Privacy Policy
What personal data Pental holds, what it does not, and how the fact that your engagement data lives in your own database changes the answer.
This policy explains how Pental Limited collects, uses and shares personal data when you visit pental.io, register an account, subscribe to the Platform, or use a portal a Pental customer hosts. It is written to meet the UK GDPR and the Data Protection Act 2018, the EU GDPR, and equivalent frameworks elsewhere.
Every Pental customer runs on a Postgres project they create in their own hosting account. Client records, assessments, findings, evidence, reports and credentials are written there, not to our systems. For that data we are not the custodian, and in most cases not a processor of it either. What we hold about you is listed in full below and it is short.
Who we are
Pental Limited is registered in England and Wales (company number 17172077) at 167-169 Great Portland Street, 5th Floor, London, W1W 5PF. For privacy enquiries or data subject requests, email hello@pental.io.
Controller or processor
| Data | Our role |
|---|---|
| Account, billing, support and marketing data we collect directly | Controller. We decide why and how it is processed. |
| Engagement data in a customer's own database | Neither custodian nor host. It resides in the customer's infrastructure account. Where a narrow operational function requires us to act on it, we act as processor on that customer's instructions. |
| Personal data of a firm's own clients and portal users | The firm is the controller. We are not, and we have no independent relationship with those individuals. |
If you are an End Client using a portal operated by a testing firm, that firm controls your data. Your requests should go to them; we will support them in responding.
What we collect as controller
- Account. Name, work email address, company name, and the role you hold on the account.
- Subscription. Plan, term, status, renewal dates and plan limits.
- Billing. A customer reference held with our payment processor, together with the billing address and tax details you supply. We never see or store full card numbers.
- Domain routing. The subdomain or custom domain you use, and its DNS status, so requests reach your portal.
- Correspondence. What you send us by email or through the contact form, and our replies.
- Plan usage. Two numbers and a date: how many internal users and how many client records exist in your Platform instance, and when they were last counted. Not who they are, not what they are called, not what they contain.
- Website telemetry. Standard server logs for pental.io, including IP address, user agent and requested path, used for security and diagnostics.
Your clients, your assessments, your findings, your evidence, your reports, your templates and any credentials you collect. None of it reaches our systems in the ordinary course of using the Platform, because the Platform reads and writes it in your database. The plan usage figures above are counts of rows and nothing else: knowing that you have forty client records tells us nothing about who those clients are.
Why we process it, and on what basis
| Purpose | Lawful basis |
|---|---|
| Providing the Platform and supporting your account | Performance of a contract |
| Checking that use of the Platform stays within the plan you pay for | Performance of a contract |
| Taking payment and keeping financial records | Contract, and legal obligation for records |
| Sending service messages about your subscription, security or the Platform | Contract, and our legitimate interest in operating the service |
| Protecting the service against abuse, fraud and automated attack | Legitimate interest in security |
| Marketing emails to prospects who ask for them | Consent, withdrawable at any time |
Sub-processors and third parties
These are the third parties involved in running Pental. Each is engaged under terms requiring appropriate safeguards.
| Provider | Purpose | What it sees |
|---|---|---|
| Vercel | Hosting for pental.io and the application layer | Request telemetry, not your engagement data |
| Supabase | Postgres for your own project, in your account, and for our own account records | Your database, under your account and your control |
| Stripe | Payments and subscription billing | Billing identity and payment details |
| Google reCAPTCHA | Abuse protection on public forms | Signals from the form submission |
If you configure an AI provider or an email relay, those are your arrangements, made on your keys and governed by your agreement with that provider. They are not our sub-processors, and the traffic does not pass through us.
International transfers
Your Postgres project sits in the region you chose when you created it. Our own account records are held in the UK or EEA. Where a provider processes data outside the UK or EEA, transfers rely on adequacy decisions or on standard contractual clauses with supplementary measures.
Retention
- Account and subscription records: for the life of the account, then up to 12 months.
- Financial records: six years, as required by UK tax law.
- Support correspondence: up to 24 months.
- Plan usage figures: the latest count only. Each report overwrites the one before it, so there is no history to keep, and the figures are deleted with the account.
- Server logs: up to 90 days.
- Marketing consent records: until consent is withdrawn, plus a suppression record so we do not contact you again.
- Your engagement data: retained by you, in your database, on whatever schedule you set. We cannot delete it and do not hold a copy.
Security
Measures we apply to the systems we do operate, and that the Platform applies inside your database:
- TLS 1.2 or higher on every endpoint, with certificates issued and renewed automatically.
- Row-level security policies evaluated by Postgres on every query against your data.
- Multi-factor authentication required before the portal opens, with data access gated on a recent second-factor check rather than on enrolment alone.
- Secrets such as mail credentials and provider API keys encrypted on write inside your own database, using a key generated in that same database, with the plaintext column nulled.
- Passwords hashed, never encrypted or stored recoverably; reset tokens stored only as hashes and single use.
- Least privilege on internal access, and multi-factor authentication on Pental staff accounts.
- A documented incident response procedure, and periodic review of the Platform by the people who wrote it, who test systems of this kind professionally.
No system is perfectly secure and we do not claim otherwise. What we can say precisely is which data would be exposed by a compromise of our systems, and the answer is the account list above.
Your rights
Where we are the controller you may request access, rectification, erasure, restriction, portability, or object to processing based on legitimate interests, and withdraw consent to marketing at any time. Email hello@pental.io and we will respond within one month.
You may complain to the Information Commissioner's Office (ico.org.uk) or your local supervisory authority. We would rather you told us first.
Cookies
pental.io sets a small number of cookies and local storage entries, all functional. They are listed in the Cookie Policy.
Children
The Platform is a business tool sold to companies and is not directed at children. We do not knowingly collect personal data from anyone under 16.
Changes
We may update this policy. Material changes will be notified by email or in the Platform before they take effect, and the date at the top of this page always reflects the current version.
Pental Limited, 167-169 Great Portland Street, 5th Floor, London, W1W 5PF. Registered in England and Wales, company number 17172077.
Questions about this document go to hello@pental.io. We answer them ourselves.