Privacy Policy
Effective date: 10 July 2026
This policy explains what personal data Cyber Report ("we", "us") collects, why we collect it, who we share it with, and what rights you have. It is written to be read — if anything is unclear, email us at [email protected].
1. Who is responsible for your data
The data controller is amondi Media d.o.o. za usluge, Radnička cesta 47, 10000 Zagreb, Hrvatska (OIB: 20380401877). Contact for privacy matters: [email protected]. See our Impressum for full company details.
2. What we collect and why
Account data
When you register we collect your name, email address and a password (stored only as a one-way hash — we cannot read it). We record when you accepted our Terms of Service. Legal basis: performance of a contract (Art. 6(1)(b) GDPR).
Scan data
When you submit a website for scanning we store the domain name, an ownership-verification token, and the scan results: a technical fingerprint of the site (response headers, HTML metadata, detected technologies), security findings, and risk scores. We do not store full page bodies or the values of cookies set by the scanned site. Legal basis: performance of a contract (Art. 6(1)(b) GDPR).
Session and security data
While you are logged in, our session store holds your IP address and browser user-agent. Your IP address is also used transiently to rate-limit login attempts. Legal basis: our legitimate interest in keeping accounts secure and preventing abuse (Art. 6(1)(f) GDPR).
Notification settings (optional)
If you opt in to scan-completion notifications we email you when a scan finishes. If you configure a Slack webhook, we store that webhook URL and post scan summaries to it. Both are off by default and can be removed on your profile page at any time. Legal basis: consent (Art. 6(1)(a) GDPR).
Support messages
If you use the "need help with these findings?" contact form we process your name, email address, optional phone number and message so we can reply. Legal basis: performance of a contract / legitimate interest in answering your request.
What we do not collect
- No advertising or analytics trackers — this site sets no marketing cookies and loads no analytics scripts.
- No marketing emails — we only send transactional email (account verification, password reset, opt-in scan notifications).
- No payment card data — we currently process no payments.
3. Cookies
We use only strictly-necessary first-party cookies, all exempt from cookie-consent requirements because they are essential to operate the service:
- a session cookie that keeps you logged in;
- an XSRF-TOKEN cookie that protects forms against cross-site request forgery;
- an optional "remember me" cookie, set only if you tick that box at login, so you stay signed in across browser restarts.
None of these are used for tracking or advertising, and no third-party cookies are set. Web fonts are loaded from Bunny Fonts (bunny.net, an EU provider), which receives your IP address as a technical necessity of serving the font files and does not track you.
4. Who we share data with
We use a small number of service providers (processors) to run the service:
| Provider | Purpose | Location |
|---|---|---|
| Hetzner Online GmbH | Application hosting (servers, database) | Germany (EU) |
| Laravel Forge (Laravel LLC) | Server management | USA |
| Mailgun (Sinch) | Transactional email delivery | EU region |
| Anthropic | AI-generated finding explanations (receives scan finding data, never your name or email) | USA |
| Bunny Fonts (BunnyWay d.o.o.) | Web font delivery | Slovenia (EU) |
| Slack | Scan notifications — only if you configure your own webhook | USA |
During a scan, technical queries about the scanned domain (never about you) are sent to public security data sources: certificate-transparency logs (crt.sh), the WPScan vulnerability database, api.wordpress.org, FIRST.org (EPSS scores), CISA (KEV catalogue), DNS resolvers (Google, Cloudflare) and Team Cymru (IP/ASN lookups).
Where a provider is outside the EU/EEA, transfers are safeguarded by the EU–US Data Privacy Framework and/or Standard Contractual Clauses. We do not sell personal data to anyone.
5. How long we keep data
- Scans, findings and fingerprints: deleted automatically 90 days after the scan was created.
- Account data: kept until you delete your account.
- Sessions: the session cookie expires after 120 minutes of inactivity; the optional "remember me" cookie lasts longer so you stay signed in. All your sessions are erased when you delete your account.
- Password-reset tokens: expire within an hour and are swept daily.
- Failed background-job records: may briefly reference a scanned domain; pruned within 7 days.
- Support emails: retained in our mailbox for as long as needed to handle your request and our legal obligations.
6. Your rights
Under the GDPR you have the right to:
- Access the personal data we hold about you;
- Rectify inaccurate data (name and email can be edited on your profile page);
- Erase your data — deleting your account on the profile page permanently removes your account, scans, reports and findings;
- Receive a copy of your data in a portable format;
- Object to or restrict processing based on legitimate interest;
- Withdraw consent at any time for optional features (notifications, Slack webhook).
You can rectify your name and email and erase your account directly on your profile page. To exercise any other right — including access, a portable copy of your data, objection or restriction — email [email protected] and we will respond within the statutory time limit. You also have the right to lodge a complaint with your supervisory authority — in Croatia, the Agencija za zaštitu osobnih podataka (AZOP), azop.hr.
7. Security
Passwords are stored as bcrypt hashes. All traffic is encrypted in transit (TLS). Scans run in isolated, ephemeral containers with restricted network access. Access to production systems is limited to authorized personnel. No system is perfectly secure — if we become aware of a breach affecting your personal data, we will notify you and the supervisory authority as required by Articles 33–34 GDPR.
8. Children
The service is intended for website owners and is not directed at children. Do not register if you are under 16.
9. Changes
We may update this policy as the service evolves (for example, when paid plans launch). Material changes will be announced on this page with a new effective date, and by email where required.