By Using The Service, The User Is Agreeing To Be Bound By This Agreement. If You Are Agreeing To This Agreement On Behalf Of Or For The Benefit Of A Company, Then The User Represents And Warrants That It Has The Necessary Authority To Agree To This Agreement On The Company’s Behalf.
The purpose of this “Terms of Service” is to inform you or the person or entity you represent (“you,” or “your”) of Breachsense’s (“our”) expectations regarding your use of our data breach search engine (the “Service”). The Service includes the breachsense.com website and everything published on it, the API, and any data, report, or figure obtained from either. These terms apply to anyone who accesses that material, whether or not they hold a subscription, and whether access is by a person using a browser or by automated means. The Service is the exclusive property of Breachsense or its licensors and is protected by United States of America and international intellectual property rights. This Terms of Service is a legally binding agreement between you and Breachsense (“we”) to which, as conditions precedent to offering you any Service, you expressly affirm the accuracy of each of the following statements:
- You are lawfully able to enter into contracts in the jurisdiction which you presently reside;
- You are authorized to enter into this agreement on your behalf or on behalf of the person or entity you represent;
- You consent to the application of the laws of the State of Delaware, United States of America and waive any claim of forum nonconveniens;
- You consent to resolve all disputes arising from or related to the Service in accordance to the Terms of Service and in your individual capacity (and not as a plaintiff or class member in any purported class or representative proceeding);
- You consent to and shall abide by the Terms of Service at all times.
Breachsense requires your use of the Service to comply with applicable law and to be consistent with our community standards.
By using or continuing to use the Service, you accept and consent to the rights, obligations, and practices described in the Terms of Service.
- Code of Conduct. By agreeing to these Terms of Service, you are agreeing that, when using the Services, you will follow these rules:
- Do not do anything illegal. The Service may only be used for lawful purposes. You shall not use the Service to engage in, foster, or promote illegal, abusive, fraudulent, or irresponsible behavior, including without limitation:
- Creation or distribution of unsolicited bulk email and mailing lists;
- Unauthorized disruption or interference of any data system or network, computer or communications system, software application, or network or computing device;
- Unauthorized distribution of any application or code that covertly gathers information about a user or covertly transmits information about the user
- Unauthorized collection or use of any personally identifiable information or personally identifying information (including, without limitation, phishing, Internet scamming, password engineering, scraping, and harvesting)
- Any conduct that is likely to result in retaliation against Breachsense or our representatives, including engaging in behavior that results in any server being the target of a denial of service attack.
- Do not engage in any activity that exploits, harms, or threatens to harm children.
- Do not send spam or engage in phishing. Spam is unwanted or unsolicited bulk email, postings, contact requests, SMS (text messages), instant messages, or similar electronic communications. Phishing is sending emails or other electronic communications to fraudulently or unlawfully induce recipients to reveal personal or sensitive information, such as passwords, dates of birth, Social Security numbers, passport numbers, credit card information, financial information, or other sensitive information, or to gain access to accounts or records, exfiltration of documents or other sensitive information, payment and/or financial benefit.
- Do not publicly display or use the Services to share inappropriate content or material (involving, for example, nudity, bestiality, pornography, offensive language, graphic violence, or criminal activity).
- Do not engage in activity that is fraudulent, false, or misleading (e.g., asking for money under false pretenses, impersonating someone else, manipulating the Services to increase play count, or affect rankings, ratings, or comments).
- Do not circumvent any restrictions on access to or availability of the Services.
- Do not engage in activity that is harmful to you, the Services, or others (e.g., transmitting viruses, stalking, posting terrorist or violent extremist content, communicating hate speech, or advocating violence against others).
- Do not infringe upon the rights of others (e.g., unauthorized sharing of copyrighted music or other copyrighted material, resale, or other distribution of materials).
- Do not engage in activity that violates the privacy of others.
- Do not help others break these rules.
- Do not duplicate, decompile, reverse engineer, publish, or redistribute the Services, including without limitation their underlying technology.
