Legal
Privacy notice
Last updated 9 September 2026
This notice explains what personal data e1NET collects, why we collect it, who else can see it, and what you can ask us to do with it.
Draft pending legal review. This document describes how e1NET currently operates and has not yet been reviewed by a qualified legal adviser. It is published for transparency, not as a binding agreement. If anything here matters to a decision you are making, please contact us and we will confirm it in writing.
Who we are
e1NET provides a cybersecurity and compliance readiness platform. When you create a workspace, you decide what evidence to upload and which frameworks to work toward, and we process that material to give you a readiness position and a list of gaps.
What we collect
- Account information. Your email address and the identifier issued by our authentication provider when you sign in.
- Organisation information. The organisation name, sector and profile details you enter during setup, such as headcount and where you operate.
- Evidence you upload. The documents you choose to add, and the text extracted from them so they can be assessed.
- Enquiries. If you request a demo or contact us, the name, email address and any other details you enter on that form.
We do not ask for payment card details, government identifiers, or any special category data, and you should not upload documents containing them.
Passwords
e1NET never stores your password. Sign-in is handled by Auth0, and we receive only a token confirming that you authenticated successfully. There is no password field anywhere in this product because there is no password for us to hold.
Who can see your evidence
Your documents and findings belong to your organisation and are not visible to any other organisation using e1NET. Access is scoped to your workspace on every request, not merely hidden in the interface.
Within your organisation, people you invite can see your workspace according to the role you give them. You control that list in your settings.
Automated analysis and third parties
To assess your evidence against a framework, extracted passages from your documents, with the names of the documents they come from, are sent to a third-party language model provider, OpenAI. This is how the platform reads your evidence, and it means your document text leaves our systems for that purpose. Passages are sent for assessment only, and are not used by us to train any model.
We also rely on Auth0 for sign-in, on Microsoft Azure for hosting and storage, and on our email provider to answer demo requests and contact messages.
Demo requests and contact messages
When you submit the demo or contact form, your details are recorded in our systems so a member of the team can respond. We use them to answer your enquiry and for no other purpose. We do not sell them, and we do not add you to a marketing list on the basis of that form.
Keeping your information
We keep your workspace data for as long as your account is open. Documents you withdraw stop counting toward your score immediately. The file and the text read from it stay with your workspace, so your compliance history can still show what each result was based on, and are deleted when your workspace is deleted.
We have not yet finalised fixed retention periods for enquiry records and closed accounts. Rather than state a period we cannot currently guarantee, we will confirm our retention schedule here once it is settled. In the meantime you can ask us to delete your data using the contact details below.
Your rights
Depending on where you are, you may have the right to ask for a copy of your personal data, to have it corrected or deleted, to object to how we use it, or to ask us to restrict its use. You can also complain to your local data protection authority.
To exercise any of these, please contact us and choose the security or general topic.
Changes to this notice
If we change how we handle your data, we will update this page and the date at the top of it.