Privacy Policy
How CyberRecon handles account, scan, monitoring, billing, support, and technical data.
Last updated 28 August 20261. Controller and privacy contact
The data controller is GREGLABS CO, the registered business identified in the Imprint. CyberRecon is a product of its CGregLab Security brand. Privacy requests can be sent to support@cgreglab.space.
2. Data we process
- Account data such as email address, profile name, verification state, timezone, account identifiers, and session information.
- Workspace data such as client records, team invitations, roles, verified domains, monitoring schedules, notification preferences, and report branding.
- Scan data such as submitted domains, timestamps, status, DNS and WHOIS evidence, hosting and technology indicators, subdomains, services, phishing signals, results, and reports.
- Billing data such as Stripe customer, checkout, subscription, price, status, and invoice identifiers. Full card details remain with Stripe.
- Communication and operational data such as support messages, alert-delivery history, security events, IP-derived request information, rate-limit state, and application logs.
3. Purposes and legal bases
Data is processed to create and secure accounts, provide requested scans and monitoring, enforce ownership and plan limits, deliver alerts and reports, administer subscriptions, prevent misuse, troubleshoot failures, comply with legal duties, and respond to support or privacy requests.
- Contract performance and steps requested before a contract.
- Legitimate interests in operating, securing, improving, and defending the service.
- Compliance with legal obligations, including accounting and lawful requests.
- Consent where a specific optional activity legally requires it.
4. Service providers
CyberRecon uses specialized processors and independent providers where needed to deliver the service.
- Supabase for authentication and PostgreSQL-backed application data.
- Render for the FastAPI scanning backend and supporting infrastructure.
- Vercel for the public Next.js web application and delivery network.
- Stripe for checkout, subscriptions, invoices, payment methods, and fraud controls.
- Resend for transactional account and security-alert email delivery.
5. Retention
Scan and alert history follows the plan limits shown in the pricing table: the trial uses shorter retention and paid plans currently provide up to 12 months. Account and workspace data is retained while the account is active and is removed or anonymized when deletion is completed, except where security, dispute, accounting, or other legal obligations require longer retention. Stripe and other providers apply their own legally required retention.
6. Your choices and rights
Depending on applicable law, you may request access, correction, deletion, restriction, objection, or portability, and may withdraw consent without affecting earlier lawful processing. You may also lodge a complaint with a competent data-protection authority.
7. International processing
Some providers may process data outside Germany or the European Economic Area. Where required, the responsible operator must ensure an applicable transfer mechanism and safeguards are in place.
8. Security and incident response
CyberRecon uses authenticated access, scoped API authorization, rate limits, target validation, signed Stripe webhooks, protected account deletion, and transport encryption. No service can guarantee absolute security. Contact support promptly if you suspect unauthorized access.
9. Changes
This notice may be updated when data practices, providers, legal requirements, or product features change. The revision date at the top identifies the current version.