Privacy Policy

Last Updated: November 5, 2025

What is this policy?

This is the privacy policy of Maze AI Limited (t/a Maze) ("Maze", "we", "us" or "our") for The Exploit, our cybersecurity satire publication. It explains who we are, why and how we process your personal information (also referred to as personal data) when you visit our website at theexploit.co ("Site"), subscribe to our newsletter, submit content, and your rights and how to contact us if you need to.

Our contact details are set out at the end of this policy (see the 'How to contact us?' section). We are the controller in relation to the personal data processed in accordance with this policy (except where this policy explains otherwise) – this means we make decisions about why and how your personal information is being processed.

Please read this policy carefully and ensure that you understand it, as it explains our views and practices regarding your personal information and how we will treat it.

This policy should be read together with our Terms and Conditions.

What personal information do we collect and how do we collect it?

Depending upon your use of our Site, newsletter subscription, and content submissions, we may collect and process some or all of the personal information set out below.

Information we collect about you:

Identity Information consists of your name, email address, and social media handles. We collect this information when you:

  • Subscribe to The Exploit newsletter
  • Submit content (articles, comments, tips, images) through our Site, email, or social media
  • Fill out our contact forms
  • Communicate with us by email or social media
  • Enter competitions or participate in surveys

Communication Information includes any personal information that is not Identity Information that you include in your communications with us, including:

  • Feedback you provide about our content or services
  • Content you submit for publication
  • Comments on our social media posts
  • Inquiries or support requests

Submission Content includes any content you submit to us for potential publication, which may contain:

  • Your professional background or expertise
  • Your opinions, analysis, or creative work
  • Any personal information you choose to include in your submissions

Information we receive about your use of our Site:

Technical Information includes:

  • Internet protocol (IP) address used to connect your device to the Internet
  • Browser type and version
  • Time zone setting and location
  • Browser plug-in types and versions
  • Operating system and platform
  • Device information

Usage Information encompasses:

  • Full Uniform Resource Locators (URL)
  • Clickstream data
  • Content you viewed or searched for
  • Page response times
  • Download errors
  • Length of visits to certain pages
  • Page interaction information (scrolling, clicks, mouse-overs)
  • Methods used to browse away from the page
  • Pages visited before and after our Site

Location Information may be derived from:

  • Your approximate regional location based on your IP address when you access our Site
  • Location data you provide when submitting content

Information we receive from other sources:

Social Media Information includes:

  • Your social media handle and profile information
  • Information relating to your interactions with us on social media platforms
  • Public posts or comments you make on or about our content
  • Messages or content you send to our official social media accounts

We collect this information when you interact with us through third-party social media sites, such as Facebook, LinkedIn, and X (formerly Twitter).

Third-Party Analytics Information includes aggregated and anonymized data we receive from analytics providers about how users interact with our Site.

How do we use your personal information?

Under data protection law, we must always have a lawful basis for using your personal information. The following explains how we use your personal information and our lawful bases for doing so.

Newsletter delivery and communication

Purpose: To send you The Exploit newsletter, respond to your enquiries, and manage your subscription.

Data used: Identity Information, Communication Information

Lawful basis: Performance of contract (newsletter subscription), or our legitimate interest in ensuring your questions are answered and you have a great user experience.

Retention: Until you unsubscribe or we cease operations of The Exploit newsletter.

Content publication and management

Purpose: To review, edit, publish, and manage user-submitted content on The Exploit.

Data used: Identity Information, Submission Content, Communication Information

Lawful basis: Performance of contract (based on submission agreement in our Terms and Conditions), or our legitimate interests in operating and maintaining our publication.

Retention: Published content and associated information is retained indefinitely in accordance with the license granted in our Terms and Conditions. Unpublished submissions are retained for 24 months unless you request earlier deletion. If you exercise your right to erasure, we will remove or anonymize your personal information while retaining the substantive (non-personal) content under the intellectual property license you granted.

Marketing communications about Maze

Purpose: To send you information about Maze AI Limited's services that we think you might be interested in.

Data used: Identity Information

Lawful basis: Our legitimate interests in running our business and showing you services that might be of interest to you, or your consent where required by law.

Retention: Until you opt out of marketing communications or we cease marketing activities.

Your rights: You can opt out of marketing communications at any time while remaining subscribed to The Exploit newsletter. Each marketing email contains an unsubscribe link.

