PRIVACY POLICY
Last updated August 14, 2026
This privacy notice describes how RX Advanced Technologies Ltd, trading as ResilientX and ResilientX Security (“ResilientX”, “we”, “us” or “our”) collects, uses, shares and protects personal data when you:
- visit our websites, including https://www.resilientx.com, or any site of ours that links to this notice;
- use the ResilientX platform — our Unified Exposure Management (UEM), Attack Surface Management, Third-Party Risk Management (TPRM) and related products (the “Platform”);
- engage us for professional services such as penetration testing, security assessments or GDPR, NIS2, DORA and ISO 27001 compliance services (“Professional Services”); or
- interact with us in sales, marketing, events, webinars or support.
Questions or concerns? Reading this notice will help you understand your privacy rights and choices. If you have any questions, contact us at privacy@resilientx.com.
1. OUR ROLE: CONTROLLER AND PROCESSOR
In short: we are the controller for our websites, marketing and your account; we are a processor for the data you or your organisation put into the Platform or expose to us during Professional Services.
For personal data collected through our websites, in sales and marketing, and when administering customer accounts and contracts, ResilientX acts as a data controller and this notice applies in full.
When your organisation uses the Platform or engages us for Professional Services, the assets to be assessed, the configurations and the resulting findings (“Customer Data”) are controlled by that organisation. We process Customer Data as a data processor under our contract and data processing agreement (DPA) with the customer, acting only on documented instructions. If your personal data appears in Customer Data — for example, your work email address appears in a scan result — the organisation that runs the assessment is the controller, and you should direct privacy requests to it in the first instance. We will assist that controller in responding, as our DPA requires.
2. WHAT PERSONAL DATA WE COLLECT
Information you provide to us. Depending on how you interact with us, this may include:
- identity and contact data — name, business email address, phone number, job title, company and country;
- account data — usernames, authentication data and preferences for the Platform;
- commercial data — billing contact and address, orders, and correspondence about contracts. Payments are handled by our payment providers; we do not store full payment-card numbers ourselves;
- communications — messages you send us through forms, email, chat or support channels, and your marketing preferences;
- event and webinar data — registrations, attendance and any questions you submit;
- call and meeting data — where a sales or support call is recorded or transcribed, you are informed at the time and the recording, transcript and notes are retained as described below.
Information collected automatically. When you visit our websites or use the Platform we automatically collect log and device data such as IP address, browser type and settings, operating system, language, referring URLs, pages viewed, actions taken and timestamps, and approximate (IP-based) location. We use cookies and similar technologies as described in section 5.
Information from other sources. We may receive business-contact and firmographic data from enrichment providers, public sources and social networks (for example a company name, role or business email associated with your organisation), and intent or engagement signals from our marketing partners, to keep our records accurate and make our outreach relevant. Where required, we rely on your consent collected by those partners.
Data processed on behalf of customers. Through the Platform, customers submit or connect the assets they want assessed — domain names, host names, IP addresses, URLs, cloud and third-party access keys, and infrastructure metadata — and receive findings such as vulnerabilities, misconfigurations, exposure scores and leaked-credential alerts. This is Customer Data (section 1): it is processed on the customer’s instructions and is not used by us for marketing.
Sensitive data. We do not intentionally collect special categories of personal data (such as health data or data revealing political or religious beliefs) and ask that you do not submit any to us. Note that credential-exposure monitoring can surface breached credentials — see section 4.
3. HOW AND WHY WE USE PERSONAL DATA
In short: we process personal data to run our business and deliver our services, with a legal basis under the GDPR and UK GDPR for each purpose.
- To provide the websites, Platform and Professional Services — creating and administering accounts, authenticating users, delivering assessments and reports, and providing support. Legal basis: performance of a contract; legitimate interests where you use a workplace account provided by your employer.
- To manage our customer and supplier relationships — contracts, invoicing, accounting and records. Legal basis: performance of a contract; compliance with legal obligations.
- To respond to enquiries and requests — demo bookings, exposure reports, content downloads and support questions. Legal basis: performance of a contract or steps prior to a contract; legitimate interests.
- For marketing — sending you information about products, services, events and content, measuring campaigns and tailoring outreach. Legal basis: consent where required; otherwise our legitimate interest in promoting our services to business audiences. You can opt out at any time via the unsubscribe link in any marketing email or by writing to privacy@resilientx.com.
