Why you received an email from Vulscan

What happened

Vulscan regularly runs a passive security check of the websites of Czech companies, sole traders and associations — it reads only what the server already publishes to an ordinary visitor (HTTPS, headers, publicly accessible files, DNS/email records). We do not try passwords, do not bypass any protection, and do not interfere with the site in any way. When the check finds a setting worth reviewing, we send a one-time notice to the published contact address.

This page is linked from the email you received — it explains where we got your address, on what legal basis we process it, and what rights you have.

Where we got your contact

This outreach program currently runs only for entities registered in the Czech Republic, under Czech law. Your website’s domain came from public sources (domain registry, DNS zone data). We verified the operator’s identity — name, registration number, registered seat, legal form — in the Czech public register of economic subjects (ARES), and we only contact active entities holding their own registration number that run the website as part of their business or association activity: commercial companies (s.r.o., a.s., v.o.s., k.s.), cooperatives, registered sole traders (OSVČ) and associations (spolky). We do not contact private individuals outside their business, sites for which we found no registration number, or public bodies such as schools, authorities and municipalities.

We did not get your email address from you. We mined it from the publicly available pages of your own domain — typically a “contact” or “about” page, or the homepage — from a mailto: link or visible text. Addresses such as gdpr@, dpo@ or abuse@ are deliberately skipped — they route to a different purpose, not to whoever can act on a website finding. We do not use WHOIS contacts.

Legal basis

Because an email address can be personal data (particularly a firstname.lastname@ shape, or one belonging to a sole trader), we process it on the basis of legitimate interest under Article 6(1)(f) GDPR — informing the operator of a website about a security weakness that is already publicly visible to anyone who looks.

The balancing test we applied weighs three things: (1) we only contact entities registered in ARES under their own registration number, never private individuals outside their business, (2) the address was taken from where the operator itself published it for the purpose of being contacted, and (3) the message is one-time, contains no offer, and the opt-out is immediate and permanent. In our assessment, the benefit — a warning about a real security weakness before someone with worse intent finds it — outweighs the minimal burden of a single email to a contact address published for business or association purposes. You can object at any time and further messages stop immediately.

What data we process

We store your data with processors who provide the technical infrastructure necessary to run this service — database hosting for the contacts, findings, and opt-out list we keep, and the email-delivery provider that sends the message. All of them act as processors under Article 28 GDPR. We do not sell your data, and we do not use it for anything beyond this notice and any reply or objection you send.

How long we keep it

We keep the address only as long as necessary for the purpose above — sending the notice and handling any reply. If you object or unsubscribe, the address goes on a suppression list and we never use it to contact you again — that is the only purpose it is kept for after opting out. We do not currently run an automated deletion job for older records after a fixed number of days; if you would like full erasure rather than just a stop on further messages, write to privacy@vulscan.app and we will handle it by hand.

Your rights

The controller is Vulscan Labs s.r.o., Czech registration number (IČO) 29659191. Our full privacy notice is at vulscan.app/en/privacy.

Not a commercial pitch

The email contains no product offer, no price, and no call to purchase — it is a security notice, not marketing. We still honour the immediate, permanent opt-out described above regardless of how a given jurisdiction classifies the message. Rules on unsolicited business email vary by country, and this program currently sends only within the Czech Republic under Czech law — this page does not make a legal claim about any other country’s rules.

What Vulscan does and does not do

The check behind this message is purely passive: it reads only publicly available content, TLS/DNS metadata, and HTTP headers — exactly what any visitor or search engine already sees. We do not try login credentials, do not run penetration tests, and do not otherwise interfere with your site’s operation. You can run the same check yourself anytime at vulscan.app.

References