Privacy Policy
Last updated: September 16th, 2026
This Privacy Policy explains how SECURIX LIMITED collects, uses, retains and protects personal data, and sets out your rights and how to exercise them. It applies to the securix.hk website and to the personal data SECURIX processes as a data controller — in particular through its products Nightprill and Scrytide. The way we handle data during client engagements is addressed separately in Section 2.
1. Data Controller
The data controller is:
SECURIX LIMITED — Lee Garden Two, 28 Yun Ping Road, Causeway Bay, Hong Kong
- Email: hello@securix.hk
2. Our Activities and Our Role
SECURIX is a cybersecurity firm. The capacity in which we process personal data — and therefore which rules apply — depends on the activity.
2.1 Client engagements (consulting, audit, security testing)
Our core business is cybersecurity consulting: advisory and audit work, penetration testing and red-team engagements, compliance projects, incident response and ongoing security support. When we carry out any such assignment for a client, we act on that client’s behalf and under contract. The client determines the purpose and scope; we execute their request on their systems and data. In data-protection terms, the client is the controller and SECURIX acts as a processor.
The processing of personal data in these engagements is governed by the agreement concluded with each client (including any data processing agreement), not by this public policy. This applies to all such assignments, whatever their nature.
Deliverables we produce during an engagement — reports, technical evidence, indicators of compromise — may contain personal data. Where we hold such deliverables on our own infrastructure after delivery, we act as controller for that limited retention: they are kept for a bounded period (see Section 10) and then deleted.
2.2 Our own products (Nightprill, Scrytide)
When we operate our own products, we determine how the processing is carried out, and act as the data controller. This policy applies in full to those activities, described in Sections 4 and 5.
3. Data We Collect
- Contact data — when you email us, we process the information you choose to send (typically your name, email address, company and role).
- Usage data — collected automatically by the website: IP address, browser type and version, pages visited, date and duration of visit, technical identifiers and diagnostic data.
- Cookies — our website is static and sets no cookies: no necessary, analytics, functional or advertising cookies. Nothing is stored on your device and no tracking takes place.
4. Nightprill — Exposure Monitoring
Nightprill matches the perimeter you declare against exposure sources (data leaks, stealer logs, clandestine marketplaces, public infrastructure). As controller of this product, we apply the following:
- Perimeter declared by you — domain names, brands, public IP addresses, email addresses, keywords, partners. Nothing is guessed or added without your knowledge.
- Secrets are never stored in cleartext — passwords and tokens are turned into an irreversible fingerprint that allows recognition without retention, and excerpts shown to you mask the secret while preserving its length.
- No copy of leak databases is retained — only a line of context, a fingerprint and a link to the source.
- GDPR Article 9 data is identified and discarded — health, orientation, beliefs, trade-union membership — including where the leak’s name alone reveals them. Mixed leaks are flagged as such.
- Data minimisation — only data necessary for qualification is recorded.
- Declared partners — at your request, we check whether a leak concerning you also contains a partner you have designated. We do not monitor that partner and disclose none of their data to you: only the fact that you appear in the same source is reported. You confirm, under the agreement, that you have a legitimate interest in this cross-exposure check.
- Third-party data — a line may be retained because it contains your name while belonging to a person unconnected to you. Secrets within it are masked, the line is kept only for as long as qualification requires, and it is discarded once the absence of any link is established.
- Named-individual monitoring — at your request and under contract, we monitor specific named individuals (typically executives) across exposure sources, including their personal email addresses. As this concerns individuals, you confirm under the agreement that you have a lawful basis to request it, and we handle any objection from the person concerned.
- Payment-card monitoring — at your request, we search clandestine marketplaces for compromised card numbers matching corporate card prefixes you provide. We process card-prefix and listing data solely to alert you, and we do not store full card numbers.
5. Scrytide — Vulnerability Scanning
Scrytide scans web applications and APIs that you own or are authorised to test, and confirms findings before reporting them. As controller of this product, we apply the following:
- Scope declared and authorised by you — we only scan the targets you have authorised in writing.
- Technical, not personal, focus — the scan targets application and API vulnerabilities; any personal data incidentally encountered is not the object of the processing and is not retained beyond what is needed to evidence a finding.
- Findings are confirmed — reports contain reproducible proofs; sensitive values within a proof are masked.
- AI-assisted analysis runs on open-weight models hosted by Scaleway in France (EU). Scaleway does not collect, read or reuse prompts or model outputs, and inference data is not used to train shared models. No client data is sent to consumer AI services.
