Privacy Policy
Last updated: Aug 17, 2026
This Privacy Policy explains how VeDomEll s. r. o. ("OUTSIDE", "we", "us" or "our") collects, uses, stores and protects personal data when you visit outsideguardian.eu, create an account, use the OUTSIDE platform, communicate with us or otherwise interact with our services.
OUTSIDE is an external attack surface management and security monitoring platform. It helps authorized users discover publicly observable internet-facing assets, review evidence-backed findings and monitor changes affecting domains and infrastructure they are entitled to assess.
For questions about this Privacy Policy or the processing of personal data, contact us at security@outsideguardian.eu.
1. Who is responsible for your data
For personal data processed in connection with our website, customer accounts, billing, communications, service administration and product improvement, VeDomEll s. r. o. acts as the data controller.
When a customer submits personal data to OUTSIDE for processing on the customer's behalf, the customer generally acts as the controller and VeDomEll s. r. o. acts as the processor. Such processing may be governed by a separate Data Processing Agreement.
2. Personal data we collect
Depending on how you use OUTSIDE, we may collect the following categories of personal data.
2.1 Account and identity information
This may include:
- name;
- business email address;
- company or organization name;
- job title;
- account identifier;
- authentication and account-security information;
- organization membership and user role;
- communication preferences.
We do not store plaintext passwords. Authentication credentials are processed using appropriate technical safeguards.
2.2 Billing and transaction information
If you purchase a subscription or paid service, we may process:
- billing name and address;
- company and tax information;
- subscription plan;
- payment status;
- invoice details;
- transaction identifiers;
- limited payment-method information supplied by our payment provider.
Complete payment-card details are processed by the applicable payment provider and are not intended to be stored directly by OUTSIDE.
2.3 Service and usage information
When you use OUTSIDE, we may collect:
- login and session information;
- IP address;
- browser and device information;
- timestamps;
- pages and features used;
- scan requests;
- domain verification status;
- selected settings;
- generated reports;
- audit events;
- diagnostic and error information;
- security and abuse-prevention records.
2.4 Customer-submitted content
You may submit information such as:
- domains and hostnames;
- organization names;
- asset labels;
- comments;
- remediation notes;
- report settings;
- integration configuration;
- webhook destinations;
- internal workflow metadata.
You are responsible for ensuring that you have a lawful basis and appropriate authority to submit this information to OUTSIDE.
2.5 Publicly observable technical data
OUTSIDE may collect and analyze technical information that is publicly accessible or observable from the public internet, including:
- DNS records;
- certificate-transparency information;
- public IP addresses;
- domain-registration and RDAP information;
- HTTP response metadata;
- TLS certificate information;
- public technology indicators;
- externally accessible service information;
- public vulnerability and threat-intelligence references;
- relationships between publicly observable assets.
Some public technical records may contain personal data, for example where a personal email address appears in a public registration record, certificate, webpage or security contact file.
OUTSIDE does not treat the public availability of information as permission to use it for unrelated purposes. Public technical data is processed only for legitimate security, asset-discovery, risk-analysis and service-protection purposes.
2.6 Communications
When you contact us, request support, report a vulnerability or participate in a product demonstration, we may process:
- your name and contact details;
- the content of your message;
- attachments;
- support history;
- meeting details;
- technical information needed to investigate your request.
3. How we collect personal data
We collect personal data:
- directly from you;
- from users authorized by your organization;
- automatically when you use the website or platform;
- from payment, authentication, hosting and communication providers;
- from public internet sources;
- from security and vulnerability-information providers;
- from integrations enabled by you or your organization.
4. Why we use personal data
We may use personal data for the following purposes.
4.1 Providing the service
This includes:
- creating and administering accounts;
- authenticating users;
- processing authorized scans;
- generating findings, reports and dashboards;
- monitoring verified domains;
- maintaining historical observations;
- providing support;
- processing subscriptions and payments;
- delivering service notifications.
The legal basis is generally performance of a contract or taking steps requested before entering into a contract.
4.2 Protecting OUTSIDE and its users
We process information to:
- prevent fraud and abuse;
- detect unauthorized access;
- enforce rate limits;
- investigate incidents;
- preserve audit trails;
- secure accounts and infrastructure;
- protect our legal rights and those of our users.
The legal basis is our legitimate interest in operating a secure and reliable service and, where applicable, compliance with legal obligations.
4.3 Improving and maintaining the platform
We may use limited service and diagnostic data to:
- troubleshoot failures;
- measure reliability;
- understand feature usage;
- improve usability;
- test changes;
- maintain detection quality;
- reduce false positives;
- plan capacity.
Where possible, we use aggregated, de-identified or minimized information. The legal basis is our legitimate interest in improving the service.
4.4 Communicating with you
We may send:
- account and security notices;
- scan and monitoring alerts;
- billing communications;
- service updates;
- responses to support requests;
- legally required notifications.
Operational communications are necessary to provide the service. Marketing communications are sent only where permitted by law, and you may unsubscribe at any time.
4.5 Complying with law
We may process personal data where necessary to:
- comply with accounting, tax and legal obligations;
- respond to valid legal requests;
- establish, exercise or defend legal claims;
- cooperate with competent authorities;
- enforce our agreements.
5. Artificial intelligence features
Certain OUTSIDE features may use an artificial intelligence provider to generate plain-language explanations, summaries or remediation guidance.
AI features are intended to assist users and do not replace professional cybersecurity judgment.
Where AI functionality is enabled:
- only information reasonably necessary for the requested function should be transmitted;
- sensitive values should be minimized or redacted where technically feasible;
- AI output may be incomplete or inaccurate;
- AI output is not treated as independent proof of a vulnerability or compromise;
- customers should verify recommendations before acting on them.
