Privacy Policy
Last updated: October 7, 2026 · GDPR-compliant
1. Who we are
CryptoSec Labs ("we", "us") operates the CryptoSec Labs investigation platform at cryptosec.xo.je. We are based in the Netherlands and act as the data controller for personal data collected through the Platform.
Contact for privacy matters: [email protected].
2. What we collect
| Data | Purpose |
|---|---|
| Email address | Account creation, activation code delivery, service notifications |
| Password (hashed) | Account authentication. We never store plaintext passwords. |
| Cryptocurrency payment reference | Matching your payment to your subscription |
| IP address & user agent | Security, fraud prevention, rate limiting, abuse detection |
| Tool usage logs | Understanding which features are used, detecting misuse, billing accuracy |
| Investigation targets you submit | Processing your investigation requests. Not retained beyond your session unless you save them to a case. |
3. What we don't collect
- No tracking pixels or advertising IDs
- No social media logins or third-party OAuth
- No payment card details (we accept only crypto)
- No biometric data
- No data sold to advertisers or data brokers
4. Legal basis for processing (GDPR Art. 6)
- Contract performance: to provide the service you purchased
- Legitimate interest: security, fraud prevention, product improvement
- Legal obligation: responding to lawful requests from authorities
- Consent: optional newsletter (if you opt in)
5. How long we keep data
- Account data: while your account is active, plus 12 months after last activity
- Payment records: 7 years (Dutch tax law)
- Audit logs: up to 12 months
- Visitor analytics: 12 months
- Case data: deleted on request or when you close your account
6. Who we share data with
We do not sell personal data. We share only with essential service providers:
- Hosting provider (InfinityFree) — stores the site and database
- QR code generator (api.qrserver.com) — generates payment QR codes. Only your wallet address is sent; no personal data.
- Law enforcement — only in response to a valid legal request
7. Your rights (GDPR Art. 15–22)
- Access: request a copy of all personal data we hold on you
- Rectification: correct inaccurate data
- Erasure ("right to be forgotten"): delete your account and personal data
- Restriction: limit how we process your data
- Portability: receive your data in a machine-readable format
- Objection: object to processing based on legitimate interest
- Complaint: lodge a complaint with the Dutch Data Protection Authority (Autoriteit Persoonsgegevens)
To exercise any right, email [email protected]. We respond within 30 days.
8. Cookies
We use a single session cookie (cryptosec_sess) strictly necessary for login and CSRF protection. No tracking or advertising cookies are used.
9. Security
- All traffic encrypted with TLS 1.3 (HTTPS only)
- Passwords hashed with bcrypt
- CSRF protection on all forms
- Rate limiting on authentication and API endpoints
- Regular backups and audit logging
While no system is perfectly secure, we take reasonable measures to protect your data.
10. International transfers
Your data may be transferred to and processed in countries outside the EU where our service providers operate. In such cases we ensure appropriate safeguards are in place (standard contractual clauses or equivalent).
11. Changes to this policy
We may update this policy. Material changes will be announced by email at least 14 days before taking effect.
12. Contact
For any privacy question or to exercise your rights, email [email protected].