Site content delivery and optimization

Purpose: To deliver relevant Site content to you in the most effective manner for you and your device, and to improve our Site's performance and user experience.

Data used: Technical Information, Usage Information, Location Information

Lawful basis: Our legitimate interests in ensuring Site visitors have a great user experience when accessing and using our Site.

Retention: Technical and usage data is retained for 26 months. Aggregated analytics data is retained indefinitely.

Site security and analysis

Purpose: To keep our Site safe and secure, prevent fraud and abuse, and analyze usage patterns to improve our services.

Data used: Technical Information, Usage Information

Lawful basis: Our legitimate interests in network security, protecting our Site and users, and improving our services.

Retention: Security logs are retained for 12 months. Aggregated analytics data is retained indefinitely.

Social media engagement

Purpose: To engage with our community on social media, respond to comments and messages, and share content on social media platforms.

Data used: Social Media Information, Communication Information

Lawful basis: Our legitimate interests in building our audience, engaging with our community, and promoting our content.

Retention: We retain records of significant social media interactions for 24 months. Public posts remain visible as per the social media platform's policies.

Copyright and legal compliance

Purpose: To process copyright complaints, DMCA notices, and other legal requests; to comply with our legal and regulatory obligations; and to bring and defend legal claims.

Data used: Identity Information, Communication Information, and any information provided in complaints or legal notices.

Lawful basis: Compliance with legal obligations, or our legitimate interest in defending ourselves against claims and enforcing our rights.

Retention: Copyright complaints and legal notices are retained for 7 years from resolution. Active legal matters are retained until the matter is closed plus 7 years.

Data subject rights requests

Purpose: To process your requests to exercise data protection rights (access, rectification, erasure, etc.).

Data used: Identity Information and any information relevant to your request.

Lawful basis: Compliance with legal obligations under UK GDPR and EU GDPR.

Retention: Records of data subject requests are retained for 3 years from completion.

Consent management and regional compliance

Purpose: To determine the applicable privacy regime (for example, EU/UK GDPR or the California Consumer Privacy Act) based on your approximate location and to apply the appropriate default cookie settings before Google Tag Manager loads.

Data used: Technical Information (including IP-derived region headers), Location Information, and the consent preferences you save in our banner.

Lawful basis: Our legal obligations under GDPR/UK GDPR and CPRA as well as our legitimate interests in providing a compliant service while respecting your privacy choices.

Retention: We store a non-personal `tex_consent_region` cookie for 24 hours to remember your regional defaults and keep your consent settings in your browser's local storage until you delete them.

Marketing

Where permitted by our legitimate interest or with your prior consent where required by law, we will use your personal information for marketing analysis and to provide you with:

  • The Exploit newsletter content
  • Marketing communications about Maze AI Limited's services by email

Opting Out of Marketing

You have the right to opt out of marketing communications at any time:

  • The Exploit newsletter: Use the "unsubscribe" link at the end of each newsletter, or email the-exploit@mazehq.com
  • Maze marketing: Use the "unsubscribe" link at the end of each marketing email, or email the-exploit@mazehq.com

Opting out of Maze marketing does not affect your subscription to The Exploit newsletter, and vice versa.

Email Compliance

We comply with CAN-SPAM Act requirements for commercial emails:

  • We clearly identify promotional emails as advertisements where required
  • We include our physical address in all commercial emails
  • We honor opt-out requests promptly (within 10 business days)
  • We monitor email sending practices of third parties acting on our behalf

How long will we keep your personal information?

We will only retain your personal information for as long as reasonably necessary to fulfill the purposes we collected it for, including for the purposes of satisfying any legal, regulatory, tax, accounting or reporting requirements. We may retain your personal information for a longer period in the event of a complaint or if we reasonably believe there is a prospect of litigation in respect to our relationship with you.

When personal information is no longer needed, we will securely delete or anonymize it.

Retention Schedule

Data TypeRetention PeriodReason
Newsletter subscriber dataUntil unsubscribe or cessation of newsletterContractual obligation
Published submissions (content)IndefinitelyLicense granted in Terms; business records
Published submissions (personal data)As above, unless erasure requestedGDPR rights honored
Unpublished submissions24 months from submissionPotential future use
Marketing consent recordsUntil opt-out + 3 yearsLegal compliance
Technical/usage data26 monthsAnalytics and improvement
Security logs12 monthsSecurity purposes
Consent region cookie (`tex_consent_region`)24 hoursMaintain regional default cookie compliance between page views
Copyright complaints7 years from resolutionLegal compliance
Data subject request records3 years from completionLegal compliance
Legal/litigation recordsDuration of matter + 7 yearsLegal compliance

Automated Decision-Making and Profiling

We do not use your personal information for automated decision-making or profiling that produces legal effects or similarly significantly affects you.

