Effective date: August 1, 2026. Last updated: August 1, 2026.
1. Who we are
Security Techx LLC ("we", "us", or "our"), a District of Columbia limited liability company, operates PTM Intelligence and Property Technology Magazine and is the controller of personal information processed through the Platform.
Our address is Security Techx LLC, 2001 L Street N.W., Suite 500, Washington, DC 20036, United States.
For privacy questions and to exercise your rights, contact privacy@securitytechx.com.
We have not appointed a Data Protection Officer. We are not required to appoint one, because we do not carry out large-scale systematic monitoring of individuals and we do not process special category data on a large scale. Privacy matters are handled at the address above.
2. Scope
This policy explains what personal information we collect, how we use it, who we share it with, and the rights available to you. It applies to visitors, registered users, and subscribers, wherever you are located. Where the EU General Data Protection Regulation or the UK GDPR applies to our processing, Sections 5, 7, 9, and 15 carry the additional information those laws require.
3. Information we collect
The lists below reflect the forms and features the Platform operates today.
- Account information: name, email address, organization, role, and credentials you provide when registering.
- Access requests: name, email, company, role, the offering you are interested in, and any message you include when you submit the request-access form.
- Profile claims: name, work email, and role when you claim a company profile, plus the work-email verification record. Claim details are visible to you and to our administrators only.
- Threshold self-assessment: the name, email, and company captured at the assessment gate, together with your answers and the provisional result. Results are private to you and our administrators; they are never published.
- Threshold audit and practitioner enquiries: the contact and company details you submit through the audit scoping and practitioner application forms.
- Watch List nominations: the nominator name, email, relationship, and evidence you submit. Nominator details are never publicly visible.
- Subscription and billing information: plan, transaction records, and limited payment metadata, where paid subscriptions are active. Full card details are collected and processed by our payment provider, Stripe, not by us.
- Commercial profile content: the overlay content (logo, description, media, contact) a verified company representative supplies for display.
- Editorial research data: where our research concerns a named individual, such as a founder or executive, we process information about that person's professional role and public professional activity, drawn from public or licensed sources.
- Device and technical information: IP address, browser type, and server logs generated in operating the Platform.
- Communications: messages, corrections, disputes, and support requests you send us.
- Cookies and similar technologies: as described in our Cookie Policy. The Platform does not currently run third-party analytics; if analytics is enabled, this policy and the Cookie Policy will be updated first.
We do not ask for, and do not knowingly collect, special category data such as health, biometric, or political information.
4. How we use your information
- to provide, operate, and secure the Platform and your account;
- to process subscriptions, payments, and entitlements;
- to respond to enquiries, corrections, and disputes;
- to conduct and publish independent research on companies and the people who lead them;
- to review and improve the Platform and our methodology;
- to send service messages and, where permitted, updates you have opted into;
- to comply with legal obligations and enforce our terms.
5. Legal bases for processing
Where the EU or UK GDPR applies, we rely on the following bases.
| Purpose | Legal basis |
|---|---|
| Creating and maintaining your account, providing the Platform | Performance of a contract, Article 6(1)(b) |
| Processing subscriptions, payments, and entitlements | Performance of a contract, Article 6(1)(b); legal obligation for tax and accounting records, Article 6(1)(c) |
| Responding to access requests, enquiries, corrections, and disputes | Legitimate interests in operating a research publication and answering those who contact us, Article 6(1)(f); performance of a contract where you are a subscriber |
| Profile claims and work-email verification | Legitimate interests in confirming that a person claiming to represent a company is authorized to do so, Article 6(1)(f) |
| Threshold self-assessment, audit scoping, and practitioner enquiries | Your consent where you volunteer the information, Article 6(1)(a); steps taken at your request before entering a contract, Article 6(1)(b) |
| Watch List nominations | Legitimate interests in receiving evidence relevant to editorial research, Article 6(1)(f) |
| Editorial research and publication, including research concerning named individuals in their professional capacity | Legitimate interests in publishing independent research, Article 6(1)(f), and the provisions for processing carried out for journalistic purposes under Article 85 and its national implementations |
| Security, fraud prevention, and service logging | Legitimate interests in keeping the Platform secure, Article 6(1)(f) |
| Marketing messages you have opted into | Your consent, Article 6(1)(a), which you may withdraw at any time |
| Complying with legal obligations, enforcing our terms, and establishing, exercising, or defending legal claims | Legal obligation, Article 6(1)(c); legitimate interests, Article 6(1)(f) |
Where we rely on legitimate interests, we have considered the effect on you and concluded that our interest is not overridden by your rights. You may ask us for a summary of that assessment, and you may object as described in Section 9.
