Remnant Privacy Policy_
1. About This Policy
1.1 This Privacy Policy explains how Brimstone Site Investigation Ltd (“Brimstone”, “we”, “us” or “our”) collects, uses, stores, and shares personal data when you use Remnant (the “Platform”).
1.2 Remnant is an unexploded ordnance (UXO) and explosive remnants of war (ERW) intelligence platform that aggregates incident data from open sources. Remnant is operated by Brimstone and is available at remnant.brimstoneuxo.com.
1.3 Brimstone is the controller of your personal data for the purposes of the UK General Data Protection Regulation (“UK GDPR”) and the Data Protection Act 2018.
1.4 Our registered office is at Innovation Centre Medway, Maidstone Road, Chatham, ME5 9FD, United Kingdom. Our company number is 10253758.
1.5 This Policy applies to all users of Remnant. Remnant is not intended for users under the age of 18 and we do not knowingly collect personal data from anyone under 18. Access to the Platform is gated by an age confirmation prompt.
1.6 Please read this Policy carefully. By using Remnant you confirm that you have read and understood how we process your personal data. If you do not agree with this Policy, please do not use the Platform.
2. Personal Data We Collect
2.1 We collect personal data in the following categories. The specific categories that apply to you depend on whether you are an unregistered visitor, a registered free-tier user, or a paid-tier subscriber.
Account Data (registered users)
- Name, email address, and password (stored as a salted hash, never in plain text).
- Optional profile information you choose to provide, such as job title, organisation, or professional sector.
- Account preferences, including communication preferences and accessibility settings.
- Subscription tier (Free, Pro, Analyst, or Intelligence) and tier history.
Usage Data (registered users)
- Search history within the Platform.
- Saved searches, watchlists, and alert preferences.
- Records of incidents you have viewed, bookmarked, or interacted with.
- Aggregated patterns of how you use the Platform (for example, time spent on different features).
Technical Data (all users including unregistered visitors)
- IP address (used for security, fraud prevention, and approximate geolocation).
- Browser type and version, device type, operating system, and screen size.
- Time-zone setting.
- Authentication and session data (for registered users).
- Log data, including pages visited, errors encountered, and timestamps.
Payment Data (paid-tier subscribers only)
- Subscription tier and billing status.
- Billing name and billing address.
- Transaction history and invoices.
- Payment card details are not stored by us. They are collected and processed directly by our payment processor (see section 5).
Communications Data
- Records of correspondence between you and us, including support enquiries and feedback.
- Marketing preferences and your responses to marketing communications (where you have consented to marketing).
Cookies and Similar Technologies
2.2 We use cookies and similar technologies for authentication, security, analytics, and (where you consent) other purposes. Further detail is set out in our Cookies Policy at remnant.brimstoneuxo.com/cookies.
Data We Do Not Collect
2.3 We do not collect special category data (data revealing racial or ethnic origin, political opinions, religious or philosophical beliefs, trade union membership, genetic data, biometric data, data concerning health, or data concerning a person’s sex life or sexual orientation) under UK GDPR Article 9. We ask that you do not provide such data through the Platform.
2.4 We do not knowingly collect personal data from anyone under the age of 18. If we discover that we have collected such data, we will delete it without undue delay.
Hashing for Marketing Purposes
2.5 When account data is deleted from our active systems at the end of its retention period (see section 7), we may retain a one-way cryptographic hash (SHA-256) of certain identifiers, including hashed email addresses. These hashes:
- Cannot be reversed to reveal the original data.
- Are designed so that they cannot reasonably be used to identify a specific living individual without additional information that we no longer hold following deletion.
- May be used by us to build marketing audiences on advertising platforms (such as creating “custom audiences” or “lookalike audiences”).
2.6 You have the right to object to the use of your data for marketing purposes at any time, in which case we will exclude your hashed identifiers from any marketing audiences we maintain. See section 9 for details on how to exercise your rights.
3. How We Collect Your Personal Data
3.1 We collect personal data in three ways:
3.1.1 Directly from you, when you register for an account, complete your profile, save searches, contact us, or otherwise interact with the Platform.
