Legal

Privacy Policy

Updated April 17, 2026

This Privacy Policy explains how SolidLayer collects, uses, stores, and shares information when you use the platform and related services.

01

Data Controller

SolidLayer is the controller for personal data processed through your user account.

Company: SolidLayer
Address: [Add registered business address]
Privacy contact: support@solidlayer.tech

02

What We Collect About Users

  • Account data (name, email) from authentication flows.
  • Billing and subscription data from payment providers.
  • Targets and scan history submitted through the platform.
  • Technical data such as IP addresses, logs, and device/session metadata.
03

Public Security Data and Legitimate Interest

SolidLayer processes publicly observable technical data about internet-facing infrastructure. This data usually relates to organizations and systems rather than identified individuals.

Where collected data may incidentally contain personal data, processing is based on legitimate interest under GDPR Article 6(1)(f): providing cybersecurity intelligence and risk visibility services.

04

How We Use Data

  • Provide security scanning, scoring, and reporting.
  • Authenticate users and secure accounts.
  • Process payments and subscriptions.
  • Detect abuse, fraud, and violations of our Terms.
  • Improve product quality, reliability, and support.
05

Subprocessors

We use vetted subprocessors, including:

  • SolidLayer authentication (Better Auth, self-hosted)
  • Neon (PostgreSQL database, EU region)
  • Polar (payments, subscriptions, and EU VAT as Merchant of Record)
  • Shodan (security enrichment)
  • Vercel (hosting and delivery)
06

International Transfers

Where personal data is transferred outside the EEA (including to the United States), transfers are protected using Standard Contractual Clauses (SCCs) or another lawful transfer mechanism approved by the European Commission.

07

Retention

  • User account data: deleted within 30 days after account closure (unless legally required otherwise).
  • Application/security logs: retained up to 90 days.
  • Domain cache data: retained per configured cache windows (e.g. 24h / 72h / 7d).
  • Scan result retention: [Define by plan/tier and insert exact period].
08

Cookies

We use strictly necessary cookies to keep you signed in, protect the platform, and maintain security. Functional cookies remember preferences you choose, such as language. Analytics and marketing cookies are optional and only enabled if you accept them in cookie settings.

  • Necessary: authentication, security, and session continuity.
  • Functional: theme and locale preferences (SameSite=Lax).
  • Analytics: optional usage measurement (PostHog) and error session replay (Sentry).
  • Marketing: optional measurement and email-related preferences if you opt in.
  • Consent and CSRF cookies are HttpOnly, SameSite=Strict, and HMAC-signed by our backend.

You can change your choices anytime from the footer Cookies link or in Profile & Settings under Preferences.

09

Your GDPR Rights

Subject to legal limits, you may request:

  • Access to your data
  • Rectification
  • Deletion
  • Restriction of processing
  • Objection to processing
  • Data portability
  • Review of automated decision impacts
  • Complaint to the Belgian Data Protection Authority (APD/GBA)

To exercise rights, contact support@solidlayer.tech.

10

Updates

We may update this Privacy Policy periodically. Material changes will be published with a revised date.

11

Contact

For privacy requests, contact support@solidlayer.tech.

© 2026 SolidLayer BV. All rights reserved.