> For the complete documentation index, see [llms.txt](https://doc.keepnetlabs.com/llms.txt). Markdown versions of documentation pages are available by appending `.md` to page URLs; this page is available as [Markdown](https://doc.keepnetlabs.com/legal-hub/for-everyone/free-phishing-email-analysis/privacy-policy.md).

# Privacy Policy

## Privacy Policy

**PLEASE READ THIS POLICY CAREFULLY**

**Last Modified:** 23 September 2026

This Privacy Policy explains how Keepnet Labs Ltd ("Keepnet", "we", "us" or "our") processes personal data when you use the Free Phishing Email Analysis service at <https://keepnetlabs.com/free-phishing-email-analysis> (the "Service"). Our website Privacy Policy applies to your use of keepnetlabs.com more generally, and our Cookie Policy explains how we use cookies.

### 1. Who we are

1.1 Keepnet Labs Ltd, a company registered in England and Wales with company number 11047987, of 124 City Road, London, England, EC1V 2NX, is the controller of personal data processed through the Service. Keepnet Labs Ltd owns Keepnet, Inc., a Delaware corporation.

1.2 The Service does not require an account. We do not ask for your name or email address to use it.

### 2. What we collect

2.1 **Submitted emails.** The email files you upload (.eml or .msg, up to 10 MB), including headers, body text, links, attachments, sender and recipient details, and any personal data contained in them.

2.2 **Analysis results.** The verdict, indicators and report generated for each submission.

2.3 **Technical data.** Your IP address, browser type, device information, the date and time of your submission, and usage data collected through cookies and similar technologies, as described in our Cookie Policy.

2.4 Please remove any personal data that you do not need analysed before you submit an email, and do not submit special category data (for example health, biometric or financial account data).

### 3. How we use personal data

3.1 We use the personal data described in section 2 to:

(a) analyse your submission and show you the results;

(b) protect the Service against abuse, fraud and automated misuse;

(c) improve our phishing and threat detection; and

(d) comply with our legal obligations.

3.2 We do not sell your personal data, and we do not publish your submissions or analysis results.

### 4. Legal basis (UK and EEA)

4.1 We process personal data on the basis of our legitimate interests in providing the Service, keeping it secure and improving our threat detection, and where required to comply with a legal obligation.

### 5. How the analysis works and who receives data

5.1 **Keepnet analysis.** Your submission is analysed by Keepnet's own analysis engines and by AI models run through Microsoft Azure OpenAI Service, as described on our AI Transparency page.

5.2 **Third-party analysis services.** To analyse your email, we send indicators extracted from it, such as URLs, domains, IP addresses, file hashes and attachments, to third-party threat analysis services (for example VirusTotal, FortiSandbox and Google Web Risk). The services we use may change over time. These providers process what they receive under their own terms and privacy policies, which may allow them to retain it and make it available to their own users.

5.3 **Service providers.** We use service providers for hosting, content delivery, security and analytics, including Microsoft Azure, Cloudflare and Google Analytics. They process personal data only on our instructions.

5.4 **Legal disclosure.** We may disclose personal data where required by law, or to protect the rights, property or safety of Keepnet, our users or others.

### 6. International transfers

6.1 Personal data submitted through the Service is stored on Keepnet's cloud infrastructure. Some of our service providers and threat analysis engines process data in other countries, including the United States.

6.2 Where we transfer personal data from the UK or EEA to a country without an adequacy decision, we rely on the European Commission's Standard Contractual Clauses, the UK International Data Transfer Addendum or the UK International Data Transfer Agreement, as applicable.

### 7. Retention

7.1 We keep submitted emails and analysis results only for as long as necessary for the purposes described in section 3, and then delete them.

7.2 We may keep threat indicators extracted from submissions (such as malicious URLs, domains and file hashes) for longer to improve our threat detection. These indicators do not identify you.

### 8. Security

8.1 We protect personal data with encryption in transit and at rest, access controls and monitoring, as described on our Platform Security page.

### 9. Your rights

9.1 Depending on where you are located, you may have the right to access, correct, delete or restrict the processing of your personal data, to object to its processing, and to data portability.

9.2 Because the Service does not use accounts, please include the file name and the date and time of your submission so that we can locate it.

9.3 To exercise your rights, email <privacy@keepnetlabs.com>. If you are not satisfied with our response, you may complain to your local data protection authority. In the UK, this is the [Information Commissioner's Office](https://ico.org.uk/make-a-complaint/).

### 10. Children

10.1 The Service is not intended for children under 16, and we do not knowingly collect their personal data.

### 11. Changes

11.1 We may update this Privacy Policy by posting a revised version on this page. The "Last Modified" date above shows when it was last changed.

### 12. Contact

Questions about this Privacy Policy: <privacy@keepnetlabs.com> or Keepnet Labs Ltd, 124 City Road, London, England, EC1V 2NX.


---

# Agent Instructions
This documentation is published with GitBook. GitBook is the documentation platform designed so that both humans and AI agents can read, navigate, and reason over technical content effectively. Learn more at gitbook.com.

## Querying This Documentation
If you need additional information that is not directly available in this page, you can query the documentation dynamically by asking a question.

Perform an HTTP GET request on the current page URL with the `ask` query parameter, and the optional `goal` query parameter:

```
GET https://doc.keepnetlabs.com/legal-hub/for-everyone/free-phishing-email-analysis/privacy-policy.md?ask=<question>&goal=<endgoal>
```

`ask` is the immediate question: it should be specific, self-contained, and written in natural language.
`goal` is optional and describes the broader end goal you are ultimately trying to accomplish on behalf of the user. GitBook uses it to tailor the answer towards what is most useful for that goal.

The response will contain a direct answer to the question and relevant excerpts and sources from the documentation.

Use this mechanism when the answer is not explicitly present in the current page, you need clarification or additional context, or you want to retrieve related documentation sections.
