Effective August 2026. This policy explains what personal information we collect through planckdefense.com, why we collect it, how long we keep it, who we share it with, and the rights you hold over it.
We are a security firm, and we treat visitor data the way we advise our clients to treat theirs: collect little, protect what you hold, and delete what you no longer need. The sections below describe our practice in full. There is no fine print beyond what you read here.
Planck Defense & Aerospace is a boutique cybersecurity consultancy providing penetration testing and offensive security, organization-specific threat intelligence, and dedicated IP VPN infrastructure to business clients. For the purposes of applicable data protection law, we act as the controller of personal information collected through this website.
This policy covers the website only. Data we handle inside a client engagement is governed by the contract for that engagement, which typically imposes stricter confidentiality and handling obligations than this policy does.
We run a deliberately quiet website. The categories below are the full extent of our collection.
This site sets no advertising trackers and no analytics cookies. The contact form composes an email in your own mail client rather than posting data to our servers, so nothing you type into it reaches us until you choose to send that email. We do not buy information about visitors from data brokers and we do not build marketing profiles.
We do not use your information for advertising and we do not sell it. We send no newsletters or marketing email unless you explicitly ask to receive updates, and you can withdraw that request at any time by replying to any message from us.
Where the GDPR or a similar law applies, each use above rests on a recognized legal basis. In plain terms:
When a retention period ends, we delete the data or anonymize it irreversibly.
We share personal information in two situations only.
We never sell personal information and we never share it with advertisers or data brokers.
Our service providers may store or process data outside the country where you live. Where personal information leaves the European Economic Area, the United Kingdom, or another jurisdiction with transfer rules, we rely on recognized safeguards such as adequacy decisions or standard contractual clauses, and we hold the receiving provider to the same confidentiality and security obligations described in this policy.
Depending on where you live, you may hold some or all of the following rights over your personal information.
To exercise any of these rights, email us at the address below. We may need to verify your identity before acting on a request, and we respond within the timelines the applicable law sets.
Security is our trade, and we apply to our own systems what we recommend to clients.
No system is perfectly secure. If an incident ever affects your personal information, we will notify you and the relevant authorities as the law requires.
Questions, requests, or complaints about this policy go to [email protected]. We acknowledge privacy inquiries within one business day. If our answer does not satisfy you, you retain the right to complain to your local data protection authority.