Privacy notice
Last updated: July 2026
1 · Who this notice is about
This notice covers personal data about you: someone reading this website, submitting the demo form, subscribing to the research digest, or named as a contact on a customer account. It explains what we collect from you, why, for how long, and what you can require us to do about it.
It does not cover the data inside the platform itself. General Intels indexes credentials and identifiers that criminals stole and published, and those records concern people who never contacted us and never consented to anything. That is a different relationship with a different lawful basis, different safeguards and a different process for exercising rights, and it has its own document: the legal-basis page in our Trust Center. If you are here because your details appeared in a breach we index, that is the page you want, and the data-protection address below still reaches us.
Two documents, deliberately. One is about you as a reader and a buyer; the other is about the victims whose data the product exists to find.
2 · Who is responsible
General Intels is the controller for the personal data described in this notice, meaning we decide why it is collected and what happens to it. The registered entity details and postal address are on the imprint page, and the data-protection address below reaches the person who handles these requests.
Where we act instead as a processor, handling personal data inside a customer's account on their instructions, the terms of that processing are set by the data processing agreement attached to the customer's contract, not by this notice.
3 · What we collect, and only this
The list is short because the site is deliberately quiet. There are no advertising or remarketing tags, no third-party session recording, and the site itself sets no cookies. Web fonts are served from our own origin rather than fetched from a font provider. We do count page views, and we do record our own errors, but both run on our own servers and neither identifies you: see the two entries below.
This site is delivered through Cloudflare, which sits in front of our servers to absorb attacks and filter abusive traffic. Every request for every page therefore passes through Cloudflare before it reaches us, and they see the address it came from as any network carrying your traffic would. They act on our instructions, and section 6 says what that relationship is.
Separately, and on two pages only, your browser fetches something directly from Cloudflare: the home page, which has the research-digest box, and the demo request page. Those load Cloudflare's Turnstile anti-bot script. No other page on this site fetches anything from any other company.
- Demo requests
- Your name, work email, company, optionally your role, the product areas you ticked, and anything you wrote in the message field. You type all of it deliberately.
- Digest subscriptions
- Your email address, and nothing else.
- Our reply to you
- Submitting either form sends an automatic message back to the address you gave, confirming what we received and what happens next. It goes out through the same mailbox as everything else we send, and a subscription confirmation carries the link that removes you from the list.
- Submission context
- The page the form was submitted from and your browser's user-agent string, stored alongside the submission to help us tell a person from a script. We do not store your IP address with a form submission.
- Anti-spam checks
- The forms are protected by Cloudflare Turnstile, which evaluates signals from your browser to decide whether you are a bot. Its script loads only on the two pages that carry a form. Cloudflare processes that data as described in section 6.
- Server logs
- Our web servers record requests, including IP addresses, as any web server does. Cloudflare records the same kind of thing for the traffic it carries, which is every request to this site. These are operational logs used for availability and abuse investigation, are not joined to form submissions, and are not used to build a profile of you.
- Page counts
- We count how often each page is opened, and whether the visit arrived from a search engine, from a link on this site, from an external link, or from none of those. It runs on our own servers and is served from this website's own address, so your browser never contacts another host for it. It sets no cookie and stores nothing that could pick you out: two visits and two hundred look the same to it. We also keep a plain per-page counter inside the site itself, which holds no more than a total.
- Error reports
- When something breaks, our servers send the error and the address of the page it happened on to our own error tracker, which also runs on our infrastructure. Your IP address is not attached, and anything you had typed into a form is stripped before the report is sent.
- Customer account contacts
- For customers, the business-contact details needed to run the account and the relationship. Anything inside the customer's own console workspace is governed by their agreement, not this notice.
4 · Why we are allowed to hold it
Under the GDPR every purpose needs a named lawful basis. Ours are:
- Demo requests and sales contact
- Steps taken at your request before entering a contract, and our legitimate interest in responding to a business enquiry you sent us. Article 6(1)(b) and 6(1)(f).
- Research digest
- Your consent, given by submitting the form. You can withdraw it at any time and every issue carries an unsubscribe route. Article 6(1)(a).
- Anti-spam, security and availability
- Our legitimate interest in keeping an unauthenticated public form from being abused as a spam relay or a list-bombing target. Article 6(1)(f).
- Running a customer account
- Performance of the contract with the customer, and our legitimate interest in administering the relationship. Article 6(1)(b) and 6(1)(f).
- Legal and accounting obligations
- Compliance with obligations we are subject to. Article 6(1)(c).
