Legal · Privacy

    Privacy Policy

    A short, factual summary of what data we process and why. No cookie banners, no dark patterns. Just GDPR.

    Last updated: 31 August 2026

    1. Data controller

    The data controller within the meaning of Regulation (EU) 2016/679 (GDPR) is Kybit s.r.o., company ID 23953284, registered office at Homolová 522, 196 00 Prague-Čakovice, Czech Republic, entered in the Commercial Register kept by the Municipal Court in Prague.

    Contact for data-protection matters: privacy@kybit.cz.

    2. Data we collect

    This website has three forms. From each one we process only the data that is actually needed for its purpose.

    Contact form (standard B2B inquiry):

    • name
    • email address
    • company name (optional)
    • the content of your message

    Emergency Response form (request for an immediate incident response):

    • company name
    • phone number for callback

    The external exposure report request follows its own rules. The data, the legal basis and the retention periods are set out in chapter 4.

    For the contact and Emergency Response forms we also log the source IP address. It is used solely for rate-limiting and abuse prevention against DoS and fake 3 a.m. incident calls. The IP is not linked to the message content and is not retained beyond the rate-limit window.

    3. Purpose and legal basis

    Contact-form data is processed to handle B2B inquiries, communicate with your organisation and carry out pre-contractual steps at your request (Art. 6(1)(b) GDPR).

    Emergency Response data is processed so that we can call you back without delay during an active security incident and coordinate the response of our incident-response team. The legal basis is performance of pre-contractual steps at your request (Art. 6(1)(b) GDPR) and our legitimate interest in keeping the emergency channel available and abuse-free (Art. 6(1)(f) GDPR).

    For the contact and Emergency Response forms we rely in parallel on our legitimate interest in running our business communication with prospective clients (Art. 6(1)(f) GDPR). That basis does not extend to the external exposure report request.

    The data is used solely for internal business and operational communication. We do not share it with third parties for marketing or profiling purposes, and we do not transfer it to third countries outside the EU and EEA.

    4. External Exposure Report request (OSINT)

    The external exposure report page carries a form for requesting the report. The processing around it is described separately, because it differs from the other two forms on several points.

    The purpose is to compile and deliver a free external exposure report on a domain you are authorised to represent. The report is produced with passive OSINT over publicly available sources. It is written and signed by Lukáš Jonák, lukas.jonak@kybit.cz.

    The legal basis is the performance of pre-contractual steps at your request under Art. 6(1)(b) GDPR. We collect no marketing consent at this time and the form contains no such checkbox. The one tick box the form does require is a declaration of scope and of your authority to request the analysis.

    From the request we process:

    • your name
    • your work email address in the domain being profiled
    • your company name
    • the domain derived from your work email address, which is also the scope of the analysis
    • the timestamps and IP addresses of the submission and of the confirmation click
    • your browser user agent
    • the URL of the page you submitted from
    • a technical request identifier
    • the verbatim text of the declaration you accepted

    Request metadata is stored in our own infrastructure in the EU.

    We send the report to nobody but the mailbox that asked for it. We do not publish it, we do not name you as a recipient anywhere, and we share no finding with anyone else. The only third party that touches it is the SMTP provider that delivers it, see chapter 8.

    Two messages reach the domain being profiled, and both go to the mailbox the request came from. The confirmation carries a single-use link, and after the requester confirms, that same address receives an acknowledgment stating the delivery date. We write to no other address in that domain automatically. If you believe somebody requested a report for your organisation without authority, write to security@kybit.cz and we will block the domain from further requests.

    Retention periods are as follows:

    • collection working data, including every raw source response, is deleted within 90 days
    • raw responses containing credential material are deleted at the end of the collection run
    • the delivered report stays in our outbound mail records for 12 months
    • request metadata, meaning the domain, the timestamps and the source IP address, is kept separately for 12 months for abuse investigation; the copies held inside the declaration record follow the four-year period below
    • the record of the accepted declaration is kept for 4 years as proof of lawful processing

    The rights listed in chapter 6 apply to this data as well. To exercise them write to privacy@kybit.cz. We respond within thirty days.

    5. Retention period

    We retain the data only for as long as necessary to resolve the inquiry or incident, or to establish a contractual relationship. If the exchange does not lead to further cooperation, we delete the data no later than twelve months after the last contact.

    Records related to an actual incident-response engagement (an Emergency Response that turns into a paid engagement) are kept for the duration of the contractual relationship and afterwards for the statutory archival period where applicable (e.g. accounting).

    The external exposure report request carries its own retention periods, set out in chapter 4.

    6. Your rights

    As a data subject you have the following GDPR rights:

    • access your personal data (Art. 15 GDPR)
    • rectify inaccurate data (Art. 16 GDPR)
    • erasure (“right to be forgotten”, Art. 17 GDPR)
    • restrict processing (Art. 18 GDPR)
    • data portability (Art. 20 GDPR)
    • object to processing (Art. 21 GDPR)
    • lodge a complaint with the Czech Office for Personal Data Protection (uoou.cz)

    To exercise these rights contact us at privacy@kybit.cz. We respond within thirty days.

    7. Cookies and analytics

    This website does not use tracking or marketing cookies.

    For basic performance and traffic measurement we use Vercel Analytics, a privacy-friendly service that works exclusively with aggregated and anonymised data, stores no persistent identifiers or cookies on your device, and cannot track individual users across sessions or sites.

    For this reason no cookie consent banner is displayed. None is required for this type of analytics.

    8. Processors (sub-processors)

    To run the service we use the following processors. Each is contractually bound to GDPR standards and receives the minimum data needed.

    • Vercel Inc. provides website hosting and privacy-friendly analytics, with data processed in the EU region (vercel.com/legal/privacy-policy)
    • Amazon Web Services EMEA SARL (Amazon SES) delivers form submissions to sales@kybit.cz and sends confirmation emails and the finished report. Sending runs in the eu-central-1 region (Frankfurt, Germany), inside the EU (aws.amazon.com/privacy)
    • PagerDuty Inc. pages our incident-response team during Emergency Response. It receives metadata only, meaning a timestamp and a region label, with no plain-text form content (pagerduty.com/privacy-policy)
    • Cloudflare Inc. (Turnstile) protects the forms against bots. Verification is cookieless and sets no persistent identifiers (cloudflare.com/privacypolicy)

    9. Security

    As a security company we take appropriate care of your data. It is stored and transmitted encrypted, access is limited to staff who need it, and our entire EU-based infrastructure is subject to regular security review.

    10. Changes to this policy

    This policy may be updated from time to time. The current version is always available on this page with the date of the latest update marked.