Website privacy

Privacy notice

This notice explains how Balhence handles personal information submitted through this website. It covers website enquiries and optional analytics; a signed client agreement governs information handled during a penetration-testing engagement.

Information you choose to provide

The scope-request form may collect your name, work email, company, product URL, requested service, deadline, business reason for testing, any generated Draft Scope Brief you choose to attach, and any context you add. Please do not submit passwords, access tokens, customer data, vulnerability details, or confidential architecture through the website form.

Scope planner storage

The scope planner runs in your browser. Draft answers are saved locally under balhence_scope_builder_v1 so you can resume on that device; they are not sent to Balhence merely by using the planner. When you continue to the contact page, a generated brief is passed through session storage under balhence_scope_brief_v1, expires after two hours, and is submitted only if you choose to send the contact form.

Use the planner’s reset control to remove saved planner data, or clear this site’s browser storage. Browser storage is tied to the browser profile rather than a user account, so do not use the planner on a shared device for sensitive planning and never enter credentials, tokens, customer records, or confidential architecture.

How the information is used

Enquiry information is used to respond, assess fit, prepare for a scoping conversation, produce a proposal if requested, maintain a record of the business conversation, and protect the form from abuse. It is not sold or used to build advertising profiles.

AI-assisted engagement work

Balhence may use approved AI assistance for limited penetration-testing tasks such as scope cross-reference, test-hypothesis development, sanitized artifact organization, or report quality control. A signed engagement agreement defines whether that use is permitted, the approved purposes and data classes, and any provider or retention restrictions. Client credentials, active tokens, customer records, source code, and unredacted vulnerability evidence are not submitted to a public AI service unless the client explicitly approves the provider, purpose, and processing terms.

AI output is treated as an untrusted lead rather than evidence. Live test actions, exploit validation, impact, severity, reporting, and re-test decisions remain under human control. The AI-native VAPT operating model explains these boundaries in more detail.

Form processing

The enquiry form is processed by Formspree. When you submit it, the form contents, campaign tags present in the page URL, the same-site referring path or cross-site referring origin, and technical information needed to deliver the message are transmitted to that service. Query strings and fragments are removed from the stored referral value. Review Formspree’s privacy policy before submitting if you need more detail about that processing. You can avoid the form and email contact@balhence.com directly.

Analytics choice

Google Analytics is configured on eligible informational pages to understand page and conversion performance. It is not loaded on the scope planner, contact form, or this privacy page. On eligible pages, its script is not loaded unless you choose “Accept” in the analytics notice. Your choice is stored in your browser as balhence_analytics_consent. Choosing “Decline” prevents the analytics script from loading.

You can change the choice by clearing this site’s local storage in your browser and reloading the page. If analytics is accepted, Google processes usage information under its own terms and privacy controls.

Legal basis and retention

Information supplied with an enquiry is processed to take steps you request before a possible contract and for the legitimate purpose of responding to business enquiries and preventing abuse. Optional analytics is based on your choice. Enquiry records are kept only as long as reasonably needed for the conversation, related legal or security needs, and ordinary business recordkeeping, then deleted or de-identified.

Sharing and international processing

Information may be handled by service providers needed to operate email, forms, hosting, or analytics. Those providers may process data in other countries. Information may also be disclosed when legally required or necessary to protect rights, safety, and service integrity. Balhence does not publish client or prospect information without permission.

Your choices and requests

You may ask what enquiry information is held about you, request a correction or deletion, withdraw an analytics choice, or object to further contact. Some records may need to be retained where law or a live contractual dispute requires it.

Security

Reasonable administrative and technical safeguards are used for website enquiries, but no internet transmission is risk-free. Sensitive engagement data, credentials, evidence, and reports use separately agreed delivery and retention controls rather than this public form.

Contact

Send privacy questions or requests to contact@balhence.com with “Privacy request” in the subject line.