Privacy Policy
Last updated: October 2026
This policy explains what personal data Keepvik collects when you use this website and the Keepvik agent, why, who we share it with, how long we keep it, and the rights you have under the EU General Data Protection Regulation (GDPR), the UK GDPR and similar laws.
1. Who is responsible for your data
The controller of your personal data is Keepvik. You can contact us about anything in this policy at the contact details at the top of this page.
2. What we collect
Details you give us
- Your name, email address and phone number, and optionally your company name, when you sign up for a scan.
- What you tell us when you contact us or buy a service (messages, and billing details handled by our payment provider).
Technical data from the Keepvik agent
When you run the agent on a computer, it reads technical information about that computer: computer name and Windows version, network connections (remote IP addresses and ports and which program opened them — browser connections are only counted), open ports, security settings (antivirus, firewall, UAC, Remote Desktop, BitLocker and similar), startup programs and scheduled tasks, running programs (name, publisher, signature), network adapter settings, the hosts file, proxy and DNS settings, and basic performance figures. User folder names are replaced with a placeholder before upload. See the full list.
The agent never reads file contents, documents, photos, emails or messages, passwords or cookies, browsing history, keystrokes, the screen, the camera or the microphone.
Some of this data can relate to an identifiable person (for example a computer name, or the programs someone uses), so we treat all of it as personal data.
Website and security logs
- A one-way hash of your IP address, used to prevent abuse (for example rate limiting) and to keep a security log of scans and actions.
- If you turn on browser notifications, the push address your browser gives us.
- We do not use advertising or analytics cookies. Staff sign-in uses one strictly necessary cookie.
3. Why we use it, and our legal basis
| Purpose | Legal basis (GDPR Art. 6) |
|---|---|
| Running the scan you asked for and showing you the result | Performing a contract with you, or steps you asked for before one (6(1)(b)) |
| Delivering paid services: reports, monitoring, fixes, support, billing | Contract (6(1)(b)); keeping accounting records — legal obligation (6(1)(c)) |
| Contacting you about the results of your free scan and how we can help | Our legitimate interest in following up on a scan you requested (6(1)(f)). You can tell us to stop at any time. |
| Preventing abuse and keeping our service secure | Legitimate interests (6(1)(f)) |
| Browser notifications | Your consent (6(1)(a)), which you can withdraw in your browser at any time |
| Marketing emails (only if you opt in) | Your consent (6(1)(a)) |
Only run the agent on a computer you own or are authorised to check. If a business runs it on computers used by its staff, that business is responsible for informing them, and we process the data on its behalf under a data processing agreement, which we provide on request.
4. Automated analysis and AI
Findings come from automated rules and public threat-intelligence lists (lists of known-malicious IP addresses). A member of our team reviews findings before we advise you. We do not make decisions with legal or similarly significant effects about you based solely on automated processing.
5. Who we share it with
We do not sell your personal data or share it for advertising. We use these service providers (processors), under contracts that require them to protect it:
- Hosting: our hosting provider (servers in the EU).
- Browser notifications (if you turn them on): your browser vendor's push service (for example Google, Mozilla, Apple or Microsoft) delivers the message.
- Payment processing (paid services): our payment provider, which receives your billing details directly.
We may also disclose data if the law requires it, or to protect our rights or the safety of others.
6. International transfers
Where a provider processes data outside the UK or the European Economic Area, we rely on an adequacy decision or on the European Commission's Standard Contractual Clauses (and the UK Addendum), with additional safeguards where needed. Contact us for a copy.
7. How long we keep it
- Raw technical data uploaded by the agent: erased automatically after 90 days. The findings and risk score derived from it are kept with your account.
- Your sign-up details, findings and reports: for as long as you use our services, and deleted automatically after 24 months without any activity — or sooner if you ask.
- Security logs (hashed IP addresses, actions taken): 365 days.
- Invoices and accounting records: as long as tax law requires (usually 6–10 years).
8. Your rights
You have the right to:
- Access your personal data and get a copy of it.
- Correct data that is wrong or incomplete.
- Delete your data ("right to be forgotten").
- Restrict how we use it, or object to uses based on legitimate interests — including follow-up contact.
- Portability: receive the data you gave us in a machine-readable format (we provide JSON).
- Withdraw consent at any time, without affecting what we did before.
- Complain to a data protection authority — in the EU, the authority where you live or work; in the UK, the Information Commissioner's Office (ico.org.uk).
To use any of these rights, email the contact details at the top of this page. We reply within one month. We may need to confirm it's you, usually by replying from the email address you signed up with.
California residents: you have similar rights to know, delete and correct your data. We do not sell or share personal information as defined by the CCPA/CPRA.
9. How we protect it
Data is encrypted in transit (HTTPS). Access codes and device keys are stored only as one-way hashes, staff access is limited and logged, and the agent can only run fixes from a fixed list after approval on the computer. No system is perfectly secure, but we work to keep the risk low and will notify you and the authorities of a personal data breach when the law requires.
10. Children
Our services are not directed at children under 16, and we do not knowingly collect their data. If you believe a child has signed up, contact us and we will delete it.
11. Changes
If we change this policy we will update the date at the top, and tell you directly about significant changes.