Privacy & Cookie Policy
alwayspen is a service operated by Sona IT ("Sona IT", "alwayspen", "we", "us"). This policy explains how we collect, use, and protect personal data when you use alwayspen.com and our services. Sona IT is the data controller. For any privacy question, contact [email protected].
Information we collect
- Account details - name, work email, and organisation when you start a trial or create an account.
- Assets you register - the domains or IPs you add, and records proving you're authorised to test them.
- Testing data - the results of penetration tests we run against your verified assets, and the reports produced.
- Usage & device data - basic logs, IP address, and, with your consent, analytics about how the site is used.
- Billing details - handled by our payment processor; we do not store full card numbers.
How we use it
- To provide the service - verifying ownership, scheduling and running tests, and delivering reports.
- To secure the platform and prevent misuse (we only test assets you have verified you own).
- To communicate with you about your account, tests, and support.
- With consent, to understand and improve how the site and product are used.
Our legal bases (UK GDPR) are performance of a contract, our legitimate interests in operating and securing the service, consent (for non-essential cookies and marketing), and compliance with legal obligations.
Cookies
We use a small number of cookies and similar technologies:
- Essential - required for the site and app to work (e.g. session, security, and remembering your cookie choice). These are always on.
- Analytics - help us understand traffic and improve the site. These are only set after you accept via the cookie banner, and you can withdraw consent at any time by clearing cookies or contacting us.
Sharing & sub-processors
We share data only with providers that help us run the service (for example hosting, email, payments, and - where you enable it - source-review tooling). Each is bound by data-processing terms. We do not sell your data. [List sub-processors here.]
International transfers
Where data is processed outside the UK/EEA, we rely on appropriate safeguards such as adequacy decisions or standard contractual clauses. We do not send client vulnerability data to jurisdictions without such safeguards.
Retention
We keep personal data only as long as needed to provide the service and meet legal obligations, then delete or anonymise it. Test reports are retained for [retention period] unless you ask us to delete them sooner.
Your rights
You may request access, correction, deletion, restriction, or portability of your data, and object to certain processing. Contact [email protected]. You can also complain to the UK Information Commissioner's Office (ICO) at ico.org.uk.
Changes
We'll update this page when our practices change and revise the date above.
Contact
Sona IT [confirm full registered name, e.g. Sona IT Ltd], [registered address], United Kingdom (company no. [number]). Email: [email protected].