Applicable Jurisdictions: United Kingdom • European Union
Effective Date: 10th February 2025
Last Updated: 20th August 2026
This version of the Privacy Policy applies exclusively to users located in the United Kingdom and European Union. If you are located elsewhere, a different regional version of this Policy may apply; contact customer-support@unscammed.com for the applicable version.
1. Introduction
Unscammed AI LLC (“Company,” “we,” “our,” or “us”) is committed to protecting your privacy. This Privacy Policy describes how we collect, use, disclose, and safeguard your personal information when you interact with our website, services, and cybersecurity solutions.
We comply with applicable privacy laws, including the UK General Data Protection Regulation (UK GDPR) and the EU General Data Protection Regulation (GDPR).
We obtain your consent before or at the time of collecting personal information, except where otherwise permitted by law. Where we rely on implied consent, we do so only for non-sensitive information collected for an obvious purpose. For sensitive information (such as financial data), we obtain your express consent.
If you do not agree with our policies and practices, please do not use our services.
2. Information We Collect
We may collect different types of personal information, including:
A. Personal Information (Directly Provided by You)
We collect information when you:
- Register for an account.
- Contact us for support or inquiries.
- Subscribe to our newsletters or security updates.
- Purchase our cybersecurity services.
This may include:
- Name, email address, phone number.
- Company name, job title, business contact details.
- Payment and billing information, bank account details (e.g., credit card details, billing address).
B. Technical & Security Information (Automatically Collected)
When you use our services, we collect:
- IP Address & Device Data: Browser type, operating system, device ID.
- Log Files & Security Events: Records of login attempts, threat detections, and system interactions.
- Cybersecurity Threat Intelligence: Detected malware, phishing attempts, or unauthorized access attempts.
C. Cookies & Tracking Technologies
We use cookies, tracking pixels, and analytics tools to enhance user experience and security. These help us detect suspicious activity, prevent fraud, and analyze service performance.
In accordance with the UK Privacy and Electronic Communications Regulations (PECR) and the EU ePrivacy Directive, we obtain your prior, informed consent before activating any non-essential cookies or tracking technologies. You may withdraw consent at any time through our cookie preference centre or your browser settings. Essential cookies necessary for the operation of our services do not require consent.
D. Business Plan Personnel Information
Where a business or other organization enrolls you in the Services under a Business Plan (see our Terms of Service), we collect the following information about you from that organization:
- Name and email address.
- Employer or organization name, and role or department, where provided.
- Training, simulation, and phishing-awareness participation and completion records.
3. How We Use Your Information
We use collected information only for the purposes identified at the time of collection, or for a purpose that a reasonable person would consider appropriate in the circumstances. Purposes include:
A. Service Delivery & Security Operations
- Provide and improve our cybersecurity services.
- Monitor, detect, and mitigate security threats i.e. running search scans on matching data-broker sites, breach corpuses and dark web sources, generating alerts, and submitting broker removal requests, carried out in partnership with Array for dark web monitoring, data broker removal, and breach scanning. These services are available to users in all supported regions.
- Authenticate user access and enforce security controls.
- Liaise with external entities whether Public or Private to achieve resolution.
B. Communication & Customer Support
- Respond to inquiries, troubleshoot issues, and provide technical support.
- Send security alerts, service updates, and important notices.
C. Compliance & Legal Obligations
- Investigate and prevent fraud, cyber threats, and security breaches.
- Comply with legal, regulatory, and law enforcement requirements under applicable laws in the United Kingdom and European Union and other jurisdictions.
- Enforce our Terms of Service and other policies.
D. Business & Service Improvement
- Analyze website and service performance.
- Conduct research and improve cybersecurity solutions.
- Develop new features and security enhancements.
E. Cybersecurity Operations & Risk Management
- Provide penetration testing, threat detection, and security monitoring.
- Investigate cyber threats, unauthorized access, and fraud.
- Improve our cybersecurity products and response strategies.
F. Business Plan Training & Reporting
- Deliver scam-awareness training, simulations, and related educational content to personnel enrolled under a Business Plan.
- Provide the Business Customer’s designated administrator(s) with aggregate or individual training completion, participation, and simulation results.
- Administer enrollment, seats, and billing for the Business Plan.
4. Sharing & Disclosure of Information
We do not sell or rent personal information. However, we may share data with:
A. Service Providers & Partners
We use third-party vendors to support our operations, such as:
- Cloud Hosting & Storage: Secure data centres (e.g., AWS, Google Cloud).
- Payment Processors: Secure payment transactions.
- Analytics Providers: To monitor and improve service performance.
- Dark Web Monitoring, Data Broker Removal & Breach Scanning Partner (Array): Array, an independent third-party provider, performs dark web monitoring, data broker removal, and breach scanning services on our behalf. These services are available to users in all supported regions.
All third-party service providers are bound by contractual obligations to protect personal information and use it only for the purposes for which it was disclosed.
B. Legal & Security Compliance
We may disclose personal information if required by law, such as:
- Responding to lawful government requests, subpoenas, or court orders.
- Investigating cybersecurity threats or preventing fraudulent activities.
C. Public and Private Entities
We will use the information provided to liaise with public and private entities, such as:
- Reporting cases to Action Fraud (UK), Europol, national police services, and other government bodies to support in retrieval of funds.
- Liaising with banks on your behalf to report, progress, and expedite case resolution.
