Legal

Privacy Policy

Last updated: July 13, 2026

This Privacy Policy explains how Bolwerk ('we', 'us') collects, uses, and protects personal data when you use our domain security monitoring service at bolwerk.ai. Bolwerk is the data controller for these processing activities under the General Data Protection Regulation (GDPR).

1. Data we collect

We collect account information (such as your name, email address, and login details via Google or GitHub), the domain names you add for monitoring, usage data (such as login times and interactions with the Service), and billing information for paid plans. We also process publicly available data about the domains you add, such as certificate transparency logs and DNS records; this is generally not personal data about you.

2. Why we process data

We use your data to provide and improve the Service, monitor domains and send security alerts, manage your account and process invoices, and respond to support requests. The legal basis is performance of our contract with you, our legitimate interest in securing and improving the Service, and, where required, your consent.

3. Sharing with third parties

We only share data with service providers that help us operate the Service, such as our hosting and database provider (Supabase) and our payment processor for paid plans. For AI-powered security analysis, we use Anthropic. These providers process data solely on our instructions and are contractually bound to appropriate security and confidentiality obligations. We never sell your data.

4. International transfers

Some of our service providers may process data outside the European Economic Area. Where this happens, we put appropriate safeguards in place, such as EU Standard Contractual Clauses, to ensure an adequate level of protection.

5. Retention

We retain your data for as long as your account is active and as needed to provide the Service. After your account is closed, we keep data no longer than necessary for administrative, legal, or tax obligations, after which we delete or anonymize it.

6. Security

We take appropriate technical and organizational measures to protect your data against loss, misuse, and unauthorized access, including encryption in transit and access restrictions. No system is completely secure, and we cannot guarantee absolute security.

7. Your rights

Under the GDPR, you have the right to access, rectify, erase, and restrict the processing of your personal data, the right to data portability, and the right to object to certain processing. You can exercise these rights by contacting us at [email protected]. You also have the right to lodge a complaint with your local data protection authority.

8. Cookies

We use functional cookies that are necessary to sign in and operate the Service. Where we use analytics or marketing cookies, we'll ask for your consent in advance in line with applicable law.

9. Changes to this policy

We may update this Privacy Policy from time to time. We'll notify you of material changes by email or a notice within the Service. The date at the top of this page shows when it was last updated.

10. Contact

For questions about this Privacy Policy or to exercise your rights, contact us at [email protected].

Questions? Drop us a line at [email protected]