Privacy Policy
How RADECTI collects, uses, shares and protects personal data — and the rights you have over it.
Language: English · Ελληνικά
Last updated: 19 September 2026
1. Who we are
RADECTI provides self-serve threat intelligence, brand and domain monitoring, scanning and static malware analysis to organisations and individuals, chiefly small and medium-sized enterprises across the EU. Managed detection and response (MDR) and digital forensics and incident response (DFIR) are under development and not yet offered.
Controller. The data controller for the processing described here is the sole proprietor (ατομική επιχείρηση) established in Greece who trades as RADECTI. RADECTI is not a company and no company is being formed; this designation is final. The controller's full legal identity (name, geographic address and telephone number) is stated in the order confirmation every customer receives before being bound, and is available on request at the address below.
Contact for privacy matters: support@radecti.com. Please use this address for any data-protection request or question, including the exercise of your rights below.
2. Two roles: controller and processor
We process personal data on two distinct footings, and which one applies changes your relationship with us:
- As a processor, on behalf of our customers. When we run detection, monitoring and incident response for a customer, we process the personal data inside that customer's own systems and logs on their documented instructions. There, the customer is the controller and we act under a data processing agreement (Article 28 GDPR). If your data was processed because you are an employee, user or contact of one of our customers, please direct your request to that organisation; we will support them in responding.
- As a controller, for the data we collect to deliver monitoring. To detect threats to our customers we collect certain third-party personal data ourselves — for example leaked or breached credentials, dark-web and leak-site content, and domain registration data. For that collection we are the controller and this policy is your notice under Article 14 GDPR.
3. What personal data we process
Depending on the service and your relationship with us, this can include:
- Account data — your name, business email address, organisation name, service tier and account identifiers.
- Free-check and access requests — the email address and the domain you give us on the free lookalike check or a waitlist form, so we can run the check and reply.
- Sign-in and security events — the email address, IP address, time and outcome of sign-ins, password changes, API-key and two-factor changes, kept as an audit trail so that we and you can tell what happened to an account.
- Technical and asset data — the domains, IP addresses, hostnames, exposed ports and services you ask us to monitor or that we observe while monitoring your assets.
- Scan and finding data — the results of the monitoring, detection and enrichment we run for you, and their history.
- Files you submit for analysis, and what we derive from them — the file itself, the readable text inside it, the functions it contains and the relationships between them. A malicious file routinely carries other people's personal data: the addresses a phishing kit was built to collect, the mailbox or server credentials a sample uses to reach whoever is operating it, and the account name of the person who compiled it, left behind in a file path. We do not go looking for this and do not use it for anything beyond showing you the analysis of the file you submitted. How long it is kept is in section 6.1.
- Dark-web and credential-monitoring data — this is the sensitive category. To warn a customer that their people are exposed, we process personal data such as email addresses, usernames and the existence of leaked or breached credentials belonging to that customer's executives, employees and associated individuals. This data is breach-origin: it originates from third-party data breaches, dark-web sources, ransomware leak sites and similar, and the individuals concerned did not provide it to us and did not consent to its original exposure.
- Look-alike / typosquat domain data — domain permutations of a customer's brand and the associated registration (WHOIS), DNS and mail records, which can contain the personal data of the person who registered a domain.
- Screenshots — best-effort screen captures of look-alike or suspicious pages, which may incidentally contain personal data visible on those pages.
- Support and billing data — the content of support conversations and, for invoiced customers, the name, invoicing address, VAT number (businesses) and bank-transfer reference needed to issue and reconcile an invoice.
We do not deliberately seek special-category data (Article 9 GDPR). Breach and dark-web sources can nonetheless contain it incidentally; where that happens we minimise it, do not use it for any purpose beyond alerting the affected customer, and delete it under the retention rules below.
4. Why we process it, and our legal basis
We rely on a specific legal basis for each purpose:
- To provide the service you contracted for — creating and running your
account, monitoring the assets you register, delivering findings and support.
Legal basis: performance of a contract (Article 6(1)(b) GDPR), or steps taken at your request before entering into one. - To detect threats through brand, credential and dark-web monitoring —
collecting and correlating third-party data so we can warn customers about exposed
credentials, look-alike domains and leaks affecting them.
Legal basis: our legitimate interests and those of our customers (Article 6(1)(f) GDPR) in preventing fraud, credential abuse and cyber-attacks. We have carried out a balancing test (a documented Legitimate Interests Assessment) weighing this against the interests and rights of the individuals concerned, applying strict purpose limitation, data minimisation and short retention, and never bypassing any login or vetting step to obtain data. You can object to this processing (see Your rights). - To take payment and meet accounting and tax duties.
Legal basis: performance of a contract, and compliance with a legal obligation (Article 6(1)(c) GDPR) for the tax and accounting records we are required to keep. - To secure our own platform and investigate abuse of our systems.
Legal basis: legitimate interests (Article 6(1)(f) GDPR) in the security of processing.
