Radark — Privacy Policy

Version 2026-08-22 · Data controller: [Legal entity name], [address], [country] · contact [privacy email].
Draft. Review with a qualified data-protection lawyer before publishing. GDPR applies (EU operator). Replace [bracketed] items.

1. What we collect

DataWhyLegal basis
Telegram user id & usernameIdentify your account, deliver alertsContract
Watch keywords / stack, filtersMatch relevant CVEsContract
Domains / assets & ownership proof / authorisation attestationsPerform authorised assessments; legal audit trailContract; legal obligation / legitimate interest
Scan & dependency results, reportsProvide the Service, history, driftContract
Repository URL and a read-only access token (encrypted at rest)Read dependency manifests for version-precise matchingContract
Terms acceptance (version, timestamp)Prove consentLegal obligation / legitimate interest
Payment referenceManage subscription (handled by the payment provider)Contract

We do not collect your source code. Only dependency manifest metadata (package names and versions) is read from connected repositories.

2. How we use it

To provide and secure the Service, deliver alerts and reports, prevent abuse, comply with law, and improve the product. We do not sell personal data.

3. Sharing & sub-processors

4. Security

Access tokens are encrypted at rest; transport is over TLS; access is restricted. Tokens are read-only and never used to write to your repositories.

5. Retention & deletion

We keep data while your account is active and as needed for the purposes above. You can delete assets, repositories and tokens at any time in the app. To delete your account and associated data, contact [privacy email]; we retain minimal records (e.g. Terms-acceptance and authorisation logs) where required to establish legal compliance.

6. Your rights (GDPR)

You may access, rectify, erase, restrict or port your data, and object to processing. Contact [privacy email]. You may lodge a complaint with the Spanish Data Protection Agency (AEPD) or your local authority.

7. International transfers

Where data is processed outside the EEA (e.g. by a sub-processor), we rely on appropriate safeguards such as Standard Contractual Clauses.

8. Changes & contact

We may update this Policy; the version/date appear above. Questions: [privacy email].