Loading

Privacy Policy (EU VERSION) | NiamonX LTD.

The original document is in English only. The last date of document revisions and edits was November 15, 2025.

The processing and storage of user data of European users is carried out by the OVH: OVHCloud SBG5 Data Center is located at 9 Rue du Bassin de l'Industrie 6700, Strasbourg, France and in OVHcloud DE1 - data center by OVH in Frankfurt, Germany (Limburger Str. 45, Limburg). In a cryptographically protected form!


Privacy Policy (EU Version)

NiamonX LTD

Last updated: 15 November 2025

Legal entity: NiamonX LTD

Company number: 16710504 (England & Wales)

Registered address: 71–75 Shelton Street, Covent Garden, London, United Kingdom, WC2H 9JQ

Contact details:

This EU‑tailored Privacy Policy applies to data subjects in the European Union (EU), the European Economic Area (EEA) and, where applicable, Switzerland and other jurisdictions which apply GDPR‑equivalent standards.

By using the NiamonX platform, you acknowledge that you have read, understood and accepted this Privacy Policy (EU Version).


1. Scope of this Policy

1.1.

This Privacy Policy applies to the processing of personal data carried out by NiamonX LTD ("NiamonX", "we", "us", "our") in connection with:

  • the use of the NiamonX OSINT and cybersecurity platform,
  • all tools and services made available under domains controlled by NiamonX LTD, including but not limited to:
  • Dashboard, Pricing, NiamonX Academy (Academy Dashboard, Courses);
  • Data Breach Search (Public Breaches, ULP, PBS v2);
  • Breach Monitoring (Manage, Reports);
  • OSINT Tools (Visual OSINT, Reverse Image Search 18+, Social Media Search, Brand Reputation, Exif Remover, Flight Info / Schedules / Delay / Tracker);
  • Networks and WiFi (WiFi Map and Data Search, IP Intelligence Search, IP Calculator, IP Explorer, GlobeLine Ping / DNS, GeoPing, GeoDNS, DNS Resolver or Reverse, IP Reverse Lookup, IP Informations, ASN Informations);
  • Website and Host Analysis (Phishing Check, Host Diagnostics, Domain WHOIS, Web ScreenShot, Web to PDF, IP WHOIS, Subdomains Check / V2, URL Shortener, DNSSEC Configuration, DMARC Policy & Conf, PageRank, Domain Rank, Microsoft Tenant, SSL/TLS Conf, Security Headers);
  • Email and Accounts (Gmail Generator, Temp Mail);
  • Payment Security (BIN Card Checker, Test Card Generator);
  • Virus Check (Check URL, File Hash, Domain, IP);
  • Cyber Tools (Password Generator, Proxy List / v2, Time Zone, Password Check);
  • CorpData and Vulnerabilities (EntityGraph, VulnAtlas, InfraDB);
  • Crypto and Sanctions (BlockChain Explorer, Sanction Atlas, Cryptocurrency Sanctions Check, IP Sanctions Check);
  • OSINT Maps (Maps Explorer, Airspaces Map, Sea Map, Flight Radar, NASA GIBS, NASA Black Marble);
  • Other services (AI Chat, WiFi Map, Osint Agent AI, Temp Mail, Password Vault, WiKi, API, FAQ, Data Wells, Limits, Profile Settings, Notification, Category, API Query, Update List, Blog, Support).

1.2.

If you do not agree with this Policy, you must cease using our services immediately.


2. Roles under EU Data Protection Law

2.1.

For the purposes of the GDPR, NiamonX acts as:

Data Controller

In relation to personal data that we collect and process for our own purposes, e.g. user account data, billing and payment data (to the extent we receive it), logging for security and fraud prevention, and platform administration.

Data Processor

In relation to personal data that you, as a user, submit, search or process via our tools (e.g. OSINT queries, uploaded files, images, domains, IP addresses, breach datasets) on behalf of yourself or your organization.

2.2.