We do not use your data for automated decision-making that produces legal or similarly significant effects, and we do not profile you for advertising.
5 · How long we keep it
Deletion here means removal from the live systems, not merely hiding a row from a list.
- Demo requests that do not become a relationship
- Deleted 24 months after the last contact.
- Digest subscriptions
- Kept until you unsubscribe, then deleted.
- Customer account contacts
- Kept for the life of the contract, then for as long as we are required to retain records of it.
- Server logs
- Rotated on a short operational cycle and not archived.
6 · Who else touches it
The list is complete, and it is short by design: every additional processor is another place your data lives and another agreement to keep current.
- Cloudflare
- Two things, and they are worth telling apart. They deliver this site: every request passes through their network on the way to our servers, which is what protects it from attack and abuse. And they provide Turnstile, the anti-bot check, which is the only thing on this site your browser fetches from another company, and only on the home page and the demo page.
- Google (Workspace)
- Our mailbox. Form submissions are emailed to us, so the notification and any reply pass through it.
- Our own infrastructure
- The website and its database run on infrastructure we operate. The database is reached over a certificate-pinned TLS connection.
We do not sell personal data, we do not share it for cross-context behavioural advertising, and we do not pass it to data brokers. Those are not aspirations; there is no mechanism in this site that could do any of them.
7 · International transfers
Cloudflare and Google are established in the United States and may process data there or in other countries. Where personal data leaves the European Economic Area, the transfer relies on the European Commission's standard contractual clauses or on an adequacy decision covering the recipient, together with the supplementary measures required by the transfer-impact assessment we hold for each.
Copies of the relevant transfer mechanism are available to customers and to regulators on request.
8 · How it is protected
Access to systems holding this data is restricted to the people who need it, over authenticated connections, and is logged. The database connection is encrypted and certificate-pinned. Our broader security posture, including how to report a vulnerability to us, is described on the security page in the Trust Center.
If a breach affects your personal data and is likely to result in a risk to your rights, we notify the competent supervisory authority within 72 hours of becoming aware of it and inform you directly where the risk is high.
9 · Your rights under the GDPR
If you are in the European Economic Area or the United Kingdom, you have the right to:
- ask what we hold about you and get a copy of it;
- have inaccurate data corrected;
- have data erased, where we have no overriding basis to keep it;
- restrict how we use it while a dispute about it is resolved;
- receive the data you gave us in a portable format;
- object to processing we base on legitimate interest, including at any time to direct marketing;
- withdraw consent where consent is the basis, without affecting what was lawful before you withdrew it.
Write to the data-protection address below. We answer within one month, and we will tell you before the end of that month if a request is complex enough to need longer. You may also complain to the supervisory authority where you live or work.
10 · Your rights under the CCPA and CPRA
If you are a California resident, the categories of personal information we collect are identifiers (name, email address, company), professional or employment-related information (your role), commercial information (the product areas you expressed interest in), and limited internet activity information (the page a form was submitted from and your browser's user-agent string). The purposes are the ones in section 4 and the sources are you and, for the anti-bot check, your browser.
We do not collect sensitive personal information as the CPRA defines it, we have not sold or shared personal information for cross-context behavioural advertising in the preceding twelve months, and we do not do so today. We therefore have no "Do Not Sell or Share My Personal Information" mechanism to offer, because there is nothing for it to switch off.
- Right to know
- the categories and specific pieces of personal information we have collected about you.
- Right to delete
- personal information we collected from you, subject to the exceptions the statute allows.
- Right to correct
- inaccurate personal information.
- Right to limit
- use of sensitive personal information. Not applicable: we hold none.
- Right to non-discrimination
- we will not deny you service, charge you differently or give you a lesser experience for exercising any of these.
Use the same address as for a GDPR request. You may use an authorised agent; we will ask for proof of their authority and, where the law permits, verify your identity directly.
11 · Children
This is a business-to-business product sold to organisations. The site is not directed at children, and we do not knowingly collect personal data from anyone under 16. If you believe a child has sent us personal data, write to us and we will delete it.
12 · Changes to this notice
We update this page when what we do changes, and the date at the top of the page moves with it. Where a change materially affects how we use personal data we already hold, we tell affected people directly rather than relying on them to re-read a web page.
Data protection contact
Data-subject requests, regulator enquiries and DPA copies: privacy@generalintels.com. We answer within one month, and we tell you inside that month if a request needs longer.
If your details appeared in a breach we index and you are writing about that, read the legal basis page first, since it explains the trade-off we will raise with you before acting, then write to the same address.