6. How we share information
We do not sell your personal information, and we do not share it for cross-context behavioral advertising. We share it only with:
- Service providers who process data on our behalf under written terms: our hosting and application platform provider (Base44) and our payment provider (Stripe, where paid subscriptions are active). If analytics is later enabled, the analytics provider will be named in the Cookie Policy before it is enabled.
- Professional advisers and authorities where required by law or to protect our rights.
- Successors in the event of a merger, acquisition, or reorganization, subject to this policy.
Commercial and advertising relationships never receive access to editorial scoring or ranking processes, consistent with our editorial firewall.
7. International transfers
We are established in the United States and process personal information there.
Where we transfer personal information from the European Economic Area, the United Kingdom, or Switzerland to a country that has not received an adequacy decision, we rely on the European Commission's Standard Contractual Clauses, together with the UK International Data Transfer Addendum where the UK GDPR applies, and we assess the risks of the transfer. You may request a copy of the relevant safeguards by writing to privacy@securitytechx.com.
8. Data retention
We keep personal information only as long as we need it. Our standard periods are below. Where a longer period is required by law, or where information is needed to establish, exercise, or defend a legal claim, we keep it for that longer period.
| Data | Retention |
|---|---|
| Account records | For the life of the account, then 24 months after closure |
| Access requests, audit scoping, and practitioner enquiries | 24 months from last contact |
| Profile claim records and work-email verification | Duration of the claim, then 24 months, as the record of who was granted authority |
| Threshold self-assessment submissions and results | 24 months from submission, or until you ask us to delete them |
| Watch List nomination records | 36 months, because the nomination supports an editorial decision that may later be questioned |
| Subscription and billing records | 7 years from the end of the relevant tax year, to meet accounting and tax obligations |
| Commercial profile content | Duration of the commercial relationship, then 12 months |
| Server and security logs | 12 months |
| Correspondence, corrections, and disputes | 6 years from resolution, covering the limitation periods that may apply where our users are located |
Published editorial research is retained indefinitely as part of the archival record of the publication. Corrections are recorded alongside it rather than replacing it.
9. Your rights
Depending on where you live, you may have the right to access the personal information we hold about you, to have it corrected, to have it deleted, to restrict or object to how we process it, to receive it in a portable form, and to withdraw a consent you have given. Withdrawing consent does not affect processing carried out before you withdrew it.
To exercise a right, write to privacy@securitytechx.com. We will respond within one month, and we will tell you if we need a further two months because the request is complex. We do not charge for this unless a request is manifestly unfounded or excessive. We may ask you for information to confirm your identity.
We do not make decisions about you that produce legal or similarly significant effects on you based solely on automated processing. PRIME scoring produces findings about companies rather than individuals, and its application in any given case is an editorial judgment made by a person.
If you are in the European Economic Area, the United Kingdom, or Switzerland, you may complain to your national supervisory authority. In the United Kingdom that is the Information Commissioner's Office. We would prefer that you raise the matter with us first so that we can try to resolve it.
10. Security
We use technical and organizational measures designed to protect personal information, including encryption in transit, access restricted on a need-to-know basis, and role-based controls on administrative surfaces. No method of transmission or storage is completely secure, and we cannot guarantee absolute security.
11. Children
The Platform is intended for business and professional users and is not directed to anyone under 18. We do not knowingly collect personal information from anyone under 18. If you believe a child has provided us with personal information, write to privacy@securitytechx.com and we will delete it.
12. Third-party links
The Platform may link to third-party sites with their own privacy practices, for which we are not responsible.
13. United States state privacy rights
Residents of United States states with comprehensive privacy laws may have rights to know what personal information we hold, to have it corrected or deleted, and to receive a copy of it. We do not sell personal information, we do not share it for cross-context behavioral advertising, and we do not use sensitive personal information to infer characteristics. We will not deny you service, charge you a different price, or provide a different level of service because you exercised a privacy right. To make a request, write to privacy@securitytechx.com.
14. Changes to this policy
We may update this policy from time to time. Material changes will be posted with a revised effective date, and where the change materially affects registered users we will notify them by email or by notice in the Platform.
15. Contact and complaints
For privacy questions or requests, contact privacy@securitytechx.com, or write to Security Techx LLC, 2001 L Street N.W., Suite 500, Washington, DC 20036, United States.
