Why you received an email from Vulscan
What happened
Vulscan regularly runs a passive security check of company websites — it reads only what the server already publishes to an ordinary visitor (HTTPS, headers, publicly accessible files, DNS/email records). We do not try passwords, do not bypass any protection, and do not interfere with the site in any way. When the check finds a setting worth reviewing, we send a one-time notice to the company’s contact address.
This page is linked from the email you received — it explains where we got your address, on what legal basis we process it, and what rights you have.
Where we got your contact
This outreach program currently runs only for companies registered in the Czech Republic, under Czech law. Your company’s domain came from public sources (domain registry, DNS zone data). We verified the company’s identity — name, registration number, registered seat, legal form — in the Czech public commercial register (ARES), and we only contact active commercial companies and cooperatives (s.r.o., a.s., v.o.s., k.s., and družstvo) — never private individuals or sole traders.
We did not get your email address from you. We mined it from the publicly available pages of your own domain — typically a “contact” or “about” page, or the homepage — from a mailto: link or visible text. Addresses such as gdpr@, dpo@ or abuse@ are deliberately skipped — they route to a different purpose, not to whoever can act on a website finding. We do not use WHOIS contacts.
Legal basis
Because an email address can be personal data (particularly a firstname.lastname@ shape), we process it on the basis of legitimate interest under Article 6(1)(f) GDPR — informing the operator of a company website about a security weakness that is already publicly visible to anyone who looks.
The balancing test we applied weighs three things: (1) we only contact companies, never private individuals, (2) the address was taken from where the company itself published it for the purpose of being contacted, and (3) the message is one-time, contains no offer, and the opt-out is immediate and permanent. In our assessment, the benefit — a warning about a real security weakness before someone with worse intent finds it — outweighs the minimal burden of a single email to a business contact. You can object at any time and further messages stop immediately.
What data we process
- Contact email address found on your website (and, if it contains a first and last name, that name).
- Company identification data from the Czech commercial register — name, registration number, registered seat, legal form, industry.
- The result of the passive website check — the server/site settings the message describes (this is a technical fact about the domain, not personal data about you).
We store your data with processors who provide the technical infrastructure necessary to run this service — database hosting for the contacts, findings, and opt-out list we keep, and the email-delivery provider that sends the message. All of them act as processors under Article 28 GDPR. We do not sell your data, and we do not use it for anything beyond this notice and any reply or objection you send.
How long we keep it
We keep the address only as long as necessary for the purpose above — sending the notice and handling any reply. If you object or unsubscribe, the address goes on a suppression list and we never use it to contact you again — that is the only purpose it is kept for after opting out. We do not currently run an automated deletion job for older records after a fixed number of days; if you would like full erasure rather than just a stop on further messages, write to privacy@vulscan.app and we will handle it by hand.
Your rights
- Right to object (Article 21 GDPR) — at any time, without giving a reason. The unsubscribe link is in the footer of the email you received.
- Right to access, rectification and erasure (Articles 15, 16 and 17 GDPR) — write to privacy@vulscan.app.
- Right to restrict processing (Article 18 GDPR).
- Right to lodge a complaint with your data protection supervisory authority — in the Czech Republic, the Office for Personal Data Protection (uoou.gov.cz).
The controller is Vulscan Labs s.r.o., Czech registration number (IČO) 29659191. Our full privacy notice is at vulscan.app/en/privacy.
Not a commercial pitch
The email contains no product offer, no price, and no call to purchase — it is a security notice, not marketing. We still honour the immediate, permanent opt-out described above regardless of how a given jurisdiction classifies the message. Rules on unsolicited business email vary by country, and this program currently sends only within the Czech Republic under Czech law — this page does not make a legal claim about any other country’s rules.
What Vulscan does and does not do
The check behind this message is purely passive: it reads only publicly available content, TLS/DNS metadata, and HTTP headers — exactly what any visitor or search engine already sees. We do not try login credentials, do not run penetration tests, and do not otherwise interfere with your site’s operation. You can run the same check yourself anytime at vulscan.app.