1. Who is responsible for processing?
Amuneth acts as controller for personal data processed through our websites, platform modules, forms, report requests, account registrations and direct communication. Where specialised suppliers are used, this is done under appropriate agreements, purpose limitation and security obligations.
2. Which personal data may we process?
Depending on your relationship with Amuneth, we may process name, email address, phone number, company name, role, tenant or organisation name, login and session data, MFA preferences, report requests, scan input, communication content, technical metadata, IP address, user agent and preferences needed to keep the platform secure and usable.
3. Why do we process data?
We use personal data to register and manage accounts, support login and access security, handle fraud reports and contact requests, organise CTI and report access, perform scans or assessments, deliver reports, meet legal obligations and protect our digital environment against abuse, brute force, spam or unauthorised access.
4. Legal bases
We process data on the basis of consent, contract performance, legitimate interest and, where necessary, legal obligations. Legitimate interest may apply to platform security, logging, incident analysis, service improvement and abuse prevention. Where consent is the basis, it can generally be withdrawn.
5. Sharing data
We do not share data lightly. Sharing only takes place when needed for hosting, email processing, logging, security support, report delivery or other parts of our service. Suppliers receive no more data than necessary.
6. Retention
Retention periods differ per purpose. Account data is kept while an account is active or as long as needed for security, auditability and service delivery. Contact requests, report requests, scan history and legal or fiscal data may be kept longer where reasonable or required by law.
7. Security
Amuneth applies technical and organisational measures appropriate to the nature of the data and the risk, including access limitation, password hashing, session hardening, rate limiting, MFA support, careful logging, separated configuration files and role-based access.
8. International transfers
When suppliers outside the European Economic Area are used, this happens only with appropriate safeguards such as transfer mechanisms, contractual arrangements or supplier terms permitted by applicable privacy law.
9. Your rights
You generally have rights of access, correction, deletion, restriction, portability and objection. You may also withdraw consent. These rights are not unlimited in every situation, for example where security, audit obligations or legal duties weigh more heavily.
10. Contact
For privacy questions or requests, contact info@amuneth.com. Please describe your request clearly so we can respond carefully and quickly.