We do not intentionally use customer content to train publicly available third-party models unless this is expressly disclosed and lawfully agreed.
6. Cookies and similar technologies
OUTSIDE may use cookies, local storage and similar technologies for:
- authentication;
- session continuity;
- security;
- fraud prevention;
- saving user preferences;
- maintaining essential platform functionality.
Strictly necessary technologies may be used without optional consent where permitted by law.
Analytics, advertising or other non-essential technologies will be used only where an appropriate legal basis exists and, where required, after consent has been obtained. You may withdraw consent through the available cookie controls.
For basic audience and product-journey measurement, OUTSIDE operates a self-hosted Umami analytics service within its own infrastructure. The tracker does not use cookies or local storage and does not track visitors across unrelated websites. It records anonymized page views, visits, referrer origin or internal path, browser, operating system, device type, screen size, language and approximate country, together with a deliberately limited set of product events. Query strings and fragments are removed before collection; password-reset, invitation and public-report token routes are not collected. Product-event properties are restricted to the journey mode, subscription-plan name and validated UTM campaign codes. Names, email addresses, organization identifiers, domains submitted for assessment, finding text, secrets and access tokens must not be sent to analytics. Browser Do Not Track signals are respected.
The analytics service receives ordinary network request metadata, including an IP address and user-agent, to process the request and derive anonymous visit statistics, but OUTSIDE does not use that information to identify a visitor or track them across websites. Analytics records are kept for the configured bounded retention period and then removed by an automated retention job; encrypted backups expire under the infrastructure backup policy. You may object to analytics processing by enabling Do Not Track or contacting security@outsideguardian.eu.
EU guidance distinguishes necessary cookies from non-essential cookies and generally requires informed consent before non-essential cookies are stored or accessed.
7. Who receives personal data
We may share personal data with carefully selected service providers that support the operation of OUTSIDE, including providers of:
- cloud infrastructure and hosting;
- managed databases and backups;
- email delivery;
- payment processing;
- authentication;
- monitoring and error tracking;
- customer support;
- security and abuse prevention;
- AI-assisted explanations;
- public technical and vulnerability-data enrichment.
These providers may process data only for the agreed purposes and under applicable contractual safeguards.
We may also disclose information:
- to professional advisers;
- to auditors;
- to competent authorities where legally required;
- in connection with a merger, financing, restructuring, acquisition or sale of assets;
- to protect OUTSIDE, our users or the public against fraud, abuse or security threats.
We do not sell personal data to data brokers or advertisers.
8. International data transfers
Some service providers may process personal data outside the European Economic Area.
Where required, we use an appropriate transfer mechanism, such as:
- an adequacy decision;
- European Commission Standard Contractual Clauses;
- another legally recognized safeguard;
- a permitted statutory derogation.
Where appropriate, we also assess supplementary technical and organizational measures.
9. Data retention
We retain personal data only for as long as reasonably necessary for the purposes described in this Privacy Policy.
Retention periods depend on the type of information and may include:
- account data: for the duration of the account and a reasonable period afterward;
- billing and accounting records: for the period required by applicable law;
- scan results and monitoring history: according to the customer's plan, configuration and contractual relationship;
- security and audit logs: for a period appropriate to security, fraud prevention and accountability;
- support communications: for as long as necessary to resolve the request and preserve relevant business records;
- backups: until overwritten through the normal backup lifecycle.
We may retain limited information for longer where necessary to comply with law, resolve disputes, prevent abuse or enforce agreements.
After the applicable retention period, data is deleted, anonymized or securely isolated from active use.
10. Security
We use technical and organizational measures designed to protect personal data against unauthorized access, alteration, disclosure, loss and destruction.
These measures may include:
- encryption in transit;
- access controls;
- role-based permissions;
- environment separation;
- logging and monitoring;
- secure development practices;
- dependency and vulnerability management;
- backups and recovery procedures;
- incident-response processes;
- restrictions on administrative access.
No service can guarantee absolute security. You are responsible for protecting your credentials, configuring integrations securely and promptly notifying us of suspected unauthorized access.
Further information is available on our Security page.
11. Your rights
Subject to applicable law, you may have the right to:
- obtain confirmation that we process your personal data;
- access your personal data;
- correct inaccurate or incomplete data;
- request deletion;
- restrict processing;
- object to processing based on legitimate interests;
- receive portable data in an applicable format;
- withdraw consent at any time;
- lodge a complaint with a competent supervisory authority;
- request information about applicable international-transfer safeguards.
These rights may be subject to legal conditions and exceptions.
To exercise a right, contact security@outsideguardian.eu. We may need to verify your identity before responding.
Where we process data solely on behalf of a customer, we may refer your request to that customer.
12. Automated decision-making
OUTSIDE may calculate findings, classifications and scores using deterministic rules, configured detection logic and supporting technical evidence.
These outputs are intended to assist security review. They are not intended to produce legal or similarly significant effects concerning natural persons without human involvement.
13. Children
OUTSIDE is a business-oriented service and is not directed to children.
You must be legally capable of entering into the applicable agreement or be authorized to act for an organization using the service.
14. Third-party services and links
OUTSIDE may contain links to third-party websites, documentation, vulnerability databases or integrations.
We are not responsible for the privacy practices, security or content of third-party services. Their own terms and privacy notices apply.
15. Changes to this Privacy Policy
We may update this Privacy Policy to reflect changes in the service, law, technology or our processing practices.
The updated version will be published on this page with a revised "Last updated" date. Where required, we will provide additional notice.
16. Contact
For privacy questions, data-subject requests or complaints, contact:
VeDomEll s. r. o.
Alžbetina 55, 040 01 Košice – mestská časť Staré Mesto, Slovakia
IČO: 52498751 · DIČ: 2121045729 · IČ DPH: SK2121045729
security@outsideguardian.eu