Companies using the tools can rely on these terms; the operator does not receive personal data of your customers, because no data set is transmitted to it.
A processing agreement matters when one party processes personal data on behalf of another. It is worth being precise about whether that is happening at all before signing anything.
Here is the honest position: the tools evaluate what a user enters and return a result. There is no account backend, no stored history and no customer data set sent to this site. Where that is the situation, a processing agreement mainly records the roles and the absences.
Roles and scope
- The company that directs its staff to use the tools remains the controller of anything its staff type, and of the decisions taken from a result.
- The operator of this site acts as a processor only for the transient handling of a check request, and only for the time needed to return a result.
- No set of personal data belonging to the company's customers is transferred to this site for processing, because the tools have no such feature.
- Where a company embeds a link to a tool in its own materials, the company's own privacy notice obligations are unaffected by that link.
- This document describes the operator, not a group of companies: there is no affiliate that receives data separately.
Subprocessors and locations
- Hosting: the site is served from a European hosting provider in the European Union, and the static files are served from there.
- Breach exposure data: supplied through an established breach-checking service, whose attribution requirement travels with the data it provides.
- Password check: performed against a published hash-range service, where only a partial hash leaves the browser and the full password never does.
- There is no advertising network, no data broker and no third-party tracking script on the site.
- A current list of subprocessors is available on request, and changes to it are announced on this page before they take effect where they can be.
Technical and organisational measures, and their limits
- Transport encryption on every request, and a strict content security policy that restricts what the page may load or contact.
- No storage of the content of a check: no database of links checked, messages pasted, addresses or numbers entered.
- Passwords never leave the browser in full, and are never logged, hashed or stored on the server side.
- Access to the hosting account is limited to the operator, with two-factor authentication at the account level.
- What is not claimed: no certification, no audit report and no independent attestation. The measures above are described, not certified.
Frequently asked questions
Do you sign a customer's own DPA template?
For a business arrangement involving stored personal data, there is little to sign today: nothing is stored and no customer data set is processed here. If you need a specific document, contact us and describe what it is for.
Where is data processed?
In the European Union, on the hosting provider described above. The only external services involved are the breach-checking service and the hash-range password service, both of which are described on this page.
Is this legal advice?
No. It is a factual description of how the tools work, written so that a lawyer can assess it quickly. It is not a substitute for legal advice.
Written by The BaitScan team
Last updated September 16, 2026
Results are automated risk estimates based on public indicators and heuristics.