Privacy Policy
Effective date: 2 July 2026 · Version 1.1
1. Who we are (data controller)
Nullivo (“Nullivo”, “we”, “us”, “our”) provides a self-service tool that lets you check an email address you own for exposure in known data breaches and helps you reduce that exposure. For the personal data described in this policy, the data controller is [Legal entity name], [company number], registered at [registered address], United Kingdom. You can reach us at privacy@nullivo.com or through the Contact page.
If we have appointed a Data Protection Officer or an EU/UK representative, their details are: [DPO / representative contact, if applicable].
2. The data we collect
We deliberately collect as little as possible. Depending on how you use Nullivo, we process:
- Identity & contact data: the email address you submit and verify, and (if you contact us) the content of your message.
- Verification data: the one-time passcode we send to confirm you control the address. The code itself is short-lived and is not stored in readable form.
- Exposure findings: the breach and data-broker results associated with your verified address, which we obtain from third-party breach data and broker listings.
- Account & subscription data: your plan, subscription status, and cleanup progress. Billing and card details are collected and stored by our payment processor, not by us; we receive only limited information (such as plan, status, and the last four digits or a payment token).
- Technical & usage data: limited information such as IP address, device/browser type, and basic logs needed to operate the service securely and prevent abuse.
- Cookie-consent choices and, with your consent, measurement data: if you accept optional cookies, our advertising-measurement and support tools (described in section 10) process limited data such as page visits and conversion events.
We do not ask for, and do not want, special-category data (health, racial or ethnic origin, political opinions, etc.). Please don’t send it to us.
3. Why we use your data and our legal bases
Under the UK/EU GDPR we rely on the following legal bases:
- Performance of a contract: to verify your address, run the scans you request, generate your report, provide cleanup tools, and manage your subscription.
- Consent: to send optional monitoring alerts and any marketing emails. You can withdraw consent at any time without affecting prior processing.
- Legitimate interests: to keep the service secure, prevent fraud and abuse, and improve Nullivo, balanced against your rights and freedoms.
- Legal obligation: to comply with accounting, tax, and lawful requests from authorities.
4. What we never do
We do not sell or rent your personal data. We do not “share” it for cross-context behavioural advertising. We do not let you (or anyone) look up other people: Nullivo only works on an address whose owner has just proven control of it. We do not use your data to train third-party advertising profiles.
5. Who we share data with
We share data only with the service providers (processors) needed to run Nullivo, under contracts that restrict their use of it:
- Breach-data provider: Have I Been Pwned, to check your address against known breaches.
- Email provider: Resend, to deliver verification codes and alerts.
- Payment processor: Stripe, to take and manage payments securely.
- Hosting & database: Amazon Web Services (hosting) and our managed-database provider.
- Support chat: Tawk.to, only if you accept optional cookies and open the chat.
- Reviews: Trustpilot, whose widget loads only if you accept optional cookies.
- Analytics & advertising measurement: Google Analytics, and conversion tags from X (Twitter) and Microsoft Advertising, loaded only with your consent (section 10).
- Data brokers: only when you ask us to submit an opt-out or removal request on your behalf, and only the information needed for that request.
We may also disclose data if required by law, to enforce our terms, or as part of a merger or acquisition (in which case we’ll notify you).
6. International transfers
Some of our providers (for example Stripe, Resend, Have I Been Pwned, and Tawk.to) process data in the United States or other countries outside the UK/EEA. Where that happens, we rely on appropriate safeguards such as the UK International Data Transfer Agreement (IDTA)/Addendum, the EU Standard Contractual Clauses, or an adequacy decision (including the UK/EU–US Data Privacy Framework where the provider is certified), plus additional measures where needed.
7. How long we keep it
We keep personal data only as long as necessary for the purposes above:
- Verification codes: minutes (they expire automatically).
- Account, scan, and cleanup data: for as long as your account is active, then deleted or anonymised within a reasonable period after closure.
- Billing records: for the period required by tax and accounting law.
- Security logs: for a limited period needed to detect and investigate abuse.
8. Your rights (UK/EU)
Subject to conditions, you have the right to: access your data; correct it; delete it (“right to be forgotten”); restrict or object to processing; data portability; and to withdraw consent. To exercise any of these, email privacy@nullivo.com or use the Contact page; we’ll respond within one month. Deletion requests are actioned against all of our systems: your account, scan history, cleanup progress, and monitoring settings are permanently removed. You also have the right to lodge a complaint with the UK Information Commissioner’s Office (ICO) at ico.org.uk, or your local EU data protection authority.
9. Your rights (California / US states)
If you are a California resident, the CCPA/CPRA gives you the right to know what personal information we collect, to access and delete it, to correct it, and to opt out of any “sale” or “sharing”, although Nullivo does not sell or share personal information as those terms are defined. We will not discriminate against you for exercising these rights. Residents of other US states with comparable laws (e.g. Virginia, Colorado, Connecticut, Utah) have similar rights. To make a request, contact us as above; you may use an authorised agent.
10. Cookies & similar technologies
Essential cookies (always on) keep you signed in and remember your cookie choices; the site can’t work without them. Optional cookies load only if you accept them in our consent banner: Tawk.to (support chat), Trustpilot (review widget), Google Analytics (aggregate usage statistics), and conversion-measurement tags from X (Twitter) and Microsoft Advertising, which help us measure whether our ads work. We do not use cookies to build cross-site advertising profiles or sell data to ad networks. You can change or withdraw your choices at any time via the cookie settings link in the footer, and declining optional cookies never affects the scan or your results.
11. Children
Nullivo is not directed to children. We do not knowingly collect data from anyone under 16 (or the minimum age in your country). If you believe a child has used the service, contact us and we’ll delete the data.
12. Security
We encrypt data in transit, minimise what we store, hash verification codes, restrict internal access, and use reputable hosting and payment providers. No system is perfectly secure, but we work continuously to protect your data.
13. Data breaches
If a breach of your personal data occurs that is likely to result in a risk to your rights and freedoms, we will notify the relevant supervisory authority within 72 hours where required, and inform affected users without undue delay.
14. Changes to this policy
We may update this policy as the service evolves. We’ll post the new version here with a revised effective date and, for material changes, notify you by email or in-app.
15. Contact
Questions or requests about privacy? Email privacy@nullivo.com or use the Contact page. To complain to a regulator in the UK: the Information Commissioner’s Office, ico.org.uk.