see or store your card number)

We also automatically collect standard server log data including IP address and browser type, used solely for security and operational purposes.


3. How we use your data

We use your data exclusively to:

  • Process your payment and deliver your report
  • Send transactional emails related to your order
  • Respond to support queries
  • Maintain financial records as required by law
  • Protect the security and integrity of our service

We will never use your email for marketing without explicit consent. We will never sell or share your data with third parties for their marketing purposes.


4. Legal basis for processing

Under UK GDPR, we process your data on the following legal bases:

  • Contract performance — to deliver the service you have purchased
  • Legal obligation — to maintain financial records required by HMRC
  • Legitimate interests — to operate and secure our platform

5. Third-party services

We use a small number of trusted third-party services:

  • Stripe — payment processing. Your card data goes directly to Stripe. PCI-DSS Level 1 certified.
  • Email delivery provider — to send confirmation and report emails.
  • Hosting provider — to serve this website.

6. Data retention

We retain your order data for 7 years to comply with UK financial record-keeping requirements. After this period your data is securely deleted.


7. Cookies

We use only essential cookies necessary to operate the checkout process and maintain session security. We do not use tracking or advertising cookies.


8. Your rights

Under UK GDPR you have the right to access, correct, or request deletion of your data, and to lodge a complaint with the ICO at ico.org.uk. Contact us here. We will respond within 30 days.


9. Changes to this policy

We may update this policy from time to time. The date at the top of this page will reflect the most recent version.