Legal
Privacy Policy
Effective date: 2026-08-06
This Privacy Policy explains how CybSenseSecure (legal entity details pending) (“we”, “us”) processes personal data when you use CybSenseSecure at https://cybsensesecure.com. We aim to comply with the EU General Data Protection Regulation (GDPR) and applicable Bulgarian law.
Controller identity details will be completed when the trading entity (UIC/EIK and registered address) is confirmed.
1. Data controller
Controller: CybSenseSecure (legal entity details pending)
Address: Address to be confirmed - Bulgaria, Bulgaria
Registration: UIC / EIK pending
Contact: billing@cybsensesecure.com
2. Data we collect
- Account data - email, name (if provided), authentication identifiers (via Clerk)
- Billing data - processed by Stripe (card details are not stored on our servers); we store plan status, customer and subscription IDs
- Usage data - feature usage, IOC lookups, watchlist keywords, dark web scan inputs you submit, cases you create
- Technical data - IP address, browser type, approximate location derived from IP, logs for security and reliability
- API keys you choose to store - third-party keys you enter in Settings to unlock providers
- Communications - support emails you send us
3. Purposes and legal bases (GDPR)
- Provide the Service - contract performance (Art. 6(1)(b))
- Billing and fraud prevention - contract and legitimate interests (Art. 6(1)(b), 6(1)(f))
- Security, abuse prevention, logs - legitimate interests (Art. 6(1)(f))
- Legal obligations - e.g. accounting records (Art. 6(1)(c))
- Product improvement - aggregated / limited analytics under legitimate interests where applicable
4. Processors and recipients
We use specialized providers (processors) such as:
- Clerk - authentication
- Stripe - payments and subscriptions
- Vercel - application hosting
- Neon (or configured database host) - application database
- Third-party intel APIs - only when you use features that call them (and with your keys where required)
These providers process data under their terms and appropriate safeguards. Some may process data outside the EEA with Standard Contractual Clauses or equivalent mechanisms.
5. Retention
We retain account and subscription records for as long as your account is active and as required for legal, tax, and dispute purposes afterward. Security logs are retained for a limited period. You may request deletion subject to legal holds.
6. Security
We apply technical and organizational measures appropriate to the risk (access control, TLS in transit, environment isolation). No method of transmission or storage is 100% secure.
7. Your rights
Where GDPR applies, you may have rights to access, rectification, erasure, restriction, portability, and objection, and to lodge a complaint with a supervisory authority (in Bulgaria: Commission for Personal Data Protection). To exercise rights, email billing@cybsensesecure.com.
8. Cookies
We use essential cookies and similar technologies required for authentication and security. We do not use third-party advertising cookies by default.
9. Children
The Service is not directed to children under 16. We do not knowingly collect their data.
10. Changes
We may update this Policy by posting a new version with a revised effective date. Material changes may be highlighted in the product or by email where appropriate.
11. Contact
Privacy questions: billing@cybsensesecure.com