⚓ Running on beta — hold tight, things may still shake.

Privacy Policy

Last updated: September 3, 2026

Controller: "NNTEAM" UAB, Perkūnkiemio g. 13, LT-12114 Vilnius, Lithuania ("we," "us," "Trawlsec").

1. What We Collect

Trawlsec is a threat intelligence monitoring product, so beyond account credentials we also process the asset and finding data you and your team put into the Service:

Data Purpose Legal basis (GDPR) Retention
Email address, name Account identification, login, password reset, service communications Contract (Art. 6(1)(b)) Until account deletion or 3 months of inactivity
Password (hashed) Authentication Contract (Art. 6(1)(b)) Until account deletion or 3 months of inactivity
Session cookie Keeps you logged in between requests Contract (Art. 6(1)(b)) Expires on logout or after 30 days
Asset inventory data you configure Matching threat intel findings to your assets Contract (Art. 6(1)(b)) Until account deletion, manual removal, or 3 months of inactivity
Findings, review dispositions, sign-off records Producing the review trail and reports used as compliance evidence Contract (Art. 6(1)(b)) / legitimate interest in security monitoring (Art. 6(1)(f)) Based on your subscription plan's retention period
Billing details (handled by Stripe) Processing subscription payments Contract (Art. 6(1)(b)), legal obligation (Art. 6(1)(c)) for invoicing/tax records 10 years, per Lithuanian accounting law

We never store your password in plain text — only a salted hash.

2. Cookies

We use one strictly necessary session cookie to keep you authenticated. This cookie is required for the Service to function and isn't used for advertising or cross-site tracking. Because it's strictly necessary, GDPR/ePrivacy rules don't require a cookie-consent banner for it — but this section must be updated if analytics or marketing cookies are added later.

3. How We Use Your Data

We do not sell your data, and we do not use it for advertising.

4. Sharing

We share data only with:

We do not sell or rent personal data to third parties. Where a subprocessor is used, we have a data processing agreement in place with them.

5. Data Security

We use industry-standard measures (password hashing, HTTPS, access controls) to protect your data. No system is 100% secure, and we can't guarantee absolute security — but we take reasonable, good-faith steps to protect it.

6. Your Rights (GDPR)

As a data subject under the GDPR, you have the right to access, rectify, erase, restrict, or port your personal data, and to object to processing based on legitimate interest. You can:

7. Children's Privacy

The Service is a B2B security tool not directed at children, and we don't knowingly collect data from anyone under 16.

8. International Transfers

Your data is hosted with Laravel Cloud (running on AWS) in EU data centers and, as a general rule, does not leave the EU/EEA. If a subprocessor (e.g. our payment processor) transfers data outside the EU/EEA, that transfer is covered by an adequacy decision or Standard Contractual Clauses.

9. Changes to This Policy

We may update this policy occasionally. Material changes will be posted here with an updated date, and where required, we'll notify you directly.

10. Contact

Questions or requests about your data: info@trawlsec.com, or by post at "NNTEAM" UAB, Perkūnkiemio g. 13, LT-12114 Vilnius, Lithuania.