Defaults.Exposed › Privacy Policy
Privacy Policy
Last updated: 2026-07-07 · Version: 1.0
The short version
- If you run a free scan, we log the domain, your rough location/IP, and where you came from — to run the check, prevent abuse, and understand our traffic. No account, no email needed. A short notice at the scan box tells you this before you submit.
- If you ask for a Fix Guide or buy something, we collect your email and domain. There are no accounts and no passwords — you sign in with your email and a one-time code, and reach your deliverables through signed magic links.
- Payments go through our payment provider, Stripe. Your card details go straight to Stripe — we never see or store your full card number.
- We only email you marketing if you opt in, and every email carries an unsubscribe link. Service messages (receipts, the guide, alerts you asked for, renewal notices) are a closed set and carry no ads.
- Cookies: strictly necessary cookies, Google Analytics 4 for aggregate usage statistics, and a first-touch attribution cookie that remembers where you first came from. No advertising cookies.
- We use a small set of trusted processors (payments, email, analytics, hosting, DNS). We don’t sell your data.
- You have rights over your data — access, correction, deletion, opt-out. Being UAE-based doesn’t remove the rights you have under EU/UK law. Contact us and we’ll act.
1. Who is responsible for your data
The controller is Defaults Exposed FZ-LLC, a UAE free-zone company (“Defaults.Exposed”, “we”), registered office CWEP3805, Compass Building, Al Shohada Road, Al Hamra Industrial Zone-FZ, Ras Al Khaimah, United Arab Emirates · trade licence no. 47034427 · registration no. 0000004091879 (Ras Al Khaimah Economic Zone Authority). Privacy contact: [email protected].
We serve EU and UK customers and process and store data in the EU, so we operate as if GDPR/UK-GDPR applies to that data, and we also respect the UAE PDPL (Federal Decree-Law No. 45 of 2021) as a UAE entity.
1.1 Data Protection Officer / representative. We have not appointed a statutory DPO or EU representative; privacy questions go to [email protected] and are handled by the founder.
2. What we collect, why, and our lawful basis
| We collect | When | Why | Lawful basis |
|---|---|---|---|
| Domain you enter | Free scan, Fix Guide, purchase | To run the assessment / deliver the service | Legitimate interest (scan); contract (paid) |
| Approximate location, IP, referrer, UTM/source | Every scan | Security, abuse-prevention, traffic analytics, attribution | Legitimate interest (documented LIA — see §2.3) |
| Grade, score, failing checks for a domain | Scan / Fix Guide | To produce and store the result and lead record | Legitimate interest; contract (paid) |
| Email address | Fix Guide request, purchase, sign-in | To send the guide/receipt/deliverable and service messages, and to sign you in (one-time codes + magic links — no passwords, no accounts) | Fix Guide: legitimate interest to deliver (a free guide is not a “contract”); purchase: contract |
| Marketing consent flag | If you tick opt-in | To send marketing only if you agreed | Consent |
| One-time verification codes | Sign-in and ownership checks | To confirm it’s you / that you control a domain | Contract; legitimate interest |
| Third party’s admin/technical contact (name, email, phone) you give us so we can act on your behalf | Done-for-you / Managed intake | To coordinate the work you bought — nothing else (see §2.5) | Legitimate interest (documented LIA — see §2.3), with notice to that person at first contact |
| Order + subscription details (amount, tier, status, processor reference) | Purchase | To fulfil, support, refund, and keep tax records | Contract; legal obligation |
| Evidence bundle (the public DNS/TLS/email records observed) for paid Deliverables | Dossier / certificate | To produce the report | Contract |
Orders and entitlements are keyed to (email, domain) and stored in our application database on our EU servers.
2.1 We do not deliberately collect special-category data, and you should not send us any. The domain data we assess is publicly published DNS/web configuration, not private content. We never collect passwords or credentials — not yours, not your registrar’s, not your DNS provider’s. Delegated access or guided change only; our intake rejects password-like content.
