Compliance

GDPR Compliance

Last updated: December 28, 2025

GDPR Compliant

RiskHunter is fully compliant with the General Data Protection Regulation (GDPR). We are committed to protecting the privacy and security of personal data.

1. What is GDPR?

The General Data Protection Regulation (GDPR) is a comprehensive data protection law that came into effect on May 25, 2018. It applies to all organizations that process personal data of individuals in the European Union, regardless of where the organization is located.

GDPR establishes strict requirements for how personal data must be collected, processed, stored, and protected, and grants individuals significant rights over their personal data.

2. Our Role Under GDPR

2.1 As a Data Controller

When you create an account, visit our website, or interact with our services directly, RiskHunter acts as a Data Controller. This means we determine the purposes and means of processing your personal data.

2.2 As a Data Processor

When our customers use our API to verify their users' data, RiskHunter acts as a Data Processor. In this capacity, we process personal data on behalf of and under the instructions of our customers (the Data Controllers).

3. Legal Bases for Processing

Under GDPR, we must have a valid legal basis to process personal data. We rely on the following legal bases:

Contract Performance

Processing necessary to fulfill our contractual obligations to you, such as providing our services, managing your account, and processing payments.

Legitimate Interests

Processing necessary for our legitimate interests, such as improving our services, fraud prevention, and security. We always balance our interests against your rights and freedoms.

Consent

Where required, we obtain your explicit consent before processing personal data, such as for marketing communications or non-essential cookies.

Legal Obligation

Processing necessary to comply with legal obligations, such as tax requirements, fraud prevention laws, or responding to lawful requests from authorities.

4. Your Rights Under GDPR

As a data subject, you have the following rights under GDPR:

Right of Access

Request a copy of the personal data we hold about you.

Right to Rectification

Request correction of inaccurate or incomplete data.

Right to Erasure

Request deletion of your personal data (“right to be forgotten”).

Right to Restriction

Request limitation of processing in certain circumstances.

Right to Data Portability

Request transfer of your data in a machine-readable format.

Right to Object

Object to processing based on legitimate interests or for marketing.

5. How to Exercise Your Rights

To exercise any of your GDPR rights, you can:

We will respond to your request within 30 days. In complex cases, we may extend this period by up to 60 additional days, but we will notify you of any extension.

6. Data Protection Measures

We implement comprehensive technical and organizational measures to protect personal data:

Encryption:TLS 1.3 for data in transit, AES-256 for data at rest
Access Controls:Role-based access, multi-factor authentication, audit logging
Data Minimization:We only collect data necessary for our services
Regular Audits:Periodic security assessments and penetration testing
Staff Training:Regular GDPR and security awareness training
Incident Response:Documented procedures for handling data breaches

7. International Data Transfers

When we transfer personal data outside the European Economic Area (EEA), we ensure appropriate safeguards are in place:

  • Adequacy Decisions: We transfer data to countries deemed adequate by the European Commission
  • Standard Contractual Clauses: We use EU-approved SCCs with our data processors
  • Supplementary Measures: Additional technical and organizational safeguards where required

8. Data Processing Agreement

For customers who use our API services, we offer a Data Processing Agreement (DPA) that complies with Article 28 of the GDPR. Our DPA includes:

  • Subject matter and duration of processing
  • Nature and purpose of processing
  • Types of personal data processed
  • Categories of data subjects
  • Rights and obligations of the controller
  • Sub-processor requirements
  • Security obligations
  • Data deletion and return provisions

To request a DPA, please contact us at gdpr@riskhunter.es.

9. Data Breach Notification

In the event of a personal data breach, we will:

  • Notify the relevant supervisory authority within 72 hours of becoming aware of the breach (where required)
  • Notify affected data subjects without undue delay if the breach is likely to result in high risk to their rights and freedoms
  • Document all breaches, including facts, effects, and remedial actions taken
  • Notify our customers (Data Controllers) promptly when we detect a breach affecting their data

10. Data Protection Officer

We have appointed a Data Protection Officer (DPO) who is responsible for overseeing our GDPR compliance. You can contact our DPO at:

Data Protection Officer

Email: dpo@riskhunter.es

Address: Calle Ejemplo 123, 28001 Madrid, Spain

11. Supervisory Authority

If you are not satisfied with how we handle your personal data or respond to your requests, you have the right to lodge a complaint with your local supervisory authority. In Spain, the supervisory authority is:

Agencia Española de Protección de Datos (AEPD)

Website: www.aepd.es

Address: C/ Jorge Juan, 6, 28001 Madrid, Spain

12. Contact Us

For any questions or concerns about our GDPR compliance, please contact us:

RiskHunter

Email: gdpr@riskhunter.es

Phone: +34 91 XXX XX XX

Address: Calle Ejemplo 123, 28001 Madrid, Spain