- Do not use the Service for the purpose of creating or maintaining a competitive product or service.
- Do not do anything illegal. The Service may only be used for lawful purposes. You shall not use the Service to engage in, foster, or promote illegal, abusive, fraudulent, or irresponsible behavior, including without limitation:
2.Enforcement. Violation of any provision of the Terms of Service, whether as a single-instance or repeated occurrence, may result in the immediate interruption, suspension, or termination of your access and use of the Service, as determined by Breachsense at Breachsense’s sole discretion. You may also be subject to civil or criminal penalties. You acknowledge, understand, and agree that Breachsense shall not be required to issue warnings, reprimands, or undergo any formal or informal process prior to causing the Service to be interrupted, suspended, and/or terminated.
3.Applicability. This policy applies to you with respect to the Service. You shall be responsible for: informing yourself of any amendments, updates, or modifications made to this policy and you hereby acknowledge and agree to this policy, as amended, updated, or modified from time to time.
4.Excessive Use of System Resources. You shall not use the Service in a way that unnecessarily interferes with the normal operation of the system, or that consumes a disproportionate share of the resources or data on the system.
5.Governing Law. The Terms of Services are governed by the laws of the State of Delaware and may be amended in writing and signed by Breachsense. No waiver shall be effective against any party unless it is in writing and signed by Breachsense.
6.Service Credits. No service credit shall be available under the Terms of Service for interruptions, suspensions, or terminations of service arising from or related to any violation of this Policy.
7.Data. The database is updated on a best efforts basis. Data breaches are added as they become available after they are validated. We do not guarantee when and if a given breach will be imported into the service. Breachsense does not intentionally possess or have access to secure or private information. The underlying breach records are derived from publicly available sources. The compilation, verification, correlation, enrichment, and presentation of that material, and any counts, measurements, or assessments Breachsense derives from its own corpus, are the original work of Breachsense and are protected as such. While Breachsense tries to verify the data, we make no warranties or guarantees about any of the information offered. Breachsense attempts to convert hashed passwords to plaintext where possible. This is dependent on a number of factors and not always possible.
8.Published Content. This clause applies to everything Breachsense publishes on breachsense.com, including breach records, ransomware group profiles, reports, and the credential exposure figures shown alongside them. It applies whether or not you hold a subscription and whether you access the material through a browser, a crawler, or any other means.
Quoting and citing is welcome. You may read, quote, and cite the Published Content, including the credential exposure figures, for research, journalism, analysis, and reporting. No permission is required and no fee applies. We ask only that Breachsense is named as the source and, on any page or interface that displays the material, linked to the page it came from. Journalists who want context, a comment, or a figure checked before publication can reach us at pr@breachsense.com.
What you may not do. You may not redistribute the Published Content in bulk; re-serve it through an API, feed, dataset, or download; or incorporate it into a product or service, whether paid or free, without prior written permission from Breachsense. You may not use automated means to collect the Published Content at a volume or frequency that burdens the site, and you may not circumvent any rate limit, access control, or restriction placed on it.
Permission. Requests for permission to redistribute or incorporate the Published Content may be sent to support@breachsense.com. Permission granted for one purpose does not extend to any other.
9.API License. You may not transfer, resell, or share the API license key without prior written consent from Breachsense.
10.Access. An API license grants access only to data associated with a set of predefined domains owned by the licensee. Further access may be granted to security providers after a verification process to ensure the data is not abused.
11.Domain Takedowns. Where included as part of your Subscription Plan, Breachsense will file takedown requests with domain registrars, hosting providers, and abuse contacts on your behalf, targeting domains used for phishing, brand impersonation, or other malicious activity affecting your monitored assets. Takedowns are best-effort: success depends on the cooperation of the registrar and hosting provider receiving the request, and outcomes cannot be guaranteed. Domains registered or hosted with non-cooperative registrars, hosting providers, or jurisdictions are subject to materially lower success rates and longer resolution timelines, and in some cases may not be actionable at all. Best-effort attempts in these cases still count against your annual takedown allotment. Takedown requests in excess of the included annual allotment are billed per request at the rate published in the then-current Subscription Plan.