3.1.2 Automatically, when you use the Platform. Our servers automatically log Technical Data and Usage Data as you interact with Remnant.
3.1.3 From third parties, including our payment processor (in respect of paid-tier subscriptions), our authentication providers (if you choose to log in via a third-party single sign-on option we may offer in the future), and our analytics providers.
4. How We Use Your Personal Data and Lawful Bases
4.1 We process personal data only where we have a lawful basis to do so under UK GDPR Article 6. The lawful bases on which we rely, and the purposes for which we use personal data, are summarised below.
| Purpose | Data used | Lawful basis |
|---|---|---|
| Creating and managing your account; providing access to the Platform | Account Data, Technical Data | Performance of contract (Article 6(1)(b)) |
| Operating, improving, and developing the Platform | Usage Data, Technical Data | Legitimate interests (Article 6(1)(f)): operating and improving a useful product |
| Processing payments and managing paid-tier subscriptions | Account Data, Payment Data | Performance of contract (Article 6(1)(b)) |
| Sending service emails (account confirmation, password resets, security alerts, billing notices, service updates) | Account Data | Performance of contract (Article 6(1)(b)); legitimate interests for service updates |
| Sending marketing communications | Account Data, Communications Data | Consent (Article 6(1)(a)); soft opt-in for existing customers under PECR |
| Building marketing audiences on third-party advertising platforms using hashed identifiers | Hashed identifiers derived from Account Data (see section 2.5) | Legitimate interests (Article 6(1)(f)) where personal data; once hashed, no longer personal data |
| Responding to enquiries and providing support | Communications Data, Account Data | Performance of contract; legitimate interests in responding to non-customers |
| Security, fraud prevention, and abuse detection | Technical Data, Account Data, Usage Data | Legitimate interests (Article 6(1)(f)): protecting Brimstone, our users, and the Platform |
| Analytics (aggregated and pseudonymised use patterns) | Usage Data, Technical Data | Consent (where cookie-based); legitimate interests (where server-side and pseudonymised) |
| Complying with legal and regulatory obligations | All categories as required | Legal obligation (Article 6(1)(c)) |
| Establishing, exercising or defending legal claims | All categories as required | Legitimate interests (Article 6(1)(f)): protecting Brimstone’s legal rights |
4.2 Where we rely on legitimate interests as our lawful basis, we have carried out a balancing test to confirm that our interests are not overridden by your rights and freedoms. You may request further information about our legitimate interests assessments by contacting us at privacy@brimstoneuxo.com.
4.3 Where we rely on consent, you may withdraw that consent at any time by adjusting your account preferences or by contacting us. Withdrawal of consent does not affect the lawfulness of processing before withdrawal.
4.4 We will not use your personal data for any new purpose materially different from the purposes set out in this Policy unless we have notified you, updated this Policy, and (where required by law) obtained your consent.
5. Who We Share Your Personal Data With
5.1 We share personal data only with the categories of recipient set out below.
Service providers (data processors)
5.2 We engage trusted third-party service providers to help us operate the Platform. These providers act as data processors and process your personal data only on our documented instructions. Categories of provider include:
- Cloud hosting and infrastructure (servers, databases, content delivery).
- Payment processing (for paid-tier subscriptions).
- Email delivery (for service and marketing communications).
- Analytics and product telemetry.
- Security, fraud prevention, and authentication services.
- Customer support tools.
5.3 All service providers are bound by written data processing agreements that include the safeguards required by UK GDPR Article 28. The current list of our key service providers is available on request from privacy@brimstoneuxo.com.
Professional advisers
5.4 We may share personal data with our legal, financial, insurance, audit, and other professional advisers, where reasonably necessary for the management of our business.
Regulators and law enforcement
5.5 We may disclose personal data to regulators, law enforcement, courts, or other authorities where required by law, where necessary to comply with a legal process, or where we believe in good faith that disclosure is necessary to protect our rights, your rights, the rights of others, or to prevent or investigate suspected illegal activity, fraud, or abuse.
Business transfers
5.6 If Brimstone is involved in a merger, acquisition, sale of assets, financing, or restructuring, personal data may be transferred as part of that transaction. We will notify you of any such transfer and any consequent change in how your personal data is handled.
