Naunet Scan Portal Privacy Notice
Version 2.0. Effective 5 August 2026. This notice replaces all earlier versions.
This notice explains what the Naunet Scan Portal (the “Portal”) collects, why, who it is shared with, and how long it is kept. It covers the Portal itself and the scanning that the Portal performs. What the scan does, and what you are responsible for, is described in the Terms of service.
1. Who is responsible
Naunet is the controller for the account, session, scan-request and audit data described below. For the content of a scan — the assets you submit and what the scan observes about them — you decide what is scanned and we act on your instruction, so you are responsible for having a lawful basis for that scanning and for the authorisation the Terms require. Contact: mate.torok@naunet.eu.
2. Account and identity data
Sign-in runs through our own sign-in service, and through Google, Microsoft or GitHub if you choose one of them. From that sign-in we store a unique account identifier, your email address, your display name, the provider you used, and an identifier for your session. Your profile record holds your language and theme preference, your account tier, and when the account was created and last changed. Your password is held by the sign-in service and never by the Portal. Where you change your email address, we send you a link to confirm it.
3. Session and security data
For each active session we record its identifier, the IP address it connects from and information about the browser you use, so that you can see and revoke your own sessions. We write an audit record for sensitive actions, including session revocation, profile and email changes, scan lifecycle changes and booking events, noting who acted, what they did and which record was affected. These records exist to protect the account and to investigate abuse.
4. Scan data
For every scan request we store:
- the web addresses, domains and hosts you submit;
- the scope you declare: additional domains, address ranges and exclusions;
- any notes you add;
- when you accepted the Terms and confirmed your authorisation;
- the progress of the scan, and any error or retry information;
- your domain ownership verification records and their result;
- your findings, the attack surface we observed, your annotations, and the exports generated from them;
- whether and when a report was first opened, and any readout booking.
Scan output describes systems, not people, but it can contain personal data: email addresses and names discovered from public sources during discovery, personal data published on the assets in scope, and identifiers inside publicly served files. Credential-like material found in your own publicly served files is stored and displayed in redacted form. Do not put credentials, secrets or unnecessary personal data into notes or other free-text fields.
5. Notification data
We send you email about your scans and your account. If you opt in to SMS, we store the mobile number and timezone you give us, use them to send scan-ready messages within your quiet-hour window through our SMS provider, and record when a message was sent. You can withdraw SMS consent, or unsubscribe from scan reminders, at any time; withdrawing it does not affect messages already sent. Where meeting scheduling is offered, bookings are handled by a third-party scheduling provider and we store the resulting booking reference.
6. Cookies
The Portal sets only its own cookies, only the ones it needs to work, and their contents are encrypted so that they cannot be read or altered in your browser. There are no advertising cookies, no analytics cookies and no third-party trackers, and we do not profile you. We use them for:
- keeping you signed in, for the length of your session;
- protecting the sign-in process, deleted as soon as sign-in finishes;
- remembering a scan you started before signing in;
- holding your unfinished scan request, for up to two hours;
- confirming a completed email verification, for 15 minutes;
- remembering your language choice, for up to a year.
7. Why we process it, and on what basis
- To perform our contract with you: creating your account, running the scans you request, producing results and exports, and sending the service email that belongs to them.
- Our legitimate interests: keeping the Portal and its customers secure, preventing and investigating misuse and unauthorised scanning, enforcing plan limits, auditing sensitive actions, troubleshooting, and improving the service.
- Your consent: SMS notification, and any optional identity provider you choose to sign in with. You can withdraw consent at any time.
- Legal obligation: where we must keep or disclose records, including responding to a lawful request or a report of unauthorised scanning.
We do not sell your data, and we do not use it to train models.
8. Who else processes it
The Portal runs on infrastructure operated by Naunet at its hosting providers, and relies on a small number of external services:
- the sign-in provider you choose, if you sign in with Google, Microsoft or GitHub;
- our email delivery provider, which handles your email address and the message content;
- our SMS provider, which handles your mobile number and the message content;
- a third-party scheduling provider, if you book a readout;
- during a scan, an address-ownership lookup service, which receives the addresses of the assets in scope, and the public information sources we query, which necessarily learn the domains being scanned.
The matching of detected versions against known vulnerabilities happens on our own systems and sends nothing to any third party. We disclose data to authorities, and to the operator of an affected system, where the Terms allow it or the law requires it.
9. How long we keep it
The detailed raw data collected during a scan is deleted automatically once it is older than 90 days, unless the scan is still running. Results, findings, annotations and exports stored in the Portal are kept for as long as your account exists, so that you can compare a scan against earlier ones, until you or we delete them. Account, profile and verification records are kept while your account exists. Session records are removed when the session ends or is revoked. Audit records and abuse-related records are kept longer where we need them to establish or defend a claim, or to keep the service secure.
10. Your rights
If you are in the EU or the UK you have the right to ask for a copy of your personal data, to have inaccurate data corrected, to have data erased, to restrict or object to processing including processing based on our legitimate interests, to receive your data in a portable form, and to withdraw a consent you gave. Some of this you can do in the Portal: your profile, your sessions, your SMS setting and your reminder subscription are all under your own control. For anything else, including deletion of an account and its scan history, write to mate.torok@naunet.eu and we will respond within one month. We may need to keep limited records after erasure where the law requires it or where we need them to defend a claim. You can also complain to your data protection supervisory authority; in Hungary this is the Hungarian National Authority for Data Protection and Freedom of Information (NAIH).
11. Security
Access to the Portal requires you to sign in, your session cookies are encrypted, sensitive actions are audited, and access to the systems that hold your data is restricted. No service can promise perfect security; if a breach affects your personal data and is likely to present a risk to you, we will notify you and the relevant authority as the law requires.
12. Children
The Portal is a business tool and is not intended for anyone under 18. We do not knowingly collect data from children.
13. Changes
We may update this notice as the Portal changes. The version and effective date at the top of this page always show the current text, and we will notify material changes through the Portal or by email where we can.
14. Language
This notice is published in English and in Hungarian. The two versions are intended to say the same thing. If they differ, the English version prevails, except where the law that applies to you requires otherwise.