We do not rely on your consent for the monitoring above, and we do not use your personal data to make solely automated decisions with legal or similarly significant effects about you.
5. Who we share it with
We do not sell personal data. We share it only with service providers who process it on our behalf, and only as far as needed to deliver the service:
- Contabo — hosting and compute for the platform (Germany, EU).
- Cloudflare — content delivery, edge security and DDoS protection for our websites (a US company operating a global edge network).
- Zoho — our email (EU data centre).
- Backblaze — encrypted off-site backups. Backblaze is a US company; our backups are stored in its EU data centre in the Netherlands and are encrypted on our own server before upload, so Backblaze cannot read them.
- Stripe — payment processing (United States). Not currently used; listed because it will process card payments if we open an online checkout. No payment data has been shared with Stripe or any other payment processor.
- Our bank and our accountant — for invoices paid by bank transfer, and the tax filings the law requires; invoice data is transmitted to the Greek tax authority (ΑΑΔΕ myDATA) as required by law.
- Public malware hash registries — when you upload a file, its SHA-256 hash is checked automatically against CIRCL hashlookup (Luxembourg), the Team Cymru malware hash registry (United States) and abuse.ch MalwareBazaar (Switzerland). They receive only the hash, which tells them that someone asked about it and nothing about you.
- Threat-intelligence lookup services — when you look up an indicator of compromise (for example an IP address, domain or URL) we send that indicator to reputation and enrichment services so they can tell us what they already know about it. An indicator can itself be personal data. The services we query include AbuseIPDB, abuse.ch (URLhaus, ThreatFox, MalwareBazaar), AlienVault OTX, CrowdSec, GreyNoise, Pulsedive, Spamhaus, DShield, Talos, Robtex, RIPE, urlscan.io, urlDNA, Phishstats, Stalkphish, Shodan InternetDB and public DNS resolvers. Several of these are operated from the United States. The current list is available on request.
We do not submit your files to anyone. The services above are queried with an indicator — a hash, an address, a name. A file you upload for analysis is analysed on our own infrastructure and is not sent to a public sandbox, a multi-engine scanning service or any other third party, and it is never published. We do not use VirusTotal.
Vulnerability data. Where we report a known vulnerability against software we detected on a host, the vulnerability record comes from the U.S. National Vulnerability Database. This product uses the NVD API but is not endorsed or certified by the NVD. No customer data is sent to the NVD: we query it by product and version, never by host, domain or account.
Support conversations stay with us. Support is handled over our own email; we do not use an external helpdesk provider.
International transfers
Some of the providers above are located outside the European Economic Area, mainly in the United States. Where personal data is transferred to a country without an EU adequacy decision, we rely on an appropriate transfer safeguard under Chapter V of the GDPR — the EU Standard Contractual Clauses and/or the provider's certification under the EU–US Data Privacy Framework, together with any supplementary measures required. You can ask us for details of the safeguard used for a specific transfer using the contact address above.
6. How long we keep it
We keep personal data only as long as necessary for the purpose it was collected for. Two different periods do that work and they measure different things. One is counted from the day a record is created (section 6.1). The other is counted from the day a subscription ends (section 6.2).
6.1 While your subscription is active
Each period below runs from the day the record itself is created:
- Account data — for as long as you have an account with us. When your subscription ends, section 6.2 applies.
- Free-check and access requests — 12 months from the request, then deleted; sooner if you ask.
- Sign-in and security events — 12 months, then deleted.
- Scan and analysis history — for the number of days your plan states, counted from each scan. The figure for every plan is published on our Security page.
- Raw monitoring findings — governed by confidence-based decay in our intelligence platform, and purged once expired.
- Findings that never became an incident — deleted 90 days after we record the finding.
- Findings that became an investigated incident — retained for 3 to 5 years, because they may be needed as incident evidence.
- Billing and accounting records — retained for the period required by Greek tax law (generally up to about 10 years).
- Files you submit for analysis — our working copy is kept for 4 hours from upload, together with the analysis derived from it, then deleted. The analysis engine that runs the first pass keeps its own copy of the file until its nightly clean-up removes it, which happens within 48 hours of upload. See the working window below.
The analysis working window. A file you upload is analysed and then held for 4 hours, along with the results we derive from it, so that examining it does not make you upload the same file again at every step. At the end of that window our working copy and everything derived from it are deleted automatically; the analysis engine's copy follows the nightly clean-up above, so no copy of your file exists on our systems 48 hours after upload. The derived results carry the file's own expiry rather than their own, so none of them outlives the file. Both copies are readable only from the account that submitted the file, and neither leaves our own infrastructure. This window is separate from the scan history your plan retains: that history holds the verdict, the indicators we found and the readable text extracted from the file, and it does not hold your file.
6.2 After your subscription ends: the 90-day hold
This period is counted from the day your subscription ends, whatever the age of the records it covers, and it applies the same way whether you cancel, a payment fails or a card expires. It is a different period from the 90 days in section 6.1, which is counted from the day each finding is recorded.
