Privacy Policy
1. Who we are
Gravitas is a threat intelligence platform operated by Laneden Ltd, a company registered in England and Wales (company number 12297903), with its registered office at Kemp House, 160 City Road, London, England, EC1V 2NX.
Gravitas monitors breach databases, stealer logs, and dark web sources to help organisations identify compromised credentials, exposed personal data, and stolen information linked to their domains and employees.
For the purposes of UK data protection law, Laneden Ltd is the data controller. Our Data Protection Officer can be contacted at dpo@withgravitas.io.
2. What data we collect
We process two distinct categories of personal data:
A. Customer data
Personal data provided by our platform users and their organisations:
- Name and email address
- Organisation name and role
- Authentication credentials (stored as cryptographic hashes)
- Billing and payment information
- Platform usage data and preferences
- Seed data submitted for monitoring (domains, email addresses, IP addresses)
B. Threat intelligence data
Personal data found in external breach and threat intelligence sources:
- Email addresses and usernames
- Passwords and credential hashes
- Names, phone numbers, and physical addresses (from stealer log autofill data)
- IP addresses and device identifiers
- Browser and software profiles
- Cryptocurrency wallet addresses
This data originates from data breaches, information stealer malware logs, and dark web marketplaces. Gravitas does not cause or contribute to these breaches — we detect and report exposed data to help affected organisations respond.
C. Free exposure scan & enquiries
If you run a free exposure scan on our website, we process the details you submit — your work email, and any optional details you choose to add (name, personal email, work or personal phone number, and location) — together with your IP address. We use these solely to run your one-off scan (searching breach data, open-source intelligence, and data-broker/people-search sources for exposure linked to you) and to generate and deliver your confidential report via a secure one-time link. We do not add these details to our monitoring platform or use them for ongoing monitoring, and we do not sell them.
We retain your scan request and the report we generate only as long as needed to make your report available, and in any case delete them within 7 days. If you request a demo or contact us, we use your name, company and contact details only to respond to your request and arrange a follow-up; these are sent to our team by email and are not stored in our platform.
The lawful basis for this processing is your consent, given when you submit the form. You may withdraw consent, or ask us to delete your scan data, at any time by contacting dpo@withgravitas.io.
3. How we collect it
Customer data
Collected directly from you when you register an account, configure monitoring seeds, use the platform, or communicate with us.
Threat intelligence data
Collected through automated monitoring systems that scan breach databases, dark web forums and marketplaces, stealer log repositories, and paste sites. We also receive data from trusted intelligence-sharing partners and commercial threat intelligence feeds.
4. Lawful basis for processing
Customer data — Contract (Article 6(1)(b) UK GDPR)
We process your account and usage data because it is necessary to perform the contract between your organisation and Laneden Ltd — specifically, to provide the Gravitas platform and its monitoring, alerting, and intelligence services.
Threat intelligence data — Legitimate interests (Article 6(1)(f) UK GDPR)
We process threat intelligence data on the basis of legitimate interests. The specific interests are:
- The legitimate interest of subscribing organisations in knowing that their employees' credentials have been compromised, so they can take protective action
- The broader security interest in identifying credential compromises, malware infections, and data exposures that could lead to further harm if undetected
We have conducted a Legitimate Interest Assessment and concluded that these interests are not overridden by the rights of data subjects, because:
- The data is already exposed through breaches — our processing does not create or increase the exposure
- Data subjects benefit indirectly from this processing, as it helps organisations secure compromised accounts and prevent further misuse
- Access to threat intelligence data is restricted to authorised security personnel within subscribing organisations
- We implement strong technical and organisational safeguards to prevent misuse
Marketing communications — Consent (Article 6(1)(a) UK GDPR)
Where we send marketing communications, we do so only with your explicit opt-in consent. You may withdraw consent at any time.
