Privacy Policy
Last updated: TBD
What we collect
| Data | Source | Purpose | Retention |
|---|---|---|---|
| Account details (email, name, password hash) | Provided by customer | Authentication and audit trail | Contract term plus 90 days |
| Brand configuration | Provided by customer | Matching | Contract term |
| Findings and evidence (domains, screenshots, HTML snapshots, registration data) | CT logs, threat feeds, RDAP, public pages | Monitoring and evidence | 24 months |
| Enquiry form (company, name, email, phone, message) | Provided by visitor | Responding to the enquiry | 24 months, or on request |
| Appeal records (domain, contact email, statement) | Provided by appellant | Review and record of handling | 36 months |
| Access IP (rate limiting, abuse prevention) | Automatic | Abuse prevention | 30 days |
What we do not do
- No third-party analytics, advertising or tracking scripts. This site loads no scripts or fonts from any external domain.
- No reCAPTCHA — our challenge is a local arithmetic question and sends nothing to any third party.
- We never collect, store or use credentials found on monitored pages.
- We display no specific domains and no personal data on public pages.
- We do not sell, rent or share customer data with other customers or third parties.
Cookie
One strictly necessary session cookie (login state), with Secure, HttpOnly and SameSite=Lax, valid for 8 hours. There are no analytics or advertising cookies, which is why this site has no cookie banner — there is nothing non-essential to consent to.
Disclosure in takedown notices
Takedown notices sent to registrars, hosts or platforms contain the reported domain, public registration data, time-limited links to the screenshot and HTML snapshot (expiring after 14 days), and the customer letter of authorisation. They contain no personal data about customer staff.
Your rights
You may request access to, correction of, or deletion of personal data we hold about you, and may object to or restrict processing. Contact us through the contact form. We respond within 30 days. If you are a flagged party, please use the appeals form instead — it is faster.
Where data is held
(TBD: to be completed once the server jurisdiction is fixed, with cross-border transfer clauses confirmed by counsel.)
Questions for counsel
- Lawful basis for processing personal data of flagged registrants obtained from WHOIS/RDAP — legitimate interest or otherwise? Is there a notification duty?
- Are the retention periods above appropriate, in particular 24 months for evidence?
- With customers across several Southeast Asian jurisdictions, do we need per-jurisdiction versions?
- Do we need to appoint a Data Protection Officer and register with the Philippine National Privacy Commission?