Privacy Policy

Last updated: August 5, 2026

This policy describes the data used by the current AdverseMonitor website and platform. It does not claim certifications, fixed deletion schedules, or technical safeguards that are not documented by the current service.

1. Data we collect

Depending on how you use the service, we may process:

2. How we use data

3. Outbound alert delivery

New profile matches are recorded in the signed-in dashboard. Where you configure them, matches are also delivered to the email addresses, Slack or Teams webhooks, browser push subscriptions and API webhooks you supply. Those destinations are used only to deliver your own alerts, and you can remove them at any time in Alerts and Settings.

4. Collected threat records

The searchable feed contains records that ransomware groups and other third parties publish on leak sites and dark web sources. Those records are collected from third-party sources, not from the people or organisations named in them, and they may name individuals as well as companies. They are unverified third-party claims: they may be false, exaggerated, out of date, misattributed or fabricated, and we do not verify them.

We act as an independent controller for this corpus. We collect and make these records available in reliance on our legitimate interests in detecting and reporting criminal data exposure so that affected organisations can investigate. Because the records come from third-party sources rather than from the individuals named in them, providing individual notice would involve disproportionate effort, and we operate the removal route below in its place.

Anyone named in a record — whether or not they are a customer — can ask us to remove or correct it. No account is required. Email support@adversemonitor.com. We acknowledge within 5 business days and aim to confirm the outcome, with reasons, within 30 days. Where fabrication, misidentification or unlawful content is credibly alleged we may suppress the record while we review it, and we may mark a record as disputed and record the response of the person or organisation named in it. This route is also set out in clause 14 of our Terms of Service.

5. Service providers and disclosures

AdverseMonitor uses service providers to operate the product, including database/authentication infrastructure, hosting, payment processing through Stripe, and website analytics/tag management. Data may be sent to a provider when required to perform that function. We may also disclose data when required by law, to protect the service and users, or as part of a business transaction subject to appropriate safeguards.

6. Data retention

We retain data for as long as reasonably needed to provide and secure the service, maintain required business and financial records, resolve disputes, and meet legal obligations. Different records may have different retention periods. Backups and logs may persist after active records are removed. This policy does not promise a fixed deletion interval.

7. Security

The application implements password hashing, passkey flows, authenticated sessions, server-side authorization checks, user-scoped database queries, API-key hashing, rate limits, and activity logging. No security program eliminates all risk. See the current Security & Assurance page for bounded details and limitations.

8. Cookies and similar technologies

The website and platform use essential browser storage or cookies for authentication, preferences, and security. The marketing site removes URL query parameters and does not load Google Analytics until you choose Allow analytics. Choosing Reject keeps it off. AdverseMonitor’s analytics code uses fixed labels and does not add form values, scan values, result counts, returned categories, error text, or referrer values to event payloads. Blocking essential storage may prevent sign-in or other product features.

9. Your choices and rights

Depending on your location, you may have rights to request access, correction, deletion, restriction, portability, or objection regarding personal data. These rights can be limited by identity verification, legal obligations, security needs, and applicable exceptions. You can remove stored webhook configurations from API Access.

10. International use

The service and its providers may process data in countries other than your own. Applicable transfer mechanisms and protections depend on the relevant provider, location, and law. This page does not claim a specific transfer mechanism for every processing activity.

11. Children

The service is intended for business users and is not directed to children. Do not submit children’s personal data through monitoring criteria or support channels.

12. Changes

We may update this policy as the service changes. The date above identifies the current published version.

13. Contact

For privacy requests or questions, contact support@adversemonitor.com. We may need to verify account ownership before acting on a request.