Privacy Policy
Pentester Space Ltd. (“Pentester Space,” “we,” “us,” or “our“) respects your privacy. This Privacy Policy explains how we collect, use, share, and protect personal information when you visit or use pentesterspace.com (the “Website“) and our services.
This Privacy Policy should be read together with our Terms of Service.
1. Who We Are
Pentester Space is the controller of personal information collected through the Website and in the course of our business relationships, such as information about prospective customers and the staff of our customers.
Pentester Space Ltd.
15/A/10 New, West Rajabazar, Panthapath
Sher-e-Bangla Nagar, Dhaka 1215, Bangladesh
Email: privacy@pentesterspace.com
2. Information We Collect
Depending on how you use the Website or our services, we may collect:
- Contact information: name, email address, company name, job title, and phone number.
- Communication information: information you provide when contacting us, requesting a proposal, or corresponding with us.
- Commercial information: proposals, contracts, invoices, and payment records. We do not store full payment card numbers; payments are handled by our payment provider.
- Technical information: IP address, browser type, device information, operating system, referring pages, and basic Website usage information collected through server logs and any essential cookies.
- Service information: information necessary to scope and provide penetration testing, vulnerability assessment, or related services, including asset lists, contact persons, and test accounts.
- Marketing preferences: your choices about receiving communications from us.
- Recruitment information: if you apply to work with us, the information in your application.
We do not intentionally collect sensitive personal information, such as health, biometric, or racial or ethnic data, unless it is necessary for a specific service and provided with appropriate authorization.
3. How We Use Information and Our Legal Bases
We use personal information for the following purposes. Where the law requires a legal basis for processing, the basis we rely on is shown for each purpose.
- Providing and managing our services, including preparing proposals, reports, and service documentation — performance of a contract with you, or steps taken at your request before entering a contract.
- Responding to inquiries and service requests — our legitimate interest in responding to people who contact us.
- Communicating with customers and prospective customers about our services — our legitimate interest in promoting our services, or your consent where the law requires it.
- Improving the Website and our services — our legitimate interest in understanding how the Website is used.
- Maintaining security and preventing fraud or abuse — our legitimate interest in protecting our business, systems, and users.
- Complying with legal obligations, including accounting, tax, and lawful requests from authorities — compliance with a legal obligation.
Where we rely on consent, you may withdraw it at any time. Withdrawal does not affect processing that took place before it.
We do not sell or rent personal information, and we do not use personal information for automated decision-making that produces legal or similarly significant effects.
4. Data We Process During Security Testing
When providing penetration testing, vulnerability assessment, or other security services, we may access information belonging to our customers or held in their systems. This may include personal data about their employees, customers, or users.
For this data:
- Our customer is the controller, and we act as a processor on the customer’s documented instructions under the applicable Engagement Agreement and, where required, a data processing agreement, which is available on request.
- We access data only to the extent necessary to perform the agreed testing and demonstrate findings.
- We do not copy, extract, or retain data beyond what is reasonably needed as proof of concept for reported findings.
- Engagement data, including credentials, evidence, and screenshots, is stored securely for the duration of the engagement and afterwards retained only for the periods set out in the retention schedule in Section 9. Credentials, API keys, and tokens are destroyed as soon as they are no longer required, and never held for more than 90 days.
- Where we use associate testers or subprocessors for an engagement, they are bound by written confidentiality and data protection obligations.
Customers remain responsible for ensuring that they have the necessary authorization to provide systems, data, or information to us for testing.
If you are an employee, customer, or user of one of our customers and wish to exercise privacy rights over data we processed during an engagement, please contact that customer directly. We will assist them as required.
5. Cookies and Analytics
The Website does not currently use analytics tools or advertising cookies. It may use essential cookies or similar technologies only where they are required for the Website to function or to maintain security.
If we introduce analytics or other non-essential cookies in the future, we will update this Privacy Policy to describe them and, where required by law, ask for your consent before setting them. You can control or delete cookies through your browser settings. Disabling essential cookies may affect how the Website works.
6. Information Sharing
We may share personal information with:
- Service providers that help us operate our business or the Website, such as hosting, email, document storage, customer relationship management, and payment processing providers. They process information only on our instructions.
