LEGAL · PRIVACY
Privacy Policy
Weblume Labs works only on systems you are authorized to have tested. Engagement findings are confidential by default.
On this page
- About this policy
- Information we collect
- Please do not send secrets in the intake form
- How we use information
- Legal bases and no marketing by default
- Engagement data and findings confidentiality
- How we share information
- Retention
- Security of your information
- Your choices and rights
- Children
- Third-party links and fonts
- International visitors and data location
- Changes to this policy
- Contact
About this policy
Weblume Labs LLC (“Weblume Labs,” “we,” “us,” “our”) is a Kentucky-based cybersecurity and information-security company. This Privacy Policy explains what personal information we collect through weblumelabsllc.com (the “Site”), our request-intake form, and related correspondence; how we use it; who may receive it; and what choices you have.
It applies to visitors and prospective clients. Information we handle as part of a contracted engagement, including system data, configuration details, and findings, is governed by the written engagement agreement, the rules of engagement, and our confidentiality commitments in addition to this policy.
Information we collect
We collect only what we need to respond to inquiries, scope work, and keep the Site secure.
Information you give us
- Name, work email address, company name, and any phone number you include
- The engagement type you select and the free-text description of systems, timing, and constraints you submit through the intake form or by email
- Correspondence, call notes, and documents exchanged while we scope and contract an engagement
- Billing contact and business details you provide when an engagement is accepted
Information collected automatically
- Basic request data when the intake form is submitted, such as IP address, user-agent string, timestamp, and submission outcome, used for abuse prevention and troubleshooting
- Standard web-server logs kept by our hosting provider
- Limited preference and session data stored in your browser as described in our Cookie Policy
Please do not send secrets in the intake form
The intake form is a first-contact channel. Do not include passwords, API keys, private keys, session tokens, customer records, payment card numbers, or other sensitive credentials or personal data in an intake message. If credentials or access are needed for an engagement, we will agree a secure exchange method in writing before any access is granted. If you send sensitive material by mistake, tell us promptly so we can delete it.
How we use information
We use personal information for the following purposes:
- Responding to inquiries and preparing fit questions and scoped proposals
- Verifying that the requester is authorized to commission work on the systems described
- Delivering, invoicing, and supporting contracted engagements
- Operating, securing, and improving the Site and intake process, including detecting spam, abuse, and unauthorized use
- Meeting legal, tax, accounting, and recordkeeping obligations
- Establishing, exercising, or defending legal claims
Legal bases and no marketing by default
Where privacy law requires a legal basis, we rely on steps taken at your request before entering a contract, performance of a contract, our legitimate interest in running a secure and professional business, and compliance with legal obligations. Marketing email is not part of our default intake process. We will not add you to a newsletter or mailing list unless you ask us to.
Engagement data and findings confidentiality
When you engage us, we may handle information about your systems, networks, vulnerabilities, and security posture. We treat that information, and every finding we produce, as confidential client information.
- We access only the systems named in the written authorization and rules of engagement
- We use engagement data solely to perform and document the agreed work
- Findings, reports, and working notes are shared only with the contacts you designate, unless disclosure is required by law
- We do not publish, benchmark, or reuse your findings in marketing, research, or case studies without your written consent
- We minimize the personal data we capture during testing and ask that you tell us in advance if in-scope systems hold regulated or sensitive data
- Where we believe we have seen evidence of an active compromise or imminent harm, we will notify your designated contact; we will not report to third parties unless the agreement or the law requires it
How we share information
We do not sell personal information and we do not share it for third-party advertising. We share information only in these circumstances:
- Service providers that help us operate the business, such as web hosting, email delivery, document storage, accounting, and payment processing. They may use the information only to provide services to us and are expected to protect it.
- Professional advisers such as lawyers, accountants, and insurers, under duties of confidentiality.
- Legal and safety disclosures where required by law, court order, or valid legal process, or to protect the rights, property, or safety of Weblume Labs, our clients, or others.
- Business transfers in a merger, acquisition, or sale of assets, subject to continued protection of the information.
Retention
We keep personal information only as long as needed for the purposes above.
- Unengaged inquiries and intake messages: generally up to 24 months, then deleted or anonymized
- Engagement agreements, invoices, and payment records: as required for tax and accounting purposes, commonly seven years
- Engagement working data and test artifacts: returned or securely deleted within the period stated in the engagement agreement, by default within 90 days after final delivery, unless longer retention is required by law or agreed with you
- Delivered reports: one archival copy may be kept for support and dispute resolution unless you ask us in writing to delete it and no legal hold applies
- Server and form logs: typically 30 to 90 days
Security of your information
We use administrative, technical, and organizational measures appropriate to our size and the sensitivity of the data, including access limited to people who need it, encrypted transport for the Site, and controlled handling of engagement artifacts. No method of transmission or storage is completely secure, and we cannot guarantee absolute security. If we become aware of a breach affecting your personal information, we will notify you as required by applicable law.
Your choices and rights
You may contact us to request access to, correction of, or deletion of the personal information we hold about you, or to object to or restrict certain uses. We will verify your identity and respond within a reasonable time and in line with applicable law. Residents of some states and countries have statutory privacy rights; we will honor valid requests to the extent those laws apply to us. We may decline requests where we must retain information for legal reasons, and will explain why.
To exercise a right, email network@weblumelabsllc.com or write to the address below.
Children
The Site and our services are directed to businesses and are not intended for anyone under 16. We do not knowingly collect personal information from children. If you believe a child has sent us information, contact us and we will delete it.
Third-party links and fonts
The Site loads web fonts from Google Fonts, which means your browser may send your IP address and standard request headers to that provider. Links to other websites are provided for convenience; we are not responsible for their content or privacy practices.
International visitors and data location
We operate from the United States and deliver services primarily to United States clients. If you access the Site from outside the United States, your information will be processed in the United States, where data-protection rules may differ from those in your country.
Changes to this policy
We may update this policy as our practices or the law change. The effective date at the top shows the latest revision. Material changes will be reflected on this page; continued use of the Site after an update means you accept the revised policy.
Contact
Questions about this policy or our handling of personal information can be sent to:
Weblume Labs LLC
710 E Main St, Lexington, KY 40502, United States
network@weblumelabsllc.com ·
+1 (224) 974-3213