- For analytics and product improvement — understanding how our websites and Platform are used so we can improve them. Legal basis: consent for non-essential cookies and similar technologies; otherwise legitimate interests using aggregated or pseudonymised data.
- For security and abuse prevention — protecting our services, monitoring for fraud and misuse, and enforcing acceptable use. Legal basis: legitimate interests; compliance with legal obligations.
- To comply with the law — responding to lawful requests from authorities, and exercising or defending legal claims. Legal basis: compliance with legal obligations; legitimate interests.
4. SECURITY AND THREAT-INTELLIGENCE DATA
In short: our products analyse the security of organisations. In doing so we process technical data about internet-facing systems, which can include a limited amount of personal data, handled strictly for cybersecurity purposes.
Externally observable data. To power attack-surface analysis, third-party risk assessments and security ratings, we collect and analyse information about organisations’ internet-facing infrastructure from public and commercial sources — for example DNS records, TLS certificates, WHOIS and domain registration records, exposed services and banners, and published breach corpora. This data describes systems rather than people, but it can incidentally include personal data such as names or business contact details of IT staff appearing in registration records or certificates. We process it under our legitimate interest — and that of our customers — in identifying and reducing cybersecurity risk (Recital 49 GDPR), we do not use it for marketing, and we notify the individuals concerned through this notice, as collecting it directly from each person would be impossible or involve disproportionate effort.
Credential-exposure monitoring. Where a customer monitors its own domains, the Platform may surface credentials (such as work email addresses and associated password data) exposed in third-party data breaches. We process this data solely to alert the affected organisation so it can protect the accounts concerned. We do not verify, use or share exposed credentials for any other purpose.
Penetration testing and assessments. During authorised security testing we may incidentally access personal data held in the client systems in scope. Testing is performed under a written engagement that defines scope and authorisation; we access personal data only to the extent technically necessary, treat anything accessed as confidential, and do not retain personal data from client systems beyond what is needed for the report and any contractual evidence obligations.
Compliance services. When we deliver GDPR, NIS2, DORA or ISO 27001 services, we may review documentation and records that contain personal data. We act on the client’s instructions under the engagement contract and DPA.
5. COOKIES, ANALYTICS AND VISITOR IDENTIFICATION
In short: our websites use cookies and similar technologies for functionality, analytics and marketing. Non-essential technologies are used with your consent, which you can withdraw at any time.
Strictly necessary technologies keep the site secure and functional (for example load balancing and consent storage). They do not require consent.
Analytics and performance. We use Google Analytics, Microsoft Clarity and PostHog (hosted in the EU) to measure how our sites are used — pages visited, interactions and technical context. Microsoft Clarity may record how a session interacts with a page (mouse movement, scrolling, clicks) in the form of heatmaps and session replays; text you type into forms is masked wherever possible. These tools are loaded only after consent where required.
Marketing and advertising. We use HubSpot (EU data centre) for forms, scheduling, email marketing and our cookie banner, the Meta pixel for campaign measurement, and sales-intelligence tools — currently Apollo.io, Koala, Leadfeeder and RB2B — that attempt to identify the organisation (and, where permitted, the business contact) associated with a website visit using IP addresses, cookies and similar identifiers. These technologies operate only with your consent where consent is required.
Your choices. You can accept or decline non-essential cookies in the consent banner when you first visit, change your choice at any time through the banner’s settings, block or delete cookies in your browser, and use tool-specific controls such as the Google Analytics opt-out add-on. Declining non-essential cookies does not affect your use of the sites.
6. WHO WE SHARE PERSONAL DATA WITH
In short: we share personal data with service providers that help us run our business, under contracts that protect it. We do not sell personal data.
We share personal data with:
- Hosting and infrastructure providers — including Cloudflare, Amazon Web Services (primary region: Frankfurt, eu-central-1) and Vercel, which host our websites, Platform and data;
- Business tools and processors — providers of CRM, marketing, analytics, communications, meeting-recording and transcription, support and billing services (including the tools named in section 5), each processing personal data on our behalf under a data processing agreement;
- Professional advisers — lawyers, accountants, auditors and insurers, where necessary;
- Authorities — courts, regulators and law enforcement, where the law requires or permits it;
- Parties to a corporate transaction — in connection with a merger, acquisition, financing or sale of assets, in which case this notice continues to apply to your personal data;
- Our affiliates — companies under common control with us, which must honour this notice.
