Legal

Privacy Policy

This privacy policy explains how Unsearch collects, uses, stores and protects personal information in connection with the digital footprint audit services we provide. We are committed to transparency and to protecting your privacy throughout every aspect of our engagement.

1. Data Controller

For the purposes of the UK General Data Protection Regulation (UK GDPR), the European Union General Data Protection Regulation (EU GDPR) and applicable data protection legislation, the data controller is Unsearch (the "Controller", "we", "us" or "our").

Contact details for the data controller, including a registered address and data protection officer contact, will be provided upon engagement or upon request through our secure enquiry form.

If you have any questions about how your personal data is processed, or wish to exercise any of your data subject rights, please contact us through the secure enquiry form on this website.

2. Information We Collect

We collect personal information that you provide directly to us through our secure intake form. This includes: full legal name, known name variations, date of birth, residential addresses (current and historical), email addresses, phone numbers, social media handles, jurisdictions of concern and any specific concerns or additional information you choose to provide.

During the course of the digital footprint audit, we collect information about you from publicly accessible sources. This includes information from corporate registries, search engines, press and media archives, data broker platforms, credential breach databases, social media platforms, trademark registries and other publicly available sources. This information is collected solely for the purpose of identifying your digital footprint exposure and preparing the audit report.

We collect limited technical information when you visit this website, including IP address, browser type, device type and pages visited. This information is used solely for the purpose of maintaining website security and is not used for marketing, analytics or profiling purposes.

3. Purpose of Processing

Personal information provided through the intake form is processed for the sole purpose of conducting the digital footprint audit service that you have requested. This includes executing searches across public sources, identifying exposure findings, classifying risk levels, compiling the audit report and providing remediation guidance.

Information collected from public sources during the audit is processed solely for the purpose of preparing your audit report. This information is not used for any other purpose, is not shared with any third party and is securely deleted upon completion of the engagement.

Technical information collected through website visits is processed for the legitimate purpose of maintaining website security and functionality. It is not used for marketing, profiling or any purpose beyond operational security.

4. Lawful Basis for Processing

Under UK GDPR and EU GDPR, we rely on the following lawful bases for processing your personal data:

Contractual necessity (Article 6(1)(b)): Processing of intake information and the conduct of the audit is necessary for the performance of the contract between you and Unsearch for the provision of the digital footprint audit service.

Legitimate interests (Article 6(1)(f)): Processing of publicly available information during the audit is based on our legitimate interest in providing the service you have requested, balanced against your rights and freedoms. The information processed is, by definition, already publicly accessible, and the purpose of the processing is to identify and help you remediate your exposure.

Consent (Article 6(1)(a)): Where you provide specific consent through the intake form, processing is based on that consent. You may withdraw consent at any time by contacting us, though this may affect our ability to complete the engagement.

Legitimate interests (Article 6(1)(f)): Processing of technical website data is based on our legitimate interest in maintaining the security and functionality of our website.

5. Data Retention

Intake information, search records, intermediate findings, draft reports and all associated metadata are securely deleted upon completion of the engagement and delivery of the final report. Secure deletion is performed using methods that ensure data cannot be recovered.

We provide written confirmation of data deletion upon request.

The only exception to this deletion policy is where retention is required by applicable law or regulation. In such cases, the minimum required data is retained for the minimum required period, under the same security controls that apply during the active engagement.

Technical website data is retained for a maximum of 30 days and is then automatically deleted.

Correspondence records (such as email communications regarding the engagement) are retained for a period of 12 months following completion of the engagement, to support any post-engagement queries or aftercare requirements, and are then securely deleted.

6. Security Measures

All client data is encrypted both in transit and at rest. We employ TLS 1.3 for data in transit and AES-256 encryption for data at rest.

Access to client data is restricted to authorised personnel directly involved in the engagement. We maintain strict access controls, audit trails and separation of duties.

Our infrastructure is subject to regular security reviews. We do not store client data on local devices, removable media or cloud services that do not meet our security standards.

All personnel with access to client data are bound by confidentiality obligations and receive regular training on data protection and security practices.

7. Third-Party Processors

We may use a limited number of third-party service providers to support the delivery of our service. These may include secure hosting providers, encrypted communication platforms and digital signature services.

All third-party processors are subject to contractual obligations that require them to process personal data only in accordance with our instructions and to maintain appropriate technical and organisational security measures.

We do not sell, share, license or otherwise disclose client data to any third party for their own purposes. Our third-party relationships are limited to operational support for the delivery of the service you have requested.

A list of our current third-party processors is available upon request.

8. Data Subject Rights (UK and EU Residents)

Under UK GDPR and EU GDPR, you have the following rights in relation to your personal data:

Right of access: You have the right to request a copy of the personal data we hold about you.

Right to rectification: You have the right to request that we correct any inaccurate personal data we hold about you.

Right to erasure: You have the right to request that we delete your personal data. Given our standard deletion policy, this right is typically exercised automatically upon completion of the engagement.

Right to restriction of processing: You have the right to request that we restrict the processing of your personal data in certain circumstances.

Right to data portability: You have the right to receive your personal data in a structured, commonly used and machine-readable format.

Right to object: You have the right to object to our processing of your personal data where we rely on legitimate interests as the lawful basis.

Right to withdraw consent: Where processing is based on your consent, you may withdraw that consent at any time.

To exercise any of these rights, please contact us through the secure enquiry form on this website. We will respond to all data subject requests within one month, as required by applicable legislation.

9. Rights of US Residents

Residents of states with comprehensive privacy legislation, including California (CCPA/CPRA), Virginia (VCDPA), Colorado (CPA), Connecticut (CTDPA) and others, may have additional rights under applicable state law.

These rights may include: the right to know what personal information is collected and how it is used; the right to delete personal information; the right to opt out of the sale or sharing of personal information; and the right to non-discrimination for exercising privacy rights.

We do not sell personal information. We do not share personal information for cross-context behavioural advertising. We do not use personal information for profiling in furtherance of decisions that produce legal or similarly significant effects.

To exercise any rights under applicable US state privacy legislation, please contact us through the secure enquiry form on this website. We will respond in accordance with the timeframes required by applicable law.

10. International Data Transfers

Where personal data is transferred across jurisdictions in the course of providing our service, we ensure that appropriate safeguards are in place. These may include Standard Contractual Clauses approved by the European Commission, the UK International Data Transfer Agreement, or reliance on an adequacy decision where applicable.

Details of the specific safeguards in place for any international data transfer can be provided upon request.

11. Cookies and Tracking

This website does not use marketing cookies, analytics cookies or any form of cross-site tracking. We do not use pixel trackers, social media widgets or third-party advertising tools.

Essential cookies may be used solely for the purpose of maintaining website functionality and security. These cookies do not collect personal information and are not used for tracking or profiling.

12. Changes to This Policy

We may update this privacy policy from time to time to reflect changes in our practices, technology or applicable legislation. Any material changes will be communicated through this website. The date of the most recent update is noted at the bottom of this page.

We encourage you to review this policy periodically.

13. Contact

For all privacy-related queries, data subject requests or complaints, please contact us through the secure enquiry form on this website. We take all privacy concerns seriously and will respond within the timeframes required by applicable legislation.

If you are not satisfied with our response to a privacy concern, you have the right to lodge a complaint with your relevant supervisory authority. In the United Kingdom, this is the Information Commissioner's Office (ICO). In the European Union, this is the data protection authority in your member state.

Last updated: February 2026