ROOTCRAK · AI-founded cybersecurity

Privacy Policy

RootCrak Security BV (Belgium) · Last reviewed 2026 · EN / NL / FR

English — Privacy Policy

How we collect, use, and protect your personal data.

ROOTCRAK SECURITY BV ("we", "our", "us") is committed to protecting your privacy. This policy explains how we collect, use, and safeguard your personal data when you use our services. This static page is the agent-readable and multi-language legal reference; the interactive app may also present the same policy with language switching.

Data We Collect

Account DataEmail address, account creation date, subscription status (when you register).
Scan DataURLs you submit for scanning, scan results, vulnerability reports (stored securely).
Usage DataPages visited, features used, scan frequency (anonymized analytics).
Payment DataWe use Stripe as our payment processor. We never store full credit card details.
Support contentChat and email messages you send to support, plus contact-form inquiries.

How We Protect Your Data

Encryption in TransitAll data transmitted via TLS 1.3 encryption.
Secure StorageScan results stored in encrypted databases with access logging.
Security AuditsRegular security audits of our own infrastructure.
Access ControlsStrict access controls — only authorized personnel can view your scan data.
Data RetentionScan results stored for 12 months unless you request earlier deletion. Account and billing records may be retained longer where required for legal or dispute purposes.

Data Processing

LocationYour data is processed on secure servers in the European Union where feasible for our control plane, with processors as described below.
InfrastructureWe use Firebase (Google Cloud Platform) for authentication and datastore, which is GDPR-compliant and certified under the EU-US Data Privacy Framework. Payments are handled by Stripe. Email delivery uses our configured mail provider.
Why we processTo provide cybersecurity scanning and monitoring, authenticate users, bill paid plans, prevent abuse, meet legal obligations, and improve reliability. Legal bases include contract performance, legitimate interests in securing the service, and consent where required.
SharingWe do not sell personal data. Public verify pages and badges only publish security posture information you choose to make public for a domain.

Your rights (GDPR)

You may request access, correction, deletion, restriction, portability, or object to certain processing. Contact our Data Protection Officer at [email protected]. You may lodge a complaint with your supervisory authority. Related: Terms of Service · GDPR overview · Contact.

For privacy-related inquiries, contact our Data Protection Officer at [email protected].

Nederlands — Privacybeleid

Hoe wij uw persoonsgegevens verzamelen, gebruiken en beschermen.

ROOTCRAK SECURITY BV ("wij", "ons", "onze") hecht groot belang aan de bescherming van uw privacy. Dit beleid legt uit hoe wij uw persoonsgegevens verzamelen, gebruiken en beschermen wanneer u onze diensten gebruikt. RootCrak is een Belgische vennootschap; dit Nederlandstalige deel is bedoeld voor bezoekers en klanten die de privacyverklaring in het Nederlands willen lezen (AVG/GDPR).

Gegevens die wij verzamelen

AccountgegevensE-mailadres, datum van accountaanmaak, abonnementsstatus (bij registratie).
ScangegevensURL's die u indient voor scanning, scanresultaten, kwetsbaarheidsrapporten (veilig opgeslagen).
GebruiksgegevensBezochte pagina's, gebruikte functies, scanfrequentie (geanonimiseerde analyses).
BetalingsgegevensWij gebruiken Stripe als betalingsverwerker. Wij slaan nooit volledige creditcardgegevens op.
SupportinhoudChat- en e-mailberichten die u naar support stuurt, plus contactformulieren.

Hoe wij uw gegevens beschermen

Versleuteling tijdens transportAlle gegevens worden verzonden via TLS 1.3-versleuteling.
Veilige opslagScanresultaten worden opgeslagen in versleutelde databases met toegangsregistratie.
BeveiligingsauditsRegelmatige beveiligingsaudits van onze eigen infrastructuur.
ToegangscontrolesStrikte toegangscontroles — alleen bevoegd personeel kan uw scangegevens inzien.
GegevensbewaringScanresultaten worden 12 maanden bewaard, tenzij u eerder verwijdering verzoekt. Account- en facturatiegegevens kunnen langer worden bewaard wanneer dat wettelijk of voor geschillen noodzakelijk is.

