Privacy, in plain words.

The full legal policy lives below the plain-English version โ€” but here's what actually matters, the way we'd want it explained to us.

We don't keep your data

The only thing we store is your account โ€” your email and billing. Your report and the data behind it are destroyed on a 30-day clock. Not hidden โ€” shredded. Never a permanent profile.

You hold the key

Your report is encrypted to a key tied to you. Delete it, or let the 30 days run out, and it becomes permanently unrecoverable.

We never sell or train on it

Your data is not a product we resell, and it never trains a model. We can't sell what we delete โ€” that's the point.

Only your own exposure

We only run a full report on an address you've verified is yours. You can't use dirigent to look someone else up.

Only public data

We use the same public sources an attacker would โ€” disclosed breaches, public profiles, public records. Nothing private, nothing past a login, every finding traceable to its source.

DRAFT โ€” pending legal review & entity details. Not contractual until the bracketed fields are completed.

1. Controller

[LEGAL_ENTITY], registered at [REGISTERED_ADDRESS], KvK [KVK_NUMBER], VAT [VAT_NUMBER].
Contact: [CONTROLLER_CONTACT].
Data Protection Officer: [DPO_OR_NONE].

2. Data we process

Account data โ€” your email address and billing metadata (payment reference, amount, currency, card last four digits) supplied when you create an account or make a purchase.

Transient OSINT โ€” publicly available information (disclosed breach records, public social-profile data, public records) fetched at report-build time, processed entirely in-memory, and never written to persistent storage in raw form.

Encrypted report โ€” findings, sources, and profile data derived from the OSINT run, encrypted under a per-user cryptographic key and stored server-side for up to 30 days. The key is destroyed at the end of the retention window; thereafter the ciphertext is permanently unreadable.

3. Lawful bases (GDPR Art. 6)

Consent (Art. 6(1)(a)) โ€” processing your exposure data to build and deliver the report. You may withdraw consent at any time by requesting deletion; withdrawal does not affect lawfulness of prior processing.

Contract / legal obligation (Art. 6(1)(b) and (c)) โ€” processing billing records necessary to perform the purchase contract and to comply with statutory bookkeeping requirements under applicable law.

4. Retention

Your encrypted report is crypto-shredded 30 days after the report is built, or immediately on your request โ€” whichever comes first. Once shredded, the data is unrecoverable.

Billing records (payment reference, amount, currency, card last four digits) are retained for approximately 7 years to satisfy statutory bookkeeping duties under [GOVERNING_LAW].

OTP / verification codes are transient and stored only as a one-way hash; they are purged once used or expired.

5. Your rights

Under the GDPR you have the right to: access your personal data and receive a copy (export); erasure ("delete now") โ€” we will crypto-shred your report and delete your account data, subject to billing retention obligations; rectification of inaccurate data; object to processing; withdraw consent at any time; and lodge a complaint with a supervisory authority in the EU member state of your habitual residence, place of work, or the place of the alleged infringement.

To exercise any right, email [CONTROLLER_CONTACT]. We will respond within 30 days.

6. Sub-processors and third-party transfers

We use the following sub-processors to deliver the service:

Stripe โ€” payment processing (card data handled entirely by Stripe; we receive only the billing metadata listed above).
Resend โ€” transactional email delivery.
Have I Been Pwned (HIBP) โ€” public breach-record lookup.
Apify โ€” public-profile collection.
Anthropic โ€” AI-assisted analysis of collected data.
LinkedIn โ€” OAuth identity verification for connected social accounts.

Some processors operate outside the European Economic Area. Transfers are made under appropriate safeguards (e.g. EU Standard Contractual Clauses or an adequacy decision). You may request details of the safeguards by contacting [CONTROLLER_CONTACT].

7. No sale; no model training

We never sell, rent, or broker your personal data to third parties. We never use your data โ€” in identifiable or aggregated form โ€” to train machine-learning models, including the Anthropic models we use for analysis.

8. Security

Reports are encrypted at rest under per-user keys, and each key is destroyed when the report's 30-day window ends or you delete it, making the report permanently unrecoverable. All data in transit is protected by TLS. Access to production systems is restricted. No security measure is infallible; we will notify you of any breach affecting your personal data as required by law.

9. Cookies and tracking

We use only functional cookies strictly necessary to operate the service (session management, CSRF protection). We do not use advertising trackers or analytics cookies.

10. Changes to this policy

We may update this policy. Material changes will be communicated by email to registered users at least 14 days before they take effect. Continued use after the effective date constitutes acceptance.

11. Effective date

Effective: [POLICY_EFFECTIVE_DATE]. Document version: 2026-06-17.