Privacy Policy
Updated April 17, 2026
This Privacy Policy explains how SolidLayer collects, uses, stores, and shares information when you use the platform and related services.
Data Controller
SolidLayer is the controller for personal data processed through your user account.
Company: SolidLayer
Address: [Add registered business address]
Privacy contact: support@solidlayer.tech
What We Collect About Users
- Account data (name, email) from authentication flows.
- Billing and subscription data from payment providers.
- Targets and scan history submitted through the platform.
- Technical data such as IP addresses, logs, and device/session metadata.
Public Security Data and Legitimate Interest
SolidLayer processes publicly observable technical data about internet-facing infrastructure. This data usually relates to organizations and systems rather than identified individuals.
Where collected data may incidentally contain personal data, processing is based on legitimate interest under GDPR Article 6(1)(f): providing cybersecurity intelligence and risk visibility services.
How We Use Data
- Provide security scanning, scoring, and reporting.
- Authenticate users and secure accounts.
- Process payments and subscriptions.
- Detect abuse, fraud, and violations of our Terms.
- Improve product quality, reliability, and support.
Subprocessors
We use vetted subprocessors, including:
- SolidLayer authentication (Better Auth, self-hosted)
- Neon (PostgreSQL database, EU region)
- Polar (payments, subscriptions, and EU VAT as Merchant of Record)
- Shodan (security enrichment)
- Vercel (hosting and delivery)
International Transfers
Where personal data is transferred outside the EEA (including to the United States), transfers are protected using Standard Contractual Clauses (SCCs) or another lawful transfer mechanism approved by the European Commission.
Retention
- User account data: deleted within 30 days after account closure (unless legally required otherwise).
- Application/security logs: retained up to 90 days.
- Domain cache data: retained per configured cache windows (e.g. 24h / 72h / 7d).
- Scan result retention: [Define by plan/tier and insert exact period].
Your GDPR Rights
Subject to legal limits, you may request:
- Access to your data
- Rectification
- Deletion
- Restriction of processing
- Objection to processing
- Data portability
- Review of automated decision impacts
- Complaint to the Belgian Data Protection Authority (APD/GBA)
To exercise rights, contact support@solidlayer.tech.
Updates
We may update this Privacy Policy periodically. Material changes will be published with a revised date.
Contact
For privacy requests, contact support@solidlayer.tech.