Privacy notice
Last updated: July 2026
This notice explains how d4vinder Ltd (trading as d4) collects, uses and looks after
your personal data when you visit d4vinder.com, contact us, or use our free tools. We build
privacy in by default: no advertising trackers, no analytics cookies, and no selling of data, ever.
Who we are
d4vinder Ltd is the data controller. We are a company registered in England and Wales (company number 17149864), with our registered office at 352 Bearwood Road, Birmingham, B66 4ET.
For anything about your personal data, contact privacy@d4vinder.com.
The short version
- We only hold personal data you actively give us: a message through our feedback form, or your email address if you subscribe to the Decrypted newsletter or ask for product announcements.
- The newsletter is double opt-in: nothing is sent until you confirm from your own inbox, and every issue has an unsubscribe link.
- Our public tools (the CIDR calculator, DNS lookup, email-security and CVE tools) run in your browser or make lookups on your behalf; we do not keep a record of what you look up.
- We set no tracking cookies. The only cookie is a strictly-necessary session cookie in our admin area, which you never see.
- You can ask us to show, correct or delete your data at any time.
What we collect, why, and our lawful basis
| What |
Why |
Lawful basis |
Website feedback & support Name, email address, message content, page URL, browser user-agent, hashed IP address. |
Receive and respond to feedback and support messages from visitors. |
Legitimate interests |
Product announcement emails (broadcasts) Email address, subscription status. |
Send occasional product announcements to people who asked to receive them. |
Consent |
Administrator account Username, password hash, TOTP secret, login timestamps, hashed IP of attempts. |
Authenticate the site operator and secure the admin area. |
Legitimate interests |
Privacy-preserving analytics Aggregate page counts and salted-hash unique counts. No cookies, no raw IPs, no profiles. |
Understand aggregate traffic without tracking individuals. |
Legitimate interests |
Security & audit logging Admin username, action, affected record, hashed IP, timestamp. |
Keep a record of administrative actions and security events. |
Legal obligation |
Decrypted newsletter Email address, subscription status, sign-up and confirmation timestamps, hashed IP at sign-up and confirmation. |
Email each new Decrypted post to people who subscribed and confirmed (double opt-in). |
Consent |
CVE alerts Email address, subscription status, sign-up and confirmation timestamps, hashed IP at sign-up and confirmation. |
Email people who subscribed and confirmed (double opt-in) a short digest whenever new vulnerabilities are added to CISA's Known Exploited Vulnerabilities catalogue. |
Consent |
File drop The uploaded file and its contents, the filename, an optional note, its MD5 and SHA-256 checksums, the account it came from or was shared with (username and email address), a hashed IP address, and the date and count of any downloads. |
Receive files sent to us by people we have given a drop-box account to, confirm receipt by email, and hand files back to named accounts we have chosen to share them with. |
Legitimate interests |
Ransomware leak tracker Organisation name and website, the claiming group, the claim date, country and sector where given, and a truncated description written by the claiming group. No stolen data, no leak-site addresses, no screenshots. |
Republish, as a public early-warning service, the claims ransomware groups make on their leak sites, as aggregated by third-party threat-intelligence trackers. |
Legitimate interests |
Leak tracker alerts Email address, the watch-list terms the subscriber chose, subscription status and consent timestamps, a one-way salted hash of the IP used at sign-up and confirmation, and a marker of the last claim they were told about. |
Email a subscriber when a ransomware group claims something matching the watch list they gave us. |
Consent |
Where we rely on legitimate interests, we have weighed those against your rights;
you can object at any time (see below). Where we rely on consent (the Decrypted newsletter and announcement emails), you can withdraw it at any time.
The Decrypted newsletter
If you subscribe to Decrypted, our news commentary email, this is exactly what happens:
- Double opt-in. Entering an address only triggers a confirmation email. Nobody is subscribed, and nothing else is ever sent, until the link in that email is used. Unconfirmed sign-ups are deleted automatically after 7 days.
- What we store. Your email address, the subscription status, and the consent evidence: when you signed up, when you confirmed, and a one-way salted hash of the IP addresses used (never the raw IP).
- What we send. One email per newly published Decrypted post, usually a few times a week. No tracking pixels and no per-recipient link tracking; we count how many messages were sent, not who opened them.
