Last updated: July 2026
This notice explains how d4vinder Ltd (trading as d4) collects, uses and looks after your personal data when you visit d4vinder.com, contact us, or use our free tools. We build privacy in by default: no advertising trackers, no analytics cookies, and no selling of data, ever.
d4vinder Ltd is the data controller. We are a company registered in England and Wales (company number 17149864), with our registered office at 352 Bearwood Road, Birmingham, B66 4ET.
For anything about your personal data, contact privacy@d4vinder.com.
| What | Why | Lawful basis |
|---|---|---|
| Website feedback & support Name, email address, message content, page URL, browser user-agent, hashed IP address. |
Receive and respond to feedback and support messages from visitors. | Legitimate interests |
| Product announcement emails (broadcasts) Email address, subscription status. |
Send occasional product announcements to people who asked to receive them. | Consent |
| Administrator account Username, password hash, TOTP secret, login timestamps, hashed IP of attempts. |
Authenticate the site operator and secure the admin area. | Legitimate interests |
| Privacy-preserving analytics Aggregate page counts and salted-hash unique counts. No cookies, no raw IPs, no profiles. |
Understand aggregate traffic without tracking individuals. | Legitimate interests |
| Security & audit logging Admin username, action, affected record, hashed IP, timestamp. |
Keep a record of administrative actions and security events. | Legal obligation |
| Decrypted newsletter Email address, subscription status, sign-up and confirmation timestamps, hashed IP at sign-up and confirmation. |
Email each new Decrypted post to people who subscribed and confirmed (double opt-in). | Consent |
| CVE alerts Email address, subscription status, sign-up and confirmation timestamps, hashed IP at sign-up and confirmation. |
Email people who subscribed and confirmed (double opt-in) a short digest whenever new vulnerabilities are added to CISA's Known Exploited Vulnerabilities catalogue. | Consent |
Where we rely on legitimate interests, we have weighed those against your rights; you can object at any time (see below). Where we rely on consent (the Decrypted newsletter and announcement emails), you can withdraw it at any time.
If you subscribe to Decrypted, our news commentary email, this is exactly what happens:
Decrypted is the personal opinion of its author. It is general commentary, not professional or security advice.
We keep the number of processors small and UK/EU-based where we can:
Each acts only on our instructions under a data processing agreement. We do not transfer your personal data outside the UK or EEA.
We keep personal data only as long as we need it, and our systems enforce this automatically:
Under UK data protection law you can ask us to: give you a copy of your data (access); correct it (rectification); delete it (erasure); give you a portable copy; restrict how we use it; or object to our use of it. You will not be charged, and we will respond within one calendar month.
We hope to resolve any concern directly, so please contact us first. You also have the right to complain to the Information Commissioner's Office (ICO), the UK regulator, at ico.org.uk or on 0303 123 1113.
We use one strictly-necessary cookie, only in our admin area, to keep the operator signed in. There are no other cookies and nothing that needs a consent banner. See our cookie statement for detail.
If we change this notice we will update the date above and, for significant changes, tell subscribers by email.