
The original document is in English only. The last date of document revisions and edits was November 15, 2025.
Policy on Removal and Blocking of Data
Primary contact for takedown requests:
This Remove Content Policy (the "Policy") sets out:
This Policy applies to all tools and components of the NiamonX platform, including (but not limited to):
Important: NiamonX may, at its sole discretion, request identity verification and additional documentation. All requests are subject to review by the NiamonX legal and security teams, and processing timelines may vary depending on the specific circumstances and team workload.
NiamonX allows data subjects and authorised representatives to request the exclusion of the following categories of data from our search and indexing systems (to the extent technically and legally feasible):
| Data type | Description |
|---|---|
auto |
Automatically recognised type (email / phone / hash, etc.) |
email |
Personal and corporate email addresses |
username |
Unique user names / handles (subject to limitations below) |
phone |
Mobile and landline phone numbers |
hash |
Hashes of accounts, passwords, tokens |
domain |
Domains and email domains of organisations |
ip |
IPv4/IPv6 addresses |
password / wifikey |
Compromised passwords, WPA keys and other sensitive keys |
essid / bssid |
Wi‑Fi network names (SSID/ESSID) and MAC addresses of access points |
| Other categories | Considered on a case‑by‑case basis by the NiamonX legal/security teams |
Once removed, such data:
After a takedown request has been verified and approved by NiamonX:
id — internal unique record ID;value — the value to be blocked (email, phone, IP, etc.);type — data type (e.g. email, phone, ip);reason — reason for blocking/removal;created_at — timestamp of creation;created_by — internal administrator or process ID (or NULL for automated processing).Important: All timeframes in this Policy are indicative and may be extended in complex cases, where additional legal review, technical investigation or identity verification is required.
NiamonX can remove or block data only within its own platform. We cannot remove data from:
Our actions are limited to excluding such data from NiamonX search and indexing. We do not control the original sources.
In general, if a breach or dataset contains only a username, and it is not linked to:
then removal may not be possible, because a username in isolation does not always constitute uniquely identifiable personal data under GDPR / UK‑GDPR / CCPA / CPRA and similar laws.
To process a removal request related to usernames, the requester may need to provide a linked identifier (for example, the email address or other data that ties that username to a specific individual) and sufficient evidence that they are the relevant data subject.
All such requests are subject to legal and factual assessment by the NiamonX legal team.
Corporate domains may be blocked or excluded from certain detection features. However, the consequences must be clearly understood:
For corporate takedown requests, NiamonX may, at its discretion, require verification of control or ownership, for example via:
Additional documentation (such as corporate authorisation letters, proof of identity, proof of role) may be requested, at the discretion of the NiamonX legal and security teams.
We cannot remove or block data which:
In such cases, removal from our platform may be limited or unavailable where it would conflict with legal obligations or public interest considerations. Each request is reviewed individually.
All takedown and removal requests MUST be sent to:
Requests sent to other addresses may be redirected and therefore processed with delay.
NiamonX may require you to go through a verification process to establish your identity and/or authority (in the case of corporate or third‑party requests). This may include additional documents and information, assessed by the legal and security teams on a case‑by‑case basis.
To allow us to review your request efficiently, please provide at least:
e.g. email address, phone number, IP address, domain, username, hash, or other specific identifier.
e.g. email, phone, ip, domain, username, etc.
e.g. your personal data is exposed in a breach; the data is inaccurate or outdated; specific legal grounds (e.g. GDPR/CCPA rights); other substantiated reasons.
Depending on the nature of the request, identity documents (e.g. ID or passport copy), corporate authorisation letters, power of attorney or other supporting documentation may be required. The scope and type of such documentation is determined by the NiamonX legal team in light of applicable privacy laws, security requirements, and potential abuse risks.
NiamonX maintains an internal takedown and block registry ("takedown‑list"). Each record typically contains:
id — unique internal record identifier;value — the specific value to be blocked (e.g. email, phone number, IP, domain, hash);type — data type (e.g. email, phone, ip, domain, hash);reason — the rationale for blocking (e.g. user request, legal requirement, policy violation);created_at — date and time the record was created;created_by — internal administrator or system ID (or NULL when processed automatically).All indexing and search engines within the NiamonX ecosystem are designed to consult this takedown‑list and honour the block entries, subject to technical and operational limitations.
The following timelines are indicative and may vary depending on the complexity of the request, the need for legal analysis, the necessity of identity verification, and the current workload of the NiamonX teams.
| Action / Step | Indicative timeline |
|---|---|
| Acknowledgement of request | Within 48 hours |
| Initial exclusion from search results | Within 24 hours after verification/approval |
| Full exclusion from all relevant tools | Within 72 hours after approval |
| Complete removal from system indices | Within 7 days, where technically feasible |
| Exclusion from future indexing (re‑crawl) | Effective once the value is added to the takedown‑list |
In complex or exceptional cases (e.g. contested ownership, regulatory investigations, large‑scale corporate requests), timelines may be extended. NiamonX will use reasonable efforts to process requests promptly, but does not guarantee fixed deadlines unless required by applicable law.
NiamonX implements a multi‑layered security architecture, including but not limited to:
Takedown requests are processed within encrypted infrastructure. Access to such requests is restricted to authorised legal, security and support personnel. Logging is limited to what is strictly necessary to handle and document the request in compliance with applicable law and internal security policies.
NiamonX reserves the right to refuse or partially refuse a takedown or removal request, including (but not limited to) the following situations:
In such cases, NiamonX may provide a brief explanation, to the extent permitted by law and security considerations. Additional documents or clarifications may be requested before a final decision is taken.
For data removal / takedown requests:
For legal and regulatory requests (e.g. from authorities, regulators, or corporate legal teams):
NiamonX will assess each request individually, taking into account the rights of data subjects, security considerations, legal obligations and the potential impact on other users.
Need assistance with our AI tools, platform, or integrations? Our support team is here to help.
[email protected]For legal inquiries, compliance questions, or documentation requests, contact our legal team.
[email protected]To request data removal, takedowns, or privacy-related actions, contact our security desk.
[email protected]