Privacy policy
Effective and last updated: October 5, 2026
This policy describes personal information connected with the Lyrata Security website at lyratasecurity.com and inquiries sent to our team. Client assessment data is handled under the applicable engagement agreement.
1. Information we receive
When you contact us by email, we receive the information you choose to send, such as your name, email address, company, project description, and related correspondence.
The inquiry form prepares a draft locally in your browser. It does not submit its fields to a website server, store them in browser storage, or add them to a mailing list. If you choose to send the prepared email, your email provider transmits it and we receive it through our email service.
Our hosting and security providers may process technical request information to deliver and protect the website, such as an IP address, requested URL, time of request, browser information, and security events.
| Information | How it is received | Purpose |
|---|---|---|
| Contact and project details | Email you choose to send | Respond to your inquiry and discuss services |
| Technical request information | Hosting and security infrastructure | Deliver, maintain, and protect the website |
| Follow-up correspondence | Communications with our team | Manage the conversation and relevant business records |
2. How we use information
We use information to respond to requests, discuss potential engagements, communicate about services, maintain relevant business records, and protect the website and our communications.
Where a legal basis is required, the applicable basis depends on the activity. It may include taking steps at your request before an agreement, performing an agreement, our legitimate interests in business communications and security, complying with legal obligations, or consent where needed.
We do not use the inquiry form to enroll you in marketing emails. We do not sell personal information or use website data for targeted advertising.
5. Retention and security
We retain inquiry correspondence only for as long as needed for the conversation, relevant business purposes, and applicable legal obligations. Retention of technical request information depends on the hosting or security service and its configured practices. Client engagement retention is defined separately.
We use appropriate safeguards for information we handle, but no method of transmission or storage guarantees absolute security. Please do not include credentials, sensitive customer data, or vulnerability evidence in an initial inquiry. We can agree on a suitable channel for sensitive assessment material.
6. Your choices and rights
You can contact us directly without using the draft form. You can also ask us to correct or delete information you have sent, subject to information we need to retain for legitimate or legal purposes.
Depending on where you live and the law that applies, you may have rights to access, correct, delete, or receive a copy of your personal information, restrict or object to processing, or withdraw consent where processing depends on consent. You may also be able to complain to a relevant privacy regulator.
Send requests to [email protected]. We may need to verify your identity before fulfilling a request, and will respond as required by applicable law. We will not treat you adversely for exercising an applicable privacy right.
7. International processing
Our service providers may process information in countries other than your own. Where applicable law requires protections for international transfers, the relevant contractual or other lawful safeguards must apply. Contact us with questions about processing relevant to your inquiry or engagement.
8. Client assessment information
Systems, credentials, technical evidence, and personal data encountered during an assessment require engagement-specific handling. The written agreement defines authorized access, confidentiality, approved tools and providers, retention, deletion, and any necessary data protection terms.
The website inquiry is not an approved channel for submitting assessment data. Contact us first to agree on how it will be shared.
9. Children
This website is intended for business users and is not directed to children under 16. We do not knowingly solicit personal information from children. If you believe a child has sent us personal information, contact us so we can address it.
10. Updates and contact
We may update this policy when our website or information practices change. The effective date at the top identifies the current version. Questions and privacy requests can be sent to [email protected].