GDPR Compliance Statement
1. Our commitment to data protection
Laneden Ltd (trading as Gravitas) is committed to full compliance with the UK General Data Protection Regulation (UK GDPR) and the Data Protection Act 2018 in all aspects of operating the Gravitas threat intelligence platform.
We recognise that our platform processes sensitive personal data — including data exposed through breaches and malware infections — and we take our data protection responsibilities seriously. Privacy by design and data minimisation are core principles in how we build and operate Gravitas.
2. Data Protection Officer
Our Data Protection Officer can be contacted at:
- Email: dpo@withgravitas.io
- Post: Data Protection Officer, Laneden Ltd, Kemp House, 160 City Road, London, EC1V 2NX
3. ICO registration
Laneden Ltd is registered with the Information Commissioner's Office. Registration number: [ICO_REGISTRATION_NUMBER].
4. Lawful bases for processing
| Processing Activity | Lawful Basis | Details |
|---|---|---|
| Customer account data | Contract (Art. 6(1)(b)) | Necessary to provide the Gravitas platform service |
| Threat intelligence data | Legitimate interests (Art. 6(1)(f)) | Protective purpose: alerting organisations to compromised credentials and exposed data |
| Marketing communications | Consent (Art. 6(1)(a)) | Opt-in only, withdrawable at any time |
| Platform analytics | Legitimate interests (Art. 6(1)(f)) | Service improvement, anonymised where possible |
For full details on our lawful bases, including our Legitimate Interest Assessment for threat intelligence data, see our Privacy Policy.
5. Technical measures
We implement the following technical safeguards to protect personal data:
- Encryption at rest — All databases and storage volumes are encrypted
- Encryption in transit — All communications use TLS 1.2 or higher
- Role-based access controls — Platform access is restricted based on user roles and organisational scope
- Audit logging — All data access and administrative actions are logged
- Hashed seed storage — Monitoring seeds are stored as cryptographic hashes where appropriate
- Secure development practices — Code review, dependency scanning, and security testing are part of our development lifecycle
- Regular security assessments — Periodic review of infrastructure and application security
6. Organisational measures
- Staff training — All team members receive data protection awareness training
- Data Processing Agreements — In place with all sub-processors
- Incident response procedures — Documented processes for identifying, containing, and reporting data breaches
- Data minimisation — We collect and retain only the data necessary for our stated purposes
- Privacy by design — Data protection considerations are integrated into all new features and systems from the design stage
- Acceptable Use Policy — Governing how customers may use threat intelligence data, preventing misuse
7. Data Protection Impact Assessments
We conduct Data Protection Impact Assessments (DPIAs) for processing activities that are likely to result in a high risk to individuals' rights and freedoms. DPIAs have been conducted for:
- Stealer log PII extraction and analysis — Processing personal data (names, addresses, phone numbers) extracted from information stealer malware logs
- AI-powered domain analysis and enrichment — Automated analysis of breach data to identify services, assess risk, and generate recommendations
- Large-scale breach data processing — Indexing and matching billions of breach records against customer monitoring seeds
DPIAs are reviewed and updated when processing activities change materially.
8. Data subject rights
Under UK GDPR, individuals have the right to:
- Access the personal data we hold about them
- Rectification of inaccurate data
- Erasure in certain circumstances
- Restrict processing
- Data portability
- Object to processing based on legitimate interests
- Not be subject to solely automated decision-making that produces legal or significant effects
To exercise any of these rights, email dpo@withgravitas.io. We will respond within 30 days as required by UK GDPR.
9. Breach notification
In the event of a personal data breach, we are committed to:
- Notifying the ICO within 72 hours of becoming aware of a breach that is reportable under UK GDPR
- Notifying affected individuals without undue delay where the breach is likely to result in a high risk to their rights and freedoms
- Notifying affected customers in accordance with our Data Processing Agreement
- Documenting all breaches, including those not meeting the reporting threshold, as required by Article 33(5)
10. Contact
For questions about our data protection practices:
- Data Protection Officer: dpo@withgravitas.io
- Post: Laneden Ltd, Kemp House, 160 City Road, London, EC1V 2NX
To complain to the supervisory authority:
- Information Commissioner's Office: ico.org.uk
- Telephone: 0303 123 1113
- Post: Information Commissioner's Office, Wycliffe House, Water Lane, Wilmslow, Cheshire, SK9 5AF