NiamonX does not carry out any legal assessment of whether your use of the platform is lawful in your jurisdiction or under your contractual/framework obligations. You are solely responsible for ensuring you have a valid legal basis (e.g. consent, legitimate interest, contract, legal obligation) for processing any personal data you input or otherwise process through our services.

2.3.

The fact that NiamonX technically allows particular queries or operations does not constitute a legal authorization, endorsement or validation of such activities.


3. Categories of Personal Data

3.1. Data you provide to us

We may process the following categories of data you provide:

  • Identification data: name (or alias), username/login, email address;
  • Authentication data: password (stored in hashed form using bcrypt or Argon2id);
  • Account configuration: preferences, tool configuration, notification settings;
  • Uploaded content: images, files, URLs, domains, IP addresses, blockchain addresses, text queries, descriptions and other user‑provided material;
  • Support communications: messages you send to our support or legal team.

Encryption: All such data is encrypted at the application level using AES‑256‑GCM and envelope encryption with keys managed via KMS/HSM infrastructures.

3.2. Technical and security data

We may collect technical information including:

  • authentication logs and events (successful/failed logins, session identifiers);
  • security telemetry, including IP addresses used to access the service, approximate geolocation, device identifiers (in pseudonymous form), browser or client data;
  • aggregated usage statistics for APIs and tools.

Zero log of OSINT queries.

The content of OSINT/tool queries (including specific search terms, targets, and parameters) is not stored on our servers. Such data is stored only locally on your device/browser (e.g. via localStorage) and is under your control.

3.3. Breach / OSINT data from external sources

We may process breach‑related datasets and OSINT data that:

  • originate from publicly accessible or previously compromised datasets made available by third parties;
  • are provided by data suppliers, operators, and partners acting in their own capacity as controllers.

In this context:

  • NiamonX does not create, decrypt or augment such datasets beyond what is technically required for search and display;
  • NiamonX exposes only fields that are permitted by applicable law and our internal safety policies;
  • sensitive fields with elevated risk are masked, hidden or not indexed for search;
  • we do not give access to non‑public elements if this would evidently contravene applicable legal provisions.

We do not verify the correctness, origin, or legal compliance of these data sources; that responsibility lies with the original controllers and with you as the user processing such data.


4. Legal Bases and Purposes of Processing (GDPR)

We rely on the following legal bases under Article 6 GDPR (and equivalent provisions) when acting as a controller:

Contract performance (Art. 6(1)(b) GDPR)

To create and maintain your account, supply you with our services, administer your subscription, and provide customer support.

Legitimate interests (Art. 6(1)(f) GDPR)

To protect the security and integrity of our systems, prevent fraud, abuse or attacks, monitor and improve performance, and defend our legal rights. Our legitimate interests do not override your fundamental rights and freedoms.

Legal obligations (Art. 6(1)(c) GDPR)

To comply with applicable laws, regulatory obligations, tax rules, accounting requirements and binding orders from competent authorities.

Consent (Art. 6(1)(a) GDPR)

Where required by law (e.g., certain categories of cookies, optional marketing communications). You may withdraw consent at any time, without affecting the lawfulness of processing based on consent before its withdrawal.

When acting as a processor, we process personal data strictly on the documented instructions of our customer (you or your organization), as described in the GDPR document (see separate GDPR notice), and the responsibility for the legal basis lies primarily with the controller.


5. User Responsibility and Lawfulness of Use

5.1.

You acknowledge and agree that:

  • You are solely responsible for ensuring that any personal data you process via NiamonX is processed lawfully, fairly and transparently under the GDPR or other applicable data protection laws.
  • You obtain and maintain any necessary consents, notices, approvals or other legal bases before using our tools on personal data relating to third parties.
  • You will not use NiamonX to conduct unlawful surveillance, harassment, discrimination, unauthorized intrusion into privacy, or any form of illegal activity.

5.2.

NiamonX does not provide legal advice and does not verify whether:

  • you have sufficient legal grounds to process certain data;
  • your processing respects local criminal, administrative, employment, financial, professional‑secrecy or sector‑specific rules.

All such responsibility is exclusively yours.


6. Limitation of Liability

6.1.

To the maximum extent permitted by applicable law, NiamonX LTD, its affiliates, directors, officers, employees and agents shall not be liable for:

  • the accuracy, completeness, lawfulness or timeliness of any data obtained or displayed via our platform (including breach datasets, OSINT sources, third‑party feeds, or operator data);
  • any damages (direct, indirect, incidental, consequential, special, punitive or exemplary) arising out of or in connection with your use of the platform or your reliance on the information obtained through it;
  • any unlawful or unauthorized use of the services by you or by third parties using your credentials;
  • any use of the platform that violates GDPR or national data protection laws by the user or their organization;
  • the availability, correctness, or functioning of external APIs, data suppliers, antivirus companies, operators or payment gateways.

6.2.

The platform and all services are provided on an "AS IS" and "AS AVAILABLE" basis. We do not warrant:

  • uninterrupted or error‑free operation;
  • full compatibility with all devices or software;
  • absence of vulnerabilities, attacks or external disruptions.

6.3.

Nothing in this section limits any mandatory statutory rights you may have under EU or Member State law, to the extent such rights may not be contractually waived or limited.


7. Security Architecture and Encryption

7.1. Layer 01 — Authentication & Identity (Zitadel IAM)

  • Authentication is provided via Zitadel IAM hosted in Reykjavík, Iceland;
  • All communication occurs over encrypted channels;
  • Storage encryption uses AES‑256‑GCM within the Zitadel Storage Encryption Layer;
  • Passwords are stored using bcrypt or Argon2id; refresh tokens, ID tokens, private keys and OAuth credentials are secured;
  • Strict password policies, mandatory 2FA (where applicable), and automated detection of anomalous sessions (e.g. session theft, unusual geo‑logins);
  • Staff access to authentication systems is restricted to corporate VPN endpoints and hardware‑based security keys.

7.2. Layer 02 — Encrypted Data Processing & Storage

  • Application‑level encryption: AES‑256‑GCM with envelope encryption;
  • Transparent Data Encryption (TDE) at the database layer;
  • Pseudonymization and anonymization techniques used for PII where feasible;
  • API keys hashed with SHA‑256 and not retrievable in plaintext;
  • Requests generated by your tools are not logged server‑side (zero‑log policy for query contents);
  • Browser‑side storage (e.g. localStorage) is used to maintain local query history, controlled by you.

7.3. Layer 03 — Personnel Access & AI Oversight

  • All staff actions in administrative and support tools are logged and monitored;
  • Access rights are granted on a strict "need‑to‑know" and "least privilege" basis;
  • AI‑based security models analyze staff interactions and can trigger immediate access suspension;
  • Any irregular server or administrative activity is treated as a potential privacy breach, with isolation of the affected node or cluster.

7.4. Layer 04 — Confidential & Breach Data Protection

  • Field‑level encryption (AES‑256‑GCM) with unique IV/nonce per field;
  • Envelope encryption for data keys; keys stored separately in KMS/HSM;
  • Regular rotation of cryptographic keys;
  • No developer or operator access to raw PII or cryptographic material;
  • Confidential computing environments for highly sensitive operations;
  • Partner data undergoes additional anonymization and integrity checks and, where possible, is delivered directly to the client without passing through unnecessary transit servers.

8. Payment Processing (Stripe and NOWPayments)

8.1. Card payments – Stripe

For card‑based payments, we use the payment service provider Stripe. Stripe acts as an independent data controller with respect to payment data. We do not receive full card numbers or sensitive payment data; such data is processed directly by Stripe.

For more information on Stripe's data processing, please refer to the Stripe Privacy Policy.

8.2. Cryptocurrency payments – NOWPayments

For cryptocurrency payments, we use NOWPayments. NOWPayments acts as an independent data controller with regard to the processing of your payment data on its own infrastructure.

For more information, please refer to the NOWPayments Privacy Policy.

8.3.

