Defaults.Exposed

Defaults.Exposed › Privacy Policy

Privacy Policy

Last updated: 2026-07-07 · Version: 1.0


The short version


1. Who is responsible for your data

The controller is Defaults Exposed FZ-LLC, a UAE free-zone company (“Defaults.Exposed”, “we”), registered office CWEP3805, Compass Building, Al Shohada Road, Al Hamra Industrial Zone-FZ, Ras Al Khaimah, United Arab Emirates · trade licence no. 47034427 · registration no. 0000004091879 (Ras Al Khaimah Economic Zone Authority). Privacy contact: [email protected].

We serve EU and UK customers and process and store data in the EU, so we operate as if GDPR/UK-GDPR applies to that data, and we also respect the UAE PDPL (Federal Decree-Law No. 45 of 2021) as a UAE entity.

1.1 Data Protection Officer / representative. We have not appointed a statutory DPO or EU representative; privacy questions go to [email protected] and are handled by the founder.


2. What we collect, why, and our lawful basis

We collectWhenWhyLawful basis
Domain you enterFree scan, Fix Guide, purchaseTo run the assessment / deliver the serviceLegitimate interest (scan); contract (paid)
Approximate location, IP, referrer, UTM/sourceEvery scanSecurity, abuse-prevention, traffic analytics, attributionLegitimate interest (documented LIA — see §2.3)
Grade, score, failing checks for a domainScan / Fix GuideTo produce and store the result and lead recordLegitimate interest; contract (paid)
Email addressFix Guide request, purchase, sign-inTo send the guide/receipt/deliverable and service messages, and to sign you in (one-time codes + magic links — no passwords, no accounts)Fix Guide: legitimate interest to deliver (a free guide is not a “contract”); purchase: contract
Marketing consent flagIf you tick opt-inTo send marketing only if you agreedConsent
One-time verification codesSign-in and ownership checksTo confirm it’s you / that you control a domainContract; legitimate interest
Third party’s admin/technical contact (name, email, phone) you give us so we can act on your behalfDone-for-you / Managed intakeTo coordinate the work you bought — nothing else (see §2.5)Legitimate interest (documented LIA — see §2.3), with notice to that person at first contact
Order + subscription details (amount, tier, status, processor reference)PurchaseTo fulfil, support, refund, and keep tax recordsContract; legal obligation
Evidence bundle (the public DNS/TLS/email records observed) for paid DeliverablesDossier / certificateTo produce the reportContract

Orders and entitlements are keyed to (email, domain) and stored in our application database on our EU servers.

2.1 We do not deliberately collect special-category data, and you should not send us any. The domain data we assess is publicly published DNS/web configuration, not private content. We never collect passwords or credentials — not yours, not your registrar’s, not your DNS provider’s. Delegated access or guided change only; our intake rejects password-like content.

2.2 Card data. Payments are processed by our payment provider, Stripe. Your card details are submitted directly to Stripe; we never receive or store your full card number.

2.3 Legitimate-interest assessments (LIA). Where we rely on legitimate interest above (scan logging + IP/location, the third-party admin contact, non-marketing lead retention), we keep a documented balancing test (LIA) on file and will make its outcome available on request. Legitimate interest is not used as a substitute for consent where consent is required (marketing — see §5).

2.4 Point-of-collection notice (free scan). The scan box shows a one-line notice before you submit: “We log the domain you check, your IP and rough location to run the scan, prevent abuse and improve the service — Privacy”, linking to this Policy. This collection is transparent at the point it happens.

2.5 Third-party contacts you give us. If you name your IT admin or a liaison so we can act on your behalf, we use their details only to coordinate the work you bought. On first contact we tell that person who we are, why we have their details, and point them to this Policy and their rights. When the job closes, we delete their details. You confirm you may lawfully share their details with us.


3. Who we share it with (processors and recipients)

We use a small set of trusted providers, each acting on our instructions under a data-processing agreement. We do not sell your personal data.


