Privacy Policy
This Privacy Policy explains how OsintCTI collects, uses, stores, and safeguards information when you interact with our Cyber Threat Intelligence platform. Your privacy and the lawful handling of data are at the core of our operations.
Last Updated: April 24, 2026 · Effective Date: April 24, 2026
How we handle your information and data.
OsintCTI operates as both a data controller (for customer account data) and a data processor/controller (for Intelligence Data sourced from public and open channels). This Policy describes the categories of data we process, the legal bases we rely on, how we protect that data, and the rights you have under applicable privacy laws including the GDPR and the Turkish KVKK (Law No. 6698 on the Protection of Personal Data).
1. Who We Are
OsintCTI ("we", "us", "our", "Company") is a Cyber Threat Intelligence and Open-Source Intelligence (OSINT) provider. For the purposes of applicable data-protection legislation, OsintCTI is the data controller responsible for personal data collected through our Service. If you have any questions about this Policy or wish to exercise any data-subject right, you may contact our privacy team at [email protected].
2. Scope of This Policy
This Policy applies to all personal data processed by OsintCTI in connection with: (a) your use of the osintcti.com website and related subdomains; (b) your registration and use of the OsintCTI platform and APIs; (c) business communications, support interactions, and marketing activities; and (d) Intelligence Data that we source from public and open channels for the purpose of providing threat-intelligence services to our customers. This Policy does not apply to third-party websites or services that are linked to, or integrated with, our Service — those are governed by their own privacy policies.
3. Categories of Data We Collect
We collect the following categories of data: (a) Account Data — name, business email, organization, role, phone number, and billing information you provide during registration; (b) Authentication Data — hashed passwords, multi-factor authentication tokens, session identifiers, and API keys; (c) Usage Data — log files, IP addresses, browser and device identifiers, referring URLs, timestamps, queries executed, and features used; (d) Communications Data — messages, support tickets, and survey responses you send to us; (e) Payment Data — processed by PCI-DSS compliant third-party payment processors; we do not store full card numbers on our servers; (f) Intelligence Data — information collected from public, open, and lawfully accessible sources (including breach-compromised credentials, leaked databases, dark-web forums, paste sites, code repositories, DNS and WHOIS records, social-media posts marked public, and sanctions lists) that may contain personal data of third parties.
4. Purposes & Legal Bases for Processing
We process personal data only where we have a lawful basis to do so. Depending on the context, our legal bases include: (a) Performance of a contract — to create and manage your account, deliver the Service, and process payments; (b) Legitimate interests — to ensure network and information security, prevent fraud and abuse, detect and investigate cyber threats, improve our platform, and protect our rights and those of our customers. We have assessed that these interests are not overridden by the fundamental rights and freedoms of data subjects, particularly because Intelligence Data is sourced from publicly available channels and is processed strictly for cybersecurity purposes, which is expressly recognized as a legitimate interest under Recital 49 of the GDPR; (c) Legal obligations — to comply with laws, regulations, court orders, and lawful requests from competent authorities; (d) Consent — where required, for specific purposes such as marketing communications; you may withdraw your consent at any time.
5. Processing of Intelligence Data
A central function of OsintCTI is the aggregation and analysis of Intelligence Data, which may contain personal data of individuals whose credentials or personal information has been exposed, leaked, or publicly disclosed. We process this data solely for the purpose of enabling our customers to identify threats, protect their own networks, investigate fraud, and fulfill their own legitimate cybersecurity obligations. We do not sell personal data. We do not process Intelligence Data for advertising, profiling of consumers for marketing, or automated decision-making that produces legal effects on individuals. Access to Intelligence Data by customers is restricted, logged, and subject to acceptable-use controls described in our Terms of Service. Where technically feasible and lawful, we apply minimization, hashing, or redaction techniques to sensitive fields.
6. How We Share Data
We share personal data only in limited, necessary circumstances: (a) Service providers & sub-processors — cloud infrastructure, payment processors, email delivery, analytics, and customer-support platforms, all bound by written data-processing agreements and confidentiality obligations; (b) Customers — Intelligence Data is made available to our customers within the scope of their subscription and acceptable-use obligations; (c) Legal authorities — where required by law, court order, or binding request from a competent authority; (d) Corporate transactions — in connection with a merger, acquisition, financing, or sale of assets, subject to confidentiality; (e) With your consent — for any other purpose disclosed to you. We do not sell personal data, nor do we rent or trade it with third parties for their independent marketing purposes.
7. International Data Transfers
OsintCTI operates globally, and your data may be transferred to, stored, or processed in countries outside your country of residence, including outside the European Economic Area and the Republic of Türkiye. When we transfer personal data internationally, we implement appropriate safeguards as required by applicable law, including Standard Contractual Clauses (SCCs) approved by the European Commission, equivalent mechanisms under the Turkish KVKK, and supplementary technical and organizational measures such as encryption in transit and at rest. You may request a copy of the safeguards applicable to transfers of your data by contacting [email protected].
8. Data Retention
We retain personal data only for as long as necessary to fulfill the purposes set out in this Policy or to comply with legal, accounting, or reporting obligations. Account Data is retained for the duration of your subscription and for up to 24 months after termination, unless a longer period is required by law. Usage and Log Data is retained for up to 12 months for security, audit, and debugging purposes. Billing Records are retained in accordance with applicable tax and commercial laws (typically 10 years under Turkish law). Intelligence Data is retained for as long as it remains relevant for cybersecurity purposes or until the source is taken offline or a valid removal request is honored. Upon expiry of the applicable retention period, data is either deleted or irreversibly anonymized.
