Legal
Privacy Policy
Last updated 2026-07-01
Placeholder for legal review. This document is a good-faith summary and must be reviewed by a qualified legal professional and adapted to your jurisdiction before production launch. It is not legal advice.
1. Who we are
WiFi Pentest AI S.L. ("we", "us") operates this website to offer AI-assisted Wi-Fi penetration testing services. For privacy questions, contact hello@wifipentest.ai. (OWNER: confirm the controller entity and a data-protection contact before launch.)
2. What we collect
When you submit the quote-request form, we collect only the details you provide:
- First name — to address you personally.
- Company name — to understand the requesting organization.
- Business email address — to respond to your request.
We also record operational metadata needed to process and protect the request: submission timestamps, a source label (which page the request came from), a consent version, the email-delivery status of your confirmation message, and the result of an automated anti-abuse check (a reCAPTCHA action and risk score). We do not store the raw reCAPTCHA token, and we do not require an account or password.
3. Why we collect it (purpose & lawful basis)
- To respond to and scope your requested quote (our legitimate interest in responding to your enquiry, and steps prior to entering a contract).
- To send you a confirmation that your request was received (the same enquiry purpose).
- To protect the form and our systems from spam and abuse (legitimate interest in security).
4. Anti-abuse and reCAPTCHA
We use Google reCAPTCHA to distinguish humans from automated submissions. Google processes information as described in its own privacy terms. Where abuse prevention requires a network-derived identifier, we prefer a short-retention, salted hash rather than storing a raw IP address.
5. Where it is processed
Quote-request data is stored in Google Cloud Firestore and processed by Google Cloud Functions. Confirmation emails are sent through a transactional email provider selected by us. (OWNER: name the chosen email provider and relevant processing regions here once selected — e.g. hosting region and provider.)
6. How long we keep it
We retain quote-request records only as long as necessary to respond to your enquiry and for a reasonable follow-up period, after which they are deleted or anonymized. Any salted network-identifier used for rate limiting is short-lived. (OWNER: set a specific retention period, e.g. 24 months, after legal review.)
7. Sharing
We do not sell your personal data. We share it only with the service providers that operate this website's infrastructure (for example our cloud host and email provider), acting on our instructions, and where required by law.
8. Your rights
Depending on your location, you may have rights to access, correct, delete, restrict or object to the processing of your personal data, and to data portability. To exercise these rights, contact hello@wifipentest.ai. You may also have the right to complain to your local data-protection authority.
9. Cookies & analytics
The core site functions without marketing cookies. If analytics is enabled, it is configured to be privacy-conscious (for example, IP anonymization and no advertising signals), and we do not send your form fields, email, name or company to analytics. (OWNER: confirm the final analytics configuration and add a cookie notice if you enable non-essential cookies.)
10. Security
Lead records are never accessible to public website visitors. They are written and read only by our trusted server environment. See our Responsible Testing policy for how engagement evidence is handled.
11. Changes
We may update this policy. The "last updated" date above reflects the latest revision.