Privacy notice

Last updated: July 2026

This notice explains how d4vinder Ltd (trading as d4) collects, uses and looks after your personal data when you visit d4vinder.com, contact us, or use our free tools. We build privacy in by default: no advertising trackers, no analytics cookies, and no selling of data, ever.

Who we are

d4vinder Ltd is the data controller. We are a company registered in England and Wales (company number 17149864), with our registered office at 352 Bearwood Road, Birmingham, B66 4ET.

For anything about your personal data, contact privacy@d4vinder.com.

The short version

What we collect, why, and our lawful basis

What Why Lawful basis
Website feedback & support
Name, email address, message content, page URL, browser user-agent, hashed IP address.
Receive and respond to feedback and support messages from visitors. Legitimate interests
Product announcement emails (broadcasts)
Email address, subscription status.
Send occasional product announcements to people who asked to receive them. Consent
Administrator account
Username, password hash, TOTP secret, login timestamps, hashed IP of attempts.
Authenticate the site operator and secure the admin area. Legitimate interests
Privacy-preserving analytics
Aggregate page counts and salted-hash unique counts. No cookies, no raw IPs, no profiles.
Understand aggregate traffic without tracking individuals. Legitimate interests
Security & audit logging
Admin username, action, affected record, hashed IP, timestamp.
Keep a record of administrative actions and security events. Legal obligation
Decrypted newsletter
Email address, subscription status, sign-up and confirmation timestamps, hashed IP at sign-up and confirmation.
Email each new Decrypted post to people who subscribed and confirmed (double opt-in). Consent
CVE alerts
Email address, subscription status, sign-up and confirmation timestamps, hashed IP at sign-up and confirmation.
Email people who subscribed and confirmed (double opt-in) a short digest whenever new vulnerabilities are added to CISA's Known Exploited Vulnerabilities catalogue. Consent
File drop
The uploaded file and its contents, the filename, an optional note, its MD5 and SHA-256 checksums, the account it came from or was shared with (username and email address), a hashed IP address, and the date and count of any downloads.
Receive files sent to us by people we have given a drop-box account to, confirm receipt by email, and hand files back to named accounts we have chosen to share them with. Legitimate interests
Ransomware leak tracker
Organisation name and website, the claiming group, the claim date, country and sector where given, and a truncated description written by the claiming group. No stolen data, no leak-site addresses, no screenshots.
Republish, as a public early-warning service, the claims ransomware groups make on their leak sites, as aggregated by third-party threat-intelligence trackers. Legitimate interests
Leak tracker alerts
Email address, the watch-list terms the subscriber chose, subscription status and consent timestamps, a one-way salted hash of the IP used at sign-up and confirmation, and a marker of the last claim they were told about.
Email a subscriber when a ransomware group claims something matching the watch list they gave us. Consent

Where we rely on legitimate interests, we have weighed those against your rights; you can object at any time (see below). Where we rely on consent (the Decrypted newsletter and announcement emails), you can withdraw it at any time.

The Decrypted newsletter

If you subscribe to Decrypted, our news commentary email, this is exactly what happens:

Decrypted is the personal opinion of its author. It is general commentary, not professional or security advice.

Sending us a file, and collecting one

If we have given you a username and password for our file drop, this is what happens to what you send, and to what we share with you:

Leak tracker alerts

The ransomware leak tracker is anonymous to browse: we do not record what anyone searches for. If you subscribe to alerts, that changes only in the ways you asked for:

What we deliberately do not do

Who we share it with

We keep the number of processors small and UK/EU-based where we can:

Each acts only on our instructions under a data processing agreement. We do not transfer your personal data outside the UK or EEA.

How long we keep it

We keep personal data only as long as we need it, and our systems enforce this automatically:

Your rights

Under UK data protection law you can ask us to: give you a copy of your data (access); correct it (rectification); delete it (erasure); give you a portable copy; restrict how we use it; or object to our use of it. You will not be charged, and we will respond within one calendar month.

Make a data request

Complaints

We hope to resolve any concern directly, so please contact us first. You also have the right to complain to the Information Commissioner's Office (ICO), the UK regulator, at ico.org.uk or on 0303 123 1113.

Cookies

We use one strictly-necessary cookie, only in our admin area, to keep the operator signed in. There are no other cookies and nothing that needs a consent banner. See our cookie statement for detail.

Changes

If we change this notice we will update the date above and, for significant changes, tell subscribers by email.