This policy explains what personal data attackless.com collects, why, on what legal basis, how long we keep it, who receives it, and the rights you have under the EU General Data Protection Regulation (RGPD / GDPR) and Spanish law. It is written to be read, so please do.
1. Basic information at a glance
This is the short version, in the layered format Spanish law recommends (Article 11 of Organic Law 3/2018). The rest of this page gives the full detail.
| Controller | GUTMIT Ventures LLP, operating attackless.com |
|---|---|
| Purpose | To let you book a discovery call, to reply to you, to contact businesses about security problems visible on their public websites, and to keep the website secure. |
| Legal basis | Steps taken at your request before a contract (Art. 6(1)(b) RGPD); our legitimate interest in contacting businesses about security problems and in keeping the website secure (Art. 6(1)(f)); legal obligations (Art. 6(1)(c)). |
| Recipients | Cal.com (booking), Stripe (payment, if a call is ever paid) and Cloudflare (hosting), plus our email provider. No one else, unless the law requires it. |
| Transfers | Some providers are based in the United States. Transfers are protected by Standard Contractual Clauses and, where applicable, the EU–US Data Privacy Framework. |
| Your rights | Access, rectification, erasure, restriction, objection, portability, and withdrawal of consent where it applies. You can also complain to the AEPD. |
| More information | The sections below. |
2. Who is responsible for your data
The controller of your personal data (responsable del tratamiento) is:
| Name | GUTMIT Ventures LLP, trading as attackless.com |
|---|---|
| Legal form | Limited liability partnership (LLP) |
| Address | Sant Cugat del Vallès, Barcelona, Spain |
| Website | attackless.com |
| support@attackless.com |
GUTMIT Ventures LLP operates attackless.com from Spain. Because we operate from Spain and offer services to businesses in Spain and the United States, the RGPD applies to our processing of personal data, together with the Organic Law 3/2018 on data protection (LOPDGDD).
We have not appointed a Data Protection Officer, because our activities do not require one under Article 37 RGPD. We will review this if our activities change. Every privacy question or request goes to support@attackless.com.
3. What this policy covers
This policy applies to personal data we handle through the website attackless.com, through calls booked from it, and through emails we send or receive. Section 14 explains how we treat personal data when we deliver services to clients, which is governed by a different legal arrangement.
In this policy, “personal data” means any information about an identified or identifiable person, and “processing” means anything we do with it, such as collecting, storing, using, sharing or deleting it. “RGPD” is the EU General Data Protection Regulation, Regulation (EU) 2016/679, also known as the GDPR.
4. The data we collect
On this website
The website itself does not store personal data about you: it has no accounts, no analytics, and no form that saves what you type. The booking calendar is provided by Cal.com, as described below.
When you book a call
The “Book a call” calendar is run by Cal.com and is shown at the bottom of some pages, or on Cal.com’s own page. There you choose a time and give:
- your name and email address;
- any notes you choose to add, and the time you choose;
- if a call is ever paid, your card details, which go to Stripe. We do not see or store your card number. We would receive confirmation that payment was made.
Cal.com and Stripe also handle that data under their own privacy policies. Please do not put sensitive information in the notes field. This includes health data, criminal records, passwords, access credentials, and confidential technical details of a security incident.
The booking form on Cal.com also asks for your company name, industry, company size and what you need most, so we can prepare for the call. We do not store these answers on our website. Cal.com holds them with your booking, and we receive them there.
If we contact you first
We sometimes email a business when we notice a security problem in information that is publicly visible on its website. In that case we hold your business email address, your company name, and a note of what we noticed. We take these from public sources, such as your own website. We do not access anything that is not public.
Correspondence and calls
If you write to us, reply to us by email, or speak with us on a call, we keep that correspondence and the notes we take.
Data we receive automatically
As with any website, the servers that deliver these pages, operated by Cloudflare (see section 8), necessarily receive your IP address and basic request details in order to send you the page and to defend it against attacks. We do not store your IP address ourselves, and we do not use this to identify or profile you.
On pages that show the booking calendar, your browser also connects to Cal.com when the page loads and loads Cal.com’s embed script, so Cal.com receives your IP address and basic request details. Cal.com may also set its own cookies (see section 15).
Data we do not collect
- No analytics, advertising or tracking tools of any kind.
- No cookies of our own, and no analytics, advertising or tracking tools (see section 15).
