Privacy Policy
How the Vulscan service handles personal data — what we process, why, for how long, and what rights you have.
1. Who we are
The controller of personal data and the operator of the Vulscan service is HRUBY Software s.r.o., with its registered office at Navrátilova 666/7, Nové Město, 110 00 Praha 1, Czech Republic, IČO 05131375, DIČ CZ05131375, registered in the Commercial Register kept by the Municipal Court in Prague.
Contact for personal-data matters: hello@vulscan.app.
We have not appointed a Data Protection Officer — the law does not require us to do so. Inquiries are handled directly by the operator at the address above.
2. The free scanner — what we process
When you run a domain scan on vulscan.app, we process:
- the name of the domain you entered (e.g.
mycompany.com), - the date and time of the first and last scan,
- the aggregate severity of the findings,
- a technical source identifier for the record.
This data is used to operate the service and to power the public, aggregated counter on the home page. We do not publish individual domain records — we show only aggregate totals. A record (domain + time + severity) cannot be linked to a specific person.
The scan is passive — it only reads information that the website itself makes publicly available to every visitor. We perform no logins and no intrusive testing.
Legal basis: legitimate interest (Art. 6(1)(f) GDPR) — operating and promoting a free service.
3. Requesting a PDF report and the newsletter
After a scan, you may voluntarily have a PDF report sent to your email. In that case we process your email address, proof of consent (the ticked checkbox), and the relevant domain and time.
We use the email to send the report and an occasional newsletter with tips on securing your website and related offers. Consent is voluntary, is not a condition of the scan, and you may withdraw it at any time — via the link in the footer of every email or by writing to hello@vulscan.app. Withdrawing consent does not affect a report you have already requested. We do not sell or pass on contacts for third-party marketing.
Legal basis: consent (Art. 6(1)(a) GDPR).
4. Trezor — secure handover of credentials
If you use the Vulscan Trezor tool to hand over access credentials, their contents are encrypted directly in your browser before being sent. Only the encrypted package is stored on our server, and it cannot be read on the server. We delete the package after it is collected, and no later than 30 days.
Legal basis: performance of a contract, or alternatively a legitimate interest in a secure means of handover (Art. 6(1)(b) and (f) GDPR).
5. Watch — paid monitoring
The continuous monitoring service (if you use it) processes your email, the monitored domain, and subscription identifiers. Payments are processed by the payment gateway provider; payment-card details never reach us. The details are governed by the terms of service for that service.
Legal basis: performance of a contract (Art. 6(1)(b) GDPR) and compliance with legal obligations for accounting and tax documents (Art. 6(1)(c) GDPR).
6. If we reached out to you by email
This section is the notice under Art. 14 GDPR for cases where we contacted you to alert you to the security configuration of your website without you having provided your data to us yourself.
Where we got your contact details
We obtained your email address from publicly available sources
— usually directly from your company's website (a contact page, a
mailto: link), or from the public Commercial Register or the WHOIS
registry. We do not use purchased contact databases.
What data we process
The domain name, the contact email, your company's identification details from the public ARES register (name, IČO, registered office, legal form, line of business), and the results of a passive security scan of your website.
Why
To give you a one-time alert about specific, publicly detectable security weaknesses on your website. The email contains no offer of services.
Legal basis
Legitimate interest (Art. 6(1)(f) GDPR) — informing website operators about security risks in their web presence. We assessed that this interest prevails and that the intrusion into your privacy is minimal: we work only with business and public data, we reach out once, and we offer immediate unsubscription.
Our scan is passive
We read only what your website itself makes publicly available. We do not verify anything beyond the ordinarily visible configuration, we do not try passwords, and we perform no intrusive testing.
How to unsubscribe
At any time — via the link in the email, the unsubscribe button in the message header, or by replying to the email. Against processing for direct-marketing purposes you have the right to object at any time; once you exercise it, we add you to the unsubscribe list and do not contact you again.
7. What we do not process
For the free scanner, we fundamentally do not store:
- visitors' IP addresses (apart from short-lived operational logs — see Section 9),
- cookies, tracking pixels, or browser fingerprints,
- browser headers or referring pages,
- any link between a specific scan and a specific person.
8. Cookies and browser storage
Vulscan uses no cookies that require consent. For traffic measurement we use the Umami tool, which we run on our own self-hosted instance in the EU. It works without cookies and without storing IP addresses or personal identifiers.
The website stores in your browser's memory (localStorage) only small functional data — your language preference and, if you requested a report, your email address, so you don't have to be asked for it again next time. This data stays only in your browser, is not sent to the server, and you can delete it in your browser settings.
9. How long we keep data
| Data | Retention period |
|---|---|
| Aggregated counter on the home page | no time limit (non-personal data) |
| Record of a domain scan | at most 24 months, then erased |
| Email from a report request / newsletter | until consent is withdrawn, at most 12 months of inactivity |
| Trezor package | until collected, at most 30 days |
| Live-chat conversation | at most 12 months |
| Infrastructure operational logs (AWS) | at most 14 days |
| Outreach data — not yet contacted | at most 12 months |
| Outreach data — contacted, no response | at most 12 months from sending |
| Unsubscribe list of contacts | no limit — necessary to permanently honour unsubscriptions |
| Accounting and tax documents (paid services) | for the period required by law |
10. Processors and data transfers
We do not sell data and do not pass it on for third-party marketing. Only the following providers take part in the processing as processors:
- Amazon Web Services EMEA SARL (Luxembourg) — operation of the server infrastructure (Lambda, DynamoDB, SES, S3, CloudFront) in the EU region (Frankfurt, Germany), including AI model inference for the live-chat assistant (Amazon Bedrock, EU regions only).
- The payment gateway provider — payment processing for paid services.
Traffic measurement is provided by Umami running on our own self-hosted instance in the EU — so we do not pass traffic data on to any third party.
If you write in our live chat while the AI assistant is handling it, the text of your messages is processed by an AI model run on our AWS infrastructure in the EU (Amazon Bedrock). Before processing, we automatically strip email addresses and other identifiers; messages are not used to train AI models. The legal basis is our legitimate interest (Art. 6(1)(f) GDPR) in providing visitor support; you can object at any time (Art. 21) and can always ask for a human agent.
Data processing takes place within the EU. Where AWS or its sub-processors exceptionally access data from outside the EU (e.g. for support), this is governed by Standard Contractual Clauses under the AWS Data Processing Addendum.
11. Your rights
In relation to your personal data you have the right:
- to access the data and to information on what we process about you,
- to rectification of inaccurate data,
- to erasure ("the right to be forgotten"),
- to restriction of processing,
- to object to processing based on legitimate interest, including direct marketing (we always grant an objection to marketing),
- to data portability,
- to withdraw consent wherever processing is based on consent.
You can exercise a request at hello@vulscan.app; we will handle it within one month at the latest. If you believe we are processing data in breach of the rules, you have the right to lodge a complaint with the Office for Personal Data Protection (Úřad pro ochranu osobních údajů, ÚOOÚ) (Pplk. Sochora 27, 170 00 Praha 7, uoou.gov.cz). We would appreciate it if you contacted us first — we resolve most matters right away.
12. Security
All communication is encrypted over HTTPS. Stored data is encrypted. The operator's access is protected by multi-factor authentication and limited to the necessary roles.
13. Changes
We may update this policy. The effective date in the header always corresponds to the latest version. We will announce material changes with a visible notice on the website.