This policy describes how DeXpose collects, uses, stores and shares personal data, including the exposed data we process to deliver dark web and breach monitoring, and the contact details we keep for service and marketing purposes.
01Who we are
DeXpose is a cyber threat intelligence company registered in Sharjah, United Arab Emirates. We provide dark web monitoring, breached credentials monitoring, attack surface mapping and related services to organizations and their security partners. Our website is https://www.dexpose.io and our registered address is Block B-B26-049, Sharjah, United Arab Emirates.
In this policy, "we", "us" and "DeXpose" refer to DeXpose, and "you" refers to anyone who visits our website, uses our free tools, contacts us, or uses our platform as a customer or on behalf of a customer.
This policy explains what personal data we collect, why we collect it, how long we keep it, who we share it with, and the choices you have. It applies to our website, our free tools, our customer platform and our API.
02The nature of our service
DeXpose collects and analyzes information that has already been exposed by third parties: data from public breaches, infostealer malware logs, credential dumps, combo lists, dark web marketplaces and forums, ransomware leak sites, and chat platforms such as Telegram and Discord. This information often contains personal data such as email addresses, usernames, passwords, names, phone numbers, IP addresses and device details.
We process this data so that organizations can find out that their employees, customers or systems have been compromised and can act before the data is abused. We do not create this data, we do not sell it, and we do not use it for any purpose other than delivering security intelligence to organizations that are entitled to receive it.
Our legal basis for this processing is our legitimate interest, and the legitimate interest of our customers, in preventing fraud, account takeover and unauthorized access. We apply safeguards described in this policy, including masking of passwords, access controls, and verification of a customer's right to monitor a domain before results are released.
03Data we collect from you
- Contact details you give us when you fill in a form, request a demo, ask for a report or write to us: name, work email, company name, job title, phone number and the content of your message.
- Free tool inputs: the domain names or email addresses you submit to the free dark web report, the email breach scan or the Oracle breach check, together with the time of the request.
- Account data if you are a customer or a user invited by a customer: login email, name, role, organization, the domains and assets you register for monitoring, and your activity in the platform such as alerts opened and resolved.
- Technical data collected automatically when you use our website or platform: IP address, browser type, device type, operating system, referring page, pages visited, and the approximate location derived from your IP address.
- Communications: emails, support tickets and call notes exchanged with our team.
- Marketing preferences: whether you have opted in to or out of our emails, and how you interact with them.
04How we use your data
We use the data described above to:
- provide the service you asked for, including running a free scan, sending a report, responding to your enquiry and delivering monitoring and alerts;
- create and manage customer accounts, verify domain ownership and authorize access;
- send service messages such as alert notifications, security notices and changes to these terms;
- send marketing communications about DeXpose products, features, research, events and offers, where the law permits or where you have agreed to receive them;
- understand how our website and platform are used, so we can improve them;
- protect our services against abuse, fraud and unauthorized access, and enforce our terms;
- comply with legal obligations and respond to lawful requests from authorities.
05Marketing and how to opt out
If you contact us, request a demo, download a report or use one of our free tools with your work email, we may store your contact details and use them to send you information about DeXpose services, security research and events that we think are relevant to your role. We rely on our legitimate interest in promoting our services to business contacts, or on your consent where the law requires it.
You can stop receiving marketing at any time by using the unsubscribe link in any email, by replying with the word unsubscribe, or by writing to info@dexpose.io. We will act on your request promptly. Opting out of marketing does not affect service messages that are necessary to deliver a product you use, such as breach alerts.
We do not sell your personal data to third parties, and we do not share your contact details with other companies for their own marketing.
06Cookies and analytics
Our website uses a small number of cookies and similar technologies. Strictly necessary cookies keep the site working, for example to remember your preferences and to protect forms. Analytics cookies help us count visits and understand which pages are useful. Google reCAPTCHA protects our forms and free tools from automated abuse; it is subject to the Google Privacy Policy and Terms of Service.
You can control cookies through your browser settings. Blocking some cookies may affect how the site works. We honor the settings of your browser and do not use cross-site tracking for advertising.
07Sharing your data
We share personal data only when needed to run our business and deliver our services:
- Service providers that host our infrastructure, deliver email, provide analytics, process payments or run customer support tools. They act on our instructions and are bound by contract to protect your data.
- Security partners and resellers: if you access DeXpose through a managed security provider, reseller or partner, we share the data needed to deliver and support that service with them.
- Professional advisers such as auditors, lawyers and insurers, where necessary.
- Authorities where we are required to by law, a court order or a lawful request, or where necessary to prevent serious harm.
- A buyer or successor if DeXpose is involved in a merger, acquisition or sale of assets, in which case this policy continues to apply.
08International transfers
DeXpose operates from the United Arab Emirates and uses service providers located in other countries, including the European Union and the United States. Where personal data is transferred across borders, we use recognized safeguards such as contractual clauses, and we choose providers that maintain strong security standards.
09How long we keep data
- Enquiries and marketing contacts: for as long as we have an active relationship with you or your organization, and for up to three years after our last contact, unless you ask us to delete it sooner.
- Free tool inputs: the domain or email you submit is kept for up to twelve months to deliver the result, prevent abuse and improve accuracy. Results are generated from data we already hold and are not stored against your identity beyond that period.
- Customer account data: for the life of the contract and for a limited period afterwards to close out billing, support and legal obligations.
- Threat intelligence data collected from breaches and dark web sources: for as long as it remains relevant to detecting and preventing the misuse of credentials. Old records are retained because attackers continue to reuse them for years.
- Technical logs: typically for ninety days, longer where needed to investigate a security incident.
10How we protect data
We apply technical and organizational measures appropriate to the sensitivity of the data we hold. These include encryption in transit and at rest, dedicated environments for each customer, role-based access with multi-factor authentication, logging and monitoring, regular security testing, and staff confidentiality obligations. Passwords found in breach data are masked in our interface and are only revealed to authorized users under strict conditions.
No system is completely secure. If we discover a breach that affects your personal data, we will notify you and the relevant authorities where the law requires it.
11Your rights
Depending on where you live, you may have the right to:
- ask what personal data we hold about you and receive a copy;
- ask us to correct inaccurate or incomplete data;
- ask us to delete your data, subject to legal and security exceptions;
- object to or restrict certain processing, including marketing;
- withdraw consent where processing is based on consent;
- receive your data in a portable format;
- complain to a data protection authority.
To exercise any of these rights, write to info@dexpose.io. We may ask you to verify your identity before acting. If you appear in breach data that we hold, we can tell you which sources exposed your details and help you take action; however, we may keep a record so that the credential continues to be flagged as compromised to organizations entitled to know.
12Children
Our website, free tools and services are intended for organizations and professionals. We do not knowingly collect personal data from children under sixteen. If you believe a child has provided us with personal data, contact us and we will delete it.
13Changes to this policy
We may update this policy from time to time to reflect changes to our services, technology or the law. When we do, we will change the date at the top of this page and, for significant changes, notify customers by email or through the platform. Continued use of our services after a change means you accept the updated policy.
14Contact
Questions, requests and complaints about privacy can be sent to info@dexpose.io or by post to DeXpose, Block B-B26-049, Sharjah, United Arab Emirates.