- The only third-party content is the Cal.com booking calendar at the bottom of some pages (see sections 8 and 15). Fonts, images and scripts are served from our own domain.
- No special categories of personal data (Article 9 RGPD), and no data about minors.
- No data bought from data brokers.
5. Why we use your data, and the legal basis
We may only process personal data if we have a legal basis under Article 6 RGPD. For each purpose, this table shows the data involved and the basis we rely on.
| Purpose | Data | Legal basis (RGPD) |
|---|---|---|
| Arrange, hold and follow up your discovery call | Name, email, notes, chosen time, your correspondence | Steps taken at your request before a contract, Art. 6(1)(b). |
| Take payment for a call, if a call is paid | Payment confirmation (card details go to Stripe, not to us) | Performance of the booking you made, Art. 6(1)(b). |
| Show you the booking calendar | IP address and request details, received by Cal.com when the page loads | Our legitimate interest in letting visitors book a call, Art. 6(1)(f). |
| Contact businesses about a security problem we noticed on their public website | Business email address, company name, a note of what we noticed | Our legitimate interest in offering relevant security services to businesses, Art. 6(1)(f). You can object at any time. |
| Keep the website secure and deliver it to you | IP address and request details, processed by our hosting provider | Our legitimate interest in operating a secure website, Art. 6(1)(f). |
| Handle your privacy requests and complaints | Identity details, the content of your request, our reply | Legal obligation, Art. 6(1)(c), to respond to the exercise of your rights. |
| Meet accounting, tax and other legal duties, including for paid calls and for clients | Payment, contract and invoicing data | Legal obligation, Art. 6(1)(c) (under Spanish and EU law). |
| Establish, exercise or defend legal claims | Any of the above, where relevant | Our legitimate interest, Art. 6(1)(f). |
Legitimate interest
Where we rely on legitimate interest, we have weighed it against your interests, rights and freedoms. When we contact a business about a problem on its public website, we use only business contact details and information that is already public, we say why we are writing, and we make it easy to stop. You may object at any time (section 10), and if you object to our emails we stop.
What providing the data means
Booking a call is voluntary. Your name, email address and chosen time are needed to arrange it. Without them we cannot book the call.
Other uses
We use your data only for these purposes. We do not sell it, and we do not use it for advertising. If we ever want to use your data for a new purpose, we will tell you first and, where the law requires, ask for your consent.
6. How we contact you
We use your email address to confirm your booking, to reply to you and to continue the conversation you started.
We may also email a business first, when we notice a security problem on its public website. Each such email says why we are writing and how to stop further emails: reply “stop”, or write to support@attackless.com. If you tell us to stop, we keep a minimal record of that so that we do not contact you again. Commercial emails are also subject to Article 21 of Law 34/2002 (LSSI-CE).
We do not send newsletters unless you have asked for them.
7. How long we keep your data
We keep personal data only as long as it is needed for the purpose it was collected for, and then delete it or anonymise it. The periods below are the ones we apply.
| Type of data | How long |
|---|---|
| Booking and call records, if you do not become a client | Up to 12 months after our last contact with you, then deleted. |
| Contact details of businesses we email first | Up to 12 months after we last contacted you, unless you become a client. If you ask us to stop, we keep only what we need to remember not to contact you. |
| Client and payment records, if you become a client | For the length of the relationship, then for the periods the law requires. For example, accounting records are generally kept for six years under Spanish commercial law. |
| Records of privacy requests | For as long as needed to show that we handled them lawfully. |
| Technical logs at our hosting provider | For the short periods set by that provider. |
Once a retention period ends we delete the data. Where the law obliges us to keep some data longer, we restrict access to it and use it only for that legal purpose. You can ask us to delete your data sooner (see section 10).
8. Who receives your data
Only the people at attackless.com who need your data to handle your request can access it. We also use service providers:
| Provider | What it does | Location |
|---|---|---|
| Cloudflare, Inc. | Hosts the website, delivers it through its network and protects it against attacks. | United States, with operations in the EU |
| Cal.com | Runs the booking calendar where you choose a time for a discovery call. It receives your IP address when a page with the calendar loads. | United States |
| Stripe | Processes card payments, if a call is ever paid. | Ireland and United States |
| Our email service provider | Provides the mailbox we use to write to you and to read your replies. | As set out in its data processing agreement; the safeguards in section 9 apply. |
Providers that process data on our behalf (encargados del tratamiento) are bound by a data processing agreement that meets Article 28 RGPD: they may act only on our instructions, must keep the data confidential and secure, and must delete or return it at the end. Some providers, such as Stripe for payments, also act as controllers of their own data, under their own privacy policies.