- Associate testers or subcontractors engaged for specific services, under confidentiality and data protection obligations.
- Professional advisers, such as lawyers, accountants, and insurers, where reasonably necessary.
- Government authorities, regulators, or law-enforcement agencies where legally required.
- A buyer or successor in the event of a merger, acquisition, reorganization, or sale of assets, in which case this Privacy Policy will continue to apply to the information transferred.
- Other parties when necessary to protect our rights, users, systems, or property.
7. International Transfers
We are based in Bangladesh. Personal information may be stored and processed in Bangladesh and in the countries where our service providers operate. We select hosting locations according to the requirements of each service we use. Where personal information is transferred from a country that restricts international transfers, we rely on appropriate safeguards, such as standard contractual clauses or an adequacy decision, and take reasonable steps to ensure the information remains protected.
8. Data Security
We use technical and organizational measures designed to protect personal information against unauthorized access, disclosure, alteration, or destruction. These include encryption of data in transit and at rest, access controls and multi-factor authentication for our systems, least-privilege access to engagement data, and secure deletion procedures.
No internet-based system can be guaranteed to be completely secure. If we become aware of a personal data breach affecting information we hold, we will notify affected customers and, where required, the relevant authorities and individuals within the timeframes required by applicable law.
9. Data Retention
We retain personal information only for as long as reasonably necessary for the purposes described in this Privacy Policy. As a general guide:
- Inquiries and prospective-customer information: up to 24 months after our last contact with you.
- Customer, contract, and invoicing records: for the duration of our relationship and 3 years afterwards, as required for accounting, tax, and legal purposes.
- Website server logs: up to 12 months.
Material produced or accessed during an engagement is retained on the following schedule, measured from delivery of the final report:
| Engagement material | Retention |
|---|---|
| Final pentest report | 3 years |
| Signed and approved deliverables | 3 years |
| Executive summary | 3 years |
| Findings and remediation history | 3 years |
| Pentest certificate or attestation | 3 years |
| Raw scan results | 6–12 months |
| Proof of concept, screenshots, and technical evidence | 6–12 months |
| Credentials, API keys, and tokens | As soon as they are no longer required, and never more than 90 days |
| Temporary processing data | 24–72 hours |
Retention differs from this schedule only where it is agreed with you in writing or required by law. You may ask us to delete reports and deliverables earlier.
When information is no longer needed, we securely delete or anonymize it.
10. Your Rights
Depending on applicable law, you may have the right to:
- Access the personal information we hold about you.
- Correct inaccurate or incomplete information.
- Request deletion of your information.
- Restrict or object to certain processing, including direct marketing.
- Receive a copy of information you provided to us in a portable format.
- Withdraw consent where processing is based on consent.
- Lodge a complaint with your local data protection authority.
To exercise these rights, contact privacy@pentesterspace.com. We may ask you to verify your identity before acting on a request. We aim to respond within 30 days, or within any shorter period required by law.
11. Marketing Communications
We may send you information about our services if you have requested it, if you are an existing customer, or where we are otherwise permitted by law. You can opt out at any time by using the unsubscribe link in our emails or by contacting privacy@pentesterspace.com. We will continue to send service-related communications, such as engagement updates and invoices, that are necessary for the services you have requested.
12. Children’s Privacy
The Website and our services are not directed at children under 18, and we do not knowingly collect personal information from them. If you believe a child has provided us with personal information, contact us and we will delete it.
13. Third-Party Services
The Website or our services may contain links to third-party websites or use third-party services. We are not responsible for the privacy practices of third parties. We recommend reviewing their respective privacy policies.
14. Changes to This Privacy Policy
We may update this Privacy Policy from time to time. The updated version will be published on this page with a revised effective date. Where changes are significant, we will take reasonable steps to notify existing customers.
15. Contact
Pentester Space Ltd.
15/A/10 New, West Rajabazar, Panthapath
Sher-e-Bangla Nagar, Dhaka 1215, Bangladesh
Website: pentesterspace.com
Privacy: privacy@pentesterspace.com