Last Updated: March 2, 2026
Your privacy matters to us. This Privacy Policy explains what information Reconnity ("we", "us", "our") collects when you use our External Attack Surface Management platform, how we use it, and your choices regarding your data.
This policy applies to our website, web application, APIs, and any other way you interact with our Service.
Who's responsible: Reconnity acts as the data controller for your personal information. For service terms, see our Terms of Use.
We collect information in several ways:
When you run scans, we generate reports about your assets - domains, IPs, vulnerabilities found, etc. This data belongs to you and you can delete it anytime.
If our scans encounter personal data on your systems (like email addresses in exposed files), we only process it to show you the finding. We don't use it for anything else.
We use your email, name, and organization info to:
Legal basis: Necessary to provide the service you signed up for.
Kept: While your account exists, plus any legally required period.
We process technical data (IP, browser, device info) to:
Legal basis: Necessary for service delivery.
Kept: Based on your subscription plan.
When you contact us, we keep records to help you effectively and improve our support.
Legal basis: Contract fulfillment and legitimate interest.
Kept: Duration of the support matter plus 2 years.
We may send you product news, security tips, and occasional promotional content. You can unsubscribe anytime.
Legal basis: Legitimate interest (existing customers) or consent (others).
Kept: Until you opt out.
We analyze usage patterns (anonymized where possible) to improve features and fix problems.
Legal basis: Legitimate interest in improving our service.
Kept: Anonymized data kept indefinitely; identifiable data deleted when no longer needed.
| Data Type | How Long We Keep It |
|---|---|
| Account info | While account is active + legal requirements |
| Scan reports (Free) | 30 days |
| Scan reports (Pro) | 6 months |
| Scan reports (Enterprise) | 12 months (customizable) |
| Support tickets | 2 years after resolution |
| Audit logs | 30-365 days by plan |
We never sell your data. Period.
We work with trusted service providers who help us run the platform:
| Provider Type | What They Do | Location |
|---|---|---|
| Cloud hosting (AWS) | Stores and processes your data | USA (us-east-1) |
| Security (Cloudflare) | Protects against attacks, speeds up delivery | Global |
| Payments (Stripe) | Processes credit card payments | USA/EU |
| Email delivery | Sends notifications and alerts | USA |
All providers are bound by contracts requiring them to protect your data and use it only as we direct.
We may share data if legally required (court order, law enforcement request) or to protect rights and safety. If we're acquired or merge with another company, your data transfers to the new owner - we'll notify you beforehand.
Your data is primarily stored in AWS data centers in the United States (N. Virginia region).
For EU/EEA users, we ensure lawful transfers through:
AWS maintains SOC 2, ISO 27001, and other certifications demonstrating their security practices.
Security is our business, so we take it seriously for our own systems too:
In the unlikely event of a data breach affecting you, we'll notify you within 72 hours and work with you to address it.
You have control over your data. Here's what you can do:
Most of these you can do yourself in Account Settings. For anything else, email [email protected].
Not satisfied? You can complain to your local data protection authority. In Poland, that's UODO (Urząd Ochrony Danych Osobowych).
We use only essential cookies to make the platform work:
| Cookie | Why | Expires |
|---|---|---|
| Session token | Keeps you logged in | 7 days or logout |
| Preferences | Remembers your settings | 1 year |
| Security token | Prevents cross-site attacks | Session |
What we don't do:
You can block cookies in your browser, but the platform won't work properly without the essential ones.
Reconnity is for business use by adults (18+). We don't knowingly collect data from minors. If you believe a child has created an account, contact us and we'll remove it.
We may update this policy as our practices evolve or laws change. For significant changes, we'll email you at least 30 days before they take effect. The date at the top shows when we last updated.
Reach out anytime:
© 2026 Reconnity. All rights reserved.
Home | Terms of Use | Privacy Policy