Data controller and scope
Data Knight, French simplified joint-stock company (SAS), whose registered office is at 11 boulevard Bineau, 92300 Levallois-Perret, France, is responsible for the processing described in this policy. It applies to data-knight.io, the Account, support and the scanning, removal and Always-on Protection services.
Data Knight helps individuals identify their digital exposure and then, at their request, prepare, send and track requests to websites, search engines, social networks, directories, data brokers and other organisations.
Organisations receiving a request remain responsible for their own processing. Their privacy policies apply when they receive and handle the request.
Account, identity and correspondence
We process information you provide: surname, first name, email address, country and, depending on the features used, town or city, postal address, phone number, usernames, profile URLs, communication preferences and support correspondence.
The Account is accessed using a temporary six-digit code (OTP) sent by email. Data Knight neither creates nor stores a password for this authentication. Supabase manages the technical identity, code and session tokens needed to keep you signed in.
This data is used to create and secure the Account, associate scans with the correct person, respond to requests and remember the settings you choose.
Public web and breach scans
To start a scan, we use the criteria supplied by the User, including their identity, contact details, location and public identifiers, to search for results that may relate to them.
The data analysed may come from search engines, publicly accessible web pages, directories, data brokers and breach reporting databases. We record the links, excerpts, sources, categories, matching indicators and risk levels needed to present the report.
We use technical providers for web searches, breach checks and automated analysis. Only the data necessary for each check is sent to them. This processing identifies, assesses, deduplicates, translates or summarises results. It is not used to make a decision producing legal or similarly significant effects on the User. The providers concerned are presented in section 9.
Our tools are designed not to intentionally search for or infer special categories of data. Sensitive information already made public may nevertheless appear incidentally in a source or excerpt; it can be reported or deleted from the Account.
Removal requests and authorisation
When the User chooses targets, we process their identity, contact details, the relevant URLs or items, their choices, authorisation, requests sent, dates and replies received. This information is needed to act within the authorised scope and track progress.
Strictly necessary information is sent to the selected organisations, their privacy teams or their request-management processors. Some organisations may ask the User directly for additional verification.
Replies received through tracking channels are analysed to update the request status, suggest a follow-up or direct the case to human review when a reply is ambiguous.
Payment, billing and reviews
Stripe processes payments and subscriptions. Data Knight retains transaction references, the offer, payment and subscription status, and information needed for support and reconciliation. Full payment card details are neither received nor stored by Data Knight.
Transactional emails are sent through an email provider. After a purchase, and only if this feature is enabled, the buyer's email address may be sent to Trustpilot to invite them to leave a review. The User may object by email or through the link provided in the invitation.
Purposes and legal bases
- Performance of the contract
- Creating and managing the Account, carrying out ordered scans, producing reports, preparing and tracking requests, managing the offer and providing support.
- Consent
- Enabling Umami, connecting YouTube, receiving optional communications and using any feature presented as optional.
- Legitimate interests
- Securing the Website, preventing abuse, diagnosing incidents, improving tools, retaining useful evidence and offering a Trustpilot invitation.
- Legal obligation
- Complying with accounting, tax, cooperation with authorities and data-rights request obligations.
Where processing is based on consent, you can withdraw it at any time without affecting the lawfulness of operations already carried out. Data Knight neither sells nor rents personal data and does not carry out profiling producing legal effects within the meaning of Article 22 GDPR.
Recipients and providers
Internal access is limited to authorised people who need it to operate the service or respond to support requests. Depending on the feature used, data may also be shared with the following categories:
For street suggestions in the authorisation form, the address text entered, country and, if provided, postcode and town or city are sent to Geoapify through our server. Your name, email and authorisation content are not included in these searches. You can keep an address entered manually without selecting a suggestion.
Hosting, backend, authentication, database and storage providers, configured in European regions.
Technical providers for web searches, breach checks and automated analysis, and Google/YouTube for OAuth features.
Stripe for payment, a transactional email provider and Trustpilot for optional invitations.
Websites, search engines, social networks, directories, brokers and privacy services selected by the User.
Professional advisers and authorities may also receive data where necessary to defend our rights or comply with a legal obligation. Our providers are subject to contractual commitments appropriate to their role.
Hosting and transfers outside the European Economic Area
Data retained in Data Knight's primary infrastructure (application, database, storage and Umami) is processed on servers located in Europe.
This location does not cover strictly necessary data sent to external payment, search, verification or analysis providers or organisations selected by the User. Some recipients may process data outside the European Economic Area.
Where a transfer outside the European Economic Area is necessary, it relies, depending on the recipient, on an adequacy decision, including the EU-US framework for certified organisations, the European Commission's standard contractual clauses, or another mechanism provided by the GDPR. A copy of the applicable safeguards may be requested using the contact details in section 14, subject to confidential elements.
Retention periods
We apply the shortest period compatible with providing the service, the User's choices and our obligations. The main rules are:
- Social archives and reports: a maximum of thirty days after the analysis ends, or earlier on request from My Account.
- Web scans and Account: while the service is used; they can be deleted from My Account. Inactive free accounts may be purged after prior warning.
- Removal requests and authorisations: while they are being tracked, then archived with restricted access where needed as evidence, until the applicable limitation period expires.
- Invoices and accounting documents: up to ten years where required by law; contractual evidence may be retained for up to five years.
- Umami audience measurement: a maximum of twenty-four months.
- Security logs: for a limited period determined according to the risk and incident, then deleted or anonymised.
- GDPR requests and consent records: for the time needed to handle the request and demonstrate compliance with our obligations.
Account deletion stops associated subscriptions and purges operational data. Some separately held data may be retained where a legal obligation or the establishment, exercise or defence of legal claims requires it.
Data security
Data Knight implements measures proportionate to the risks: HTTPS/TLS exchanges, access controls, environment separation, server-managed secrets, encryption of OAuth tokens at rest, attempt limits, logging and controlled backups.
No online service can guarantee zero risk. In the event of a breach likely to pose a risk to individuals, Data Knight applies procedures for documentation, notification to the CNIL and, where required by law, informing the people concerned.
Your rights
Depending on the processing and its legal basis, you may request access, rectification, erasure, portability or restriction of processing. You may object to processing based on legitimate interests and withdraw consent at any time.
My Account lets you change certain data, manage cookie and email preferences, disconnect YouTube, delete social archives and reports, download available data, cancel the subscription and delete the Account. These actions do not replace your right to send us a broader request.
You may also define instructions for your data after your death under French law and lodge a complaint with the CNIL .
Exercise your rights and contact us
Data Knight has not appointed a data protection officer as of this version. Questions and requests may be sent to the privacy contact:
State the subject of your request and your Account email address. We may ask for reasonable identity verification where necessary to avoid disclosing data to a third party. We normally reply within one month. This period may be extended by two months for complex or numerous requests; the User is informed within the first month.
Policy updates
This policy may change as services, providers or applicable law evolve. Its date and version number appear at the top of the page. If a material change affects ongoing processing, appropriate information will be provided and new consent obtained where required.