5. How we use the data
Customer data
- Providing and maintaining the Gravitas platform
- Authenticating users and managing access
- Processing seed data to match against threat intelligence databases
- Generating alerts when compromised credentials or data are detected
- Sending platform notifications and service communications
- Processing billing and payments
Threat intelligence data
- Matching against customer monitoring seeds to identify exposures
- Enriching alerts with service identification, risk scoring, and incident response recommendations
- AI-powered analysis of breach patterns and compromise scope
- Identifying malware campaigns, stealer families, and threat actor patterns
- Generating aggregated, anonymised statistics on breach trends
6. Data sharing
We do not sell personal data. We do not share raw breach data or stealer logs with any third party beyond our platform customers' authorised access to their own matched results.
We use the following categories of sub-processors:
- Database hosting — Neon (PostgreSQL database service)
- Website analytics — Google (Google Analytics 4), used on our public website only, for aggregated visitor statistics. Analytics cookies are set only after you consent via our cookie banner.
- Cloud infrastructure — For platform hosting and data processing
- AI analysis services — For automated domain analysis and enrichment
- Payment processing — For billing and subscription management
All sub-processors are bound by data processing agreements. A current list of sub-processors is available on request by contacting dpo@withgravitas.io.
We may share aggregated, anonymised statistics (such as breach volume trends) that cannot identify any individual.
7. International transfers
Some of our sub-processors are based outside the United Kingdom. Where personal data is transferred outside the UK, we ensure appropriate safeguards are in place, including:
- Transfers to countries with an adequate level of protection as determined by the UK Secretary of State
- International Data Transfer Agreements (UK equivalent of Standard Contractual Clauses)
Details of the safeguards in place for specific transfers are available on request.
8. Data retention
Customer data
We retain your account data for the duration of your organisation's subscription, plus 30 days after termination to allow for account reactivation or data export. After this period, customer data is permanently deleted.
Threat intelligence data
Threat intelligence data is retained for as long as it remains operationally relevant for breach monitoring and threat analysis. Older records may be archived or aggregated over time. Because the purpose of this data is to maintain a comprehensive historical record of credential compromises, indefinite retention is necessary for the service to function effectively.
9. Your rights
Under UK GDPR, you have the following rights regarding your personal data:
- Right of access — Request a copy of the personal data we hold about you
- Right to rectification — Request correction of inaccurate data
- Right to erasure — Request deletion of your data in certain circumstances
- Right to restriction — Request that we limit how we process your data
- Right to data portability — Receive your data in a structured, machine-readable format
- Right to object — Object to processing based on legitimate interests
Important note regarding threat intelligence data: Erasure requests relating to data held in our threat intelligence databases will be assessed on a case-by-case basis. Where we determine that our legitimate interest in maintaining comprehensive breach records overrides the individual's request — for example, where the data serves an ongoing protective purpose for subscribing organisations — we may decline the erasure request in accordance with Article 17(1) UK GDPR. We will always explain our reasoning.
To exercise any of these rights, contact dpo@withgravitas.io. We will respond within 30 days.
10. Cookies
Our platform uses essential cookies for authentication and session management. Our public website additionally uses Google Analytics 4 cookies to understand how visitors use the site; these are set only after you provide consent via our cookie banner, and the resulting data is aggregated. For full details, including how to withdraw consent, see our Cookie Policy.
11. Changes to this policy
We may update this Privacy Policy from time to time. Material changes will be communicated to platform users via email or in-platform notification. The "Last updated" date at the top of this page indicates when the most recent changes were made.
12. Contact and complaints
If you have questions about this Privacy Policy or wish to exercise your data protection rights, contact our Data Protection Officer:
- Email: dpo@withgravitas.io
- Post: Data Protection Officer, Laneden Ltd, Kemp House, 160 City Road, London, EC1V 2NX
You have the right to lodge a complaint with the Information Commissioner's Office (ICO) if you believe your data protection rights have been violated:
- Website: ico.org.uk
- Telephone: 0303 123 1113