- Leaving. Every issue has an unsubscribe link (including one-click unsubscribe in supporting mail apps), and there is a form at /decrypted/unsubscribe/. Withdrawing consent is immediate; the record itself is deleted within 90 days.
Decrypted is the personal opinion of its author. It is general commentary, not professional or security advice.
Sending us a file, and collecting one
If we have given you a username and password for our file drop, this is what happens to what you send,
and to what we share with you:
- What we store. The file itself, its name, any note you add, your sender account (a username and the email address we hold for it), and a one-way salted hash of your IP address (never the raw IP).
- What we use your address for. Only to confirm your uploads, and to contact you about them if we need to. It is never added to any mailing list.
- Who sees it. Only us. Files are stored outside the public website and are never listed or served to anyone visiting the site; they are not sent to any scanning, analysis or cloud storage service.
- Collecting a file we have shared with you. Your account can download the files we have
shared with it by name, and nothing else. We record how many times each one was downloaded and when it was
last downloaded. A link to a shared file only works for the account it belongs to, so forwarding it passes
nothing on. We will never email you a password, and we will never ask you for one.
- We do not scan uploads for viruses. We decided against it because the services that would do it require the file to be shared with the wider security community, which would mean publishing something you sent us privately. Please only send us files you trust.
- How long. A file you send us, and its record, are deleted automatically 30 days after
upload. A file we uploaded ourselves to share with you is kept until we delete it, so it is still there when
you come to collect it. Your account lasts until we remove it, and removing it is immediate.
Leak tracker alerts
The ransomware leak tracker is anonymous to browse: we do not record what anyone
searches for. If you subscribe to alerts, that changes only in the ways you asked for:
- Double opt-in. Entering an address only triggers a confirmation email. Nothing is sent until you use its link, and unconfirmed sign-ups are deleted after 7 days.
- Your watch list. We store the terms you chose because the filter cannot work otherwise. We know it is more revealing than an address on its own, since it usually names your own employer, so it is never shared, never used for anything else, and erased the moment you unsubscribe rather than waiting for a retention sweep.
- What else we keep. Your address, the subscription status and consent timestamps, a one-way salted hash of your IP at sign-up and confirmation, and a marker of the last claim you were told about so you are never told twice.
- Leaving. One click from any alert. The rest of the record goes within 90 days.
What we deliberately do not do
- No advertising or cross-site tracking, no analytics cookies, no fingerprinting.
- We never store your raw IP address. Where an IP is needed for rate-limiting or abuse prevention it is stored only as a one-way salted hash.
- We do not sell, rent or share your data for marketing.
- We do not use automated decision-making or profiling that has legal effects on you.
Who we share it with
We keep the number of processors small and UK/EU-based where we can:
- IONOS: our web and email hosting provider (UK/EU data centres).
- Postmark: sends our transactional emails, the Decrypted newsletter and announcement emails, and keeps a suppression list so unsubscribed addresses stay unsubscribed.
- Cloudflare: protects some of our sites and provides the anti-bot check on our sign-in and the newsletter sign-up form.
Each acts only on our instructions under a data processing agreement. We do not transfer your personal data outside the UK or EEA.
How long we keep it
We keep personal data only as long as we need it, and our systems enforce this automatically:
- Feedback and support messages: anonymised 24 months after the matter is closed.
- Newsletter subscriptions: until you unsubscribe. Unconfirmed sign-ups are deleted after 7 days, and unsubscribed records after 90 days.
- Announcement email list: until you unsubscribe.
- Files sent through the file drop, and the address given with them: 30 days. Files we uploaded ourselves
to share, and files we have shared with somebody, are kept until we delete them.
- Security and audit logs: 24 months.
Your rights
Under UK data protection law you can ask us to: give you a copy of your data (access); correct it (rectification);
delete it (erasure); give you a portable copy; restrict how we use it; or object to our use of it. You will not be
charged, and we will respond within one calendar month.
Make a data request
Complaints
We hope to resolve any concern directly, so please contact us first. You also have the right to complain to the
Information Commissioner's Office (ICO), the UK regulator, at ico.org.uk
or on 0303 123 1113.
Cookies
We use one strictly-necessary cookie, only in our admin area, to keep the operator signed in. There are no other
cookies and nothing that needs a consent banner. See our cookie statement for detail.
Changes
If we change this notice we will update the date above and, for significant changes, tell subscribers by email.