GDPR & Data Protection
Last updated: 2026-09-21
This page sets out how StealerHunt approaches the General Data Protection Regulation and equivalent data protection law.
Controller and processor roles
For this website we are the controller. When we process data on behalf of a customer under a service agreement, we are the processor and act on that customer’s documented instructions.
Processing leaked credential data
Our platform processes personal data contained in credential sets that have already been exposed. We rely on legitimate interests — specifically network and information security, which the GDPR expressly recognises as a legitimate interest — and we apply safeguards proportionate to the sensitivity of the data: masking by default, scoped and audited access, tenant isolation, limited retention and data minimization.
Data subject rights
Individuals may request access, rectification, erasure, restriction, portability, and may object to processing based on legitimate interests. Requests relating to data we hold as a processor are forwarded to the relevant controller. We respond within the statutory period.
International transfers
Where personal data is transferred outside the EEA or UK, we rely on an adequacy decision or on Standard Contractual Clauses together with a transfer risk assessment.
Sub-processors and DPAs
We maintain a current list of sub-processors and make a Data Processing Agreement available to customers on request.
Breach notification
We notify affected controllers without undue delay after becoming aware of a personal data breach, with the information needed for them to meet their own obligations.
This document is a template and should be reviewed by your legal counsel before publication.