We may use automated systems for:

  • Basic email segmentation (e.g., separating newsletter subscribers from marketing recipients)
  • Analytics to understand content preferences and site usage patterns
  • Spam filtering and security threat detection

These activities do not involve consequential automated decisions about you. You have the right to object to these processing activities.

How and where is your personal information stored?

We may store some or all of your personal information in countries outside of the UK and European Economic Area ("EEA"). We may transfer your personal information outside of the EEA or UK to:

  • Store it
  • Enable us to provide our services to you
  • Where we are legally required to do so
  • Facilitate the operation of our group of businesses, where it is in our legitimate interests, and we have concluded these are not overridden by your rights

International Transfer Safeguards

When we transfer your personal information outside the UK/EEA, we ensure appropriate safeguards are in place:

  • For UK transfers: We use the UK International Data Transfer Agreement (IDTA) or UK Addendum to EU Standard Contractual Clauses, as approved by the UK Information Commissioner's Office.
  • For EU transfers: We use Standard Contractual Clauses approved by the European Commission.
  • Adequacy decisions: Where possible, we transfer data to countries subject to adequacy decisions by the UK Government or European Commission.
  • Service providers: Our email delivery, hosting, and analytics providers may process data in the United States, Europe, and other jurisdictions. We ensure all processors implement appropriate technical and organizational measures to protect your data.

Who do we share your personal information with?

We may share your personal information with:

Group companies:

Maze AI Limited and any subsidiaries or affiliates, who may process your personal information for the purposes set out in this policy.

Service providers who process data on our behalf:

  • Email delivery services (newsletter and marketing distribution)
  • Website hosting providers
  • Cloud storage providers
  • Analytics services (website usage and email campaign analytics)
  • IT support and security services
  • Customer relationship management (CRM) systems
  • Content delivery networks (CDNs)

Analytics and search providers:

  • Google Analytics – helps us understand how visitors use our Site
  • Other analytics services that assist in optimization of our Site and services

Professional advisors:

Legal advisors, accountants, auditors, and consultants who provide professional services to us.

Business transfers:

Prospective buyers, investors, or successors in the event we sell our business or assets.

Legal obligations:

Law enforcement, regulators, courts, or other public authorities when required by law or to protect rights, property, or safety.

With your consent:

Any other third parties where you have provided explicit consent.

We require all third parties to respect the security of your personal information and to treat it in accordance with the law. We do not allow our service providers to use your personal information for their own purposes and only permit them to process your personal information for specified purposes and in accordance with our instructions.

Third-Party Websites and Services

Our Site may contain links to third-party websites, plug-ins, and applications. Clicking on those links or enabling those connections may allow third parties to collect or share data about you.

We do not control these third-party websites and are not responsible for their privacy practices. When you leave our Site, we encourage you to read the privacy policy of every website you visit.

When you use social media sharing features on our Site, the social media platform may collect information about you. This is governed by the social media platform's own privacy policy, not this policy.

Cookies and Similar Technologies

We use cookies and other similar technologies to collect and store certain information about you, which includes your personal information. These technologies help us distinguish you from other users of our Site, provide you with a better user experience, and allow us to improve our Site.

To comply with global privacy requirements we apply region-specific defaults. Visitors in the EU/EEA, UK, Switzerland, and CPRA-covered US states (California, Colorado, Connecticut, Utah, and Virginia) see non-essential cookies set to "off" until you opt in. Visitors in other US states receive analytics cookies by default but can disable marketing cookies. Visitors elsewhere receive analytics and marketing cookies by default unless you opt out. Regardless of your region, you can always change your mind by reopening the cookie settings panel.

We store your consent preferences in your browser's local storage under the key `cookie_consent_preferences`. These records stay on your device and are only read when deciding which Google Tag Manager tags to fire; they are not transmitted to our servers unless required by law.

What are cookies?

Cookies are small text files that are placed on your device when you visit a website. They are widely used to make websites work more efficiently and provide information to website owners.

