Privacy Policy
How StealerHunt collects, uses, retains and protects personal data across this website and the StealerHunt platform.
This document is a structured placeholder and should be reviewed and finalized by legal counsel before being relied upon.
Scope
This policy applies to personal data processed when you visit this website, request a demo, or use the StealerHunt platform as an authorized user of a customer organization. It does not replace any data processing agreement (DPA) concluded between StealerHunt and a customer.
Data We Collect
Depending on how you interact with StealerHunt, we may process:
- Website data — technical information required to serve the site (IP address, browser type, requested pages) and any details you submit through the demo request form (name, work email, company, role, message).
- Account data — name, work email, role and authentication metadata for platform users provisioned by a customer organization.
- Service data — breach and credential exposure records processed on behalf of customers under the applicable services agreement. Evidence shown in the platform is masked by default.
How We Use Data
- To operate, secure and improve the website and platform.
- To respond to demo requests and other enquiries.
- To provide breach intelligence services to customer organizations.
- To meet legal, security and audit obligations.
We do not sell personal data, and we do not use customer service data for advertising.
Legal Basis for Processing
Where the GDPR or similar regulation applies, processing is based on: performance of a contract (providing the platform to customers), legitimate interest (securing our services, responding to enquiries), consent (where specifically requested), and compliance with legal obligations. Details per processing activity will be finalized with legal counsel.
Data Retention
Personal data is retained only as long as needed for the purposes described above or as required by law. Service data retention follows the schedule agreed in the customer contract; demo enquiries are retained for a limited period after the conversation concludes. Specific retention periods will be published here after legal review.
Security
We apply technical and organizational measures appropriate to the sensitivity of breach intelligence data, including encryption in transit, role-based access control, tenant isolation, audit logging and evidence masking by default. See our Trust & Security page for more detail.
Your Rights
Subject to applicable law, you may have the right to access, correct, delete or restrict processing of your personal data, to object to processing, and to data portability. Platform users provisioned by a customer should direct requests to their organization first, as the customer is the data controller for service data.
To exercise your rights regarding data controlled by StealerHunt, contact us through the contact form.
Contact
Privacy enquiries can be submitted through the contact form. A dedicated privacy contact address will be published here after legal review.