Privacy Policy
Last updated 7 September 2026
Who we are
Netru Ltd (“Netru”, “we”, “us”) provides cybersecurity and compliance consultancy. We are the data controller for personal data collected through netru.io.
Registered office: TODO: registered address. Registered in England and Wales, company number TODO. ICO registration number TODO.
For anything in this policy, including a request to exercise your rights, contact privacy@netru.io.
What we collect, and why
We collect the minimum needed to answer an enquiry and to understand which parts of the site are useful. We do not buy personal data, and we do not sell it.
When you contact us
Our contact form asks for your name, email address, company, the service you are interested in, and your message. That information is sent to our CRM, HubSpot, where it is stored as a contact record with your enquiry attached as a note.
Lawful basis: legitimate interests, so we can respond to an enquiry you chose to send us. Where you ask us to keep you informed about our services, we rely on your consent, and every marketing email carries an unsubscribe link.
When you use the site
We use Google Analytics 4 to count visits and see which pages are read. It records things like the pages you view, roughly where in the world you are, and what kind of device you use. We do not use it to build advertising profiles, and we do not run advertising or session-recording trackers on this site.
Lawful basis: consent for analytics cookies, and legitimate interests for the security and delivery of the site itself.
The free toolkit
The tools in our toolkit are built so that we see as little as possible. This is deliberate, and it is worth being specific about, because “we take your privacy seriously” is not a design.
The password checker never receives your password. Your browser hashes it with SHA-1 and sends only the first five characters of that hash. The service returns every known hash ending with that prefix, around eight hundred of them, and the comparison happens on your device. We cannot reconstruct your password from what we receive, and neither can anyone watching the connection.
The domain, TLS and security-header tools take a domain or URL you type and query it from our server so your own browser and network are not exposed to the target. We use what you submit to produce your result and do not store it against you.
None of the toolkit tools requires an account, and none of them asks for your email before showing a result.
How long we keep it
Enquiries and CRM records: TODO: proposed 24 months from last contact. Analytics: TODO: GA4 default is 14 months. Client engagement records are kept for as long as the engagement requires and then for the period our professional and legal obligations demand.
Your rights
Under UK GDPR you can ask us for a copy of your data, ask us to correct or delete it, object to or restrict how we use it, ask for it in a portable format, and withdraw consent at any time. Exercising these rights is free, and we will respond within one month.
Email privacy@netru.io. If you are unhappy with our response you can complain to the Information Commissioner’s Office at ico.org.uk, though we would rather you gave us the chance to put it right first.
Changes to this policy
We update this policy when what we do changes. The date at the top tells you when it last changed. Material changes will be flagged on this page rather than made quietly.