Privacy notice

Last changed 19 September 2026. This is the version in force. We do not keep earlier versions on the site.

How JustAppSec Limited (we, us, our) collects and uses personal data through the public JustAppSec website. Accounts are not open yet, so this notice covers the contact form, the waitlist and the sample challenge. A fuller notice takes its place once accounts open.

1. Who we are and how to contact us

JustAppSec Limited, a company registered in England and Wales (Company No. 16602827). VAT registration number GB 519 8772 42. Registered office: 4th Floor, 14 Museum Place, Cardiff, CF10 3BH. We are registered with the Information Commissioner's Office under reference ZC068280.

You can reach us about privacy at [email protected], or through our contact page.

2. The contact form

The form asks for your name and your email address, and for your organisation if you choose to give one. Whatever you write in the message is personal data too, if it says anything about you.

We also use the address your browser connects from, to limit how many messages one address can send and to check that a person sent the message.

Our legal basis is our legitimate interest in replying to you, in any business relationship that follows, and in keeping the form free of automated abuse.

3. The waitlist

You can leave your work email and, if you choose, your company name, to hear once when the paid product opens. We rely on your consent, and you can come off the list at any time by writing to [email protected]. The same address limit as the contact form applies, and we send nothing else to that address.

4. The sample challenge

You can try a sample challenge with no account. It runs in your browser, and nothing you flag or score there is stored against you. We record that someone started it and that someone finished it, with no name, address or other identifier attached, and the same address limit as the contact form applies.

5. Cookies

The only cookies here are Cloudflare's, set on every page while it protects the site from bots and other attacks: one for bot management, lasting 30 minutes; one set when a visitor passes a Cloudflare challenge, lasting as long as our Cloudflare setting for the site says; and one that identifies a visitor for rate limiting, lasting for the browser session. The two page view and page speed measurement scripts we run from our own address set no cookie. There are no other cookies and no other measurement.

Nothing we set needs your consent, so there is no cookie banner.

6. Who we share your data with

A small number of providers process personal data on our behalf under contract. Each is named below, with what it does for us, where it processes and a link to its own data processing terms.

ProviderWhat it does for usWhere it processesData processing terms
VercelApplication hosting and the serverless functions the app runs in. It also counts page views and measures page speed: the page, where the visitor came from, country and city, browser and device, and how quickly the page loaded.The serverless functions run in London. Static assets are served from its global network.Vercel data processing addendumVercel Data Privacy Framework statement
NeonThe Postgres database, run by Neon, a Databricks company. While accounts are closed it holds only the rate limits for the contact form, the waitlist and the sample, the waitlist itself, and the record that a sample challenge was started or finished.London, United Kingdom.Databricks data processing addendumDatabricks privacy notice, international transfers
CloudflareDomain name service, the edge in front of the application, and Turnstile bot protection on our forms.See provider terms.Cloudflare customer data processing addendumCloudflare GDPR and Data Privacy Framework page
MicrosoftMicrosoft 365, which we run the company on, including email. It holds our business mail and files, and the messages you send us.See provider terms.Microsoft Products and Services Data Protection AddendumMicrosoft privacy statement, storage and processing of personal data

We also share data where we must, for example to comply with the law.

7. International transfers

Some of the providers above are established outside the United Kingdom. Where we transfer personal data to them, we rely on their own data processing terms, linked above, which carry the United Kingdom's recognised safeguards for the transfer.

8. How long we keep it

We keep a message you send us, and any follow-up, for as long as we are dealing with your enquiry or have a business relationship with you. You can ask us to remove it at any time; section 9 says how. The address behind the rate limit, the waitlist, and the record that a sample challenge was started or finished are kept for no longer than twelve months.

9. Your rights and how to complain

Under UK GDPR, and EU GDPR where it applies, you may ask to access, correct, delete, restrict or port your data, and object to processing based on our legitimate interests. Write to us at [email protected]. You can also complain to the Information Commissioner's Office (ico.org.uk) or, in the European Union, your local supervisory authority.

JustAppSec® is a registered trade mark of JustAppSec Limited (UK00004239907). JustAppSec Limited is registered in England and Wales, Company No. 16602827. VAT registration number GB 519 8772 42. ICO registration ZC068280. Registered office: 4th Floor, 14 Museum Place, Cardiff, CF10 3BH.