Privacy
This describes what the site and the portal actually do with your information. If anything here is unclear, ask us and we will answer plainly.
What we collect
When you ask for an exposure check we record the domain you gave us, your name, your email address, your company name if you supplied one, and anything you typed into the message field.
When you hold a client portal account we also store your account email, a hashed password (never the password itself), and your consent record — the name and job title you signed under, the time you signed, the IP address you signed from, and the signature you drew.
When a check runs we store what your own systems returned to us: the table names that responded, their column names, and how many rows each held.
Why we hold it
The domain, your contact details and your message let us reply and carry out the work you asked for.
The consent record is our evidence that testing was authorised. It is kept for as long as we may need to demonstrate that, and it is never edited after signing.
The scan findings are the substance of your report. They are held against your account so the report can be produced and re-issued to you.
What we do not do
We do not sell your data, share it with advertisers, or use it to train models.
We do not publish your findings, name you as a customer, or use your results as a case study.
We do not retrieve the contents of your database records. The check counts rows and reads column names; it does not extract the values inside them.
How long we keep it
Enquiries that do not become accounts are kept while they are commercially live and removed on request.
Account data, consent records and scan findings are kept for the life of the account. When an account is closed, findings are deleted and the consent record is retained as the authorisation audit trail.
Your rights
You can ask us for a copy of what we hold about you, ask us to correct it, or ask us to delete it. Where deletion would remove an authorisation record we still need, we will tell you and explain why.
Write to hello@infinitycreativemedia.co.uk and we will respond within one month.
Cookies
The public site sets no analytics or advertising cookies. Signing in to the client portal or the staff area sets a session cookie, which is required for the login to work and is cleared when you sign out.
Data controller and registration details are published here once the trading entity for Infinity Security is confirmed. Until then, enquiries are handled by Infinity Creative Media at hello@infinitycreativemedia.co.uk.