Privacy Policy
Explains how your personal data is processed under UK GDPR and KVKK standards, and our principles for hosting data in Turkey.
This policy explains how your personal data is collected under UK GDPR and KVKK standards, and the principles for hosting data in Turkey.
1. Data Controller and Scope
This policy explains the personal data processed as Data Controller on the LeakData.io platform operated by CyberVisir Solutions Ltd (the "Company"), registered in the United Kingdom (England and Wales) under company number 17215486 with registered address Suite 10826, 5 Brayford Square, London, United Kingdom, E1 0SG, and the principles for hosting that data.
2. Data Categories Collected
The following personal data categories are processed:
- Identity Information: First and last name.
- Contact Information: Email address and phone number.
- Digital Identity: Social media account names/usernames.
- First-party Product Measurement: Successful account, verification, manual security action, monitoring, integration, report and payment lifecycle outcomes are recorded in our own database with opaque internal IDs, server times and reviewed categorical fields. Search inputs, monitoring targets, breach contents and payment details are not copied into this measurement ledger.
- Optional Product Analytics: After you enable analytics cookies, reviewed product events, coarse categories such as plan tier and locale, a random browser identifier, and—while signed in—an opaque internal account ID. Analytics event and replay payloads do not include names, email addresses, search terms or their hashes, passwords, monitoring targets, breach details, full URLs, query strings, referrers, free-form errors, or user-agent fields.
3. Purpose of Processing and Legal Basis
Service data is processed under KVKK Article 5 and UK GDPR Article 6 based on the legal basis of "performance of a contract". Optional analytics is activated only after your affirmative analytics-cookie choice and is processed on the basis of that consent; you may withdraw it at any time in Cookie Settings.
- Providing the "Cybersecurity Monitoring" service by matching supplied identity and account information against breach databases.
- Sending urgent security alerts by email and enabled enterprise integration channels in the event of a possible data breach.
- Understanding aggregate signup, verification, manual security actions, monitoring adoption, and payment-backed subscription activation from first-party service outcomes so we can improve the product. Consented Amplitude data is supplementary and is not the source of full-population KPIs. Amplitude Session Replay may sample masked interface structure only on a limited set of low-risk public pages; it never starts on search, result, account, billing, admin, monitoring, report, API-key, webhook, or integration-configuration screens.
4. No Data Sale Commitment and Security
Assets you enter for breach scanning are queried dynamically; they are never permanently indexed and are NOT SOLD to third parties for advertising or marketing purposes. Your credit card information is not stored on our servers.
Analytics is fail-closed: no Amplitude SDK, storage, or network request is created before analytics consent. Autocapture is limited to reviewed session and navigation structure; arbitrary page text, form values, element attributes, and full locations are excluded. Session Replay masks all text and input values and blocks media, code, tables, results, and other sensitive containers. Withdrawing consent stops collection and clears the analytics identity in the browser.
5. Data Retention and Server Location (Data Sovereignty)
LeakData's core application servers and databases are physically hosted in high-security data centers within the Republic of Turkey. Service data is retained according to the applicable service and account lifecycle.
The minimized first-party product-event ledger and new consent-decision receipts are retained for up to 400 days or until linked account deletion. New consent receipts do not store request IP addresses, user-agent strings, or caller-provided timestamps. Historical consent audit rows created before this design are access-restricted and are not destructively altered without a separately reviewed retention decision.
If you consent to optional analytics, the minimized analytics data described above is sent directly by your browser to Amplitude's European Union endpoints and processed by Amplitude as our analytics provider. Analytics and sampled replay data follow the retention configured for our EU Amplitude project. This optional processing stops when you withdraw analytics consent.
6. User Rights
Under Article 11 of the KVKK and the UK GDPR, you have the right to learn whether your data is processed, request deletion, and learn the third parties to whom it has been transferred. You can submit these requests through your user panel or our support address. Self-service export includes linked first-party product events and consent receipts; account deletion removes those local rows. A request concerning previously delivered optional analytics should identify the relevant LeakData account and approximate time period; we will verify the requester and, where applicable, use the opaque internal account ID in Amplitude's EU-project deletion process without sending an email address or search data to Amplitude. Withdrawing consent stops future collection but does not itself erase data already delivered.