EGKETOS GateKeeper

Legal

Privacy Policy

What we collect, why we hold it, how long we keep it, and how to exercise your rights.

Last updated 3 September 2026

1. Who we are

ETOS GateKeeper (“ETOS”, “we”, “us”) operates this website and the ETOS GateKeeper decision-assurance platform. For enquiries about this policy or about personal data we hold, contact Demo@etosgatekeeper.com.

2. Data we collect

Contact and enquiry data: name, organisation, work email, role and the content of your message when you request a demonstration, an enterprise evaluation or agent assurance access.

Access-screening data: the organisation you declare, declared turnover, and the outcome of the eligibility assessment.

Account data: email address, authentication identifiers and account status where an account is approved.

Platform usage data: assurance submissions, evidence references and determination outputs associated with your organisation.

Payment data: order reference, package, amount and payment status. Card details are entered with our payment provider and are never received or stored by ETOS.

Technical data: aggregate page and event analytics used to understand which parts of the site are used. We do not use advertising trackers.

3. Why we use it

To assess and administer access requests, and to operate accounts we approve.

To deliver governed assurance outputs and to keep the evidence trail those outputs depend on.

To process payments for assurance credits and to meet accounting obligations.

To respond to enquiries and to improve the site and platform.

4. Legal bases

We rely on legitimate interests for assessing enterprise access requests, operating the platform securely and improving our service; on contract performance for delivering purchased assurance and account access; and on legal obligation for financial and record-keeping duties. Where we rely on consent, you may withdraw it at any time.

5. Sharing

We share personal data only with processors who help us run the service: cloud hosting and database infrastructure, transactional email delivery, and payment processing. Each acts on our instructions. We do not sell personal data. A current subprocessor list is available on request.

6. Retention

Enquiries and unsuccessful access requests are retained while they remain commercially relevant and then deleted. Account, assurance and payment records are retained for the duration of the relationship and for the period required to evidence a decision that has been relied upon or to satisfy legal obligations. Specific periods are agreed per engagement.

7. Security

Traffic is served over TLS. Application data is protected by row-level authorisation, administrative records are reachable only through validated server-side functions, and integration credentials are stored encrypted and never returned to the browser. Further detail is on our Trust & Security page.

8. Your rights

Subject to applicable law you may request access to your personal data, correction, deletion, restriction, portability, or object to processing based on legitimate interests. Write to Demo@etosgatekeeper.com and we will respond within one month. If you are in the UK or EU and are not satisfied, you may complain to your supervisory authority.

9. International transfers

Where data is processed outside your region, we use providers that offer recognised transfer safeguards. Residency requirements for an engagement can be confirmed before onboarding.

10. Changes

We will update this policy when our processing changes and will revise the date shown below.