In short
- Your email is scanned automatically, never read by a person unless you ask.
- Device checks see settings and software, not files or browsing.
- Data is encrypted, kept only as long as needed and never sold.
Who this policy covers
This policy explains how we handle information when you visit this website, request a free security score, sign up for an account or use the security services we provide to your organisation.
When a business uses our services, that business is the controller of the data about its staff, devices and email. We process that data on its behalf and only on its instructions, as set out in our Terms of Service.
Information we collect
Information you give us
- Account details: name, work email, company name, role, staff count and email system.
- Messages you send through the contact or sign-up forms.
- Billing details, processed by our payment provider. We do not store full card numbers.
Information from connected services
- Email: message metadata, headers, links and attachments, checked automatically for threats.
- Directory: user names, email addresses, group membership and two-step login status.
- Devices: operating system version, update status, encryption, firewall, screen lock and the list of installed software.
- Training: lesson completion and whether a practice test email was clicked or reported.
Information from public sources
For the free security score, we check public DNS records, certificates, exposed services and public breach collections for your domain.
What we never collect
- We do not read your email. Messages are scanned by automated systems. A person only looks at a specific message if you ask for help with it.
- We do not access personal files, photos, documents or browsing history on any device.
- We do not store readable passwords. Reuse checks rely on one-way fingerprints created on the device.
- We do not track device location.
How we use information
- To detect and block threats, and to send alerts and reports to the people your organisation chooses.
- To calculate your Security Score and recommend fixes.
- To improve our detection models. Model improvement uses threat signals and patterns, not the content of your messages.
- To run your account, provide support and send service notices.
- To meet legal obligations and protect our services against abuse.
Security of your data
- Data is encrypted in transit with TLS and at rest with AES-256.
- Access by our staff is limited, logged and protected by two-step login.
- Each customer's data is kept logically separate.
- We test our systems regularly and fix issues promptly.
How long we keep data
Threat records and alerts are kept for 12 months so you can review incidents. Quarantined messages are kept for 30 days unless released or deleted sooner. Device and directory data is refreshed continuously and old snapshots are removed after 90 days.
When an account is closed, customer data is deleted within 30 days, except where we must keep billing records by law.
Your choices and rights
Depending on where you live, you may have the right to access, correct, delete or export your personal information, or to object to certain uses. Staff of a customer organisation should first contact their employer, who controls their data.
To make a request, use the Watchtower contact page. We respond within 30 days.
Changes to this policy
If we make material changes, we will notify account owners by email before the change takes effect.