Skip to main content
← Back to Home

Compliance & Certifications

How EmailsThreatScan protects your data through regulatory compliance, industry standards, and transparent governance.

Compliant

UK GDPR

General Data Protection Regulation

We are fully compliant with the UK General Data Protection Regulation. You have the right to access, rectify, erase, port, and object to processing of your personal data at any time.

Right of Access, Rectification & Erasure
Right to Data Portability
Right to Object to Automated Processing
Data Breach Notification within 72 hours
Data Processor Agreements with all subprocessors
Verified

Google API Services

User Data Policy & Limited Use

Our use and transfer of information received from Google APIs adheres to the Google API Services User Data Policy, including the Limited Use requirements.

Strict Limited Use compliance
No use of Google data for advertising
No sharing with third parties
No use for training generalised AI models
Enforced

AI Zero-Training Guarantee

Commercial Enterprise API Commitment

We pay for Commercial Enterprise API access for every analysis — Free and Paid — guaranteeing your email data is never used to train public AI models.

Commercial Enterprise APIs exclusively
Data Processing Agreements with all AI providers
30-day notice for subprocessor changes
Your data treated as confidential forensic evidence
Regulated

UK ICO Oversight

Information Commissioner's Office

We operate under the regulatory oversight of the UK Information Commissioner's Office. You have the right to lodge a complaint directly with the ICO at any time.

Subject to ICO regulatory authority
Dedicated Data Protection Officer
Transparent complaint procedures

Security Measures

Technical safeguards protecting your data

Encryption In Transit

TLS 1.2/1.3 on all connections

Encryption At Rest

AES-256 for stored data & tokens

Password Hashing

Adaptive algorithms resistant to brute-force

OAuth 2.0 Tokens

Minimal-scope, revocable, encrypted at rest

Rate Limiting

Per-IP and per-user abuse prevention

Webhook Signing

HMAC-SHA256 payload verification

Corporate Governance

Our legal entity and oversight

UK Registered Company

Purple Box (UK) Ltd

Company No. 08212295

Regulatory Authority

UK Information Commissioner’s Office

ico.org.uk

Data Protection Officer

Enquiries & Subject Access

[email protected]

Privacy Policy

How we handle your data

Terms of Service

Usage rights & obligations

FAQ

Common questions answered

© 2026 Purple Box (UK) Ltd trading as EmailsThreatScan. All rights reserved.

77 Commercial Street, London, England, E1 6BD