Privacy Policy

Last updated: July 27, 2026

This policy explains what personal data SelfSec collects through this website and connected SelfSec products, why we collect it, on what legal basis, and how you can control it. Core scan processing runs on your infrastructure; requests to sites behind the managed firewall are inspected by SelfSec. Activation and optional product features use the specific remote data flows described below.

Who we are and what this covers

SelfSec is the controller of the personal data described here. This policy covers the SelfSec website, your account and subscription, the entitlement your connected products check, the optional and mandatory reports those products send, and the request records produced for sites you place behind the managed firewall. Data processed only inside your self-hosted scanner remains under your control on your systems and never reaches us.

This policy is written at the level of data categories and purposes, so that it stays accurate as the products develop. The sections below set out each category we process, why we process it, how long we keep it and the rights you can exercise over it.

Data we collect

  • Account and identity data. Your email address, an optional display name and country, and a password stored only as a salted hash. We never see or store your plain-text password.
  • Subscription and billing records. Your plan, subscription status, billing period and invoice history, including the amount, currency, status and the payment reference our provider returns.
  • Agreement records. The fact that you accepted the Terms of Service, this policy and the License Agreement, which versions you accepted, when, and the address the acceptance came from. We keep this so that both of us can establish what was agreed.
  • Support and correspondence. The messages and attachments you send when you open or reply to a support ticket or use the contact form, and the ticket's status history.
  • Newsletter. The email address you enter in the signup form. We use double opt-in: no address is added until the confirmation link sent to it is clicked, and every issue carries an unsubscribe link.
  • Entitlement and device records. Connected products sign in with your account credentials and identify themselves so we can grant and refresh an entitlement: a device identifier, the product and its version, and the connection metadata the request arrives with — the public IP address and, where a local database lets us resolve it, the approximate country and network operator it maps to. That resolution happens on our own servers against an installed database file; no part of your address is sent to a geolocation provider. We use this to tell your machines apart for support, to spot subscription sharing, and to answer abuse reports.
  • Optional product diagnostics. Where you enable and configure them, diagnostics describe the machine an installation runs on — installation and machine identifiers, host, user and domain names, operating-system and hardware characteristics, hardware and network identifiers, and connection metadata. Targets, requests, responses and findings are never part of this report, and it is off unless you turn it on.
  • Out-of-band interaction records. Where the scanner is pointed at a collaborator we operate and interaction reporting is left on, it reports the callbacks it correlates: scan and machine identifiers, the target, the product version, timing, the correlation token, and the protocol and remote address of each observed interaction. Out-of-band checks are brokered through a collaborator we operate, so this traffic passes through us; the interaction bodies we relay back are encrypted to your scanner's own key and we cannot read them.
  • Runtime fault reports. When a connected product hits a critical fault, it reports what is needed to diagnose it: the machine identifier, operating system, product version, the error and its stack trace, the operation and stage it happened in, correlated run identifiers, and the address of the system being processed when the fault occurred. Before anything is sent, the product strips credentials, query strings and fragments from every URL — a target address keeps only its scheme, host and path — and masks context values whose key looks sensitive, such as tokens, passwords, credentials, cookies, sessions and authorization data. Findings, and the full requests and responses a scan exchanges, are never part of a fault report. Fault reporting cannot be turned off.
  • Firewall event records. Each enforcement decision for a site you protect is recorded to your console: the time, the client address, the request line, the reason, severity and decision, the rules that matched, connection fingerprints, and which edge instance handled it. Where a rule matches, we also record the fragment it matched — up to 120 characters — together with the name of the parameter, header or field it matched in, because without it an event cannot be judged or appealed. A match inside a request body is recorded the same way, so a blocked request can leave a short fragment of that body in your console. Fragments matched in credential-bearing headers and cookies are replaced with a redaction marker instead, and response bodies are never recorded at all.
  • Security and audit records. Security-relevant events on your account — sign-ins, password and email changes, subscription changes, device activations and releases — with a timestamp and the address the request came from.

Why we process it, and on what basis

  • To provide what you signed up for — running your account, taking payment, issuing and refreshing entitlements, answering support. Basis: performance of our contract with you.
  • To meet obligations we cannot opt out of — keeping invoice and accounting records, and responding to lawful requests from a competent authority. Basis: legal obligation.
  • To keep the service safe and working — audit logging, abuse prevention and investigation, detecting shared subscriptions, diagnosing faults, and establishing, exercising or defending legal claims. Basis: our legitimate interests in a secure, non-abused service and in defending ourselves, balanced against your interests.
  • To send you the newsletter and optional diagnostics — only where you asked for it. Basis: your consent, which you can withdraw at any time without affecting what was done before you withdrew it.