2.2 Card data. Payments are processed by our payment provider, Stripe. Your card details are submitted directly to Stripe; we never receive or store your full card number.
2.3 Legitimate-interest assessments (LIA). Where we rely on legitimate interest above (scan logging + IP/location, the third-party admin contact, non-marketing lead retention), we keep a documented balancing test (LIA) on file and will make its outcome available on request. Legitimate interest is not used as a substitute for consent where consent is required (marketing — see §5).
2.4 Point-of-collection notice (free scan). The scan box shows a one-line notice before you submit: “We log the domain you check, your IP and rough location to run the scan, prevent abuse and improve the service — Privacy”, linking to this Policy. This collection is transparent at the point it happens.
2.5 Third-party contacts you give us. If you name your IT admin or a liaison so we can act on your behalf, we use their details only to coordinate the work you bought. On first contact we tell that person who we are, why we have their details, and point them to this Policy and their rights. When the job closes, we delete their details. You confirm you may lawfully share their details with us.
3. Who we share it with (processors and recipients)
We use a small set of trusted providers, each acting on our instructions under a data-processing agreement. We do not sell your personal data.
- Stripe (US/global) — payments, subscriptions, tax, receipts.
- Resend (US) — sending transactional and (consented) marketing email.
- Microsoft 365 (EU tenancy) — receiving email sent to @defaults.exposed. Where a Fix Guide or other message is copied into a @defaults.exposed mailbox, that copy sits in the M365 store and is covered by the retention rules in §6.
- Google Analytics 4 — aggregate website analytics (see Cookies below).
- Cloudflare (global anycast) — the DNS platform for service tiers where you delegate your domain’s nameservers to a zone we operate.
- Hosting / infrastructure — our servers run with OVH in the EU (France/Germany); the primary database and the scan/IP logs sit on our own servers there, not a third-party SaaS database.
- Professional advisers / authorities — only where legally required, or to establish or defend legal claims.
4. Cookies and analytics
We keep this light and honest. The Site sets no advertising cookies. What runs:
| Cookie / tech | Category | Purpose |
|---|---|---|
| Session / CSRF | Strictly necessary | Make the Site and forms work |
GA4 (_ga, _ga_*) | Analytics | Aggregate usage — pages, sources, scan/report events |
First-touch attribution cookie (de_attr) | Analytics/attribution | Remembers where you first arrived from, so we know which channels work |
Google Analytics 4 gives us aggregate statistics about how the Site is used. The first-touch attribution cookie records the source of your first visit and travels with your scan or sign-up so we can attribute it. Neither is used for advertising, and we don’t share this data with ad networks.
5. Marketing
5.1 We only send marketing email if you opted in (the consent flag on your lead/order). Every marketing email has an unsubscribe link, and you can opt out anytime by using it or emailing us. Opting out of marketing does not stop essential service messages.
5.2 Transactional messages are a closed set, sent on the basis that you asked for the service — not on marketing consent — and contain no promotional content: (a) your Fix Guide; (b) purchase receipts and invoices; (c) your Dossier / Deliverable; (d) monitoring/security alerts you subscribed to; (e) subscription renewal and cancellation notices required by law or by the Terms. A renewal notice states the renewal only; it will not up-sell. Anything beyond this list is marketing and needs your opt-in.
6. How long we keep it
- Scan data: scan results are kept as aggregate research data — they feed the Defaults.Exposed census. This is the retention counterpart to the census/aggregate carve-out in Terms §9.3.
- Leads (you asked for a free Fix Guide or opted into email): kept until you unsubscribe or ask us to erase you, then removed (minus anything we must keep for law/records).
- Orders, entitlements, and seal records: kept for 6 years as financial records.
- Delegated-zone data (service tiers where we operate your DNS zone): deleted 30 days after offboarding — matching the 30-day grace window in the offboarding process.