12.Warranties. The service is provided by Breachsense to you “as is” and “as available” and that you are accepting of the service with all faults, whether or not immediately apparent, to the furthest extent of applicable law. Breachsense and our representatives: (i) expressly disclaim all warranties, whether express, implied, statutory, or otherwise, including without limitation all expressed or implied warranties of title, merchantability, and fitness for a particular purpose; (ii) do not warrant that the services will meet your requirements, or that the service will be timely, uninterrupted, secure, error-free, or that any defects will be corrected; (iii) do not make any representations regarding the accuracy, reliability, timeliness, or completeness of the service; and (iv) are not responsible or liable for the deletion of previously stored data.
13.Liability. IN NO EVENT WILL BREACHSENSE OR ITS AFFILATES BE LIABLE FOR ANY DAMAGES WHATSOEVER, WHETHER DIRECT, INDIRECT, GENERAL, SPECIAL, COMPENSATORY, CONSEQUENTIAL AND/OR INCIDENTAL ARISING OUT OF USE OF BREACHSENSE.COM OR THE SERVICE. To the extent permitted by law, Breachsense shall have no liability, relating to your use of (or connection to) Breachsense.com. You agree to defend, indemnify, and hold Breachsense, its officers, directors, employees, agents, licensors, and suppliers, harmless from and against any claims, actions or demands, liabilities and settlements including without limitation, reasonable legal and related fees, and expenses, resulting from, or alleged to result from, your violation of these Terms of Service or your use of Breachsense.com or the Service. Breachsense reserves the right, at any time and at our sole discretion to amend, modify, suspend, or terminate Breachsense.com, any service, information or content, or any part thereof, and/or your use of or access to them, with or without notice. Breachsense shall have no liability to you or any other person or entity for any modification, suspension, or termination, or any loss of related information.
14.Sole and Exclusive Remedy. Your only right and remedy in case of dissatisfaction with the Service or Breachsense.com, or any grievance related thereto, shall be discontinuance of access to or use of the Service and/or Breachsense.com.
15.Disputes. You and Breachsense will attempt in good faith to resolve all disputes arising out of or relating to the Services and/or the Terms of Service. Unless otherwise required by applicable law without the possibility of contractual waiver or limitation, (i) neither party will bring a dispute arising out of or related to the Service and/or the Terms of Service more than one year after the cause of action arose, and (ii) after such time limit, any such legal action and all respective rights related to any such action immediately lapse.
16.Subscription Services. Upon confirmation of your purchase of a Subscription Plan, you agree to pay Subscription Fees for the entire Subscription Period. Your Subscription will be automatically billed in advance on a recurring and periodic basis according to the interval on the Subscription Plan you purchased and/or the billing frequency you select (if applicable).
Auto_Renewal. Upon the expiration of your current Subscription Period, your Subscription will automatically renew or commence respectively and you will be charged for it within twenty-four (24) hours prior to the end of the current Subscription Period (as applicable) or thereafter (unless you have cancelled your Subscription in accordance with Clause “Subscription Cancellation”). Subscription Fees may change upon the renewal of your Subscription or the commencement of your Subscription (upon the expiry of your Trial). We will notify you of any changes to the Subscription Fees in advance. If you do not agree to the changes in the Subscription Fees, you must cancel your Subscription in accordance with Clause “Subscription Cancellation.”
Subscription Cancellation. You, the Account Owner, may terminate, or choose not to renew or commence, your Subscription at any time. It is your responsibility to properly cancel your Subscription in accordance with our instructions. You must do so at least one month before the end of the current Subscription Period (as applicable) to avoid being charged for the next Subscription Period. Any cancellation of a Subscription will take effect only at the end of the Subscription Period Period respectively. Once your Subscription is cancelled, you will no longer be able to access and use the Service(s) under the cancelled Subscription.