Under Turkish data protection law the equivalent grounds apply: performance of a contract, compliance with a legal obligation, the legitimate interests of the controller, and explicit consent where the ground is consent. We do not sell personal data, we do not use it for advertising, and we do not make decisions about you by automated means that produce legal effects for you.

When the data is yours, not ours

For requests passing through the managed firewall on behalf of a site you operate, and for anything the scanner processes on your own infrastructure, you are the controller and we act only as your processor. We process that data on your documented instructions — the configuration you set — and for no purpose of our own; we keep it confidential, apply appropriate security measures, engage sub-processors only under equivalent obligations, help you respond to requests from the people whose data it is, and delete the records held for a site when you ask us to. Event records are also held under a storage limit, so the oldest are removed as newer ones arrive. If you need these commitments in a signed data processing agreement, ask us and we will provide one. Deciding what lawful basis covers your visitors' data, and telling them about it, remains your responsibility as the controller.

Payments

Card payments are handled by our payment provider. Your card number and security code are entered with and processed by the provider — they never touch our servers and we never store them. We keep only the invoice record and the provider's payment reference so we can match payments, handle corrections and meet accounting obligations.

Cookies

We set essential cookies only: an authentication cookie that keeps you signed in and an anti-forgery cookie that protects forms against cross-site request forgery. There are no analytics, advertising or cross-site tracking cookies, and because we set no optional cookies there is no cookie consent banner to click through.

Third-party services

Our web fonts are self-hosted: the font files are served directly from this site, so rendering a page sends no request to Google Fonts or any other font CDN and exposes nothing about you to a third party. The only third parties that process personal data on our behalf are our payment provider and the infrastructure providers that host the service; each is bound by a contract that limits them to our instructions. We use no third-party trackers, analytics or embedded content.

Where your data is processed

Where personal data is transferred outside the country you are in, we rely on an adequacy decision where one exists and otherwise on standard contractual clauses or the transfer route Turkish law provides, together with the technical measures needed to make the transfer safe. You can ask us which safeguard applies to a particular transfer and we will tell you.

Retention and account closure

We keep account data for as long as your account exists. When you close your account from your profile page, active subscriptions are canceled, every connected device is signed out, and the personal data on your account record — email address, sign-in name and display name — is anonymized immediately, along with the address, country and network operator recorded against each of your devices, which are erased outright.

Subscription, invoice, audit and agreement records are retained after closure because accounting obligations, security obligations and the defence of legal claims require it. They no longer carry your name or email address, but audit and agreement entries do keep the addresses the original requests came from, so that abuse reported before an account was closed can still be investigated and so that what was agreed can still be established. Each category is kept only for as long as the obligation or claim period behind it lasts, and is then deleted.

Your rights

You have the right to ask for access to the personal data we hold about you, to have inaccurate data corrected, to have data erased or its processing restricted, to object to processing based on our legitimate interests, to receive your data in a portable form, and to withdraw any consent you gave. Most of this you can do yourself: view and correct your profile, change your email address, unsubscribe from the newsletter with one click in any issue, release individual devices, sign out other sessions, disable configurable product diagnostics, and close your account entirely.

For anything else, contact us and we will respond within the period the law allows. If you think we have handled your data wrongly, we would like the chance to put it right first — but you are entitled to complain to your supervisory authority, which in Türkiye is the Personal Data Protection Board and in the European Economic Area or the United Kingdom is the authority for the country you live in.

Security

Passwords are hashed with the ASP.NET Core Identity PBKDF2 scheme, authentication uses hardened session cookies for both the browser and connected apps, and sign-in endpoints are rate limited. Security events on your account are written to an audit log so unusual activity can be traced. No system is perfectly secure, and we do not promise that ours is; we do promise to tell you and the relevant authority about a breach affecting your data within the time the law requires.

Changes to this policy

If we change this policy we will update it here and adjust the date at the top. For significant changes — a new category of data, a new class of recipient — we will notify account holders by email before the change takes effect.

Contact

Questions about this policy or your data? Reach us through the contact form or open a support ticket from your account.