9. Security Measures
OsintCTI implements industry-standard technical and organizational measures to protect personal data against unauthorized access, alteration, disclosure, loss, or destruction. These measures include: encryption of data in transit (TLS 1.2 or higher) and at rest (AES-256 or equivalent), hashed and salted password storage, role-based access controls, principle of least privilege, multi-factor authentication for administrative access, network segmentation, regular vulnerability scanning and penetration testing, secure software development practices, security logging and monitoring, and employee confidentiality and security training. Despite our efforts, no system can be guaranteed 100% secure; in the event of a personal data breach that is likely to result in a risk to the rights and freedoms of individuals, we will notify the competent supervisory authority and affected data subjects in accordance with applicable law (within 72 hours where required by the GDPR).
10. Your Data Protection Rights
Subject to applicable law, you have the right to: (a) access the personal data we hold about you; (b) request correction of inaccurate or incomplete data; (c) request erasure of your personal data ("right to be forgotten"); (d) restrict or object to certain processing activities; (e) receive your data in a portable, machine-readable format; (f) withdraw consent where processing is based on consent; (g) not be subject to solely automated decisions that produce legal effects; (h) lodge a complaint with a supervisory authority (in Türkiye, the Personal Data Protection Authority — KVKK Kurumu; in the EU, your local Data Protection Authority). To exercise any of these rights, please email [email protected]. We will respond within the period required by applicable law (typically 30 days). Please note that these rights are not absolute: certain requests may be limited or refused where an exemption applies, such as where processing is necessary for the establishment, exercise, or defense of legal claims, or where the data is required for cybersecurity purposes.
11. Requests Regarding Intelligence Data
If you are a data subject whose personal data appears within Intelligence Data (for example, in a dataset derived from a public breach disclosure), you may submit a request to [email protected]. We will assess each request individually against applicable legal bases. We may decline requests where: (a) the data originates from publicly accessible sources and continued processing remains necessary for cybersecurity purposes under Article 6(1)(f) GDPR and Recital 49; (b) removal would prejudice the establishment, exercise, or defense of legal claims; (c) processing is required by law; or (d) the request is manifestly unfounded or excessive. Where we decline, we will explain the reason and inform you of your right to lodge a complaint with a supervisory authority.
12. Cookies & Tracking Technologies
We use cookies and similar technologies to operate the Service, remember your preferences, authenticate sessions, analyze usage patterns, and improve performance. We distinguish between strictly necessary cookies (required for the Service to function), functional cookies (remember preferences), analytics cookies (measure and improve performance), and marketing cookies (where applicable). Non-essential cookies are set only with your consent, which you may manage or withdraw at any time via our cookie banner or your browser settings. Blocking certain cookies may impact Service functionality.
13. Children's Privacy
The Service is intended exclusively for business users and is not directed to individuals under the age of 18. We do not knowingly collect personal data from children. If we become aware that a child has provided us with personal data, we will promptly delete such data. Parents or guardians who believe a child has submitted personal data may contact [email protected] for removal.
14. Automated Decision-Making & Profiling
OsintCTI uses automated systems to score, enrich, and classify threat indicators (such as risk scoring of IP addresses, domains, and indicators of compromise). These automated processes are applied to technical threat data and do not produce legal or similarly significant effects on individual data subjects. We do not engage in solely automated decision-making of the type regulated under Article 22 of the GDPR with respect to consumer individuals.
15. Third-Party Services & Links
Our Service may integrate with or link to third-party services (such as identity providers, payment processors, analytics platforms, or external intelligence feeds). These third parties operate under their own privacy policies, and OsintCTI is not responsible for their practices. We encourage you to review the privacy policies of any third party before providing them with personal data.
16. KVKK-Specific Provisions (Türkiye)
For data subjects in the Republic of Türkiye, OsintCTI acts as a data controller ("veri sorumlusu") under Law No. 6698 on the Protection of Personal Data (KVKK). Your rights under Article 11 of the KVKK include learning whether your personal data is processed, requesting information about the processing, learning the purpose and whether data is used in accordance with such purpose, requesting correction, deletion, or destruction of data, and claiming damages in the event of unlawful processing. Requests under the KVKK may be submitted via [email protected] and are processed in accordance with the Communiqué on the Principles and Procedures for the Request to the Data Controller.
17. Changes to This Policy
We may update this Privacy Policy from time to time to reflect changes in our practices, technologies, legal requirements, or other factors. When we make material changes, we will notify you through the Service interface, by email, or by posting a prominent notice on our website prior to the changes taking effect. The "Last Updated" date at the top of this Policy indicates when it was last revised. Continued use of the Service after such changes constitutes your acknowledgment of the revised Policy.
18. Contact Us
If you have any questions, concerns, or requests regarding this Privacy Policy or our data-processing practices, please contact us at: [email protected]. For general inquiries, please use the contact form on our website. We will respond to all legitimate inquiries within the timeframes required by applicable law.
Ready to Gather Deep Intelligence? Get Started With a Free Trial
See how it can work for your research with a free trial. Then let's discuss the subscription plan that's right for you.