Privacy policy
Version 1.2, last updated October 5, 2026
This policy tells you what personal data the Redamp.io Quick Scan uses, why we use it, how long we keep it, and what your rights are.
Who we are
The controller of your personal data is REDAMP SECURITY s.r.o., Palackého třída 879/84, 612 00 Brno, Czech Republic. In this policy, “we” means this company.
For all questions about your data, write to [email protected].
What we collect
- Your email address, and the domain that you want to scan.
- The language that you use on the site.
- The scan results for the domain.
- Information about the known data breaches that include your email address.
- Your IP address. We use it to check that you are not a bot. Our servers also record it in technical logs, so that we can find errors and attacks.
- Whether you open our emails and click the links in them.
Why we use it
- To run the scan, and to send you the confirmation email and the report. Legal basis: you ask for the scan (Art. 6(1)(b) GDPR).
- To check that the domain is yours, and to stop abuse of the service. Legal basis: our legitimate interest (Art. 6(1)(f) GDPR).
- To contact you about the scan results, with an offer of our similar services. Legal basis: our legitimate interest in direct marketing (Art. 6(1)(f) GDPR). You can object to this processing at any time.
- To keep the service working and secure. Legal basis: our legitimate interest (Art. 6(1)(f) GDPR).
- To check that our emails arrive and that the links work. For each email, we record whether it was opened and whether a link in it was clicked. Legal basis: our legitimate interest (Art. 6(1)(f) GDPR).
We do not sell your personal data.
We do not use it for profiling, or for decisions that have legal or similarly significant effects on you in the sense of Art. 22 GDPR. The scan is an automated technical process, but it is not an automated decision about you.
Who receives your data
We give your data only to the service providers below, and only for the purposes above:
- Google (Gmail) sends the confirmation email and the report email. It gets your email address and the content of these emails.
- Anthropic (Claude) creates the short summary of your report. It gets the domain and the scan results. It does not get your email address.
- Cloudflare (Turnstile) checks that you are not a bot. It gets your IP address and data about your browser.
Where we get data from
- Have I Been Pwned checks if your email address is in known data breaches. For this, we give it your email address, and we get information about the known breaches that include this address.
- Public sources for the scan, mainly Shodan, WhoisFreaks, the RDAP registries, RIPEstat and the certificate logs (crt.sh), give information about the scanned domain and its IP addresses. The scan also connects to the public servers of the domain.
Some service providers can process data outside the EU, for example in the USA. Then we use the safeguards of the GDPR, for example an adequacy decision of the European Commission or the standard contractual clauses. If the provider takes part in the EU-US Data Privacy Framework, we can also rely on this framework.
We do not give data to recipients other than those above, unless the law requires us to disclose it.
Use of artificial intelligence
A language model, Claude from Anthropic, creates the short summary at the top of your report. It creates the summary from the scan results of the domain. It does not get your email address.
The AI does not make decisions about you, and it does not set the scan results. All findings come from automated technical checks. The AI only creates a short text summary of the results.
How long we keep it
- A scan request that you do not confirm: 30 days.
- A confirmed scan and its report: 30 days after we send you the report.
- Raw data from the scan sources: 14 days.
- Your email address and domain for the one follow-up contact: 12 months after the scan.
- Whether you opened and clicked our emails: as long as the record of your scan.
- Technical logs: 30 days, unless we must keep them longer to investigate a specific security incident.
Backups can keep data a short time longer. We do not use backups for any other purpose.
Cookies and analytics
- This site sets no cookies.
- The site stores your language choice in your browser (local storage). It stays on your device and is not sent to our servers.
- The scan form uses Cloudflare Turnstile to check that you are not a bot.
- We count visits with Plausible Analytics. It uses no cookies and creates no permanent visitor identifiers.
Your rights
You have these rights:
- Access to your data.
- Correction of data that is wrong.
- Erasure of your data.
- Restriction of the processing.
- Data portability, if the conditions of the GDPR for it are met.
- Objection to processing that is based on our legitimate interest.
- If we process your data for direct marketing, you can object to it at any time, without a reason.
- A complaint to a supervisory authority. In the Czech Republic, this is the Office for Personal Data Protection (www.uoou.cz).
To use a right, write to [email protected]. If you can, write from the email address that you scanned. If you cannot, we can ask you for reasonable information to verify your identity.
We answer a request within one month.
Changes to this policy
When we change this policy, we update the version and the date at the top of this page.