Advertising platforms
5.7 We may share hashed identifiers (one-way SHA-256 hashes) derived from your account data with advertising platforms, including Meta and similar services, for the purpose of building marketing audiences (custom audiences and lookalike audiences). We apply hashing so that the identifiers we share cannot reasonably be used to identify you without additional information that we do not provide to the platform. We rely on your consent for this processing where required, and you may object to, or withdraw your consent for, the use of your data for these purposes at any time, in which case we will exclude your identifiers from any marketing audiences we maintain (see section 9).
With your consent
5.8 We may share personal data with third parties where you have given us specific consent to do so.
Data we do not share
5.9 We do not sell your personal data. We do not share your unhashed personal data with advertising networks for advertising purposes.
6. International Transfers
6.1 Personal data collected through Remnant is hosted in the United Kingdom.
6.2 Where any of our service providers is located outside the United Kingdom, we ensure that appropriate safeguards are in place to protect your personal data in accordance with UK GDPR. Depending on the destination country, these safeguards include:
- Transfers to countries that the UK government has determined provide an adequate level of protection (“adequacy regulations”).
- The UK International Data Transfer Agreement or the UK Addendum to the European Commission’s Standard Contractual Clauses.
- Other lawful transfer mechanisms recognised under UK GDPR.
6.3 You may request further detail about the safeguards we have in place for international transfers by contacting privacy@brimstoneuxo.com.
7. Data Retention
7.1 We retain personal data only for as long as is necessary for the purposes for which it was collected, or as required by applicable law. The specific retention periods for the main categories of personal data are set out below.
| Data category | Retention period | Basis |
|---|---|---|
| Active account data | Retained while your account is active | Necessary to provide the Platform |
| Dormant account data | Deleted after 36 months without login, provided the account holder does not hold a current paid subscription. Warning emails issued at 33 and 35 months of login inactivity. See section 7.2 for the definition of an active account. | UK GDPR Article 5(1)(e) storage limitation |
| Account data on user-initiated deletion | Deleted within 30 days of your deletion request, subject to legal hold and backup retention | UK GDPR Article 17 (right to erasure) |
| Usage data | Linked to the account for the lifetime of the account; anonymised aggregate retained indefinitely | Operating and improving the Platform |
| Technical data and server logs | Up to 13 months from collection | Security, debugging, and analytics |
| Analytics data (pseudonymised) | Up to 38 months from collection | Default analytics retention |
| Payment records and invoices | 7 years from transaction date | UK tax and accounting law |
| Marketing consent records | Until consent is withdrawn, plus 24 months of inactivity, then deleted | UK GDPR Article 7 (demonstrating consent) |
| Support correspondence | 3 years from last contact | Service quality and dispute resolution |
| Marketing audience data (hashed) | Retained indefinitely as one-way SHA-256 hashes; not personal data once hashed | Marketing on the basis of legitimate interests; ceases to be personal data following hashing |
| Backup data | Rolling 35-day backup cycle | Operational resilience |
| Data subject to legal hold | Retained for the duration of the legal hold, then deleted in accordance with the relevant category | Legal obligation |
7.2 For the purposes of this Policy, an account is “active” if either:
(a) the account holder has logged into Remnant within the preceding 36 months; or
(b) the account holder holds a current paid subscription to Remnant (Pro, Analyst, or Intelligence tier), regardless of login activity.
7.3 An account is “dormant” if neither limb of section 7.2 applies. The 36-month inactivity clock runs from the date of the most recent login. Warning emails are issued at 33 and 35 months of login inactivity. Opening marketing emails, receiving system-generated emails, or passive cookie activity does not, by itself, constitute activity for these purposes.
7.4 When personal data is no longer required, we securely delete or anonymise it.
8. Security
8.1 We take the security of personal data seriously and implement appropriate technical and organisational measures designed to protect personal data against accidental or unlawful destruction, loss, alteration, unauthorised disclosure or access, in accordance with UK GDPR Article 32. These measures include:
- Encryption of personal data in transit (TLS 1.2 or higher) and at rest.
- Salted hashing of passwords (passwords are never stored in plain text).
