Legal
Privacy Policy
Last updated: June 11, 2026
BrokenIntent (“we”, “us”) provides penetration testing and security services. This policy explains what we collect through this website, why, and the choices you have. Client engagements are additionally governed by the contract and NDA for that engagement — where they conflict, the contract wins.
What we collect
- Information you give us. When you request a consult or quote: name, email, company, website, and your message. When you unlock a scan report: email, name, and role.
- Free scan data. The domain you submit, your confirmation that you are authorized to scan it, and the passive findings we generate. Your most recent scan result is also stored locally in your own browser so you can return to it; you can clear it from the scanner at any time.
- Usage data. Product analytics events (pages viewed, scan started, form submitted), device and browser information, and approximate location derived from IP. We use this to understand the conversion funnel and improve the site.
How we use it
- To run the scan you requested and deliver your report.
- To respond to consult and quote requests and schedule calls.
- To send the report email you asked for and relevant follow-up; you can opt out at any time.
- To protect the service — anti-abuse checks, bot detection, and rate limiting.
- To improve the website using aggregate analytics.
We do not sell your personal data, and we do not share scan findings with anyone but you.
Service providers
We use a small set of processors to operate the site, each receiving only what it needs:
- HubSpot — CRM for leads and consult requests
- Resend — transactional email (report delivery, replies)
- Cal.com — consult scheduling
- Slack — internal notification of new requests
- PostHog and Google Analytics — product and traffic analytics
- Cloudflare Turnstile — bot and abuse prevention
- Our hosting and infrastructure providers
Legal bases
Where GDPR or similar laws apply, we process data on the basis of: consent (scan authorization, marketing follow-up), contract (delivering a report or service you requested), and legitimate interest (site security, anti-abuse, aggregate analytics).
Retention
We keep personal data only as long as needed for the purposes above, then delete or anonymize it. Scan results tied to your email are retained so we can reference them if you engage us; you can request deletion at any time. Engagement data is retained per the terms of that engagement.
Your rights
You can request access to, correction of, or deletion of your personal data, and you can withdraw consent or object to processing. Email hello@brokenintent.com and we will respond within 30 days. If you are in the EU/EEA or UK, you may also lodge a complaint with your supervisory authority.
Security
We apply the same discipline to our own systems that we sell: least-privilege access, encryption in transit, and minimal retention. No system is perfectly secure — if we ever discover a breach affecting your data, we will notify you without undue delay.
Changes
We will post any changes to this policy here and update the date above. Material changes will be flagged on the site. Questions: hello@brokenintent.com.