Privacy Policy
Last updated: 1 October 2026. This policy explains what information Unlisted Report collects when you use our website, why we collect it, and the rights you have over it.
Unlisted Report ("we", "us", "our") operates the website unlistedreport.com. We are an independent cybersecurity newsroom, and we take the privacy of our readers as seriously as the subjects we cover. This policy describes the personal data we collect, how we use it, who we share it with, and how you can exercise your rights.
1. Information we collect
Information you give us directly
- Email address — when you subscribe to our newsletter, create an account, or contact us by email.
- Correspondence — the contents of emails, tips and correction requests you send us, including any contact details you choose to include.
- Account details — if you register for an account, we store your email address and authentication credentials (passwords are stored only as secure hashes; we can never see your password).
Information collected automatically
- Usage data — pages visited, time on page, referring website, and links clicked, used to understand what our readers find useful.
- Device and browser data — browser type and version, operating system, screen size and language settings.
- Log data — IP address, access times and error logs, kept for security monitoring and abuse prevention.
We do not knowingly collect data from children under 16, and we do not use invasive tracking technologies such as browser fingerprinting.
2. How we use your information
- To operate, maintain and secure the website.
- To send you the newsletter you subscribed to (you can unsubscribe at any time).
- To respond to your enquiries, tips and correction requests.
- To analyse readership in aggregate so we can improve our coverage.
- To comply with legal obligations and defend against fraud or abuse.
We do not sell your personal data, and we do not share it with advertisers for their own marketing purposes.
3. Legal bases for processing (EEA/UK readers)
Where the GDPR or UK GDPR applies, we process your data on the following bases:
- Consent — for newsletters and optional cookies. You can withdraw consent at any time.
- Legitimate interests — for analytics, security monitoring and improving our journalism, balanced against your rights.
- Contract — where processing is needed to provide a service you signed up for, such as an account.
- Legal obligation — where we must retain or disclose data by law.
4. Cookies
We use a small number of cookies: strictly necessary cookies that keep the site working (for example, keeping you signed in), and analytics cookies that help us understand readership in aggregate. We do not use third-party advertising cookies. You can block or delete cookies in your browser settings; the site will still work, though sign-in features will not.
5. Who we share data with
We use a small number of service providers to run the site, each bound by data-processing agreements:
- Hosting and database provider — stores site content, accounts and subscriber lists.
- Email delivery provider — sends the newsletter and transactional emails.
- Analytics provider — processes aggregated, de-identified usage statistics.
We may also disclose data if required by law, court order, or to protect the rights and safety of our readers and staff. Source material sent to our tips address is handled under strict need-to-know rules and is never shared with third parties except where legally compelled.
6. International transfers
Some of our service providers process data outside the European Economic Area and the UK. Where this happens, we rely on adequacy decisions or standard contractual clauses approved by the European Commission to protect your data.
7. Data retention
We keep newsletter subscriber data until you unsubscribe. Account data is kept while your account is active and deleted within 30 days of account closure. Server logs are kept for up to 12 months for security purposes. Correspondence relating to published stories may be kept longer where there is a legitimate editorial or legal reason.
8. Your rights
Depending on where you live, you may have the right to:
- Access a copy of the personal data we hold about you.
- Correct inaccurate data.
- Have your data deleted ("right to be forgotten").
- Object to or restrict certain processing.
- Receive your data in a portable format.
- Withdraw consent at any time, without affecting the lawfulness of prior processing.
- Lodge a complaint with your local data protection authority.
To exercise any of these rights, email privacy@unlistedreport.com. We respond to all requests within 30 days.
9. Security
As a cybersecurity publication we hold ourselves to a higher bar. We encrypt data in transit and at rest, enforce strong authentication for staff systems, limit access to personal data to those who need it, and review our security practices regularly. No system is perfectly secure; if a breach affects your data we will notify you and the relevant regulator as required by law.
10. Changes to this policy
We may update this policy from time to time. Material changes will be flagged on this page and, where appropriate, announced to subscribers by email. The "last updated" date at the top always shows the current version.
11. Contact
Questions about this policy or your data: privacy@unlistedreport.com. You can also write to us via the details on our contact page.
