Privacy Policy
Effective Date: September 10, 2026. Last reviewed under UK GDPR and Data Protection Act 2018 standards.
1. Principles of Minimal Data Collection
BuruOps Intelligence Lab adheres to a strict "data minimization by design" philosophy. We do not use third-party behavioral advertising pixels, session-recording trackers, or third-party marketing brokers. Any information collected through this website is exclusively utilized to respond to technical inquiries or perform agreed commercial audits.
2. Information We Process
We process personal data only when voluntarily transmitted through our contact and technical intake forms:
- Contact Details: Name, work email address, organisation name, and phone number (if provided).
- Technical Scope Data: Project parameters, architecture notes, and technology stack information submitted for assessment scoping.
- Server Telemetry: Anonymized IP addresses and request timestamps captured in web server access logs for rate-limiting, DDoS prevention, and security monitoring.
3. Lawful Basis for Processing
Under the UK General Data Protection Regulation (UK GDPR), our legal bases for processing include:
- Contractual / Pre-Contractual Steps: Processing technical intake data to prepare audit scopes, quotes, and delivery agreements.
- Legitimate Interests: Securing our infrastructure against hostile automated attacks, brute-force exploits, and spam.
4. Technical Security & Audit Confidentiality
All technical audit documentation, cloud architectural snapshots, and vulnerability findings are handled under rigorous non-disclosure and stored in encrypted vaults (AES-256 with KMS envelope encryption). We never share or sell client technical data.
5. Contact the Data Controller
For queries regarding data privacy or to exercise your rights of erasure, rectification, or access under UK GDPR, contact our data governance team at contact@buruops.com.