Legal

Privacy Policy

Last updated: October 7, 2026 · GDPR-compliant

1. Who we are

CryptoSec Labs ("we", "us") operates the CryptoSec Labs investigation platform at cryptosec.xo.je. We are based in the Netherlands and act as the data controller for personal data collected through the Platform.

Contact for privacy matters: [email protected].

2. What we collect

DataPurpose
Email addressAccount creation, activation code delivery, service notifications
Password (hashed)Account authentication. We never store plaintext passwords.
Cryptocurrency payment referenceMatching your payment to your subscription
IP address & user agentSecurity, fraud prevention, rate limiting, abuse detection
Tool usage logsUnderstanding which features are used, detecting misuse, billing accuracy
Investigation targets you submitProcessing your investigation requests. Not retained beyond your session unless you save them to a case.

3. What we don't collect

  • No tracking pixels or advertising IDs
  • No social media logins or third-party OAuth
  • No payment card details (we accept only crypto)
  • No biometric data
  • No data sold to advertisers or data brokers

4. Legal basis for processing (GDPR Art. 6)

  • Contract performance: to provide the service you purchased
  • Legitimate interest: security, fraud prevention, product improvement
  • Legal obligation: responding to lawful requests from authorities
  • Consent: optional newsletter (if you opt in)

5. How long we keep data

  • Account data: while your account is active, plus 12 months after last activity
  • Payment records: 7 years (Dutch tax law)
  • Audit logs: up to 12 months
  • Visitor analytics: 12 months
  • Case data: deleted on request or when you close your account

6. Who we share data with

We do not sell personal data. We share only with essential service providers:

  • Hosting provider (InfinityFree) — stores the site and database
  • QR code generator (api.qrserver.com) — generates payment QR codes. Only your wallet address is sent; no personal data.
  • Law enforcement — only in response to a valid legal request

7. Your rights (GDPR Art. 15–22)

  • Access: request a copy of all personal data we hold on you
  • Rectification: correct inaccurate data
  • Erasure ("right to be forgotten"): delete your account and personal data
  • Restriction: limit how we process your data
  • Portability: receive your data in a machine-readable format
  • Objection: object to processing based on legitimate interest
  • Complaint: lodge a complaint with the Dutch Data Protection Authority (Autoriteit Persoonsgegevens)

To exercise any right, email [email protected]. We respond within 30 days.

8. Cookies

We use a single session cookie (cryptosec_sess) strictly necessary for login and CSRF protection. No tracking or advertising cookies are used.

9. Security

  • All traffic encrypted with TLS 1.3 (HTTPS only)
  • Passwords hashed with bcrypt
  • CSRF protection on all forms
  • Rate limiting on authentication and API endpoints
  • Regular backups and audit logging

While no system is perfectly secure, we take reasonable measures to protect your data.

10. International transfers

Your data may be transferred to and processed in countries outside the EU where our service providers operate. In such cases we ensure appropriate safeguards are in place (standard contractual clauses or equivalent).

11. Changes to this policy

We may update this policy. Material changes will be announced by email at least 14 days before taking effect.

12. Contact

For any privacy question or to exercise your rights, email [email protected].