Privacy Policy

Last updated: 6 April 2026
Contents
  1. Who we are
  2. What data we collect
  3. How we collect it
  4. Lawful basis for processing
  5. How we use the data
  6. Data sharing
  7. International transfers
  8. Data retention
  9. Your rights
  10. Cookies
  11. Changes to this policy
  12. Contact and complaints

1. Who we are

Gravitas is a threat intelligence platform operated by Laneden Ltd, a company registered in England and Wales (company number 12297903), with its registered office at Kemp House, 160 City Road, London, England, EC1V 2NX.

Gravitas monitors breach databases, stealer logs, and dark web sources to help organisations identify compromised credentials, exposed personal data, and stolen information linked to their domains and employees.

For the purposes of UK data protection law, Laneden Ltd is the data controller. Our Data Protection Officer can be contacted at dpo@withgravitas.io.

2. What data we collect

We process two distinct categories of personal data:

A. Customer data

Personal data provided by our platform users and their organisations:

B. Threat intelligence data

Personal data found in external breach and threat intelligence sources:

This data originates from data breaches, information stealer malware logs, and dark web marketplaces. Gravitas does not cause or contribute to these breaches — we detect and report exposed data to help affected organisations respond.

C. Free exposure scan & enquiries

If you run a free exposure scan on our website, we process the details you submit — your work email, and any optional details you choose to add (name, personal email, work or personal phone number, and location) — together with your IP address. We use these solely to run your one-off scan (searching breach data, open-source intelligence, and data-broker/people-search sources for exposure linked to you) and to generate and deliver your confidential report via a secure one-time link. We do not add these details to our monitoring platform or use them for ongoing monitoring, and we do not sell them.

We retain your scan request and the report we generate only as long as needed to make your report available, and in any case delete them within 7 days. If you request a demo or contact us, we use your name, company and contact details only to respond to your request and arrange a follow-up; these are sent to our team by email and are not stored in our platform.

The lawful basis for this processing is your consent, given when you submit the form. You may withdraw consent, or ask us to delete your scan data, at any time by contacting dpo@withgravitas.io.

3. How we collect it

Customer data

Collected directly from you when you register an account, configure monitoring seeds, use the platform, or communicate with us.

Threat intelligence data

Collected through automated monitoring systems that scan breach databases, dark web forums and marketplaces, stealer log repositories, and paste sites. We also receive data from trusted intelligence-sharing partners and commercial threat intelligence feeds.

4. Lawful basis for processing

Customer data — Contract (Article 6(1)(b) UK GDPR)

We process your account and usage data because it is necessary to perform the contract between your organisation and Laneden Ltd — specifically, to provide the Gravitas platform and its monitoring, alerting, and intelligence services.

Threat intelligence data — Legitimate interests (Article 6(1)(f) UK GDPR)

We process threat intelligence data on the basis of legitimate interests. The specific interests are:

We have conducted a Legitimate Interest Assessment and concluded that these interests are not overridden by the rights of data subjects, because:

Marketing communications — Consent (Article 6(1)(a) UK GDPR)

Where we send marketing communications, we do so only with your explicit opt-in consent. You may withdraw consent at any time.

5. How we use the data

Customer data

Threat intelligence data

6. Data sharing

We do not sell personal data. We do not share raw breach data or stealer logs with any third party beyond our platform customers' authorised access to their own matched results.

We use the following categories of sub-processors:

All sub-processors are bound by data processing agreements. A current list of sub-processors is available on request by contacting dpo@withgravitas.io.

We may share aggregated, anonymised statistics (such as breach volume trends) that cannot identify any individual.

7. International transfers

Some of our sub-processors are based outside the United Kingdom. Where personal data is transferred outside the UK, we ensure appropriate safeguards are in place, including:

Details of the safeguards in place for specific transfers are available on request.

8. Data retention

Customer data

We retain your account data for the duration of your organisation's subscription, plus 30 days after termination to allow for account reactivation or data export. After this period, customer data is permanently deleted.

Threat intelligence data

Threat intelligence data is retained for as long as it remains operationally relevant for breach monitoring and threat analysis. Older records may be archived or aggregated over time. Because the purpose of this data is to maintain a comprehensive historical record of credential compromises, indefinite retention is necessary for the service to function effectively.

9. Your rights

Under UK GDPR, you have the following rights regarding your personal data:

Important note regarding threat intelligence data: Erasure requests relating to data held in our threat intelligence databases will be assessed on a case-by-case basis. Where we determine that our legitimate interest in maintaining comprehensive breach records overrides the individual's request — for example, where the data serves an ongoing protective purpose for subscribing organisations — we may decline the erasure request in accordance with Article 17(1) UK GDPR. We will always explain our reasoning.

To exercise any of these rights, contact dpo@withgravitas.io. We will respond within 30 days.

10. Cookies

Our platform uses essential cookies for authentication and session management. Our public website additionally uses Google Analytics 4 cookies to understand how visitors use the site; these are set only after you provide consent via our cookie banner, and the resulting data is aggregated. For full details, including how to withdraw consent, see our Cookie Policy.

11. Changes to this policy

We may update this Privacy Policy from time to time. Material changes will be communicated to platform users via email or in-platform notification. The "Last updated" date at the top of this page indicates when the most recent changes were made.

12. Contact and complaints

If you have questions about this Privacy Policy or wish to exercise your data protection rights, contact our Data Protection Officer:

You have the right to lodge a complaint with the Information Commissioner's Office (ICO) if you believe your data protection rights have been violated: