※ Legal
Privacy Policy
Platform: Dashten
Last updated: July 28, 2026
Controller: Mohammad Atwi, operating the Dashten platform as an independent service provider. For data protection inquiries, use the contact methods available through the Platform or your account.
1. Scope and relationship to other documents
This Privacy Policy explains how we collect, use, disclose, store, and protect personal data when you use Dashten (the “Platform”). It should be read together with our Terms and Conditions and, where applicable, our Cybersecurity Services Agreement presented at registration or gate.
2. Categories of data we process
Depending on how you use the Platform, we may process:
- Account and identity data: email address, hashed password, name or display identifiers you provide, organization name (if any), plan and billing references, verification status, two-factor settings, and contract signature metadata (e.g. legal name, organization, signature image or vector data, timestamp, IP address at signing) where the Platform captures them.
- Asset and intelligence content: domains, URLs, email addresses, IP addresses, person names, logins, free-text notes, uploaded files, and similar inputs you add as “assets” or attach to reports and canvases.
- Generated and ingested intelligence: OSINT and dark-web style results, breach or leak records, AI-generated summaries, report bodies, canvas graphs, tracker execution logs, counts of findings, and redacted or unredacted credential rows as permitted by your verification state and product rules.
- Technical and usage data: IP address, user agent, approximate location derived from IP, session tokens, cookies and similar storage, timestamps of actions, API request metadata, error logs, and security signals (e.g. rate limits, fraud checks).
- Communications: messages you send to support, notification preferences, and delivery status for email or integrated channels (e.g. Telegram where you connect it).
We do not require you to provide more than is reasonably necessary for the features you choose; optional fields are voluntary.
3. Purposes and legal bases (GDPR-style framing)
Where the EU/UK General Data Protection Regulation or similar laws apply, we rely on the following bases:
- Contract: to register you, authenticate you, deliver features you request (reports, trackers, verification), process payments and credits, and enforce our Terms.
- Legitimate interests: to secure the Platform, prevent abuse, analyze aggregated usage, improve reliability, send essential service emails, and defend legal claims—balanced against your rights.
- Consent: where required for marketing communications, non-essential cookies, or specific sensitive processing; you may withdraw consent without affecting prior lawful processing.
- Legal obligation: to comply with court orders, lawful requests from authorities, or accounting and tax rules.
In other jurisdictions, we process data for the same operational purposes permitted by local law.
4. How we use sensitive or high-risk categories
Cybersecurity data may include credentials, security incidents, or personal identifiers relating to third parties (e.g. employees of your organization). You must only submit such data if you have a lawful basis (authorization, legitimate interest assessment, or consent as required). We process it solely to provide the service you configured—monitoring, alerting, reporting—and not for unrelated profiling or sale.
5. Encryption and storage of credential-like fields
Where the Platform stores structured leak or credential rows (for example URL, login, and password fields associated with reports or tracker runs), we use authenticated encryption (AES-256-GCM via our application security module) for those columns at rest in our database, keyed with secrets you configure on the server. This reduces impact if storage is exposed but does not replace your obligation to protect account access and endpoint security.
Other fields (reports, summaries, asset labels) may be stored as standard database text protected by access controls and transport security (HTTPS).
6. Automated decision-making and AI
We use AI models (via third-party providers you configure on the deployment, e.g. OpenAI or others) to generate text, suggestions, or structured outputs. These outputs are assistive; they may be inaccurate. We do not use AI to make solely automated decisions that produce legal or similarly significant effects about you without human review, unless we explicitly disclose otherwise for a feature.
7. Recipients and subprocessors
We share data with limited categories of recipients:
- Infrastructure and hosting providers that store or transmit data;
- Email and messaging providers (e.g. transactional email) to deliver verification codes, password resets, tracker alerts, and notices;
- AI and search API providers when their services process prompts or queries you trigger;
- Payment processors if you purchase paid plans (they receive billing data directly under their policies);
- Professional advisers (lawyers, accountants) under confidentiality;
- Authorities when required by law or to protect rights and safety.
We do not sell your personal information as “sale” is defined under U.S. state privacy laws. We do not share data for cross-context behavioral advertising as a business model.
8. International transfers
Servers, support staff, or subprocessors may be located outside your country, including in the United States or the European Economic Area. Where required, we implement appropriate safeguards (e.g. Standard Contractual Clauses) or rely on derogations permitted by law.
9. Retention
We retain data as long as your account is active and for a reasonable period afterward for backup, audit, and legal defense, unless a shorter or longer period is required by law or agreed in writing. You may request deletion of your account subject to legal holds. Some anonymized or aggregated metrics may be retained without identifiers.
10. Security
We implement administrative, technical, and organizational measures appropriate to the risk, including access control, encryption in transit (HTTPS), encryption at rest for designated credential storage, logging, and monitoring. No method of transmission or storage is 100% secure; you should use strong passwords and enable two-factor authentication when offered.
11. Your rights
Depending on your location, you may have the right to access, rectify, erase, restrict processing, object, data portability, and to withdraw consent. You may lodge a complaint with a supervisory authority. To exercise rights, contact us through the Platform. We will verify your identity before acting. Some requests may be limited by law (e.g. ongoing investigations).
12. Cookies and similar technologies
We use cookies and local storage for session management, security (e.g. CSRF or auth tokens), theme preferences, and analytics if enabled. You can control cookies through browser settings; disabling essential cookies may break login or dashboard behavior.
13. Children
The Platform is not directed at children. We do not knowingly collect personal data from children below the digital consent age. If you believe we have, contact us for deletion.
14. Third-party sites
Links to external sites are not covered by this Policy. Their privacy practices govern data you provide to them.
15. Changes
We may update this Policy by posting a new version with an updated date. Material changes may be notified by email or in-app message where appropriate.
16. Regional notice — Lebanon
Unless a more specific addendum is published for your region, this global Policy applies. If you require a localized disclosure (e.g. California “Notice at Collection”), contact us and we will provide the applicable summary.
17. Contact
For privacy requests or questions, use the contact or support options provided in the application. For contract-related identity issues, refer to the Cybersecurity Services Agreement you accepted.