Upgrades, Downgrades and Changes. If you upgrade to a higher-level Subscription Plan, you will be billed for the upgraded Subscription Plan immediately. You may change your level of service or billing frequency at any time by submitting a written request to do so to our Support team. You acknowledge that if your Subscription is downgraded to a lower level Subscription Plan, you will immediately lose access to the Service Content, privileges, features, functionalities and/or capacity that were provided under your previous Subscription and any associated information, data and/or configuration settings in relation thereto (for which we have no responsibility to save, restore and back up) and you assume all risks relating to the same.
Refund Policy. Breachsense offers refunds in certain situations. If you’ve purchased an annual plan and decided to cancel, contact us within 30 days of the purchase and we’ll offer you a full refund. Breachsense does not offer refunds for voluntary cancellation past the 30-day point. If Breachsense materially fails to deliver the contracted service, we will remedy the issue or refund the unused portion of your subscription.
17.Removal of links from our website. If you find any link on our Website or any linked web site objectionable for any reason, you may contact us about this. We will consider requests to remove links but will have no obligation to do so or to respond directly to you. Whilst we endeavor to ensure that the information on this website is correct, we do not warrant its completeness or accuracy; nor do we commit to ensuring that the website remains available or that the material on the website is kept up to date.
18.Content Liability. We shall have no responsibility or liability for any content appearing on the Web site. You agree to indemnify and defend us against all claims arising out of or based upon the Website. No content or link(s) may appear on any page on the Web site or within any context containing content or materials that may be interpreted as libelous, obscene or criminal, or which infringes, otherwise violates, or advocates the infringement or other violation of, any third party rights. We will review requests for content removal in accordance with U.S. law. You may submit a request by submitting a notice to support@breachsense.com.
19.Resolutions. All disputes arising from or related to the service and/or the terms of service shall be governed by the laws of the state of Delaware, United States of America, excluding Delaware’s conflicts of laws rules. The parties will attempt in good faith to settle any dispute within thirty (30) calendar days after the dispute arises. if the dispute is not resolved within thirty (30) calendar days, such dispute shall be resolved by arbitration by the American Arbitration Association’s International Centre for Dispute Resolution in accordance with its expedited commercial rules in force as of the date of this Terms of Service. Each arbitration proceeding shall be conducted (i) by a mutually selected arbitrator, (ii) in the English language, and in (iii) New Castle County, Delaware, United States of America. Each arbitration proceeding shall be deemed confidential information, including without limitation, (i) the existence of, (ii) any data disclosed during, and (iii) any communications or documents related to, the arbitration proceeding.
20.Privacy Policy. Breachsense uses information that you provide to it via telephone calls, chat, email, web forms, and other communications to correspond with you about the Service. Email addresses are stored in Gmail to notify you of relevant alerts, updates to the database and/or service. API queries are logged to ensure the database is not abused and are deleted after ninety (90) calendar days. Billing information is stored directly in Stripe. Unless required by law, any information collected is not shared with third parties. If you wish to withdraw consent or delete any information we have about you, including breached data, please contact support at breachsense.com.
21.Marketing. Unless specified otherwise, Breachsense may use your company name and/or logo for marketing purposes only.
22.Changes. Amendments to these Terms of Service may be made at any time and you should check back frequently for any changes. Breachsense shall have the right and ability to amend these Terms of Service at Breachsense’s sole and absolute discretion, and any amendments herein shall be effective within seven (7) days of being posted by Breachsense or by your continued use of the Service, whichever later.
23.Export Compliance and Restricted Use. You acknowledge that the Service and the data delivered through it are subject to United States export control laws and economic sanctions administered by the Office of Foreign Assets Control. You represent and warrant that you are not located in, organized under the laws of, or ordinarily resident in any country or region subject to comprehensive US sanctions or embargoes; that you are not listed on, owned by, or controlled by any party listed on any US Government restricted-party list (including the Specially Designated Nationals List and the Entity List); and that you are not acting on behalf of any such party.
You agree not to use the Service or the data delivered through it for any purpose prohibited by applicable law, or to access any system, account, or service using credentials, tokens, or other authentication artifacts surfaced by the Service except where you have explicit, documented authorization from the system or account owner.
24.Data Processing Addendum. This Data Processing Addendum (“DPA”) governs Breachsense’s processing of personal data submitted to the Service by the customer.
Roles of the Parties. The customer may act either as a controller of the personal data it submits to the Service, or as a processor acting on behalf of its own clients. Where the customer acts as a controller, Breachsense acts as its processor. Where the customer acts as a processor, Breachsense acts as its sub-processor and the customer’s clients are the controllers. References in this DPA to the customer’s instructions include, where the customer acts as a processor, the instructions the customer has received from its own controllers. “Customer Personal Data” means personal data processed by Breachsense under this DPA in either case.
Definitions. “Personal Data,” “Processing,” “Data Subject,” “Controller,” “Processor,” and “Sub-processor” have the meanings given in the EU General Data Protection Regulation (GDPR) or applicable data protection laws.
Scope of Processing. The subject matter is data breach monitoring and credential exposure detection. Categories of data subjects include employees, customers, or other individuals whose data the customer submits for monitoring. Types of personal data include email addresses, domain names, and other identifiers submitted for monitoring; breach records returned by the Service, which may include email addresses, passwords and password hashes, session tokens, and infostealer log contents; and account contact and alert recipient email addresses, API query logs, source IP addresses, and timestamps generated by use of the Service. Processing continues for the term of the Agreement plus any retention period specified herein.
Breachsense Obligations. Breachsense shall: (i) process Customer Personal Data only on documented instructions from the customer, including with regard to transfers of Customer Personal Data to a third country or an international organization, unless required to do so by law to which Breachsense is subject, in which case Breachsense shall inform the customer of that legal requirement before processing, unless that law prohibits such information on important grounds of public interest; (ii) ensure that persons authorized to process Customer Personal Data are subject to confidentiality obligations; (iii) implement appropriate technical and organizational security measures, including encryption of data in transit and access controls; (iv) engage sub-processors under a general written authorization: Annex IV lists current sub-processors, and Breachsense will give the customer at least thirty (30) days’ notice before adding a new one, during which the customer may object on reasonable grounds relating to the protection of Customer Personal Data; (v) assist the customer in responding to Data Subject requests (access, rectification, erasure, etc.) to the extent technically feasible; (vi) assist the customer in ensuring compliance with security, breach notification, and data protection impact assessment obligations; (vii) at the customer’s choice, delete or return all Customer Personal Data upon termination of the Service, unless retention is required by law; (viii) make available to the customer information necessary to demonstrate compliance with these obligations; and (ix) not use the identifiers and other data the customer submits for monitoring, or the data generated by the customer’s use of the Service, to build, train, or otherwise enrich the breach-data corpus, databases, or other products Breachsense operates, and use that data solely to provide the Service to the customer and to fulfill Breachsense’s obligations under this DPA.
Data Retention. API queries containing Personal Data are logged for service integrity purposes and automatically deleted after ninety (90) calendar days. The customer may request earlier deletion by contacting support@breachsense.com.
Security Measures. Breachsense implements data encryption in transit (TLS), access controls limiting data access to authorized personnel, and regular security reviews. Annex III sets out the full list of technical and organizational measures.
Data Breach Notification. Breachsense shall notify the customer without undue delay (and in any event within 48 hours) upon becoming aware of a Personal Data breach affecting Customer Personal Data, providing sufficient information to enable the customer to meet its own notification obligations and those of its controllers.
Audits. Breachsense shall allow for and contribute to audits, including inspections, conducted by the customer or an auditor mandated by the customer, subject to reasonable notice and confidentiality obligations.
International Transfers. Where Customer Personal Data is transferred from the European Economic Area to Breachsense, the parties incorporate by reference the Standard Contractual Clauses approved by the European Commission in Implementing Decision (EU) 2021/914 (“EU SCCs”), which shall apply automatically and without further signature. Module Two (controller to processor) applies where the customer acts as a controller, and Module Three (processor to processor) applies where the customer acts as a processor. Annexes I through IV below complete the EU SCCs for this purpose. For the purposes of Clause 17 of the EU SCCs, the EU SCCs are governed by the law of Ireland, and for the purposes of Clause 18, disputes arising from the EU SCCs are subject to the courts of Ireland. Nothing in this DPA or in the Terms of Service, including its arbitration provisions, restricts a data subject’s right under Clause 18(c) of the EU SCCs to bring proceedings in the courts of the Member State in which they have their habitual residence.
United Kingdom Transfers. Where Customer Personal Data is transferred from the United Kingdom to Breachsense, the parties additionally incorporate by reference the International Data Transfer Addendum to the EU Commission Standard Contractual Clauses issued by the UK Information Commissioner’s Office under Section 119A(1) of the UK Data Protection Act 2018 (“UK Addendum”), which applies the EU SCCs above as modified by the UK Addendum for that purpose.
Switzerland Transfers. Where Customer Personal Data is transferred from Switzerland to Breachsense, the EU SCCs above apply as adapted per the guidance of the Swiss Federal Data Protection and Information Commissioner (“FDPIC”): the FDPIC is the competent supervisory authority for any transfer involving only Switzerland, references to the GDPR are read to include the Swiss Federal Act on Data Protection (“FADP”) where it applies instead of or alongside the GDPR, and references to an EU Member State are read to include Switzerland for that purpose. For the avoidance of doubt, Annex I below corresponds to Annex I.A of the EU SCCs, Annex II to Annex I.B, the competent supervisory authority stated in Annex II to Annex I.C, Annex III to Annex II of the EU SCCs, and Annex IV to the list of sub-processors required under Clause 9. The same Annexes serve as Tables 1 to 3 of the UK Addendum where that Addendum applies. Breachsense will on request provide any further information reasonably necessary for the customer to complete its own transfer impact assessment.
Governing Law. This DPA is governed by the same laws that govern these Terms of Service, except that the EU SCCs, the UK Addendum, and the Swiss adaptation described above are governed by their own terms and not by this clause or by the dispute resolution provisions of the Terms of Service. To the extent required by applicable data protection law, the provisions of this DPA shall prevail over conflicting provisions in the Terms of Service.
Annex I: List of Parties. Data exporter: the customer, as identified in the Order Form or Agreement. Data importer: Breachsense Inc, a corporation registered in the State of Ohio, USA, registered address 23811 Chagrin Blvd, Ste 200, Beachwood, Ohio 44122, USA, contact support@breachsense.com. Role: processor, where the customer is a controller monitoring its own data; sub-processor, where the customer is a processor monitoring its clients’ data on their behalf. Applicable module: Module 2 (controller to processor) where the customer is a controller; Module 3 (processor to processor) where the customer is a processor. Breachsense is not certified under the EU-US Data Privacy Framework and relies on the SCCs incorporated above for this transfer.
Annex II: Description of the Transfer. Categories of data subjects: employees and other personnel of the customer, whose email addresses or domains are submitted for monitoring; where the customer monitors its suppliers or other third parties for its own risk-management purposes, personnel of those organisations; where the customer is itself a processor monitoring its own clients’ data, personnel of those clients; and individuals at the customer whose email addresses are held as account contacts or as recipients for monitoring alerts. Categories of personal data: email addresses, domain names, and other identifiers submitted for monitoring; breach records returned by the Service, which may include email addresses, passwords and password hashes, session tokens, and infostealer log contents; and account contact and alert recipient email addresses, API query logs, source IP addresses, and timestamps generated by use of the Service. Purpose: data breach monitoring and credential exposure detection. Frequency: continuous, on customer-initiated API queries and scheduled monitoring. Retention: as set out in Data Retention above. Competent supervisory authority: determined under Clause 13 of the SCCs by reference to the data exporter’s country of establishment or, where the exporter is not established in an EEA member state, the member state in which its EU representative is established.
