Privacy policy
01Who processes your data
EasyHack is a product of Infosec Technologies Esp. LLC, which acts as the data controller for personal data collected through easyhack.io.
- Legal name
- Infosec Technologies Esp. LLC
- Registered office
- 407 Lincoln Road, Suite 708, Miami Beach, FL 33139 (United States)
- [email protected]
- Privacy
- [email protected]
- Website
- easyhack.io
For anything related to your data, write to [email protected].
02What data we collect
We only process the data you voluntarily provide in the contact form, plus a few technical details generated by the request itself.
Data you enter
- Required: full name, company and email address.
- Optional: phone, website or domain to protect, plan of interest and your message.
Technical data of the submission
- The IP address you submit the form from.
- Your browser identifier (user-agent).
- Date and time, page language and the address you came from.
We use no web analytics, no profiling and no automated decision-making with legal effects. We neither request nor want special categories of data: please do not include health, political, trade-union or third-party information in your message.
03Why we use it and on what legal basis
| Purpose | Legal basis |
|---|---|
| Handling your request and contacting you to quote or answer your questions about EasyHack. | Your consent when ticking the form checkbox (Art. 6(1)(a) GDPR) and pre-contractual steps taken at your request (Art. 6(1)(b) GDPR). |
| Protecting the form against automated submissions and abuse. | Legitimate interest in keeping the service secure (Art. 6(1)(f) GDPR). |
| Keeping a record of the request and the consent given. | Compliance with the accountability obligation (Art. 5(2) and 24 GDPR). |
We do not send newsletters or bulk marketing from this form. If we ever wanted to, we would ask you separately and explicitly.
04How long we keep it
- While we handle your request and throughout any conversations that follow.
- Afterwards, for up to two years from the last contact, in case you pick the conversation back up, unless you ask us to delete it sooner.
- If we sign a contract, data tied to that relationship is kept for the legal periods applicable to the contractual relationship and to the relevant tax and accounting obligations.
After those periods the data is deleted or anonymised.
05Who else accesses your data
We do not sell or share your data. We do work with providers who process it on our behalf under a data processing agreement:
| Provider | Purpose |
|---|---|
| IONOS | Hosting of the website and of the server where the submission is recorded. |
| Cloudflare | Content delivery network and protection against attacks. All visits pass through their network. |
| MailerSend | Delivery of the notification of your request to our sales mailbox. |
| Microsoft 365 | Corporate mailbox where we receive and answer your request. |
| Anti-fraud verification of the form (reCAPTCHA), only when you use it. |
The site typefaces are served from our own server: visiting the site loads no resource from Google.
Legal or tax advisers and public authorities may also access the data where there is a legal obligation.
06Transfers outside the European Union
Some of those providers are US companies or may process data outside the European Economic Area. Such transfers rely on the adequacy decision of the EU-US Data Privacy Framework or, failing that, on the standard contractual clauses approved by the European Commission, together with any supplementary measures required.
07Your rights
You may exercise the following rights at any time:
- Access: find out what data of yours we hold.
- Rectification: correct inaccurate data.
- Erasure: ask us to delete it.
- Objection: object to processing based on legitimate interest.
- Restriction: ask us to keep it but not use it.
- Portability: receive it in a structured, commonly used format.
- Withdraw consent at any time, without affecting the lawfulness of prior processing.
Write to [email protected] stating which right you wish to exercise. We will reply within one month at the latest. We may ask you to prove your identity.
08Security
All site traffic is encrypted over HTTPS. Form submissions are stored in a server directory outside the public folder, with restricted access, and the notification email is sent through a provider with SPF and DKIM authentication. We apply the technical and organisational measures required by Art. 32 GDPR and review them periodically.
09Changes to this policy
We may update this policy if our services, providers or the applicable law change. The version in force is always the one published on this page, with its update date in the header.