Policies & Terms
Complete legal documentation for securitybeaconlabs services and data handling practices.
TL;DR — Quick Reference
Privacy Policy
We collect only the data necessary to deliver our cyber security services. Your information is never sold to third parties. All data is stored within the EU and processed under GDPR Article 6(1)(b) — contractual necessity.
Terms of Service
By engaging securitybeaconlabs, you agree to scope-based pricing, milestone-driven delivery, and shared responsibility for implementing recommended security controls. All intellectual property transfers upon final payment.
Cookie Policy
We use only essential cookies for site functionality. No analytics, advertising, or tracking cookies are deployed without explicit consent. You can clear cookies at any time via your browser settings.
Refund Policy
Refund requests are evaluated based on project milestones completed. Pre-engagement assessments are non-refundable. Work-in-progress refunds are prorated based on deliverables completed at time of cancellation.
Sections
Last updated: August 2026
securitybeaconlabs
Carrer de Pelai 28, 08001 Barcelona, Spain
Privacy Policy
Effective Date: August 2026 | securitybeaconlabs
1. Data Controller
The data controller responsible for your personal data is securitybeaconlabs, located at Carrer de Pelai 28, 08001 Barcelona, Spain. For privacy-related inquiries, contact us at [email protected].
2. Data We Collect
We collect the following categories of personal data:
- Contact Information: Name, email address, phone number, and company details submitted through our contact forms.
- Service Data: Network configurations, system architecture details, and vulnerability scan results provided during engagement execution.
- Communication Records: Email correspondence, meeting notes, and support tickets related to active engagements.
- Technical Data: IP addresses, browser type, and device information collected automatically through essential cookies.
3. Legal Basis for Processing
We process your data under the following GDPR Article 6(1) legal bases:
- Article 6(1)(b) — Contractual Necessity: Processing required to perform the cyber security services you have engaged.
- Article 6(1)(f) — Legitimate Interest: For improving our service delivery, internal analytics, and security monitoring.
- Article 6(1)(a) — Consent: For any non-essential data processing, which you may withdraw at any time.
4. Data Retention
Personal data is retained for the duration of the active engagement plus 24 months following project completion. Vulnerability scan reports and penetration test findings are retained for 36 months to support compliance documentation. You may request early deletion subject to legal retention obligations.
5. Data Sharing
We do not sell, rent, or share your personal data with third parties except:
- Sub-processors engaged to deliver specific service components (e.g., cloud infrastructure providers), bound by Data Processing Agreements.
- Regulatory authorities when legally required under GDPR Article 6(1)(c).
- Law enforcement agencies upon valid legal request.
6. Your Rights
Under GDPR, you have the following rights regarding your personal data:
- Right of Access (Article 15): Request a copy of all personal data we hold about you.
- Right to Rectification (Article 16): Request correction of inaccurate or incomplete data.
- Right to Erasure (Article 17): Request deletion of your personal data, subject to legal retention requirements.
- Right to Restrict Processing (Article 18): Request limitation of data processing in specific circumstances.
- Right to Data Portability (Article 20): Receive your data in a structured, machine-readable format.
- Right to Object (Article 21): Object to processing based on legitimate interests.
Exercise any of these rights by emailing [email protected]. We will respond within 30 days.
7. International Data Transfers
All personal data is processed and stored within the European Economic Area (EEA). If any data transfer outside the EEA is required for service delivery, we ensure appropriate safeguards are in place under GDPR Chapter V, including Standard Contractual Clauses (SCCs).
Terms of Service
Effective Date: August 2026 | securitybeaconlabs
1. Scope of Services
securitybeaconlabs provides cyber security services including but not limited to: vulnerability assessments, penetration testing, regulatory compliance audits, security architecture design, incident response, and managed security operations. All services are delivered according to the specific scope defined in individual Statement of Work (SOW) documents.
2. Engagement Process
Engagements begin upon mutual execution of a Statement of Work (SOW) and receipt of initial payment. The SOW defines the exact scope, deliverables, timeline, and pricing for each engagement. Any scope changes require a written change order signed by both parties.
3. Payment Terms
Invoices are issued according to the milestone schedule defined in the SOW. Payment is due within 14 calendar days of invoice date. Late payments incur a 1.5% monthly interest charge. All prices are quoted in Euros (EUR) and are exclusive of applicable VAT.
4. Client Responsibilities
The client agrees to:
- Provide timely access to systems, networks, and documentation required for service delivery.
- Designate a primary point of contact for coordination and decision-making.
- Implement recommended security controls within agreed timeframes.
- Notify securitybeaconlabs immediately of any security incidents during active engagements.
- Maintain confidentiality of all vulnerability reports and security findings.
5. Intellectual Property
All deliverables, reports, and security assessments produced during an engagement become the exclusive property of the client upon receipt of final payment. securitybeaconlabs retains the right to use anonymized, aggregated data for internal research and service improvement purposes. Methodologies, tooling, and proprietary processes remain the intellectual property of securitybeaconlabs.
6. Limitation of Liability
securitybeaconlabs' total liability for any engagement shall not exceed the total fees paid by the client for that specific engagement. We shall not be liable for indirect, consequential, or incidental damages. Clients acknowledge that cyber security services reduce but do not eliminate risk, and that securitybeaconlabs cannot guarantee the absence of all security vulnerabilities.
7. Confidentiality
Both parties agree to maintain strict confidentiality of all non-public information exchanged during the engagement. This obligation survives termination of the agreement for a period of 36 months. Security findings, vulnerability reports, and system architecture details are classified as Confidential Information.
8. Governing Law
These Terms of Service are governed by the laws of Spain. Any disputes arising from or related to these terms shall be subject to the exclusive jurisdiction of the courts of Barcelona, Spain.
Refund & Reimbursement Policy
Effective Date: August 2026 | securitybeaconlabs
1. Pre-Engagement Assessments
Fees for preliminary consultations, scoping calls, and initial vulnerability assessments are non-refundable once the assessment has been initiated. If you cancel before any work begins, a full refund will be issued within 14 business days.
2. Active Engagements
For engagements in progress, refunds are calculated based on completed milestones:
- If cancellation occurs before the first milestone is delivered, 75% of the remaining engagement fee is refunded.
- If cancellation occurs after the first milestone, refund is prorated based on the percentage of deliverables completed.
- No refund is available for work completed and delivered prior to the cancellation request.
3. Managed Services & Retainers
Monthly retainer services (e.g., Managed SOC) require 30 days written notice for cancellation. The current billing period is non-refundable. No refund is issued for partial months of service already rendered.
4. Emergency Services
Emergency incident response deployments are billed at the contracted hourly or flat rate and are non-refundable once the response team has been deployed and work has commenced.
5. Refund Process
Refund requests must be submitted in writing to [email protected]. Refunds are processed within 14 business days of approval and credited to the original payment method. VAT charges are refunded in accordance with applicable tax regulations.
6. Dispute Resolution
If you dispute a charge or believe a refund is warranted under these terms, contact us at [email protected]. We commit to resolving disputes within 30 days. Unresolved disputes are subject to mediation before the courts of Barcelona, Spain.