This is a translation provided for your convenience. The legally binding version is the Czech original, available at vulscan.app/cs/privacy.
Data protection · effective from 3 July 2026 · version 1.1

Privacy Policy

How the Vulscan service handles personal data — what we process, why, for how long, and what rights you have.

In short When you scan a domain, we store only its name, the time, and the aggregate severity of the findings — this feeds the public counter on the home page. If you ask us to send you a PDF report, we store your email address and your consent. We do not store visitors' IP addresses, we use no cookies or tracking tools, and we do not link individual scans to specific people. If we reached out to you by email, Section 6 explains where we got your contact details and how to easily unsubscribe.

1. Who we are

The controller of personal data and the operator of the Vulscan service is HRUBY Software s.r.o., with its registered office at Navrátilova 666/7, Nové Město, 110 00 Praha 1, Czech Republic, IČO 05131375, DIČ CZ05131375, registered in the Commercial Register kept by the Municipal Court in Prague.

Contact for personal-data matters: hello@vulscan.app.

We have not appointed a Data Protection Officer — the law does not require us to do so. Inquiries are handled directly by the operator at the address above.

2. The free scanner — what we process

When you run a domain scan on vulscan.app, we process:

This data is used to operate the service and to power the public, aggregated counter on the home page. We do not publish individual domain records — we show only aggregate totals. A record (domain + time + severity) cannot be linked to a specific person.

The scan is passive — it only reads information that the website itself makes publicly available to every visitor. We perform no logins and no intrusive testing.

Legal basis: legitimate interest (Art. 6(1)(f) GDPR) — operating and promoting a free service.

3. Requesting a PDF report and the newsletter

After a scan, you may voluntarily have a PDF report sent to your email. In that case we process your email address, proof of consent (the ticked checkbox), and the relevant domain and time.

We use the email to send the report and an occasional newsletter with tips on securing your website and related offers. Consent is voluntary, is not a condition of the scan, and you may withdraw it at any time — via the link in the footer of every email or by writing to hello@vulscan.app. Withdrawing consent does not affect a report you have already requested. We do not sell or pass on contacts for third-party marketing.

Legal basis: consent (Art. 6(1)(a) GDPR).

4. Trezor — secure handover of credentials

If you use the Vulscan Trezor tool to hand over access credentials, their contents are encrypted directly in your browser before being sent. Only the encrypted package is stored on our server, and it cannot be read on the server. We delete the package after it is collected, and no later than 30 days.

Legal basis: performance of a contract, or alternatively a legitimate interest in a secure means of handover (Art. 6(1)(b) and (f) GDPR).

5. Watch — paid monitoring

The continuous monitoring service (if you use it) processes your email, the monitored domain, and subscription identifiers. Payments are processed by the payment gateway provider; payment-card details never reach us. The details are governed by the terms of service for that service.

Legal basis: performance of a contract (Art. 6(1)(b) GDPR) and compliance with legal obligations for accounting and tax documents (Art. 6(1)(c) GDPR).

6. If we reached out to you by email

This section is the notice under Art. 14 GDPR for cases where we contacted you to alert you to the security configuration of your website without you having provided your data to us yourself.

Where we got your contact details

We obtained your email address from publicly available sources — usually directly from your company's website (a contact page, a mailto: link), or from the public Commercial Register or the WHOIS registry. We do not use purchased contact databases.

What data we process

The domain name, the contact email, your company's identification details from the public ARES register (name, IČO, registered office, legal form, line of business), and the results of a passive security scan of your website.

Why

To give you a one-time alert about specific, publicly detectable security weaknesses on your website. The email contains no offer of services.

Legal basis

Legitimate interest (Art. 6(1)(f) GDPR) — informing website operators about security risks in their web presence. We assessed that this interest prevails and that the intrusion into your privacy is minimal: we work only with business and public data, we reach out once, and we offer immediate unsubscription.

Our scan is passive

We read only what your website itself makes publicly available. We do not verify anything beyond the ordinarily visible configuration, we do not try passwords, and we perform no intrusive testing.

How to unsubscribe

At any time — via the link in the email, the unsubscribe button in the message header, or by replying to the email. Against processing for direct-marketing purposes you have the right to object at any time; once you exercise it, we add you to the unsubscribe list and do not contact you again.

7. What we do not process

For the free scanner, we fundamentally do not store:

8. Cookies and browser storage

Vulscan uses no cookies that require consent. For traffic measurement we use the Umami tool, which we run on our own self-hosted instance in the EU. It works without cookies and without storing IP addresses or personal identifiers.

The website stores in your browser's memory (localStorage) only small functional data — your language preference and, if you requested a report, your email address, so you don't have to be asked for it again next time. This data stays only in your browser, is not sent to the server, and you can delete it in your browser settings.

9. How long we keep data

DataRetention period
Aggregated counter on the home pageno time limit (non-personal data)
Record of a domain scanat most 24 months, then erased
Email from a report request / newsletteruntil consent is withdrawn, at most 12 months of inactivity
Trezor packageuntil collected, at most 30 days
Live-chat conversationat most 12 months
Infrastructure operational logs (AWS)at most 14 days
Outreach data — not yet contactedat most 12 months
Outreach data — contacted, no responseat most 12 months from sending
Unsubscribe list of contactsno limit — necessary to permanently honour unsubscriptions
Accounting and tax documents (paid services)for the period required by law

10. Processors and data transfers

We do not sell data and do not pass it on for third-party marketing. Only the following providers take part in the processing as processors:

Traffic measurement is provided by Umami running on our own self-hosted instance in the EU — so we do not pass traffic data on to any third party.

If you write in our live chat while the AI assistant is handling it, the text of your messages is processed by an AI model run on our AWS infrastructure in the EU (Amazon Bedrock). Before processing, we automatically strip email addresses and other identifiers; messages are not used to train AI models. The legal basis is our legitimate interest (Art. 6(1)(f) GDPR) in providing visitor support; you can object at any time (Art. 21) and can always ask for a human agent.

Data processing takes place within the EU. Where AWS or its sub-processors exceptionally access data from outside the EU (e.g. for support), this is governed by Standard Contractual Clauses under the AWS Data Processing Addendum.

11. Your rights

In relation to your personal data you have the right:

You can exercise a request at hello@vulscan.app; we will handle it within one month at the latest. If you believe we are processing data in breach of the rules, you have the right to lodge a complaint with the Office for Personal Data Protection (Úřad pro ochranu osobních údajů, ÚOOÚ) (Pplk. Sochora 27, 170 00 Praha 7, uoou.gov.cz). We would appreciate it if you contacted us first — we resolve most matters right away.

12. Security

All communication is encrypted over HTTPS. Stored data is encrypted. The operator's access is protected by multi-factor authentication and limited to the necessary roles.

13. Changes

We may update this policy. The effective date in the header always corresponds to the latest version. We will announce material changes with a visible notice on the website.

Terms of Service → ← Back to home
Vulscan.app · hello@vulscan.app