Privacy Policy
Draft description of how Delta Consulting handles account and scan data on the public-beta EASM service.
Draft — not counsel-approved. This is working product text for the public beta, not final Terms or Privacy Policy.
Data handling summary
What we collect
Account information (email, name, hashed password), the submitted domain and notes, consent and verification records, temporary detailed scan data and reports, and security/abuse logs.
How we use data
To provide scanning, generate and deliver reports, improve the service, contact you about your scans, and for security, abuse prevention, and legal compliance.
Retention
Free: raw scan results and temporary files are deleted shortly after report delivery (archive-then-delete). Lightweight metadata is retained for operational history. A copy of the final report is archived internally.
We keep a persistent asset inventory and copies of the PDF report and evidence pack for up to 90 days (capped at the last 12 reports per account). Nuclei raw output is still deleted immediately. Daily or continuous monitoring is a Delta managed SOC service. Data is hosted by Delta on the same platform.
Sharing
We do not sell personal data. Reports are sent only to your verified account email and our internal archive. Hetzner hosts the service, Resend handles report email, and Cloudflare Turnstile handles abuse-prevention checks when enabled; each processes the minimum data needed for that role. We may also disclose data when required by law or to protect rights and security.
Your rights
You may request access to or deletion of your account data, subject to legal and operational requirements.
Related: Terms of Service.