- Monitoring stops that day. We remove your assets from every monitor and collect nothing further about you or for you.
- We keep your data for 90 days and it stays readable. You can sign in, see everything we found for you while the subscription was active, and export it. Your history is served at the plan you were on when the subscription ended, so it stays complete instead of being cut back to a smaller plan's window, and deletion by age is suspended for the whole 90 days.
- What you cannot do during the hold. Register assets, run scans, or use an API key. Export runs from the dashboard.
- Subscribing again within the 90 days restores the account, including monitoring of the assets whose ownership you had already verified.
- At the end of the 90 days we erase the account. A daily automated job deletes your findings and the separate database file that holds them, your registered assets, your reports and analysis notes, your team's user accounts, your API keys and your sign-in credentials.
What survives an erasure, and why. Invoices and payment records, because Greek tax law requires us to keep them (Article 17(3)(b) GDPR). The record of who authorised us to scan a given asset, and the record of when your plan changed, because together they evidence that we scanned only what we were authorised to scan and that monitoring stopped when your subscription did (Article 17(3)(e) GDPR). For an account opened through the free trial, the record of your acceptance of our terms at sign-up (which version, when, from which address), because it is what evidences that the contract was formed (the same Article 17(3)(e)). Your account row is reduced to a marker in which your email address is replaced by a one-way hash, so the address cannot be read back from it. Encrypted backups: we keep 7 daily, 4 weekly and 6 monthly snapshots, so an erased record can persist inside a backup for up to six months. Backups are encrypted on our own server before they leave it, are restored only whole and only for disaster recovery, and are never used to reinstate an erased account.
One copy is deleted by hand and can lag behind the rest. Findings we publish for you go into a group reserved for your account inside our threat intelligence platform, which is shared infrastructure where a deletion cannot be undone. That group is emptied by an operator rather than by the automated job, and until that step is completed for your account the records in it still exist. This is the one place where personal data taken from leak and breach sources can outlive the erasure of the account it was collected for. Ask us and we will confirm in writing when it has been done for your account.
Free trials are shorter. If you were on a trial rather than a paid plan, the equivalent period is 3 days from the day the trial expires, after which the account and its contents are erased in the same way. A trial sign-up whose set-password link is never used is deleted after 48 hours, together with the email address and name it holds, and nothing else is created for it until the link is used. The one record a trial leaves behind is your acceptance of our terms at sign-up, kept for the reason given above.
You do not have to wait for the 90 days. You can ask us to erase your account at any time, whether or not a hold is running, and the request overrides the hold. Monitoring stops immediately, you have 14 days in which you can cancel the request, and the account is then erased on the terms above. Section 7 explains how to ask.
These periods reflect our internal retention policy and are subject to legal review.
7. Your rights
Under the GDPR you have the right to:
- Access the personal data we hold about you;
- Rectify inaccurate or incomplete data;
- Erase your data ("right to be forgotten"), where the conditions apply;
- Restrict our processing in certain circumstances;
- Object to processing based on legitimate interests, including our monitoring, on grounds relating to your particular situation;
- Data portability — receive data you provided in a structured, machine-readable format, where applicable.
To exercise any of these, email support@radecti.com. We will respond within one month. If your data was processed because you are connected to one of our customers (see section 2), we may need to direct your request to that customer as controller, and we will tell you if so. There is no charge for a request unless it is manifestly unfounded or excessive.
8. Complaints
If you believe we have handled your personal data unlawfully, we would like the chance to put it right — please contact us first. You also have the right to lodge a complaint with the supervisory authority. In Greece this is the Hellenic Data Protection Authority (Αρχή Προστασίας Δεδομένων Προσωπικού Χαρακτήρα):
- Address: Kifissias Avenue 1-3, 115 23, Athens, Greece
- Telephone: +30 210 6475600
- Email: contact@dpa.gr · Website: www.dpa.gr
9. Cookies, analytics and this website
This website (radecti.com) sets no cookies and uses no third-party analytics or advertising service, and it does not profile visitors. It sends one request per page view to our own API (api.radecti.com) carrying the page path. On receipt our server combines your IP address and browser identification string with a server secret and the current date, keeps only a one-way hash of the result, and records the path, the day and that hash. The hash counts you once per day and cannot be linked to you the next day, to any other site or to an account. Nothing is stored on your device, so no consent is needed under the ePrivacy rules. The legal basis for handling your IP address for the moment it takes to hash it is our legitimate interest in knowing which pages are read (Article 6(1)(f) GDPR). The counts are deleted after 180 days. Cloudflare, which serves the site, sees your IP address as part of delivering it (section 5).
Our signed-in application (app.radecti.com) uses one cookie to keep you signed in and, only if you tick "remember this device" at sign-in, a second cookie valid for 30 days that skips the second factor on that device. Both are strictly necessary for a service you asked for and need no consent.
10. Changes to this policy
We will update this policy as our services and legal footing evolve. The date at the top shows when it was last changed.