EXTERNAL10 Back to the site

Privacy

Privacy policy

EXTERNAL10 is a service of SCORE10 SL, CIF B23860547, 29670 Marbella, Spain. This page explains what we collect, why, and what you can ask us to do with it.

Last updated 11 September 2026

  1. 01

    Who is responsible

    SCORE10 SL, CIF B23860547, 29670 Marbella, Spain. Contact: [email protected].

  2. 02

    What we collect

    When you request a test we store what you enter in the form: your name, work email, company and, if you give it, your role. We also store the domain of your email, since that is the target of the test, and the time of the request.

    Our servers keep standard access logs (IP address, browser, pages requested) for security and troubleshooting. We do not use analytics or advertising cookies. Fonts are loaded from Google Fonts, which means Google receives your IP address when the page loads.

  3. 03

    Why we use it

    • To check that you are entitled to authorize a test of the domain, and to confirm the authorization terms with you.
    • To carry out the test, write the report and hold the debrief meeting.
    • To invoice you and keep the accounting records Spanish law requires.
    • To keep our own systems secure.
  4. 04

    Data we see during a test

    A penetration test can expose data held on your systems. We access only what is needed to prove a finding, we do not copy more than a minimal sample as evidence, and everything goes into the confidential report delivered to you and nowhere else.

  5. 05

    How long we keep it

    • Requests that do not become an engagement: deleted after 6 months.
    • Engagement data, report and evidence: kept for 12 months after delivery so we can answer questions, then deleted.
    • Invoices and accounting records: kept as long as Spanish tax law requires.
  6. 06

    Who else sees it

    We are a small company and we use well-known services to run it. These providers process data on our behalf and only for the purposes above:

    • Google Workspace: email, calendar and documents, so anything you send us or we send you passes through Google.
    • GitHub: private repositories where we keep our code and engagement material.
    • Cloudflare: proxies traffic to this site and protects it.
    • Our own servers in the EU: run this site and its database.
    • Our accountants in Spain: see what is needed to invoice you and keep the books.

    During the security review itself, and only then, we use AI models from OpenAI, Anthropic and grunden.ai to help analyse findings and draft the report. What we send them is limited to the technical material needed for that work. Your sign-up details are never used for it, and we do not use your data to train any model.

    Some of these providers process data outside the EU. Where that happens we rely on the EU standard contractual clauses or the EU-US Data Privacy Framework. We never sell your data.

  7. 07

    Your rights

    Under the GDPR you can ask us for a copy of your data, to correct it, to delete it, to restrict or object to its use, and to receive it in a portable format. Write to [email protected]. You can also complain to the Spanish data protection authority, the AEPD (aepd.es).

  8. 08

    Changes

    If we change this policy we update the date at the top. Material changes to an ongoing engagement are communicated by email.