Skip to main content

Privacy Policy

Draft description of how Delta Consulting handles account and scan data on the public-beta EASM service.

Draft — not counsel-approved. This is working product text for the public beta, not final Terms or Privacy Policy.

Data handling summary

What we collect

Account information (email, name, hashed password), the submitted domain and notes, consent and verification records, temporary detailed scan data and reports, and security/abuse logs.

How we use data

To provide scanning, generate and deliver reports, improve the service, contact you about your scans, and for security, abuse prevention, and legal compliance.

Retention

Free: raw scan results and temporary files are deleted shortly after report delivery (archive-then-delete). Lightweight metadata is retained for operational history. A copy of the final report is archived internally.

We keep a persistent asset inventory and copies of the PDF report and evidence pack for up to 90 days (capped at the last 12 reports per account). Nuclei raw output is still deleted immediately. Daily or continuous monitoring is a Delta managed SOC service. Data is hosted by Delta on the same platform.

Sharing

We do not sell personal data. Reports are sent only to your verified account email and our internal archive. Hetzner hosts the service, Resend handles report email, and Cloudflare Turnstile handles abuse-prevention checks when enabled; each processes the minimum data needed for that role. We may also disclose data when required by law or to protect rights and security.

Your rights

You may request access to or deletion of your account data, subject to legal and operational requirements.

Related: Terms of Service.