Legal
Privacy Policy
Last updated: 11 August 2026
1.Who we are
AKASEC B.V., Wilhelmina van Pruisenweg 104, 2595 AN The Hague, the Netherlands. For any privacy question or to exercise your rights, contact privacy@akascan.com.
2.What we collect
- Account & contact data: name, work email, company name, job title, phone number.
- Scope data: the domains and assets you submit for discovery.
- Authentication data: hashed password and, if you enable it, an encrypted two-factor (TOTP) secret.
- Billing data: subscription status and identifiers. Card details are handled by Stripe — we do not store card numbers.
- Report & usage data: the reports we prepare for you and basic logs needed to run and secure the service.
- Communications: emails you exchange with us.
The discovery work itself concerns externally visible technical information about your organisation; where that incidentally includes personal data, we process it to provide the service you requested.
3.Why we process it and our legal bases
- To provide the service (account, discovery, reports, support) — performance of a contract.
- To take payment and manage subscriptions — performance of a contract and compliance with legal (accounting/tax) obligations.
- To secure and improve the service (authentication, logging, abuse prevention) — our legitimate interests in running a secure service.
- To send service and, where permitted, relevant updates — legitimate interests or consent, as applicable.
4.Who we share it with (processors)
We use a small number of vetted providers who process data on our behalf under data-processing agreements:
- Amazon Web Services (AWS) — application hosting, database and report storage, in the EU (Frankfurt, eu-central-1).
- Stripe — payment processing and subscription billing.
- Postmark — transactional email delivery.
- Cloudflare — DNS, inbound email routing and content delivery.
We do not sell your personal data. We disclose data to authorities only where legally required.
5.International transfers
Our application data is hosted in the EU. Some processors may process limited data outside the EEA; where they do, transfers are covered by appropriate safeguards such as the European Commission’s Standard Contractual Clauses.
6.How long we keep it
We keep account and scope data for as long as you have an account and as needed to provide the service, then delete or anonymise it within a reasonable period, unless a longer retention is required by law (for example, invoices for tax purposes). Reports are retained so you can access them via the dashboard until deleted.
7.Your rights
Under the GDPR you may:
- access the personal data we hold about you;
- have inaccurate data corrected, or data erased;
- restrict or object to certain processing;
- receive your data in a portable format;
- withdraw consent where processing is based on consent.
To exercise any right, email privacy@akascan.com. You also have the right to lodge a complaint with the Dutch Data Protection Authority (Autoriteit Persoonsgegevens).
8.Cookies
We use only strictly necessary cookies — for example a secure session cookie to keep you signed in to the dashboard. We do not use advertising or third-party tracking cookies.
9.Security
We apply technical and organisational measures appropriate to the risk, including encryption in transit, hashed passwords, encrypted two-factor secrets, access controls and non-guessable identifiers on customer-facing resources.
10.Changes and contact
We may update this policy from time to time; the “last updated” date above reflects the latest version. For any question, contact privacy@akascan.com.