Privacy notice

This describes exactly what the free Defensibility Check does with your data. The data controller is Care with Intelligence Holdings Limited. Questions, or to exercise any of your rights: chris@carewithintelligence.com.

What we collect and why

Your work email address. We use it to derive your organisation’s domain for the public DNS checks, and to send you the link that unlocks your full report.

Your ten self-check answers. They generate your score. They are self-declared and stay attached to your organisation’s record.

Public DNS results for your domain. SPF, DMARC, DKIM and MX records are already public; we store the outcome of the check (pass, gap, inconclusive), not your email traffic. We never read mailboxes and we never store email content.

Whether your email appears in a known data breach. After you click the link to confirm your address, we check that one address against Have I Been Pwned’s database of public breaches. We store only whether it appeared, how many breaches, and the most recent date — never passwords, never breached content, and never anyone else’s address. This runs only on the address you submitted, and only after you verify it.

Your IP address. Used only to rate-limit the check and prevent abuse. In our own records we keep only a one-way hash of it, with a short expiry, never linked to your report. The raw address is briefly sent to our bot-check provider (Cloudflare, below) to confirm you’re a person — we never store the raw address ourselves.

Our lawful basis. For the security check as a whole — your email, your answers, the DNS results and the breach lookup — it’s our legitimate interest in giving you the free check you asked for. For the IP hash, it’s our legitimate interest in keeping the tool secure and preventing abuse. Marketing email is the one thing we do only with your consent. Giving us your details is voluntary — there’s no legal or contractual obligation — but without your work email we can’t run the check or send your report.

Who else touches your data

We keep this list short on purpose. To run the check we rely on a few processors, each acting only on our instructions — none of them get your data for their own purposes:

One step happens outside the UK

Everything we store stays in the UK (see below). Two things briefly send data abroad: when you verify your address, that single address is sent to Have I Been Pwned to run the breach check, and your submission passes through Cloudflare’s bot-check. Both operate outside the UK. We rely on these transfers being necessary to provide the specific check you asked for; nothing else leaves the UK, and no breach content comes back beyond a count and a date.

Marketing is separate and optional

The report arrives whether or not you tick the marketing box. If you do tick it, we store the exact wording you agreed to and the time you agreed. You can withdraw your consent at any time by contacting us, and if we ever send you marketing email every message will include an unsubscribe link.

Where your data lives and how long we keep it

Everything we store lives in Google Cloud’s London region (europe-west2). The results of each check — your DNS outcomes, self-check answers and breach fact — are point-in-time snapshots that expire within days to a few months. Your work email, and (if you gave it) your record of marketing consent, are kept for up to 24 months, then deleted automatically — sooner if you ask us to delete them, or, for marketing, as soon as you unsubscribe. Keeping a cold record no longer than that is the same data minimisation this check looks for on your own systems. We never sell your data, and the only third parties who ever see it are the processors listed above.

Your rights

You can ask for a copy of what we hold about you, ask us to correct it or delete it, ask us to restrict how we use it, or object to us using it — including any use based on our legitimate interests. Where you gave us data to run the check, you can also ask for it in a portable, machine-readable form. Contact us first at chris@carewithintelligence.com. You also have the right to complain to the Information Commissioner’s Office (ico.org.uk) if you think we have handled your data wrongly.