4. Cookies and analytics

We keep this light and honest. The Site sets no advertising cookies. What runs:

Cookie / techCategoryPurpose
Session / CSRFStrictly necessaryMake the Site and forms work
GA4 (_ga, _ga_*)AnalyticsAggregate usage — pages, sources, scan/report events
First-touch attribution cookie (de_attr)Analytics/attributionRemembers where you first arrived from, so we know which channels work

Google Analytics 4 gives us aggregate statistics about how the Site is used. The first-touch attribution cookie records the source of your first visit and travels with your scan or sign-up so we can attribute it. Neither is used for advertising, and we don’t share this data with ad networks.


5. Marketing

5.1 We only send marketing email if you opted in (the consent flag on your lead/order). Every marketing email has an unsubscribe link, and you can opt out anytime by using it or emailing us. Opting out of marketing does not stop essential service messages.

5.2 Transactional messages are a closed set, sent on the basis that you asked for the service — not on marketing consent — and contain no promotional content: (a) your Fix Guide; (b) purchase receipts and invoices; (c) your Dossier / Deliverable; (d) monitoring/security alerts you subscribed to; (e) subscription renewal and cancellation notices required by law or by the Terms. A renewal notice states the renewal only; it will not up-sell. Anything beyond this list is marketing and needs your opt-in.


6. How long we keep it


7. Where your data is processed (international transfers)

Customer and scan data lives on our EU servers (OVH, France/Germany). Email is delivered via Resend (US) and received via Microsoft 365 (EU tenancy). Payments run through Stripe (US/global). The DNS platform for service tiers runs on Cloudflare (global anycast). Website analytics run through Google Analytics 4 (Google, US).

Where a processor is outside the EU/UK, transfers rely on that processor’s standard contractual clauses / EU-US Data Privacy Framework certification — each of the named processors publishes these. As a UAE entity we also apply a PDPL cross-border transfer basis to the same flows.

RecipientRoleWhereSafeguard for EU/UK data
OVHHosting, database, scan/IP logsEU (France/Germany)Processed in the EU
StripePaymentsUS/globalSCCs / DPF
ResendOutbound emailUSSCCs / DPF
Microsoft 365Inbound emailEU tenancyProcessed in the EU (Microsoft SCCs/DPF cover any ancillary transfers)
CloudflareDNS platform (service tiers)Global anycastSCCs / DPF
Google (GA4)AnalyticsUSSCCs / DPF

8. How we protect it

We are a security company and name our controls rather than leaving them generic. Technical and organisational measures include: encrypted transport (HTTPS); access controls with multi-factor authentication on administrative access; least-privilege roles; access logging and review; secrets kept out of the codebase; and regular backups. Two things get stricter treatment:

No system is perfectly secure, but we design the Services around keeping your data minimal in the first place: no accounts, no passwords, no stored card numbers.

8.1 If something goes wrong (breach response). We keep an internal breach register. If we confirm an incident affecting your data or your delegated zone, we notify you by email without undue delay and within 72 hours of confirming it, and we notify regulators where the law requires. Our processor agreements require each processor to notify us of a breach without undue delay so we can meet these deadlines.


9. Your rights

Depending on where you are, you can ask us to: access the data we hold about you, correct it, delete it, restrict or object to certain processing, withdraw consent (e.g. for marketing), and receive a portable copy. To exercise any of these, email [email protected]; we’ll verify your identity and respond within 30 days. Our UAE seat does not limit the rights you have under GDPR/UK-GDPR (or your local consumer/ data-protection law) where those apply to you. You also have the right to complain to your data-protection regulator — for EU/UK individuals, that includes your home authority.


10. Children

The Services are for businesses and adults. We don’t knowingly collect data from children under 16. If you believe a child gave us data, contact us and we’ll delete it.


11. Changes

We may update this Policy. Material changes will be notified on the Site or by email. The “Last updated” date always reflects the current version.


12. Contact

Privacy questions or requests: [email protected] · Defaults Exposed FZ-LLC, CWEP3805, Compass Building, Al Shohada Road, Al Hamra Industrial Zone-FZ, Ras Al Khaimah, United Arab Emirates · trade licence no. 47034427 · registration no. 0000004091879 (Ras Al Khaimah Economic Zone Authority).