- Intake contact details (including any third-party admin/liaison details): deleted when the job closes.
- Verification codes: minutes — they expire and are deleted automatically.
- Evidence bundles / verification pages: your Dossier or certificate is a publicly verifiable artifact — the /verify page shows the domain, grade, and seal metadata (no personal emails), and anyone can check it, forever, without an account. If you exercise a valid erasure or withdrawal right, the verify page is dated and marked “withdrawn/refunded” rather than silently deleted — your rights are honoured and the evidence chain stays honest.
7. Where your data is processed (international transfers)
Customer and scan data lives on our EU servers (OVH, France/Germany). Email is delivered via Resend (US) and received via Microsoft 365 (EU tenancy). Payments run through Stripe (US/global). The DNS platform for service tiers runs on Cloudflare (global anycast). Website analytics run through Google Analytics 4 (Google, US).
Where a processor is outside the EU/UK, transfers rely on that processor’s standard contractual clauses / EU-US Data Privacy Framework certification — each of the named processors publishes these. As a UAE entity we also apply a PDPL cross-border transfer basis to the same flows.
| Recipient | Role | Where | Safeguard for EU/UK data |
|---|---|---|---|
| OVH | Hosting, database, scan/IP logs | EU (France/Germany) | Processed in the EU |
| Stripe | Payments | US/global | SCCs / DPF |
| Resend | Outbound email | US | SCCs / DPF |
| Microsoft 365 | Inbound email | EU tenancy | Processed in the EU (Microsoft SCCs/DPF cover any ancillary transfers) |
| Cloudflare | DNS platform (service tiers) | Global anycast | SCCs / DPF |
| Google (GA4) | Analytics | US | SCCs / DPF |
8. How we protect it
We are a security company and name our controls rather than leaving them generic. Technical and organisational measures include: encrypted transport (HTTPS); access controls with multi-factor authentication on administrative access; least-privilege roles; access logging and review; secrets kept out of the codebase; and regular backups. Two things get stricter treatment:
- The signing key that seals Dossiers and certificates is kept outside the code repository and is managed under a documented incident-response and revocation procedure, with a defined rotation path; each verify page states the signing key’s validity window.
- Delegated access into client domains (service tiers) is logged and reviewed per client. We never hold your passwords — access is by NS delegation or guided change only.
No system is perfectly secure, but we design the Services around keeping your data minimal in the first place: no accounts, no passwords, no stored card numbers.
8.1 If something goes wrong (breach response). We keep an internal breach register. If we confirm an incident affecting your data or your delegated zone, we notify you by email without undue delay and within 72 hours of confirming it, and we notify regulators where the law requires. Our processor agreements require each processor to notify us of a breach without undue delay so we can meet these deadlines.
9. Your rights
Depending on where you are, you can ask us to: access the data we hold about you, correct it, delete it, restrict or object to certain processing, withdraw consent (e.g. for marketing), and receive a portable copy. To exercise any of these, email [email protected]; we’ll verify your identity and respond within 30 days. Our UAE seat does not limit the rights you have under GDPR/UK-GDPR (or your local consumer/ data-protection law) where those apply to you. You also have the right to complain to your data-protection regulator — for EU/UK individuals, that includes your home authority.
10. Children
The Services are for businesses and adults. We don’t knowingly collect data from children under 16. If you believe a child gave us data, contact us and we’ll delete it.
11. Changes
We may update this Policy. Material changes will be notified on the Site or by email. The “Last updated” date always reflects the current version.
12. Contact
Privacy questions or requests: [email protected] · Defaults Exposed FZ-LLC, CWEP3805, Compass Building, Al Shohada Road, Al Hamra Industrial Zone-FZ, Ras Al Khaimah, United Arab Emirates · trade licence no. 47034427 · registration no. 0000004091879 (Ras Al Khaimah Economic Zone Authority).