The source code of this website is stored with a code hosting provider. It contains no visitor data.
We may also share data with:
- professional advisers, such as lawyers, accountants and auditors, bound by confidentiality;
- public authorities, courts and law enforcement, where the law obliges us to or where necessary to establish, exercise or defend legal claims;
- a buyer or successor if the business is ever sold or restructured, in which case this policy would continue to protect your data and we would tell you.
We do not share your data with anyone else, and we do not sell or rent it.
9. Transfers outside the European Economic Area
Transfers to India. Some of our team and systems are in India, so data you send us may be accessed from there. The European Commission has not recognised India as providing an adequate level of data protection, so we protect that data with Standard Contractual Clauses under Chapter V RGPD.
Transfers to our providers. Cloudflare, Cal.com and Stripe run global networks and have operations in the United States. Some processing of your data, such as delivering pages, handling bookings or processing payments, may therefore take place outside the EEA.
Where that happens, the transfer is protected by one or both of these safeguards under Chapter V RGPD:
- the Standard Contractual Clauses approved by the European Commission (Implementing Decision (EU) 2021/914), which form part of the provider’s data processing agreement; and
- where the provider is certified, the EU–US Data Privacy Framework, recognised by the European Commission’s adequacy decision of 10 July 2023.
The same principle applies to any other provider we use. You can ask us for a copy of the relevant safeguards by writing to the privacy contact.
10. Your rights in detail
Under Articles 15 to 22 RGPD, and Articles 12 to 18 of Organic Law 3/2018, you have the following rights. They are free of charge.
| Right | What it means |
|---|---|
| Access | Ask whether we hold data about you, and receive a copy together with information about how we use it. |
| Rectification | Have inaccurate data corrected and incomplete data completed. |
| Erasure | Ask us to delete your data, for example when it is no longer needed, when you withdraw consent, or when you object and we have no overriding reason to keep it. We may keep data we are legally obliged or entitled to keep, such as for legal claims. |
| Restriction | Ask us to pause the use of your data while we check a correction or an objection, or when the processing is unlawful but you prefer restriction to deletion. |
| Objection | Object to processing based on our legitimate interest, on grounds relating to your situation. We will stop unless we show compelling legitimate grounds or the processing is needed for legal claims. |
| Portability | Receive the data you provided in a structured, commonly used, machine-readable format, and have it sent to another controller where technically feasible. This applies where we process it on the basis of consent or a contract, and by automated means. |
| Withdraw consent | Withdraw your consent at any time, as easily as you gave it. This does not affect earlier processing. |
| Not to be subject to automated decisions | See section 12: we do not make such decisions. |
How to exercise your rights
Write to support@attackless.com. Tell us which right you want to use and, ideally, the email address you used to book, or that we wrote to, so we can find your data. You do not need to use any special form.
What happens next
- We may ask you to confirm your identity, to be sure we do not give your data to someone else. We will ask only for what is needed.
- We answer within one month of receiving your request. If your request is complex or we receive many, we may extend this by up to two further months, and we will tell you within the first month and explain why.
- If we decide not to act on your request, we will tell you why, and about your right to complain to the supervisory authority and to seek a judicial remedy.
- If your requests are manifestly unfounded or excessive, especially if they are repetitive, we may charge a reasonable fee or refuse them, as Article 12(5) RGPD allows. We will explain our reasons.
11. Withdrawing your consent
You can withdraw consent at any time by writing to support@attackless.com with the subject “Withdraw consent”. It is as easy to withdraw as to give. After you withdraw, we stop using your data for the purpose you consented to and delete it unless another legal basis, such as a legal obligation, lets us keep it. Withdrawing consent does not make the earlier processing unlawful.
12. Automated decisions and profiling
We do not take decisions about you based solely on automated processing, including profiling, that would have legal effects on you or similarly significantly affect you (Article 22 RGPD). Bookings and replies are handled by people on our team. We use automated tools to spot problems that are publicly visible on business websites. That does not produce legal or similarly significant effects on you, and it does not involve evaluating you as a person.
