Privacy Notice
Privacy Notice
1. Who this covers
This notice explains how the operator of this UNMASK service ("we") handles personal data in running this UNMASK service. It covers two groups of people, whose data we handle in different roles:
- People researched in cases. Our customers decide whom to research and why. For that data the customer is the controller and we act only on their instructions, as their processor (a "data intermediary" under Singapore's PDPA). Section 2 explains what that means for you.
- People who use the service (analysts and administrators). For their account data we are the controller. Sections 3 to 9 apply.
2. If you are being researched
A customer may have used UNMASK to look up information about you from public and third-party sources, such as whether a username or email address is registered on websites, public web pages that mention you, or public records about a domain. That customer is responsible for having a lawful basis, for telling you where the law requires it, and for answering your requests.
If you want to exercise your rights (for example to access, correct or delete your data, or to object), please contact the organisation that researched you. If you don't know who that is, or they don't respond, contact us. Where we can lawfully do so, we will pass your request to the customer responsible and help them respond. We can't search customers' cases for you ourselves, because they are encrypted and confidential to the customer, and doing so would itself mean processing your data without their instruction. If you believe UNMASK is being used to harm you, please tell us: the Acceptable Use Policy prohibits it and we act on reports.
3. Data about users
- Account data: your email address, optional display name, a one-way hash of your password (never the password itself), whether you are an administrator, and when you created your account and last signed in.
- Settings: your theme, notification choices, and any Slack webhook you add (stored encrypted).
- Terms acceptance: the version of the Terms you accepted and when.
- Activity records: an audit log of what you do in the service (sign-ins and failed sign-ins, cases opened, decisions, notes, exports, shares) with the time and your IP address.
- Content you write: notes and assessments, which are part of the customer's cases.
- Technical data: standard server and proxy logs kept by our hosting provider, which can include IP addresses, browser type and the pages requested.
We do not use analytics, advertising or tracking tools, and we do not sell personal data.
4. Why, and on what basis
| Purpose | Data | Legal basis (where the GDPR or UK GDPR applies) |
|---|---|---|
| Providing your account and the service | Account data, settings | Performance of our contract with you or your organisation |
| Keeping the service and its data secure, and preventing and investigating misuse | Activity records, technical data | Legitimate interests: protecting the people researched, our customers and the service |
| Showing that use of the service was authorised and accountable | Activity records, terms acceptance | Legitimate interests, and compliance with legal obligations where they apply |
| Sending the notifications you choose | Email address, Slack webhook | Performance of contract; you can switch them off at any time |
| Complying with the law and responding to lawful requests | Any of the above, as required | Legal obligation |
Where Singapore's PDPA applies, we rely on your consent given when you create or use an account, on deemed consent by contractual necessity, and on the legitimate-interests and other exceptions the Act provides.
5. Sharing
We share user data only: with the hosting and email providers that run the service for us, under contracts that require them to protect it; with the customer organisation whose account you use (its administrators may be given access to its users' activity records); with the people a case is shared with (who can see your notes and decisions in it); and with courts, regulators or law enforcement where the law requires it or where necessary to prevent serious harm, as described in the Terms. If our providers are outside your country, we use appropriate safeguards for the transfer, such as standard contractual clauses.
6. How long
We keep account data while your account is active, and delete it within a reasonable time after it is closed, unless we need to keep it longer to meet a legal obligation or to establish, exercise or defend legal claims. Audit records are kept for as long as needed to account for the use of the service, which may be longer than the cases they refer to. Case data follows the retention periods described on the Trust page.
7. Your rights
Depending on the law that applies to you, you may have the right to access your personal data, correct it, delete it, restrict or object to its processing, receive it in a portable form, withdraw consent, and complain to a data protection authority (in Singapore, the Personal Data Protection Commission). To exercise these rights, contact us. We may need to verify your identity first. Some rights are limited where data must be kept for security, legal or accountability reasons, including audit records.
8. Cookies
We use only cookies that the service needs: a session cookie that keeps you signed in and protects forms against forgery, and a cookie that remembers your light or dark theme. We don't use cookies for analytics or advertising, so we don't ask for cookie consent.
9. Changes and contact
We will update this notice when our practices change and show the date at the top. For any question about privacy, contact the operator of this service.