Trust Center · Legal basis

We process data stolen from victims. Here is the law and the discipline around that sentence.

Last reviewed: July 2026 · This summary is public by policy. The underlying assessments and the DPA are available to customers, prospects under NDA, and regulators.

1 · What we process, and why it needs a written basis

The platform indexes data that criminals have already stolen and published: credentials, session cookies and personal identifiers appearing in stealer logs, underground forums and leak sites. That data concerns third parties, the victims, who never consented to anything.

Processing it is lawful when it serves a legitimate, proportionate security purpose, and only under documented safeguards. This page summarizes those safeguards; the full legitimate-interest assessment, framed on GDPR Art. 6(1)(f), is available to customers and regulators on request.

2 · Legitimate interest, narrowly construed

The purpose of processing is singular: enabling organizations to detect and remediate the compromise of their own assets and identities. The platform is licensed to vetted organizations, scoped to their assets and watchlists, and is not a people-search service.

We do not enrich victim identities, build consumer profiles, or sell records. Access to raw records requires an organizational account bound by contract to the same purpose limitation.

3 · Where credential material can go

Credential and cookie material is reachable only inside an authenticated session or an authenticated API key, held by an organization contracted to the purpose in section 2 and granted the relevant module. There is no anonymous read path to it, and the console keeps secret values hidden until an analyst deliberately reveals them.

Anything that leaves an unauthenticated context carries aggregate counts and dates only. No credential material is exposed outside an authenticated, contracted, audited context.

4 · Access auditing

Every query on the platform is logged: who searched, what, when, through which interface. Organization administrators can review their team's access at any time. Our own staff access is governed by the same logging and is reviewed internally. The control applies to us first.

5 · Retention

Records are retained only as long as they serve the security purpose: leaked-credential intelligence loses remediation value as credentials rotate and sessions expire. Retention schedules per data category are defined in our data-handling standard, available under NDA. Expired records are deleted from the live index, not merely hidden.

6 · Data-subject rights

Individuals may direct questions or objections regarding their personal data to our data-protection contact. We respond within the statutory timelines that apply, GDPR primary among them. Note that removing a victim's record from the index can remove their employer's ability to protect them. We explain this trade-off in every response and act on the data subject's decision.

Data protection contact

privacy@generalintels.com handles data-subject requests, regulator inquiries and DPA copies. We answer counsel-to-counsel questions in demos as well; bring yours.

Reading this because you want to know what we do with your data as a visitor or a customer contact? That is a different document: the privacy notice.

Your counsel will have questions.

Bring them. We answer counsel-to-counsel.

NDA-friendly briefings · global coverage · no slideware