1. Who handles your information.
XRENN Labs s.r.o., Kopřivnice, Czech Republic, operates this website and client portal. For privacy requests, contact support@xrenn.ai or +420 724 722 644. These rules cover visitors, enquiries, client accounts and the OSINT Scanner.
For account administration and enquiries, XRENN Labs s.r.o. determines the purposes of processing. When handling client information on documented instructions, the respective service agreement defines our role, permitted scope and any required data processing agreement.
2. Information, purposes and legal bases.
Enquiries: contact details, company and billing information, selected services and your message are processed to answer your request and prepare or perform a contract. Do not include passwords, access tokens or unnecessary sensitive information in forms.
Client portal: corporate email, account identifiers, login verification, authorized domains and reports are used to provide the requested service. Necessary processing is based on contractual steps or performance; security and abuse prevention may rely on legitimate interests. A privacy acknowledgement is not marketing consent.
Security logs and authorization records support access protection, incident investigation and evidence of permitted testing. Accounting records are retained where required by law. Optional analytics and advertising technologies require a separate, freely given cookie choice.
3. OSINT scope and authorization.
The scanner examines the domain derived from your corporate email. It gathers public DNS, certificate, reputation and exposure information and performs limited DNS, TLS, HTTP and TCP connection checks. Public data can still contain personal information, including corporate email addresses and indicators of credential exposure.
Before a scan, you must confirm that you own the target or have permission to authorize these checks and verify access to your corporate mailbox. Mailbox access alone is not proof of legal authority. Shared hosting and third-party systems require the relevant owner’s permission. A domain already assigned to another account is not transferred automatically.
Scanner authorization does not permit exploitation, password attacks, denial of service, social engineering or an unrestricted penetration test. Penetration testing requires a separate written agreement identifying targets, methods, dates, exclusions, responsible contacts and emergency stop conditions.
Repeated monitoring is optional. You can revoke scanning authorization in the portal; this prevents new scans, including scheduled ones. A check already in progress may finish. Revocation does not automatically delete existing reports or records required to establish the previous authorization.
4. Service providers and transfers.
Technical infrastructure and email delivery providers process data needed to operate the service. Scanner queries can disclose the target domain or IP address to Cloudflare DNS, Microsoft public discovery endpoints, crt.sh, CertSpotter and HackerTarget. Shodan, LeakRadar, URLhaus and VirusTotal are used where the relevant module or credentials are configured. Availability and results depend on those providers.
The existing template loads fonts from Google Fonts and icon resources from jsDelivr. These requests expose technical connection information such as your IP address independently of optional tracking cookies. Optional advertising providers are listed in the Cookies Manifest.
Some providers operate outside the EEA. Applicable transfer arrangements, including adequacy decisions or standard contractual clauses where needed, must be assessed for the service being used. Contact us for information about the recipients and safeguards applicable to your engagement. Cookie consent does not replace contractual transfer safeguards.
Google reCAPTCHA protects sign-in, PIN verification, scan requests and inquiries against automated abuse. When you interact with a protected form, Google receives technical browser and connection information for security assessment. We verify the result on our server. Rejected requests may generate a security email to support@xrenn.ai containing the time, connection IP address, action and reason; form contents and verification tokens are excluded.
5. Retention and report access.
Enquiries are kept for the time needed to handle the request and any resulting engagement. Accounts and reports are retained while needed for the service, agreed monitoring and resolution of disputes. Security and authorization records are kept only as necessary to investigate incidents, demonstrate permission or meet legal obligations. Specific contractual or statutory periods take precedence.
New scan reports are private by default. Previously enabled public report links remain accessible to anyone who has the link until sharing is disabled. Treat such links as confidential and contact us if access must be revoked. Cookie choices are remembered for 180 days; their audit receipts are subject to a separate retention review.
6. Your rights and contact.
Depending on the applicable conditions, you may request access, correction, erasure, restriction or portability of personal data and object to processing based on legitimate interests. You may withdraw optional consent without affecting the lawfulness of earlier processing. Some data must still be kept for contractual or legal reasons.
Send requests or security concerns to support@xrenn.ai. We may need proportionate identity verification before disclosing account information. You can lodge a complaint with the Czech Office for Personal Data Protection (ÚOOÚ) or your competent supervisory authority.