Privacy Policy
Last update: 15 September 2026
1. General provisions
1.1. This Privacy Policy (the “Policy”) sets out how personal data is collected, used, stored, protected, and disclosed when you use mysecscan.com, the free security checkers, and related services (the “Service”). This Policy has been prepared in accordance with applicable data-protection legislation, including Regulation (EU) 2016/679 (the General Data Protection Regulation, GDPR).
1.2. The data controller is MySecScan, a trading name of DZZD MARKET PULSE, a company registered under the laws of Bulgaria, VAT No. BG181450814, registered office Oborishte St., Burgas, Bulgaria. In this Policy the company is referred to as “MySecScan”, the “Company”, or “we”.
1.3. MySecScan processes personal data in accordance with the following principles: lawfulness, fairness, and transparency of processing; clear and legitimate purposes for processing; data minimisation — collecting only what is necessary; accuracy and currency of data; storage limitation, in line with the retention periods set out in this Policy; and appropriate technical and organisational security.
1.4. This Policy applies to anyone who visits mysecscan.com, uses the free security checkers, creates an account, verifies ownership of a domain, sets up domain security monitoring, or contacts the Company through the available communication channels.
1.5. MySecScan processes personal data only to the extent necessary to provide the Service, secure it, and meet contractual and legal obligations. Where the law requires separate consent, such consent is obtained separately, in clear and accessible form.
2. Scope
2.1. This Policy covers the mysecscan.com website, the free security checkers (header, TLS, email-configuration, cookie, and other checks), and the full-scan request feature.
2.2. The free checkers remain open to everyone — no account, no email address, and no signup required. None of the data described in Section 3 is collected just to run one.
2.3. An account is required only for features that need to act on your behalf over time — in particular, ongoing domain security monitoring. Creating an account is what triggers the collection of the account and domain data described in Section 3.
3. What we collect
The data described in this section relates solely to your account and the monitoring you have set up — never the contents or findings of a scan (see Section 6 for how those are handled).
- 3.1. Scan inputs — the domain or URL you submit to a checker.
- 3.2. Technical data — your IP address, browser user-agent, and the timestamp of your request, logged in server security logs. Purpose: detecting and preventing abuse — unauthorized access attempts, DDoS and automated brute-force activity, and anomalous API usage. This data is not used for profiling, behavioral analytics, or marketing purposes, and is not shared with third parties except where required by law (e.g. a law-enforcement request). It is retained for 30 days (see Section 8), then deleted automatically as logs rotate out.
- 3.3. Full-scan requests — if you request a full scan, the email address and domain you provide.
- 3.4. Analytics — Google Analytics 4 (GA4), to understand aggregate usage. GA4 sets cookies and processes usage data only with your consent, given via the cookie banner (see Section 10).
- 3.5. Account data — if you create an account, your email address and a securely hashed password. MySecScan never stores your password in plain form.
- 3.6. Domain data — if you verify ownership of a domain to unlock domain-specific monitoring, the domain name itself and proof of ownership via a DNS TXT record that you add yourself.
- 3.7. Domain security monitoring — if you verify ownership of a domain, MySecScan may run automated checks against that domain to detect signs of cloning, impersonation, or lookalike-domain activity — using signals from your own verified domain together with publicly available sources, such as Certificate Transparency logs and domain-registration records. These checks do not collect any data about individuals who interact with a suspected clone or lookalike site: findings relate solely to the domain, not to any natural person.
The specific checks offered under domain security monitoring may be added or changed over time as the Service evolves. Their underlying data-handling approach remains as described in this Policy: verified-domain and public-source signals only, no data about third-party individuals, and no change in purpose or legal basis without an update to this Policy. - 3.8. Anonymous usage counters — we also can maintain simple, aggregate usage counters - for example, the total number of times a particular button or feature is used. These counters contain no identifiers, are not linked to any individual, IP address, session, or single request, and cannot be used to identify a person. As such, they do not constitute personal data and fall outside the scope of the GDPR and this Policy.
MySecScan does not knowingly collect special-category data (Art. 9 GDPR).
4. Purpose and legal basis for processing
MySecScan processes personal data only for specific, defined, and legitimate purposes. For each purpose, a corresponding legal basis under Art. 6 GDPR has been identified:
- Running the scan you requested — domain or URL submitted for the check — Art. 6(1)(b) GDPR (service you requested).
- Security, abuse prevention, rate-limiting — IP address, user-agent, request timestamp — Art. 6(1)(f) GDPR, legitimate interest (Recital 49 — security of network and information systems).