Types of cookies we use:

Essential cookies (always active):

  • Session cookies: Allow you to navigate the Site and use essential features
  • Security cookies: Help detect and prevent security risks
  • Load balancing: Ensure the Site remains stable and available

These cookies are necessary for the Site to function and cannot be disabled.

Analytics cookies (optional):

  • Google Analytics: We use Google Analytics to understand how visitors use our Site, which pages are most popular, and how users navigate through the Site
  • Performance monitoring: Helps us identify and fix technical issues
  • Conversion tracking: Helps us understand which content drives newsletter subscriptions

Preference cookies (optional):

  • Cookie consent preferences: Remember your cookie choices
  • Display preferences: Remember your display settings (e.g., dark mode if we implement it)

Marketing cookies (optional):

  • Email campaign tracking: If you click links in our newsletter, we may use cookies to track which content interested you
  • Social media pixels: May be present if you use social sharing features

Cookie retention periods:

  • Session cookies: Deleted when you close your browser
  • Analytics cookies: Up to 26 months
  • Preference cookies: Up to 12 months
  • Marketing cookies: Up to 13 months

Managing cookies:

When you first visit our Site, you will see a cookie banner asking for your consent to use non-essential cookies. You can:

  • Accept all cookies
  • Accept only essential cookies
  • Manage preferences for different cookie categories

You can also manage cookies through your browser settings:

  • Chrome: Settings > Privacy and security > Cookies
  • Firefox: Settings > Privacy & Security > Cookies and Site Data
  • Safari: Preferences > Privacy > Cookies and website data
  • Edge: Settings > Cookies and site permissions > Cookies

Please note that blocking some cookies may impact your experience of our Site.

Third-party cookies:

Some cookies may be set by third-party services:

  • Google Analytics: See Google's privacy policy at policies.google.com/privacy
  • Social media platforms: If you interact with social sharing buttons

We do not control third-party cookies. Please review the relevant third-party privacy policies for more information.

Do Not Track signals:

Some browsers have a "Do Not Track" feature. Our Site does not currently respond to Do Not Track signals, but you can control cookies through the methods described above.

Your Rights Under Data Protection Law

Under UK GDPR, EU GDPR, and other applicable data protection laws, you have the following rights regarding your personal information:

Right to be informed

You have the right to be informed about the collection and use of your personal information. This privacy policy provides that information.

Right of access

You have the right to obtain:

  • Confirmation that we are processing your personal information
  • Access to your personal information
  • Information about how we use your personal information

You can request a copy of your personal information by contacting the-exploit@mazehq.com.

Right to rectification

You have the right to have inaccurate personal information corrected and incomplete personal information completed. Contact the-exploit@mazehq.com to request corrections.

Right to erasure ("right to be forgotten")

You have the right to request deletion of your personal information in certain circumstances:

  • The personal information is no longer necessary for the purposes it was collected
  • You withdraw consent (where processing was based on consent)
  • You object to processing and there are no overriding legitimate grounds
  • The personal information was unlawfully processed
  • The personal information must be erased to comply with a legal obligation

Important limitation: If you submitted content for publication, the intellectual property license granted in our Terms and Conditions survives erasure. We will remove or anonymize your personal information from published content, but may retain the substantive (non-personal) content itself.

Right to restriction of processing

You have the right to request that we restrict processing of your personal information in certain circumstances:

  • You contest the accuracy of the personal information
  • Processing is unlawful but you don't want erasure
  • We no longer need the personal information, but you need it for legal claims
  • You have objected to processing and verification is pending

Right to data portability

Where processing is based on consent or performance of contract, and carried out by automated means, you have the right to receive your personal information in a structured, commonly used, and machine-readable format, and to transmit it to another controller.

Right to object

You have the right to object to processing based on legitimate interests or for direct marketing purposes:

  • Marketing: You can object to marketing at any time by clicking "unsubscribe" in emails or contacting the-exploit@mazehq.com
  • Legitimate interests: You can object to processing based on our legitimate interests. We will stop processing unless we have compelling legitimate grounds that override your rights

Right to withdraw consent

Where processing is based on your consent, you have the right to withdraw consent at any time. This does not affect the lawfulness of processing before consent was withdrawn.

