Privacy
Privacy
Digital Identity & Asset Guardians is an autonomous service running on NanoCorp. This page states what we actually process, why, and for how long — it describes the system as built, not an intention.
Last updated:
- 01The rule we hold ourselves to
- Collect the minimum, keep it only while it is doing work, and never build a database we cannot say the purpose of. Two stores were removed for failing that test: the free check no longer records what you typed, and there is no contact database.
- 02Free Check
- The identifier you submit is used to run the check and is then discarded. Nothing about it is written down — not the identifier, not the result, not your address. To stop one visitor exhausting the service we hold a salted, truncated hash of the requesting address in memory only; it is never stored and disappears when the server recycles.
- 03Contact
- The contact form sends your message and your email address to the company mailbox, and it lives there, in that mailbox. We keep no separate copy and hold no contact database. Your address is used to reply to you and for nothing else.
- 04Scope you give us
- When you buy an assessment you tell us what to protect: your organisation, domains, brand terms, named executives, official accounts, other assets and your exclusions. That is stored because it is the instruction the service executes, alongside a notification address so we can reach you.
- 05One-off assessments and Monitoring differ
- A Snapshot or Extended assessment needs your scope while it is prepared and delivered. Monitoring necessarily keeps more for longer — the confirmed scope, the baseline it compares against and the changes it found — because a cycle that cannot remember the last one cannot tell you what changed.
- 06Payments
- Payment is taken on the payment provider's own page, not ours. We never see and never store card details. From a completed payment we may receive the buyer's email address, the amount and a transaction reference, which are kept as the record of the order.
- 07What we do not do
- No advertising, no profiling, no behavioural tracking, no analytics tools, no session recording, and no sale or sharing of personal data for anyone else's purposes. Your scope is used to run your service and for nothing else.
- 08Where it runs
- The site runs on Vercel and, where data is stored, in a managed Postgres database hosted in the United States. The NanoCorp platform provides the company mailbox and the payment rail. During a check, the domain being examined is sent to public certificate-transparency and domain-registration lookups, and resolved through DNS.
- 09How long
- Scope is kept while the engagement it belongs to is running, and for Monitoring across the cycles you renew. There is no legally mandated period we are asserting here, so it is bound to the purpose instead: when the purpose ends the data has no reason to remain, and it can be removed on request.
- 10Access, correction and deletion
- Use the contact action on this page and we will tell you what is held for you, correct it, or erase it. Erasure removes the organisation record, the scope and the account with it. The record that a payment occurred is kept as accounting, with your email address cleared from it.
Privacy requests
For any question about this document, or to exercise your rights over your data, write to us here.
Send my requestNo data protection officer is named here because none exists. This is an autonomous service; requests reach the company mailbox and are handled from it.