- For detecting, monitoring and removing data from the public database including but not limited to data-broker sites, and dark web sources.
D. Cross-Border Transfers
Your personal information may be transferred to, and processed in, countries outside the UK and European Economic Area, including the United States, where data protection laws may differ. Where required, we rely on appropriate safeguards such as Standard Contractual Clauses (SCCs) or an applicable adequacy decision to protect such transfers. You may contact our Privacy Officer for information about our cross-border transfer safeguards.
E. Business Transfers
In case of a merger, acquisition, or sale of assets, personal data may be transferred to the new entity. We will notify you of any such transfer and any material changes to this Privacy Policy.
F. Business Plan Administrators
Where you are enrolled in the Services under a Business Plan, we share your training completion, participation, and simulation results with the enrolling organization’s designated administrator(s). The organization that enrolled you (not the Company) is responsible for obtaining any consents, providing any notices, and satisfying any other requirements under applicable employment and privacy law before providing us with your personal information or enrolling you in the Services. Where applicable law characterizes us as a processor or service provider with respect to that personal information, we process it only as instructed by the organization and in accordance with our agreement with that organization.
5. Your Privacy Rights
A. Rights Under the UK GDPR and EU GDPR
If you are located in the UK or EU, you have the right to:
✔ Right of Access – Request access to the personal data we hold about you.
✔ Right to Rectification – Request correction of inaccurate or incomplete personal data.
✔ Right to Erasure – Request deletion of your personal data, subject to certain exceptions.
✔ Right to Restrict Processing – Request that we limit how we use your personal data in certain circumstances.
✔ Right to Data Portability – Request that your personal data be provided to you, or transmitted to another controller, in a structured, commonly used format.
✔ Right to Object – Object to processing based on legitimate interests, including for direct marketing.
✔ Rights Related to Automated Decision-Making – Request human review of decisions made solely by automated means that produce legal or similarly significant effects.
✔ Right to Lodge a Complaint – File a complaint with the Information Commissioner’s Office (ICO) at www.ico.org.uk (UK residents), or with the supervisory authority in your EU member state of residence.
To make a request, email us at customer-support@unscammed.com. We will verify your identity before processing requests. Please mention the applicable law in your subject line (e.g., “Access Request” or “Portability Request”).
6. Data Security Measures
We implement industry-standard security measures to protect personal information:
-Encryption: Data is encrypted both in transit and at rest.
-Access Controls: Multi-factor authentication (MFA) and role-based access control (RBAC).
-Passwordless Authentication: We do not create or store passwords. Access to your account is authenticated using a single-use, time-limited one-time passcode (OTP) sent to your registered email address at each login.
-Threat Monitoring: Continuous security monitoring and intrusion detection systems.
-Security Audits: Regular audits and compliance checks.
Despite these efforts, no system is completely secure. We encourage users to keep their registered email account secure and to follow cybersecurity best practices.
7. Privacy Breach Notification
In the event of a privacy breach that creates a real risk of significant harm to individuals, we will:
- Notify the Information Commissioner’s Office (ICO), or the relevant EU supervisory authority, without undue delay and, where feasible, within 72 hours of becoming aware of the breach, in accordance with the UK GDPR and EU GDPR.
- Notify affected individuals without undue delay where the breach is likely to result in a high risk to their rights and freedoms.
- Maintain a record of all privacy breaches for a minimum of 24 months.
8. Retention of Data
We retain personal information only as long as necessary for the purposes identified in this policy, to fulfil legal or regulatory obligations, or to resolve disputes. Retention periods are determined based on the nature of the information and the purpose for which it was collected. When personal information is no longer required, it will be anonymized or securely deleted.
You may contact our Privacy Officer to inquire about the specific retention period applicable to your information.
9. Third-Party Links & Services
Our website may contain links to third-party services. We are not responsible for their privacy practices. We encourage you to review their privacy policies before providing personal information.
10. Updates to This Privacy Policy
We may update this policy periodically to reflect changes in laws, technology, or business practices. We will notify users of significant changes via:
- Email notification (if applicable).
- Website announcement with an updated “Effective Date.”
11. Contact Us & Privacy Officer
We have designated a Privacy Officer responsible for overseeing compliance with applicable privacy laws and this Privacy Policy. The Privacy Officer can be reached for all privacy-related inquiries, access requests, or complaints:
📧 Privacy Officer Email: customer-support@unscammed.com (subject line: “Privacy Officer – [Your Request]”)
Address: 7150 Carneros Lane, Dublin, California, 94568
If you are not satisfied with our response, you have the right to contact the applicable regulatory authority:
- Information Commissioner’s Office (ICO) (UK residents): www.ico.org.uk | 0303 123 1113
- The supervisory authority in your EU member state of residence.
Appendix: Categories of Data Collected
| Category | Examples | Purpose | Shared With |
|---|---|---|---|
| Identifiers | Name, email, phone, IP address, bank details | Service access & communication | Service providers (hosting, support), banks and public authorities |
| Commercial Data | Billing details, transaction history | Payment processing & compliance | Payment processors |
| Internet Activity | Log data, browsing history, cookies | Security monitoring & analytics | Analytics providers |
| Geolocation Data | IP-based location | Cyber threat detection & security | None |
| Professional Data | Job title, company name | Business services & compliance | None |
| Inferences | Risk analysis, behavior patterns | Fraud detection & security | Banks and Public Authorities |
