Legal

Privacy Policy

What personal data VillainStrike collects, why, and the rights you have over it. Last updated 13 August 2026.

VillainStrike ("we", "us") is a cybersecurity company based in Lisbon, Portugal. We process personal data in accordance with the EU General Data Protection Regulation (GDPR).

What we collect

When you submit our contact or audit-request form, we collect what you choose to provide: company name, website URL, contact person, business email, organisation size and your description of the security challenge. We do not ask for special categories of personal data. Our server may record standard technical log data such as IP address for security and reliability. We do not use advertising trackers or profiling analytics.

Cookies and similar technologies

This website sets no cookies of its own. We use no advertising cookies, no cross-site trackers, no remarketing pixels and no analytics that build a profile of you. Nothing on these pages follows you to another website.

Our hosting and content-delivery provider may set a single strictly necessary cookie to tell genuine visitors apart from automated traffic and protect the site from abuse. It carries no advertising identifier and is not used to profile you or to measure campaigns.

Because we set no optional cookies, there is nothing for you to consent to and you will not see a cookie banner. Blocking cookies in your browser will not stop you reading any page or submitting the contact form.

Why we use it

  • To respond to your enquiry and prepare a proposal where relevant.
  • To communicate with you about an engagement you have requested.
  • To keep our systems secure and meet legal obligations.

Our lawful bases are your consent, our legitimate interest in responding to enquiries, and — once you are a client — performance of a contract.

How long we keep it

We keep enquiry data only as long as needed to respond and maintain a record, after which it is deleted or anonymised. Engagement data is retained for the period our contractual and legal obligations require.

Who we share it with

We do not sell your data. We share it only with trusted service providers that help us operate (such as email and hosting), under appropriate agreements, and where required by law. Engagement findings are strictly confidential.

Where it is processed

We are EU-based and prefer EU processing. Where a provider operates outside the EU, we rely on safeguards recognised under the GDPR.

Your rights

You may access, correct, delete or restrict processing of your data, object to processing, and request portability. You may also complain to the Portuguese supervisory authority (CNPD).

Contact

To exercise any right, contact [email protected] or write to Avenida da Liberdade 110, 1250-146 Lisboa, Portugal.

We may update this policy. The date above shows the last revision.