To the extent NiamonX receives or stores any related billing data (e.g., billing contact details, transaction IDs, timestamps, subscription metadata), such data is processed only for:

  • contract performance,
  • accounting and tax compliance,
  • fraud prevention and security.

We do not store card numbers or private cryptocurrency keys.


9. Sharing of Data with Third Parties

We may share data (to the minimum extent necessary) with:

  • Payment providers (Stripe, NOWPayments) as described above;
  • Antivirus companies, reputation services or security vendors in anonymized or pseudonymous form when you request URL/file/hash/domain/IP checks;
  • OSINT and data suppliers, operators and partners, who typically receive only anonymized/aggregated data unless you directly send data to them as part of your query;
  • Cloud and infrastructure providers hosting our systems;
  • Legal, tax, or cybersecurity advisors (bound by professional or contractual confidentiality);
  • Public authorities and courts where required by law.

We will not sell your personal data to third parties.


10. Data Retention

  • Account data: retained for as long as your account is active, and for a limited period thereafter if necessary for legal, accounting or security purposes.
  • Security logs: retained for the minimum period necessary to fulfil security and compliance purposes.
  • Tool/query contents: not stored server‑side; only locally on your device.
  • Partner data: encrypted and retained solely for the purpose and duration necessary to provide the services or comply with legal obligations.

Upon deletion of your account, we delete or irreversibly anonymize personal data that we no longer need. Where data remains encrypted, we may destroy the relevant cryptographic keys, making reconstruction technically impossible.


11. Your Rights under GDPR

If you are in the EU/EEA, you have, subject to conditions and legal limitations:

  • Right of access to your personal data (Art. 15 GDPR);
  • Right to rectification of inaccurate or incomplete data (Art. 16 GDPR);
  • Right to erasure ("right to be forgotten") (Art. 17 GDPR);
  • Right to restriction of processing (Art. 18 GDPR);
  • Right to data portability (Art. 20 GDPR);
  • Right to object to processing based on legitimate interests (Art. 21 GDPR);
  • Right to withdraw consent at any time where processing is based on consent (Art. 7 GDPR).

To exercise these rights, contact us at: [email protected] or [email protected].

We may request additional information to verify your identity before responding.

You also have the right to lodge a complaint with your local Data Protection Authority.


12. International Data Transfers

Data may be processed in or transferred to:

  • EU/EEA Member States;
  • Iceland;
  • United Kingdom;
  • United States and other third countries.

Where personal data is transferred outside the EU/EEA, we ensure appropriate safeguards, such as:

  • EU Standard Contractual Clauses (SCCs);
  • UK International Data Transfer Addendum (IDTA);
  • other recognized mechanisms under GDPR and applicable law;
  • strong encryption and security controls.

13. Cookies and Local Storage

We may use:

  • strictly necessary cookies for authentication and basic functionality;
  • security cookies for anti‑fraud and session protection;
  • localStorage or similar technologies to store your query history and preferences locally on your device.

We do not upload OSINT search history from your device to our servers.

You may configure your browser to block cookies or localStorage; however this may impair or block the use of parts of our platform.


14. Minors

Our services are intended exclusively for individuals of at least 18 years of age, or the age of majority in their jurisdiction, whichever is higher.

We do not knowingly process personal data of minors through our platform. If you believe a minor has used our services, please contact us.


15. Changes to this Privacy Policy (EU Version)

We may update this EU Version of the Privacy Policy from time to time to reflect:

  • changes in law or regulatory guidance;
  • changes in our services, infrastructure or security practices.

The updated version will be published on our website with a revised "Last updated" date. Continued use of the platform after such updates constitutes your acceptance of the modified Policy.

If you do not agree with the updated Policy, you must discontinue your use of the services and may request deletion of your account and data (subject to legal retention obligations).




Support Email

Need assistance with our AI tools, platform, or integrations? Our support team is here to help.

[email protected]

Legal & Compliance

For legal inquiries, compliance questions, or documentation requests, contact our legal team.

[email protected]

Data Removal Requests

To request data removal, takedowns, or privacy-related actions, contact our security desk.

[email protected]