Annex III: Technical and Organisational Security Measures. TLS encryption for all data in transit (TLS 1.2 and 1.3 only); encryption at rest at the infrastructure layer; access to the production database restricted to named administrators; API access authenticated per customer by license key, scoped to that customer’s account; query logs automatically purged after 90 days; server hardening including host firewalls, fail2ban, restricted SSH, and automatic security updates; and breach notification without undue delay and within 48 hours. All Breachsense infrastructure, including the production API, the database cluster, and all collection infrastructure, is located in the United States, hosted with Akamai (Linode); Breachsense operates no infrastructure inside the EEA and does not store or replicate Customer Personal Data outside the United States. Breachsense personnel access these US-hosted systems remotely from Israel (platform and database administration; EU adequacy decision of 31 January 2011, maintained following the review adopted 15 January 2024), India (platform and database administration; no adequacy decision), and the Philippines (billing and payment systems only, no access to the monitoring platform, the database, or any monitoring data; no adequacy decision). No Customer Personal Data is stored on personnel devices or held in any of these countries, and all personnel with platform access are subject to written confidentiality and security obligations.
Annex IV: List of Sub-processors. Linode (Akamai Technologies, Inc.): infrastructure hosting for all application and database servers, processing all customer platform data, located in the USA, EU-US DPF plus SCCs offered under the Akamai Data Protection Addendum. Cloudflare, Inc.: TLS termination and reverse proxy for api.breachsense.com, processing submitted domains, email addresses, and source IP addresses (decrypted at the edge only to terminate TLS and proxy to the origin), located in the USA with global edge points of presence, EU-US DPF with SCCs as a stated fallback in the Cloudflare DPA. Google LLC (Google Workspace): business email and document storage for customer correspondence and support, processing customer contact details and any personal data included in a support request or attachment, located in the USA, EU-US DPF. No other party has access to the Breachsense monitoring platform or its database. Each subprocessor above states it is independently certified under the EU-US Data Privacy Framework; Linode and Cloudflare also offer Standard Contractual Clauses under their own data protection addenda as an additional safeguard for this transfer. The transfer from the customer to Breachsense is governed by the EU SCCs, UK Addendum, or Swiss adaptation incorporated in International Transfers above. Breachsense will give the customer at least thirty (30) days’ notice before adding a new sub-processor, during which the customer may object on reasonable grounds relating to the protection of Customer Personal Data.
Annex V: Facts Relevant to the US Legal Regime and Government Access. The legal characterisation of Breachsense under US surveillance law is for the customer’s own privacy team to determine; Breachsense does not offer a conclusion on it. Relevant to FISA Section 702 (50 U.S.C. § 1881a), which applies only to an “electronic communication service provider”: Breachsense provides a search and monitoring service over a database of previously breached data collected from public and criminal sources; it does not provide email, messaging, telephony, or any communications service; it does not carry or transmit the communications of its customers or third parties; it does not provide general-purpose cloud storage or hosting to the public; and it does not store customer files or content beyond account records and 90-day query logs. Relevant to Executive Order 12333, which concerns collection of data in transit outside the United States: all data reaches Breachsense over TLS 1.2 or 1.3. Relevant to the CLOUD Act: Breachsense is a US corporation and is subject to US legal process for data within its possession or control, including data held by its US subprocessors. As of the date of this DPA, Breachsense has received zero national security requests (including FISA directives and national security letters) and zero law enforcement requests for customer personal data, has never complied with either, and has never been subject to a non-disclosure obligation in connection with one. Supplementary measures: customers can monitor by domain rather than by individual email address to minimise the personal data submitted; query logs are automatically deleted after 90 days; Breachsense will notify the customer of any legally binding request for their personal data unless prohibited by law and will challenge requests where there is a reasonable basis to do so; and customers may request deletion of their data at any time.