Legal
Privacy Policy
How we collect, use, and protect personal data across our website, products, and services — and how to exercise your rights.
1 min readLast reviewed July 18, 2026Threat ResQ Technologies
1. Who we are
Threat ResQ Technologies (“Threat ResQ,” “we,” “us”) provides AI-powered cybersecurity, compliance, and human risk management services. This policy covers the personal data we process through threatresq.com, our lead-capture forms, the TIARA assistant, and the risk-assessment tools on this site. It does not cover data processed for contracted clients under a separate engagement, which is governed by that client's services agreement and any accompanying Data Processing Agreement (see our Data Processing page).
2. What we collect
- Directly provided: name, work email, company, phone (where given), and any message you submit via the Contact form, a lead-capture field, or a TIARA conversation.
- Calculator inputs: the organizational answers you provide to the Cyber Risk Score Calculator and Breach Cost Estimator, used only to generate your on-screen result and, if you request it, an emailed summary.
- Automatically collected — only after you consent to Analytics cookies: pages viewed, approximate region and device/browser type, referrer, and UTM campaign parameters, via Google Analytics 4 and Microsoft Clarity. See our Cookie Policy for the full list and how to opt out.
- Never collected: payment card details (we don't process payments on this site) or special-category data (health, biometric, etc.) through any public-facing form.
3. Why we process it (lawful basis)
- Responding to your inquiry (contract / pre-contract steps) — when you submit the Contact form, a calculator lead form, or ask TIARA to connect you with the team.
- Analytics and product improvement (consent) — only once you accept the Analytics category in the cookie banner; see §6.
- Security and fraud prevention (legitimate interest) — rate-limiting and abuse detection on our forms and APIs.
- Legal compliance — where we are required to retain or disclose records by applicable law.
4. Your rights
Depending on where you live, you may have the right to:
- Access the personal data we hold about you and receive a copy;
- Correct inaccurate or incomplete data;
- Request erasure (“right to be forgotten”), subject to legal retention obligations;
- Withdraw consent at any time, without affecting processing carried out before withdrawal — for cookies, use Cookie Preferences in the footer;
- Object to processing based on legitimate interest;
- Data portability, for data you provided to us directly;
- Lodge a complaint with your local supervisory authority (EU/UK) or the Data Protection Board of India (DPDP Act).
To exercise any of these rights, email privacy@threatresq.com or use the Contact form. We aim to respond within 30 days (GDPR) / as required under the DPDP Act's implementing rules.
5. GDPR — EU/UK visitors
Where GDPR or UK GDPR applies, Threat ResQ acts as data controller for website visitor data described above. Our lawful bases are set out in §3. Where we transfer personal data outside the EEA/UK — for example to a sub-processor with infrastructure in another region — we rely on Standard Contractual Clauses or another recognized safeguard. You have the rights listed in §4 and may contact your national supervisory authority at any time.
6. DPDP Act — India
Under India's Digital Personal Data Protection Act, 2023, Threat ResQ acts as Data Fiduciary for personal data collected through this site. We process personal data on the basis of your consent, obtained through the cookie banner for analytics/marketing purposes and through your affirmative submission of any form for inquiry-response purposes. You may withdraw consent at any time via Cookie Preferences (footer) or by emailing privacy@threatresq.com, as easily as it was given. Our Grievance Officer can be reached at grievance@threatresq.com for any complaint regarding processing of your personal data, and we will acknowledge and address grievances within the timelines prescribed by the Act and its rules.
7. Retention
Inquiry and lead data is retained for as long as reasonably necessary to respond to your request and maintain a record of the business relationship, and in any case no longer than 36 months of inactivity unless a longer period is required by law or an active engagement continues. Calculator inputs submitted without an email address are not retained beyond the session. Analytics data is retained per Google Analytics' and Microsoft Clarity's standard retention windows, only for visitors who consented.
8. Sub-processors
We use a small number of service providers to operate this site: an SMTP provider to deliver form notifications, and — only where you've consented — Google (Analytics 4, Tag Manager) and Microsoft (Clarity) for analytics. None of these providers may use your data for their own purposes. A current list of sub-processors is available on request at privacy@threatresq.com.
9. Changes to this policy
We'll update the “Last reviewed” date above whenever this policy changes materially. Continued use of the site after a change constitutes acceptance of the revised policy.
10. Contact
Privacy questions or requests: privacy@threatresq.com. DPDP grievances: grievance@threatresq.com. General inquiries: Contact us.