  • Newsletter: Unsubscribe at any time using email links or contact the-exploit@mazehq.com
  • Cookies: Manage preferences through our cookie banner or browser settings
  • Marketing: Opt out using links in emails or contact the-exploit@mazehq.com

Right to lodge a complaint

You have the right to lodge a complaint with your relevant data protection authority:

How to exercise your rights

To exercise any of these rights, please contact us at:

  • Email: the-exploit@mazehq.com
  • Post: Data Protection Officer, Maze AI Limited, 45 Crescent Lane, London, SW4 9PT, United Kingdom

We will respond to your request within one month, though we may extend this by two additional months for complex requests. We will inform you of any extension and the reasons for delay.

We may need to verify your identity before processing certain requests. We will not charge a fee unless your request is manifestly unfounded, excessive, or repetitive.

California Privacy Rights (CCPA)

If you are a California resident, you have additional rights under the California Consumer Privacy Act (CCPA):

Categories of personal information we collect:

  • Identifiers (name, email, IP address)
  • Internet activity (browsing history, interactions with our Site)
  • Geolocation data (approximate location from IP address)
  • Professional information (if included in submissions)
  • Inferences (preferences derived from your activity)

Your California rights:

Right to know:

You can request details about the personal information we have collected about you in the past 12 months, including:

  • Categories of personal information collected
  • Sources from which personal information was collected
  • Business or commercial purpose for collecting
  • Categories of third parties with whom we share personal information
  • Specific pieces of personal information collected

Right to delete:

You can request deletion of personal information we have collected from you, subject to certain exceptions.

Right to opt-out of sale:

We do not sell your personal information as defined by CCPA.

Right to non-discrimination:

We will not discriminate against you for exercising your CCPA rights.

How to exercise California rights:

Email: the-exploit@mazehq.com with "California Privacy Request" in the subject line

We will verify your identity and respond within 45 days (may be extended by an additional 45 days if needed).

Authorized agents:

You may designate an authorized agent to make requests on your behalf. The agent must provide proof of authorization.

Personal information we disclose:

We disclose personal information to service providers for business purposes as described in the "Who do we share your personal information with?" section. We do not sell personal information.

Data Breach Notification

We have implemented appropriate technical and organizational measures to protect your personal information. However, no system is completely secure.

Our response to data breaches:

If we discover a data breach that poses a risk to your rights and freedoms, we will:

  • Assess the nature and severity of the breach
  • Take immediate steps to contain and remedy the breach
  • Notify the relevant data protection authority within 72 hours (UK ICO and/or EU authorities as applicable)
  • Notify affected individuals without undue delay if the breach poses a high risk to their rights and freedoms

What we will tell you:

Our notification will include:

  • Nature of the breach and categories of data affected
  • Likely consequences of the breach
  • Measures we have taken or propose to take to address the breach
  • Contact information for our Data Protection Officer
  • Where appropriate, measures you can take to protect yourself

We maintain detailed incident response procedures and conduct regular security reviews to minimize the risk of breaches.

Children's Privacy

Our Site is not intended for children under 13 years of age. We do not knowingly collect personal information from children under 13. The Exploit newsletter and content submission features are only available to individuals 18 years or older.

If you are between 13 and 17 years old, you may browse the Site only with the consent and supervision of a parent or guardian.

If we become aware that we have collected personal information from a child under 13 without parental consent, we will take steps to delete that information as quickly as possible.

If you believe we have collected information from a child under 13, please contact us immediately at the-exploit@mazehq.com.

Changes to this Policy

This policy was last updated on the date mentioned at the top of it. We may change this policy from time to time. This may be necessary, for example, if the law changes, or if we change our business in a way that affects your personal information.

How we notify you of changes:

When we make changes to this policy, we will:

  • Update the "Last Updated" date at the top
  • Post the revised policy on our Site at theexploit.co/privacy
  • For material changes that significantly affect your rights, we will provide additional notice by:
    • Sending an email to newsletter subscribers (at least 14 days before changes take effect where practicable)
    • Displaying a prominent notice on our Site
    • Requesting renewed consent where required by law

Your continued use:

Your continued use of the Site after changes to this policy constitutes your acceptance of the revised policy. If you do not agree with changes, please stop using the Site and contact us to exercise your data protection rights.

How to Contact Us

We have appointed a Data Protection Officer responsible for overseeing questions about this policy and data protection matters.

Data Protection Officer

Maze AI Limited

45 Crescent Lane

London, SW4 9PT

United Kingdom

Email:

Response times:

We aim to respond to all inquiries within 5 business days and to data subject rights requests as required by law.