13. How we protect your data
We apply technical and organisational measures appropriate to the risk, as Article 32 RGPD requires. They include:
- encrypted connections (HTTPS) for all traffic between your browser and the website;
- a strict Content-Security-Policy and other security headers, which restrict the website to our own domain plus the Cal.com booking calendar;
- access to the database limited to authorised people, using the provider’s access controls;
- no forms, accounts or databases of visitor data on this website, so there is little to lose or leak;
- collecting only the data we need;
- deleting data when the retention period ends;
- confidentiality obligations for people who can access personal data.
Security is our profession, and we apply to our own systems the standards we recommend to clients. No system is completely secure, however, and we cannot guarantee absolute security.
If something goes wrong
If a personal data breach is likely to put your rights and freedoms at risk, we will notify the competent supervisory authorities within 72 hours of becoming aware of it (Article 33 RGPD). That includes the Agencia Española de Protección de Datos where people in Spain are affected. If the breach is likely to result in a high risk to you, we will also tell you without undue delay (Article 34), explaining what happened, what data is affected and what you can do.
14. Data we handle when delivering services
This website is separate from the services we deliver. When a company becomes our client and we test, monitor or secure systems for it, we may come into contact with personal data that belongs to the client, its staff or its customers. In that situation:
- the client is normally the controller of that data and we act as its processor (encargado del tratamiento);
- we process the data only on the client’s documented instructions, under a data processing agreement that meets Article 28 RGPD;
- the client’s contract, not this website policy, sets the rules for that data, including confidentiality, security, sub-processors, retention and return or deletion;
- we minimise our access to personal data during security work and handle any we encounter in line with the contract.
This is also the position for data of business contacts (professionals who act on behalf of a company). Where we handle such contact data for business purposes, we take account of Article 19 of Organic Law 3/2018.
15. Cookies and similar technologies
This website does not set cookies of its own, and does not use analytics, advertising or tracking tools.
The booking calendar shown at the bottom of some pages is provided by Cal.com and loads together with the page. Cal.com may set its own cookies or use similar technologies. We do not control them, and they are described in Cal.com’s own privacy and cookie information. Our hosting provider may also use strictly necessary technical security mechanisms to protect the site. Cookies that are strictly necessary to provide a service you request are exempt from the consent requirement of Article 22(2) of Law 34/2002 (LSSI-CE) and of the ePrivacy Directive (2002/58/EC). If a technology needs your consent, we will ask for it first.
If we ever add analytics or any other non-essential technology, we will first ask for your consent, offer an easy way to refuse, and update this policy.
16. Links to other websites
The website may link to other websites, for example to the Spanish Data Protection Agency. We do not control them and are not responsible for their privacy practices. Read their policies before giving them personal data.
17. Minors
This website and our services are intended for businesses and professionals. We do not knowingly collect data from people under 14, the age below which parental or guardian consent is required for data processing in Spain (Article 7, Organic Law 3/2018). If you believe a minor has sent us data, tell us and we will delete it promptly.
18. Keeping your data accurate
Please give us accurate information and tell us if it changes. You can ask us at any time to correct or update it.
19. How we show we comply
Article 5(2) RGPD makes us responsible for being able to show that we comply. We do this by keeping a record of our processing activities (Article 30), recording the consent you give and the wording version you accepted, applying data protection by design and by default (Article 25), keeping our processors under written agreements, and reviewing this policy when we change what we do with data.
20. Complaints and remedies
If you think we have not handled your data properly, please contact us first so that we can put it right. You also have the right to lodge a complaint with a supervisory authority, and to seek a judicial remedy (Articles 77 and 79 RGPD).
In Spain the authority is the Agencia Española de Protección de Datos (AEPD), C/ Jorge Juan, 6, 28001 Madrid, www.aepd.es. You may instead complain to the authority of the EU member state where you live, work, or where you believe an infringement took place.
21. Changes to this policy
We may update this policy, for example if we add a tool, change a provider, or change how we use your data. The date at the top shows when it was last updated, and earlier versions are available from us on request. If a change is significant, we will make it clearly visible on the website and, where the law requires, ask for your consent again. The consent version recorded with each request lets us show which wording you accepted.
22. Contact
For anything about your personal data, write to support@attackless.com, or by post to GUTMIT Ventures LLP, Sant Cugat del Vallès, Barcelona, Spain.
Legal framework: Regulation (EU) 2016/679 (RGPD/GDPR) · Organic Law 3/2018 on data protection (LOPDGDD) · Law 34/2002 on information society services (LSSI-CE) · Directive 2002/58/EC (ePrivacy)