6. Representative in the European Union (GDPR Article 27)
We value your privacy and your rights as a data subject and have therefore appointed Prighter Group with its local partners as our privacy representative and your point of contact for the following regions:
- European Union (EU)
Prighter gives you an easy way to exercise your privacy-related rights (e.g. requests to access or erase personal data). If you want to contact us via our representative Prighter, or make use of your data subject rights, please visit the following website: https://app.prighter.com/portal/securix
You may address our EU representative in any official language of the European Union.
7. Purposes and Legal Bases
For the processing we carry out as controller (website and products), the legal bases are:
| Purpose | Legal basis (GDPR Art. 6) |
|---|---|
| Providing and maintaining our products | Performance of a contract |
| Exposure monitoring / vulnerability scanning on your declared scope | Performance of a contract / legitimate interest in security |
| Responding to enquiries and quote requests | Legitimate interest / pre-contractual steps |
| Website security and integrity | Legitimate interest |
| Marketing communications about our services | Consent / legitimate interest, with right to object |
| Complying with our legal obligations | Legal obligation |
8. Recipients and Sub-processors
We do not sell your data. Queries relating to your perimeter — domain names, brands, IP addresses — are sent to our exposure-data provider; nothing is hidden from you as to what leaves our systems. The table below distinguishes each provider’s legal entity from where your data is actually processed. Each is bound by a Data Processing Agreement.
| Sub-processor | Entity | Processing location | Purpose |
|---|---|---|---|
| netcup GmbH | Germany | Austria | Hosting |
| Impossible Cloud GmbH | Germany | France | Encrypted backups |
| Kaduu AG | Switzerland | Germany | Exposure-data source |
| Contabo GmbH | Germany | France | Hosting |
| Scaleway S.A.S. | France | France | AI-assisted analysis |
| Scaleway S.A.S. | France | France | Encrypted backups |
| Infomaniak Network SA | Switzerland | Switzerland | Client portal hosting |
| Proton AG | Switzerland | Switzerland | Document storage and delivery of client deliverables |
| Prighter EU Rep GmbH | Austria | EU | EU representative (GDPR Art. 27) |
An up-to-date register is available to clients on request.
9. Transfers Outside the European Union
All processing takes place within the European Union or Switzerland. Switzerland benefits from an adequacy decision under Article 45 GDPR.
Although SECURIX LIMITED is registered in Hong Kong, operations are conducted from France: no client data is transferred to, stored in, or accessed from Hong Kong.
10. Retention Period
We retain your data only for as long as necessary for the purposes described, plus any period required by our legal obligations.
| Data category | Retention |
|---|---|
| Portal access logs | 90 days |
| Reports published to the portal | 30 daily reports, then monthly for 12 months |
| Engagement deliverables and evidence (reports, IOCs) | 12 months after delivery |
| Findings and technical evidence (Scrytide) | Duration of the engagement + 12 months |
| Exposure findings (Nightprill) | Duration of the engagement + 12 months |
| Named-individual & payment-card findings | Duration of the engagement |
| Secret fingerprints | Duration of the engagement |
| Leak line excerpts | Duration of the engagement |
| Declared scope | Duration of the engagement |
| Contact data | 3 years from last interaction |
| Billing records | 7 years (statutory accounting retention) |
Clients may request earlier deletion of their findings and reports at any time, subject to any ongoing legal or contractual obligation.
11. Your Rights
Under the GDPR, you have the rights of access, rectification, erasure, restriction, objection and portability over your personal data.
Note: for personal data processed during a client engagement, where SECURIX acts as a processor, requests should be addressed to the client (the controller); we will assist them as required by our contract.
To exercise your rights regarding data we control, contact us at hello@securix.hk, or reach our EU representative (Section 6).
You may also lodge a complaint with a supervisory authority — in France, the Commission nationale de l’informatique et des libertés (CNIL).
12. Data Security
We implement technical and organisational measures appropriate to the risk, including:
- A dedicated instance per client — no data tenancy shared between organisations.
- Encryption at rest and encrypted backups.
- Client portal protected by multi-factor authentication and network-level access restrictions. Credentials are stored as irreversible fingerprints.
Detailed security measures are documented and made available to clients and auditors under NDA. As no method of transmission or storage is 100% secure, we implement state-of-the-art measures without guaranteeing absolute security.
13. Children’s Privacy
Our services are not directed to persons under 16 and we do not knowingly collect their data. If you believe a minor has provided us with data, contact us so we can delete it.
14. Changes to This Policy
We may update this policy. Any change is posted on this page with an updated date; material changes are notified appropriately.
15. Contact Us
- By email: hello@securix.hk
- EU representative (Art. 27): see Section 6.