A current list of our subprocessors for the Platform is available on request at privacy@resilientx.com.
7. INTERNATIONAL DATA TRANSFERS
In short: we store data primarily in the European Economic Area. Where data leaves the EEA or the UK, we use recognised safeguards.
Our primary infrastructure is located in the EEA. Some of our providers (for example Google, Meta and Microsoft) process data in the United States or other countries. Where personal data is transferred outside the EEA or the UK, we rely on an adequacy decision — including, for US providers, certification under the EU–US Data Privacy Framework — or on the European Commission’s Standard Contractual Clauses (with the UK Addendum or International Data Transfer Agreement where UK data is concerned), together with additional safeguards where appropriate. You can request a copy of the relevant safeguards at privacy@resilientx.com.
8. HOW LONG WE KEEP PERSONAL DATA
In short: we keep personal data only as long as needed for the purposes described here, then delete or anonymise it.
We determine retention periods based on the purpose of processing, our contractual and legal obligations, and applicable limitation periods. As a rule: account and contract data is kept for the duration of the relationship and for a limited period afterwards to comply with legal obligations (for example accounting and tax rules) and to establish or defend legal claims; marketing data is kept until you opt out or after a reasonable period of inactivity; website analytics and log data is kept for shorter periods appropriate to security and measurement; Customer Data is retained as instructed by the customer and deleted or returned at the end of the contract in line with the DPA. Where deletion from backups is not immediately possible, data is isolated from further processing until the backups expire.
9. HOW WE PROTECT PERSONAL DATA
Security is our business. We apply technical and organisational measures appropriate to the risk, including encryption of data in transit, access controls on a need-to-know basis, network and application security controls, logging and monitoring, and regular testing of our own systems and practices. No system can be guaranteed absolutely secure, but we work to a standard we would be prepared to assess others against. If a personal data breach affecting you occurs, we will notify you and the competent authorities where the law requires it.
10. YOUR RIGHTS
In short: depending on where you live, you can access, correct, delete, restrict or receive a copy of your personal data, object to certain processing, and withdraw consent at any time.
If you are in the EEA, the UK, Switzerland or another jurisdiction with similar laws, you have the right to: request access to and a copy of your personal data; have inaccurate data corrected; have data erased; restrict processing; receive data you provided in a portable format; object to processing based on legitimate interests, including profiling; object at any time to direct marketing, which we will always honour; and withdraw consent at any time, without affecting the lawfulness of processing before withdrawal.
To exercise any right, email privacy@resilientx.com. We may need to verify your identity before acting on a request, and we respond within the timelines set by applicable law. If your personal data appeared in a customer’s assessment (Customer Data), we will refer your request to that customer and assist them as required.
You also have the right to complain to a supervisory authority — in the EU you can find yours in the list of national data protection authorities; in Italy the Garante per la protezione dei dati personali; in the UK the Information Commissioner’s Office. We would, however, welcome the chance to address your concern first.
11. AUTOMATED DECISION-MAKING AND PROFILING
Our products generate automated security ratings and risk scores about organisations and their infrastructure — not about individuals. We do not make automated decisions that produce legal effects on individuals or similarly significantly affect them.
12. CHILDREN
Our websites and services are intended for business users and we do not knowingly collect personal data from anyone under 18. If you believe a person under 18 has provided us personal data, contact us at privacy@resilientx.com and we will delete it.
13. ADDITIONAL DISCLOSURES FOR US RESIDENTS
We do not sell personal information, and we have not sold or shared personal information as those terms are defined in the California Consumer Privacy Act and similar US state laws. Residents of California and other US states with comprehensive privacy laws may have rights to know, access, correct and delete personal information, and to non-discrimination for exercising them. You can exercise these rights — directly or through an authorised agent — by emailing privacy@resilientx.com. We may verify your request as permitted by law.
14. CHANGES TO THIS NOTICE
We may update this notice from time to time. The updated version will be indicated by the “Last updated” date above and takes effect when posted. If we make material changes, we will notify you by posting a prominent notice or contacting you directly. Please review this notice periodically.
15. HOW TO CONTACT US
RX Advanced Technologies Ltd (trading as ResilientX Security)
Privacy enquiries and data subject requests: privacy@resilientx.com
General enquiries: info@resilientx.com or our contact page.