GDPR & Data Protection
Our approach to processing personal data under the GDPR and equivalent data protection regimes.
This document is a structured placeholder and should be reviewed and finalized by legal counsel before being relied upon.
Controller & Processor Roles
For breach intelligence processed on behalf of customers, the customer is the data controller and StealerHunt acts as a data processor, processing service data only on documented instructions under the data processing agreement (DPA).
For website visitor data and direct business contacts, StealerHunt acts as the controller as described in our Privacy Policy.
Data Processing Agreement
A DPA incorporating GDPR Article 28 requirements — subject matter, duration, nature and purpose of processing, categories of data subjects, subprocessor approval, assistance with data subject rights and breach notification — is available to customers as part of the services agreement. Request a copy through the contact form.
Nature of Breach Intelligence Data
Breach intelligence inherently involves personal data that has already been exposed by third-party breaches (for example, leaked email addresses). StealerHunt's design principles for this data are:
- processing is limited to assets the customer is authorized to monitor,
- evidence is masked by default; full values are restricted and logged,
- data is segregated per customer organization (tenant isolation),
- retention follows the customer agreement, with deletion on termination.
International Transfers
Where personal data is transferred outside the EEA/UK, transfers rely on appropriate safeguards such as Standard Contractual Clauses. The current hosting and transfer topology is documented for customers in the DPA and subprocessor list.
Data Subject Requests
Requests relating to service data are handled in cooperation with the customer (controller). Where StealerHunt is the controller, requests can be made via the contact form and will be answered within statutory timelines.
Personal Data Breach Notification
StealerHunt maintains an incident response process. Confirmed personal data breaches affecting customer service data are notified to the affected customer without undue delay, with the information required for the customer's own regulatory obligations.