- Role-based access controls within Brimstone, with access limited to personnel who need it for their role.
- Multi-factor authentication for administrative access to Platform infrastructure.
- Regular security testing, including vulnerability scanning and periodic penetration testing.
- Documented information security policies and staff training.
- Incident response procedures, including breach notification to the Information Commissioner’s Office within 72 hours where required.
8.2 No security measures are perfect or impenetrable. You are responsible for keeping your account password confidential and for any activity that occurs under your account.
8.3 If you suspect any unauthorised access to your account, please contact us immediately at security@brimstoneuxo.com.
9. Your Rights
9.1 Under UK GDPR you have the following rights in respect of your personal data:
Right of access (Article 15)
9.2 You have the right to request confirmation of whether we process your personal data and, if we do, to receive a copy of that personal data together with certain supporting information.
Right to rectification (Article 16)
9.3 You have the right to request that we correct any inaccurate personal data we hold about you, or complete any incomplete personal data.
Right to erasure (Article 17)
9.4 You have the right to request that we delete your personal data in certain circumstances, including where the personal data is no longer necessary for the purposes for which it was collected, where you withdraw consent and we have no other lawful basis, or where you object to processing and we have no overriding legitimate grounds.
Right to restriction (Article 18)
9.5 You have the right to request that we restrict the processing of your personal data in certain circumstances, including where you contest its accuracy, where processing is unlawful but you do not want erasure, or where you have objected to processing pending verification of overriding grounds.
Right to data portability (Article 20)
9.6 Where we process personal data on the basis of consent or contract by automated means, you have the right to receive that personal data in a structured, commonly used, machine-readable format, and to have it transmitted to another controller where technically feasible.
Right to object (Article 21)
9.7 You have the right to object to processing of your personal data based on legitimate interests, including profiling. You also have an absolute right to object to processing for direct marketing purposes.
Right to withdraw consent
9.8 Where we process personal data on the basis of consent, you have the right to withdraw that consent at any time.
Right not to be subject to automated decision-making
9.9 We do not currently make decisions based solely on automated processing that produce legal or similarly significant effects on you. If this changes, we will update this Policy and provide the additional safeguards required by UK GDPR Article 22.
How to exercise your rights
9.10 To exercise any of your rights, please contact us at privacy@brimstoneuxo.com. We will respond to your request within one calendar month, although we may extend this period by a further two months for complex requests, in which case we will notify you within the first month.
9.11 We may need to verify your identity before processing a rights request. There is no fee for exercising your rights, although we may charge a reasonable fee or refuse to act on a request if it is manifestly unfounded or excessive.
Right to complain to the ICO
9.12 You have the right to lodge a complaint with the Information Commissioner’s Office, the UK supervisory authority for data protection issues. You can contact the ICO at:
- Website: ico.org.uk/make-a-complaint
- Helpline: 0303 123 1113
- Address: Information Commissioner’s Office, Wycliffe House, Water Lane, Wilmslow, Cheshire, SK9 5AF
9.13 We would, however, appreciate the chance to address your concerns before you approach the ICO, so please consider contacting us first at privacy@brimstoneuxo.com.
10. Cookies
10.1 We use cookies and similar technologies on the Platform. Detailed information about the cookies we use, their purpose, and how you can manage them is set out in our Cookies Policy at remnant.brimstoneuxo.com/cookies.
11. Changes to this policy
11.1 We may update this Policy from time to time to reflect changes in our practices, the law, or the Platform itself. When we make material changes, we will notify registered users by email and post a prominent notice on the Platform.
11.2 The date at the top of this Policy indicates when it was last updated. Continued use of the Platform after an update means you accept the revised Policy.
12. Contact Us
12.1 If you have any questions about this Policy or about how we handle your personal data, please contact us:
- Email: privacy@brimstoneuxo.com
- Post: Brimstone Site Investigation Ltd, Innovation Centre Medway, Maidstone Road, Chatham, ME5 9FD, United Kingdom
12.2 We do not currently have a statutory obligation to appoint a Data Protection Officer under UK GDPR Article 37. Privacy-related queries are handled by our Business Coordinator, who you can reach at the contact details above.
This Notice was last updated on 8 June 2026.