Gegevensverwerking

LocatieUw gegevens worden verwerkt op beveiligde servers, bij voorkeur binnen de Europese Unie voor ons controleplatform, met de hieronder genoemde verwerkers.
InfrastructuurWij gebruiken Firebase (Google Cloud Platform) voor authenticatie en datastore, dat AVG-conform is en gecertificeerd is onder het EU-VS Gegevensprivacyraamwerk. Betalingen verlopen via Stripe. E-mailbezorging via onze geconfigureerde mailprovider.
DoelenHet leveren van cybersecurity-scans en monitoring, authenticatie, facturatie van betaalde plannen, misbruikpreventie, wettelijke verplichtingen en betrouwbaarheidsverbetering. Rechtsgrondslagen omvatten uitvoering van de overeenkomst, gerechtvaardigde belangen en toestemming waar vereist.
DelenWij verkopen geen persoonsgegevens. Openbare verify-pagina's en badges publiceren alleen beveiligingsinformatie die u voor een domein openbaar maakt.

Uw rechten (AVG)

U kunt inzage, correctie, verwijdering, beperking, overdraagbaarheid of bezwaar tegen bepaalde verwerking vragen. Neem contact op met onze Functionaris voor Gegevensbescherming via [email protected]. U kunt een klacht indienen bij uw toezichthoudende autoriteit. Gerelateerd: Algemene voorwaarden · AVG-overzicht · Contact.

Voor privacygerelateerde vragen kunt u contact opnemen met onze Functionaris voor Gegevensbescherming op [email protected].

Français — Politique de Confidentialité

Comment nous collectons, utilisons et protegeons vos donnees personnelles.

ROOTCRAK SECURITY BV (« nous », « notre ») s'engage a proteger votre vie privee. Cette politique explique comment nous collectons, utilisons et protegeons vos donnees personnelles lorsque vous utilisez nos services. RootCrak est une societe belge ; cette section francaise permet aux visiteurs et clients de consulter la politique de confidentialite en francais (RGPD).

Donnees que nous collectons

Donnees de compteAdresse e-mail, date de creation du compte, statut d'abonnement (lors de l'inscription).
Donnees de scanURL soumises pour scan, resultats de scan, rapports de vulnerabilites (stockes de maniere securisee).
Donnees d'utilisationPages visitees, fonctionnalites utilisees, frequence des scans (analytiques anonymisees).
Donnees de paiementNous utilisons Stripe comme processeur de paiement. Nous ne stockons jamais les details complets de carte bancaire.
Contenu supportMessages de chat et e-mails adresses au support, ainsi que les formulaires de contact.

Comment nous protegeons vos donnees

Chiffrement en transitToutes les donnees transmises via le chiffrement TLS 1.3.
Stockage securiseResultats de scan stockes dans des bases de donnees chiffrees avec journalisation des acces.
Audits de securiteAudits reguliers de notre propre infrastructure.
Controles d'accesAcces strictement controle — seul le personnel autorise peut consulter vos donnees de scan.
Retention des donneesLes resultats de scan sont conserves 12 mois sauf demande de suppression anticipee. Les donnees de compte et de facturation peuvent etre conservees plus longtemps si la loi ou un litige l'exige.

Traitement des donnees

LocalisationVos donnees sont traitees sur des serveurs securises, de preference dans l'Union europeenne pour notre plan de controle, avec les sous-traitants decrits ci-dessous.
InfrastructureNous utilisons Firebase (Google Cloud Platform) pour l'authentification et le datastore, conforme au RGPD et certifie dans le cadre du EU-US Data Privacy Framework. Les paiements sont geres par Stripe. L'envoi d'e-mails passe par notre fournisseur configure.
FinalitesFournir le scanning et la surveillance cybersécurité, authentifier les utilisateurs, facturer les offres payantes, prevenir les abus, respecter les obligations legales et ameliorer la fiabilite. Bases juridiques : execution du contrat, interets legitimes et consentement le cas echeant.
PartageNous ne vendons pas de donnees personnelles. Les pages verify publiques et badges ne publient que les informations de posture de securite que vous choisissez de rendre publiques pour un domaine.

Vos droits (RGPD)

Vous pouvez demander l'acces, la rectification, l'effacement, la limitation, la portabilite ou vous opposer a certains traitements. Contactez notre Delegue a la Protection des Donnees a [email protected]. Vous pouvez introduire une reclamation aupres de votre autorite de controle. Liens : Conditions d'utilisation · Apercu RGPD · Contact.

Pour toute demande relative a la confidentialite, contactez notre Delegue a la Protection des Donnees a [email protected].