Privacy Policy
What personal data we handle, why we handle it, how long we keep it, and what you can ask us to do about it.
Effective 26 August 2026
1.Two very different kinds of data
Most privacy policies describe one relationship. This one describes two, and the distinction runs through everything below.
- Account data — personal data about the people who use SINON: names, work email addresses, job titles, and what they do in the product. We are the controller for this.
- Intelligence data — material we collect from ransomware leak sites, hacking forums, messaging channels, paste sites and Certificate Transparency logs. This material frequently contains personal data about people who are not our customers and who never gave us anything: named breach victims, exposed email addresses, threat-actor aliases, and the contents of leaked records. We are also a controller for this, on the legal basis described in section 5.
Where we process personal data on a customer’s instructions — for example the watch terms they configure — we act as a processor. We process it only on those instructions, keep it confidential, apply the security measures described in section 11, and delete or return it on termination. Customers requiring a signed data processing agreement should contact us at [email protected].
2.Account data we collect
| What | Why |
|---|---|
| Name, work email, password hash | Creating and securing your account; authentication |
| Job title, team, organisation, industry, size, countries of operation | Tailoring which findings are surfaced to you |
| Domains and watch terms you configure | Matching intelligence against your organisation |
| Log data: IP address, timestamps, pages and actions, user agent | Security, abuse prevention, debugging, service reliability |
| Billing contact and payment records | Invoicing, tax and accounting obligations |
| Correspondence with us | Support and record-keeping |
We do not sell personal data, and we do not use account data for advertising or share it with advertising networks.
3.Legal bases for account data
- Contract — providing the service you signed up for, billing, and support.
- Legitimate interests — securing the platform, preventing abuse, and improving the product, balanced against your rights.
- Legal obligation — tax, accounting, and lawful requests from authorities.
- Consent — where we ask for it specifically, such as optional marketing. You can withdraw it at any time.
4.Intelligence data: what it contains
The material we collect is produced by criminals and posted in criminal venues. It routinely contains personal data, sometimes including special-category data, that was obtained unlawfully by whoever published it. Depending on the source this can include:
- names, email addresses, phone numbers and physical addresses appearing in leaked records;
- credentials, session tokens and other authentication material;
- names of organisations and named individuals claimed as victims of ransomware or extortion;
- threat-actor handles, aliases and the content of their posts and messages;
- domain registration and certificate issuance records.
We collect this material because monitoring it is the only way to warn the people and organisations it harms. We do not obtain it from the data subjects, and we do not verify the claims made in it.
5.Legal basis and safeguards for intelligence data
We process intelligence data on the basis of legitimate interests — specifically network and information security, the prevention of fraud and crime, and warning organisations and individuals of threats to them. We consider this to be a compelling interest that data subjects would reasonably expect to be pursued by a security service, and we have carried out a balancing assessment. Where the material includes special-category data, we rely on the substantial public interest condition for the prevention and detection of unlawful acts, and we process it only so far as warning the people and organisations affected requires.
To keep the intrusion proportionate we apply the following safeguards:
- Purpose limitation. Intelligence data is used only to detect and warn about threats. It is never used for marketing, profiling individuals for commercial purposes, employment screening, credit decisions, or any other assessment of a person.
- Access limitation. Customers see items matched against their own organisation’s profile. The platform is not a people-search tool and provides no facility to look up an individual.
- Minimisation. We do not republish the contents of leaked credential sets or personal records. We report the existence, source, scope and severity of an exposure.
- No re-identification. We do not enrich, combine or cross-reference intelligence data to build profiles of individuals beyond what is necessary to identify a threat to a customer.
Under Article 14(5)(b) UK/EU GDPR we do not notify each data subject whose personal data appears in this material, because doing so would be impossible or involve disproportionate effort, and in many cases would require us to contact people using data taken from a criminal dump. This policy serves as the public notice required in those circumstances.
6.Automated processing
We use automated systems, including large language models, to translate, classify, summarise and score collected material, and to decide which items are surfaced to which customer.
These decisions are about content relevance, not about people. We do not carry out automated decision-making that produces legal or similarly significant effects on an individual within the meaning of Article 22 GDPR. Classifications are heuristic and may be wrong; customers are told the reasons an item was surfaced so they can judge it themselves.
7.How long we keep things
| Data | Retention |
|---|---|
| Account and organisation profile | For the life of the account, then deleted within 90 days of closure |
| Security and access logs | [12] months |
| Billing and tax records | As required by law, typically [6–7] years |
| Intelligence data | Retained while it has value for historical threat context, reviewed periodically; removed on a successful objection under section 9 |
| Backups | Rolling [35] days, after which deletions propagate |
9.Your rights
Subject to applicable law, you may request access to your personal data, correction, deletion, restriction, portability, and you may object to processing based on legitimate interests. You may withdraw consent where we rely on it.
If your personal data appears in our intelligence data
You can object to our processing of it. Contact [email protected] with enough detail to locate the records. We will assess whether our interest in maintaining the record is overridden by your rights and, where it is, remove or restrict it.
Please note: we did not publish the material and removing it from our systems does not remove it from the criminal venue it came from. Where possible we will tell you where we observed it so you can pursue the source.
We respond within one month, extendable by two further months for complex requests. You also have the right to complain to your local supervisory authority.
10.International transfers
We and our sub-processors may process data in countries other than yours. Where personal data is transferred out of the UK/EEA we rely on adequacy decisions where available, and otherwise on Standard Contractual Clauses together with a transfer risk assessment. Details of each provider’s location are available on request at [email protected].
11.Security
We apply technical and organisational measures appropriate to the risk, including encryption in transit, access control and least privilege, row-level isolation between customer organisations, credential segregation so that collector API keys are never exposed to browsers, audit logging, and regular review.
No system is perfectly secure. If you believe you have found a vulnerability in our platform, report it to [email protected]. We will acknowledge your report, keep you updated while we investigate, and will not pursue action against good-faith research that avoids privacy violations, service degradation and data destruction.
12.Children
SINON is a business product not directed at children, and we do not knowingly collect account data from anyone under 16. Intelligence data may incidentally contain personal data about minors where a criminal dump included it; such data is subject to the same safeguards and objection rights above, and we treat removal requests concerning minors as a priority.
13.Changes
We will post material changes here and, for account holders, give notice by email or in-product notice before they take effect.
14.Contact
Privacy enquiries and rights requests: [email protected]
Sinon Security