Privacy Policy
Last updated · October 3, 2026
This policy explains what personal data SelfSec collects through this website and connected SelfSec products, why we collect it, on what legal basis, and how you can control it. Core scan processing runs on your own infrastructure. Activation and the optional out-of-band callback relay use the specific remote data flows described below.
Who we are and what this covers
SelfSec is the controller of the personal data described here. This policy covers the SelfSec website, your account and subscription, and the entitlement your connected products check. Connected products send us nothing else: there is no product telemetry and no fault reporting. Data processed only inside your self-hosted scanner remains under your control on your systems and never reaches us.
This policy is written at the level of data categories and purposes, so that it stays accurate as the products develop. The sections below set out each category we process, why we process it, how long we keep it and the rights you can exercise over it.
Data we collect
- Account and identity data. Your email address, an optional display name and country, and a password stored only as a salted hash. We never see or store your plain-text password.
- Subscription and billing records. Your plan, subscription status, billing period and invoice history, including the amount, currency, status and the payment reference our provider returns.
- Agreement records. The fact that you accepted the Terms of Service, this policy and the License Agreement, which versions you accepted, when, and the address the acceptance came from. We keep this so that both of us can establish what was agreed.
- Support and correspondence. The messages and attachments you send when you open or reply to a support ticket or use the contact form, and the ticket's status history.
- Newsletter. The email address you enter in the signup form. We use double opt-in: no address is added until the confirmation link sent to it is clicked, and every issue carries an unsubscribe link.
- Entitlement and device records. Connected products sign in with your account credentials and identify themselves so we can grant and refresh an entitlement: a device identifier and the product it is entitled to, with the time of each refresh. That is the whole record. We do not store the product version, the operating system, or the address, country or network operator the request came from, and we use what we do hold only to tell your machines apart and to count the seats your plan allows.
- Security and audit records. Security-relevant events on your account — sign-ins, password and email changes, subscription changes, device activations and releases — with a timestamp and the address the request came from.
Why we process it, and on what basis
- To provide what you signed up for — running your account, taking payment, issuing and refreshing entitlements, answering support. Basis: performance of our contract with you.
- To meet obligations we cannot opt out of — keeping invoice and accounting records, and responding to lawful requests from a competent authority. Basis: legal obligation.
- To keep the service safe and working — audit logging, counting the seats your plan allows, and establishing, exercising or defending legal claims. Basis: our legitimate interests in a secure, non-abused service and in defending ourselves, balanced against your interests.
- To send you the newsletter — only where you asked for it. Basis: your consent, which you can withdraw at any time without affecting what was done before you withdrew it.
Under Turkish data protection law the equivalent grounds apply: performance of a contract, compliance with a legal obligation, the legitimate interests of the controller, and explicit consent where the ground is consent. We do not sell personal data, we do not use it for advertising, and we do not make decisions about you by automated means that produce legal effects for you.
Payments
Card payments are handled by our payment provider. Your card number and security code are entered with and processed by the provider — they never touch our servers and we never store them. We keep only the invoice record and the provider's payment reference so we can match payments, handle corrections and meet accounting obligations.
Cookies
We set essential cookies only: an authentication cookie that keeps you signed in and an anti-forgery cookie that protects forms against cross-site request forgery. There are no analytics, advertising or cross-site tracking cookies, and because we set no optional cookies there is no cookie consent banner to click through.
Third-party services
Our web fonts are self-hosted: the font files are served directly from this site, so rendering a page sends no request to Google Fonts or any other font CDN and exposes nothing about you to a third party. The only third parties that process personal data on our behalf are our payment provider and the infrastructure providers that host the service; each is bound by a contract that limits them to our instructions. We use no third-party trackers, analytics or embedded content.
Requests to this website also pass through a reverse proxy we operate ourselves; it runs on our own infrastructure, writes operational request logs there, and sends nothing to a third party.
Where your data is processed
Where personal data is transferred outside the country you are in, we rely on an adequacy decision where one exists and otherwise on standard contractual clauses or the transfer route Turkish law provides, together with the technical measures needed to make the transfer safe. You can ask us which safeguard applies to a particular transfer and we will tell you.
Retention and account closure
We keep account data for as long as your account exists. When you close your account from your profile page, active subscriptions are canceled, every connected device is signed out, and the personal data on your account record — email address, sign-in name and display name — is anonymized immediately.
Subscription, invoice, audit and agreement records are retained after closure because accounting obligations, security obligations and the defence of legal claims require it. They no longer carry your name or email address, but audit and agreement entries do keep the addresses the original requests came from, so that abuse reported before an account was closed can still be investigated and so that what was agreed can still be established. Each category is kept only for as long as the obligation or claim period behind it lasts, and is then deleted.
Your rights
You have the right to ask for access to the personal data we hold about you, to have inaccurate data corrected, to have data erased or its processing restricted, to object to processing based on our legitimate interests, to receive your data in a portable form, and to withdraw any consent you gave. Most of this you can do yourself: view and correct your profile, change your email address, unsubscribe from the newsletter with one click in any issue, release individual devices, sign out other sessions, and close your account entirely.
For anything else, contact us and we will respond within the period the law allows. If you think we have handled your data wrongly, we would like the chance to put it right first — but you are entitled to complain to your supervisory authority, which in Türkiye is the Personal Data Protection Board and in the European Economic Area or the United Kingdom is the authority for the country you live in.
Security
Passwords are hashed with the ASP.NET Core Identity PBKDF2 scheme, authentication uses hardened session cookies for both the browser and connected apps, and sign-in endpoints are rate limited. Security events on your account are written to an audit log so unusual activity can be traced. No system is perfectly secure, and we do not promise that ours is; we do promise to tell you and the relevant authority about a breach affecting your data within the time the law requires.
Changes to this policy
If we change this policy we will update it here and adjust the date at the top. For significant changes — a new category of data, a new class of recipient — we will notify account holders by email before the change takes effect.
Contact
Questions about this policy or your data? Reach us through the contact form or open a support ticket from your account.