Privacy Policy
Introduction
Matthews Digital Ltd ('we', 'us', 'our') operates secreview.io. This Privacy Policy explains how we collect, use, and protect your personal data when you visit our website. We are committed to protecting your privacy and handling your data in an open and transparent manner.
Data Controller
The data controller is Matthews Digital Ltd. You can contact us at privacy@secreview.io with any questions or requests relating to your personal data.
What Data We Collect
We may collect the following categories of personal data when you use secreview.io:
- Email address (when you register for our waitlist)
- Usage data (cookies, page views, time spent on site)
- Technical data (IP address, browser type, device information, operating system)
How We Use Your Data
We use the personal data we collect for the following purposes:
- To process and manage waitlist registrations
- To improve our website and user experience
- To communicate with you about our services and product updates
- To comply with our legal and regulatory obligations
- To protect the security and integrity of our website
Legal Basis for Processing (GDPR)
We process your personal data on the following legal bases under the UK GDPR and EU GDPR:
- Consent — when you join our waitlist, you consent to us processing your email address for that purpose
- Legitimate interests — for website improvement, security monitoring, and fraud prevention
- Legal obligation — where we are required to process data to comply with applicable laws and regulations
Data Sharing
We do not sell, rent, or trade your personal data to third parties. We may share your data with trusted service providers who assist us in operating our website and services:
- Vercel — our hosting provider, who processes data on our behalf under a Data Processing Agreement
- Email service provider — to be configured; will be used for waitlist communications
All third-party processors are required to handle your data securely and in accordance with applicable data protection law.
Data Retention
We retain your personal data for as long as necessary to fulfil the purposes described in this policy:
- Waitlist registration data is retained until the product launches or until you request deletion, whichever is earlier
- Usage and technical data is retained for up to 26 months
Your Rights (GDPR)
Under UK and EU GDPR, you have the following rights in relation to your personal data:
- Right of access — to obtain a copy of the personal data we hold about you
- Right to rectification — to have inaccurate data corrected
- Right to erasure — to request deletion of your personal data in certain circumstances
- Right to restriction — to restrict how we process your data in certain circumstances
- Right to data portability — to receive your data in a structured, machine-readable format
- Right to object — to object to processing based on legitimate interests
To exercise any of these rights, please contact us at privacy@secreview.io. We will respond to your request within 30 days.
Cookies
secreview.io uses essential cookies only. Cookie consent preferences are stored locally in your browser. We do not use third-party tracking cookies or advertising cookies in version 1 of this website. Essential cookies may be used to maintain session state and security functionality.
Security
We take the security of your personal data seriously. We use industry-standard security measures including:
- Encryption in transit via HTTPS (TLS)
- Strict Content Security Policy (CSP) headers to prevent cross-site scripting
- Regular security reviews of our infrastructure and codebase
Changes to This Policy
We may update this Privacy Policy from time to time to reflect changes in our practices, technology, or legal requirements. We will update the effective date below when changes are made. We encourage you to review this policy periodically.
Contact
If you have any questions about this Privacy Policy or how we handle your personal data, please contact:
Matthews Digital Ltd
Email: privacy@secreview.io
Effective date: March 2026