Skip to content

Draft. This document is under review by counsel and is not yet in force (version 2026-10-03.1).

Privacy Notice

DRAFT for counsel review. Not legal advice.

Version: 2026-10-03.1

[Company legal name], [registered address] ("we") runs OSINTTotal. Contact for anything in this notice: [privacy@domain]. [EU representative under GDPR Art. 27 and UK representative under UK GDPR Art. 27, if required: name and address. Data protection officer, if appointed under Amendment 13: name and contact.]

Part A covers people who use the website and the app. Part B covers people who are the subject of an investigation, or who appear in one.

Part A. Website and app users

WhatWhyBasis (GDPR / UK GDPR)Kept
Name, work email, password hash, MFA factoryour account and sign-incontractwhile the account exists, then 30 days
Organization details from signup: legal name, country, registration number, website, intended use, attestation, acceptance of terms with time and IP addressvetting the customer, proof of acceptancelegitimate interests (preventing misuse); legal obligation where it applieslife of the organization plus [6] years
Sign-in and security logs: IP address, user agent, time, bot check resultsecurity, fraud and abuse preventionlegitimate interests[90] days
Audit log of actions in the appaccountability, customer audit traillegitimate interests; contractlife of the organization plus [6] years
Usage and billing recordsinvoices, quotascontract; legal obligation (tax)[7] years

We use only cookies needed to run the app (session, active organization, CSRF). No advertising or analytics cookies. We do not sell personal data.

Part B. People who are investigated (GDPR Art. 14)

This part is for you if a customer of OSINTTotal ran a check about you or about a company you are linked to.

Who decides. The customer that ran the check is the controller: it chose to check you, for which purpose, and on which lawful basis. We process the data for it (dpa.md). If you do not know which customer, write to us and we will find out and pass your request on (section "Your rights").

Purposes. Due diligence before a business decision: onboarding a customer, supplier or partner; investment, lending or M&A; AML, sanctions and anti-bribery compliance; fraud or misconduct investigation; litigation support; a security exposure review; and, outside the US only, pre-engagement screening that the candidate was told about. OSINTTotal is not used for US employment, tenant, credit or insurance decisions, to locate or contact people, or about minors (aup.md).

Data. Your name and aliases; identifiers the customer gave or that sources show (email, phone, usernames, company and registration numbers); professional history and company roles; court, regulatory, sanctions, PEP and watchlist records; news and other public reporting; public social media content; whether your email appears in known data breaches (source, date, data types, never passwords); public photos for reuse checks. We do not target, and the report filter removes, health, religion, sexual life, political opinion, union membership or ethnicity.

Sources. Public company and court registries, sanctions and watchlists, news archives and search engines, public websites and social profiles viewed without logging in, archives such as the Wayback Machine, and the data providers in subprocessors.md part 2. We never contact you or the people around you, and never use false identities or leaked credentials.

Lawful basis the customer relies on. Usually legitimate interests (GDPR Art. 6(1)(f)), for example knowing who it does business with or preventing fraud, or a legal obligation (Art. 6(1)(c)) such as AML customer due diligence; consent only where the customer asked you for it. Court and offence data only where the law allows it for that purpose (Art. 10; UK DPA 2018 Schedule 1).

Recipients. The customer and, for its purpose, its own client or advisers; our sub-processors (subprocessors.md); authorities where the law requires.

Transfers. Data is stored in Germany. Some processing happens in the US under safeguards described in dpa.md section 11.

How long. Until the retention date set on the case, normally the shortest time the purpose needs, then deleted. Encrypted backups expire within [35] days after that.

Your rights. Access, correction, erasure, restriction, objection to processing based on legitimate interests, and a complaint to a supervisory authority. In Israel, the rights to review and correct information in a database (Protection of Privacy Law sections 13 and 14) and the right to be informed under Amendment 13. Send a request to [privacy@domain]; how we handle it is in subject_requests.md. Some rights may be limited by law, for example where telling you would prejudice an AML or fraud investigation; the customer decides that and must record why.

Why you may not have been told directly. The customer is responsible for telling you. Where telling each person would be impossible or need disproportionate effort, or would seriously impair the purpose (GDPR Art. 14(5)(b)), it may rely on this public notice instead and must record that assessment in its case and DPIA.

Complaints. UK: Information Commissioner's Office (ico.org.uk). Israel: Privacy Protection Authority (gov.il/en/departments/the_privacy_protection_authority). EU: the authority where you live or work. We would like the chance to fix it first.

Changes

New versions are published here with a new Version: line.