Legal
Privacy policy
Fusion Prevent Ltd (“we”) is the data controller for the personal data described here. This policy explains what we collect, why, how long we keep it, and what you can ask us to do. If anything is unclear, email hello@fusionprevent.com and a person will answer.
When you run a free scan
You give us your name, work email address, phone number and your firm’s domain. We use them to run the scan, show you the results, email you the link, and contact you about the findings. Our lawful basis is legitimate interests: you asked for the scan, and the contact details are what make the result useful to you.
The scan itself looks only at information that is already public: your DNS records, your certificates, what your servers advertise to the internet, and whether your staff addresses appear in known breach data. We never probe, test, log into or access your systems.
Where the scan data comes from
We query third parties to build your results. Each receives only what it needs, usually a domain or an email address:
- Companies House — company registration, officers and filing history
- Hudson Rock and LeakCheck — whether an address appears in breach or infostealer data
- Shodan — what your servers publish about themselves
- Cert Spotter and crt.sh — certificates issued for your domains
- Public DNS — your mail and domain records
We do not sell your data, and we do not share it with anyone other than the providers above and the services named under “Who else handles it”.
If you become a client
You tell us the domains you own and the names and work email addresses of your people. We check those addresses against breach and infostealer data every day and tell you when something changes. Our lawful basis is contract, and for your staff, legitimate interests in securing the firm they work for — please tell them we are doing it.
We never store your staff’s passwords. Where a breach record includes one, we record that a password was exposed and discard the value.
If we contacted you first
We write to UK firms about exposure we found in public data. We get contact details from Companies House, the register of your regulator, and your own website. Our lawful basis is legitimate interests under UK GDPR, and PECR permits business-to-business email of this kind.
Reply “no thanks” to any message and we will not contact you or anyone at your firm again. That suppression is permanent and applies across everything we send.
Cookies and tracking
We use a Meta (Facebook) pixel on our advertising pages to measure which adverts lead to a scan. It sets cookies in your browser and sends Meta information about your visit. We also record which advert brought you here, using parameters on the link.
You can block these with your browser settings or an ad blocker; the scan works either way. We do not use advertising cookies on the portal.
Who else handles it
- Railway — hosting and database (EU)
- Resend — sending email
- GoHighLevel — our CRM and booking
- Meta — advertising measurement
How long we keep it
- Free scan results — 90 days, then deleted
- Client data — for the life of the contract and 12 months after
- Suppression list — indefinitely, because that is the only way to honour it
Your rights
You can ask for a copy of what we hold, ask us to correct or delete it, object to processing, or ask us to stop contacting you. Email hello@fusionprevent.com and we will respond within 30 days. You can also complain to the Information Commissioner’s Office at ico.org.uk.
Changes
If we change how we use your data we will update this page and change the date at the top.