- Responding to full-scan requests — email address, domain — Art. 6(1)(b) GDPR.
- Web analytics — cookie identifiers, usage data — Art. 6(1)(a) GDPR, consent given via the cookie banner.
- Providing the account, domain-verification, and monitoring features you sign up for — email, hashed password, domain, verification data — Art. 6(1)(b) GDPR.
- Domain security monitoring (e.g. clone and lookalike-domain detection) — your verified domain, public data from Certificate Transparency logs and domain registries — Art. 6(1)(f) GDPR, legitimate interest (helping you find out if your domain has been cloned or impersonated).
5. Service emails
If you create an account, MySecScan sends transactional emails required for it to function: email-verification and password-reset links, plus — if you set up domain security monitoring — alerts when a check detects something such as a clone, lookalike domain, or matching certificate.
Legal basis: Art. 6(1)(b) GDPR — contract performance. These emails are part of delivering the Service you signed up for, not a separate marketing opt-in, and are never used to promote MySecScan's own products or those of a third party. You cannot opt out of verification or password-reset emails, since your account's security depends on them; monitoring alerts stop once you remove the corresponding domain or delete your account.
6. Scan results
Reports are generated for the domain you submit and returned directly to your browser — MySecScan does not store them, publicly or privately. MySecScan does not sell scan data or publish per-domain results.
7. Sharing and processors
7.1. MySecScan does not disclose personal data to third parties, except: the service providers listed below, who process it on MySecScan's behalf under a data-processing agreement; where disclosure is required by law; and — specific to domain security monitoring — where a check surfaces what appears to be serious fraudulent activity (e.g. an active phishing clone of your site), MySecScan may, at its discretion, report it to the relevant authorities. MySecScan does not sell personal data.
7.2. Service providers:
- Hosting provider — infrastructure hosting for the Service.
- Resend, Inc. — delivers our transactional emails (registration verification, password reset, monitoring alerts, full-scan request notifications). Processes the recipient address and the message content.
- Google Analytics 4 — web analytics, only with your consent via the cookie banner (see Section 10).
7.3. Where applicable, transfers of personal data outside the European Economic Area (EEA) rely on Standard Contractual Clauses (SCCs) or the EU–US Data Privacy Framework.
8. Data retention
MySecScan retains personal data only for as long as necessary to fulfil the purposes set out in this Policy:
- Technical security logs (IP, user-agent, request timestamp) — 30 days, then deleted automatically as logs rotate out.
- Domain security monitoring findings (e.g. clone/lookalike detection) — 30 days from when they are recorded, then deleted automatically.
- Account data — while your account is active. If you delete your account, it is deactivated immediately; you may request restoration within 30 days; after that period, all associated data is permanently and automatically erased.
9. Your rights (GDPR)
9.1. Under the GDPR, you have the right to access, rectify, erase, restrict, or object to the processing of your personal data, and the right to data portability. You may withdraw consent at any time; withdrawal does not affect the lawfulness of processing carried out before it.
9.2. To exercise these rights, email paul@mysecscan.com.
9.3. Account deletion. If you delete your account, it is deactivated immediately. You may request restoration within 30 days by contacting us at the address above. After that period, your account and all associated data — including domains and any domain security monitoring findings — are permanently and automatically erased.
10. Cookies
10.1. Essential cookies are used for core operation of the Service and do not require separate consent.
10.2. Analytics cookies (Google Analytics 4) are off by default: on your first visit, a banner asks whether to turn them on.
10.3. Your choice is stored in your browser and applies on every later visit; you can change it at any time via “Cookie settings” in the footer. If what we collect changes enough to matter, we will ask again.
11. Automated decision-making and profiling
MySecScan does not carry out automated decision-making that produces legal effects concerning you or similarly significantly affects you within the meaning of Art. 22 GDPR. The use of Google Analytics 4 is limited to aggregate usage statistics and does not involve automated decisions about specific individuals.
12. Changes to this Policy
MySecScan may update this Policy from time to time to reflect changes in law, in the functionality of the Service, or in the list of service providers involved — including new checks added under domain security monitoring (Section 3.7), for as long as their data-handling approach matches what is described in this Policy. The date at the top of this document reflects the current version. We will notify you of material changes through available channels. We recommend reviewing this Policy periodically.
13. Contact information
Data controller: DZZD MARKET PULSE (MySecScan), Oborishte St., Burgas, Bulgaria, VAT No. BG181450814.
For questions about the processing of personal data, exercising your rights, or this Policy, contact: paul@mysecscan.com.