This policy describes the data used by the current AdverseMonitor website and platform. It does not claim certifications, fixed deletion schedules, or technical safeguards that are not documented by the current service.
1. Data we collect
Depending on how you use the service, we may process:
- Account data: email address, password hash, authentication credentials, session information, and account status.
- Monitoring configuration: profile names, companies, domains, categories, threat actors, countries, industries, and any destination settings already stored on an account.
- Product activity: searches, alert history, API-key metadata, API usage, audit and activity records, browser/device information, IP address, and timestamps.
- Billing data: plan and subscription identifiers, status, and transaction references. Payment-card details are handled by Stripe rather than stored directly in the application database.
- Contact and support data: information submitted through contact forms or support communications.
- Website analytics: after you choose Allow analytics, the marketing site sends a canonical page path and fixed interaction labels to Google Analytics. Google also receives technical request data such as the IP address and browser headers.
2. How we use data
- Provide authentication, monitoring profiles, dashboard match history, search, APIs, exports, and billing features.
- Apply account, plan, data-window, abuse-prevention, and rate-limit controls.
- Diagnose errors, secure accounts, investigate misuse, and improve product reliability.
- Respond to contact, billing, privacy, and support requests.
- Measure use of the website and product funnel.
- Comply with applicable legal obligations and enforce service terms.
3. Outbound alert delivery
New profile matches are recorded in the signed-in dashboard. Where you configure them, matches are also delivered to the email addresses, Slack or Teams webhooks, browser push subscriptions and API webhooks you supply. Those destinations are used only to deliver your own alerts, and you can remove them at any time in Alerts and Settings.
4. Collected threat records
The searchable feed contains records that ransomware groups and other third parties publish on leak sites and dark web sources. Those records are collected from third-party sources, not from the people or organisations named in them, and they may name individuals as well as companies. They are unverified third-party claims: they may be false, exaggerated, out of date, misattributed or fabricated, and we do not verify them.
We act as an independent controller for this corpus. We collect and make these records available in reliance on our legitimate interests in detecting and reporting criminal data exposure so that affected organisations can investigate. Because the records come from third-party sources rather than from the individuals named in them, providing individual notice would involve disproportionate effort, and we operate the removal route below in its place.
Anyone named in a record — whether or not they are a customer — can ask us to remove or correct it. No account is required. Email support@adversemonitor.com. We acknowledge within 5 business days and aim to confirm the outcome, with reasons, within 30 days. Where fabrication, misidentification or unlawful content is credibly alleged we may suppress the record while we review it, and we may mark a record as disputed and record the response of the person or organisation named in it. This route is also set out in clause 14 of our Terms of Service.
5. Service providers and disclosures
AdverseMonitor uses service providers to operate the product, including database/authentication infrastructure, hosting, payment processing through Stripe, and website analytics/tag management. Data may be sent to a provider when required to perform that function. We may also disclose data when required by law, to protect the service and users, or as part of a business transaction subject to appropriate safeguards.
6. Data retention
We retain data for as long as reasonably needed to provide and secure the service, maintain required business and financial records, resolve disputes, and meet legal obligations. Different records may have different retention periods. Backups and logs may persist after active records are removed. This policy does not promise a fixed deletion interval.
7. Security
The application implements password hashing, passkey flows, authenticated sessions, server-side authorization checks, user-scoped database queries, API-key hashing, rate limits, and activity logging. No security program eliminates all risk. See the current Security & Assurance page for bounded details and limitations.
8. Cookies and similar technologies
The website and platform use essential browser storage or cookies for authentication, preferences, and security. The marketing site removes URL query parameters and does not load Google Analytics until you choose Allow analytics. Choosing Reject keeps it off. AdverseMonitor’s analytics code uses fixed labels and does not add form values, scan values, result counts, returned categories, error text, or referrer values to event payloads. Blocking essential storage may prevent sign-in or other product features.
9. Your choices and rights
Depending on your location, you may have rights to request access, correction, deletion, restriction, portability, or objection regarding personal data. These rights can be limited by identity verification, legal obligations, security needs, and applicable exceptions. You can remove stored webhook configurations from API Access.
10. International use
The service and its providers may process data in countries other than your own. Applicable transfer mechanisms and protections depend on the relevant provider, location, and law. This page does not claim a specific transfer mechanism for every processing activity.
11. Children
The service is intended for business users and is not directed to children. Do not submit children’s personal data through monitoring criteria or support channels.
12. Changes
We may update this policy as the service changes. The date above identifies the current published version.
13. Contact
For privacy requests or questions, contact support@adversemonitor.com. We may need to verify account ownership before acting on a request.