Controller roles
For your account data (email, profile, billing metadata, usage logs), datafetch.wtf acts as a controller. For OSINT queries you run about third parties, you act as an independent controller and must have a lawful basis.
- Account basis
- Contract (Art. 6(1)(b)) + security legitimate interest (Art. 6(1)(f))
- Queries
- You determine purpose and legal basis
Lawful bases in detail
Each purpose is tied to one basis. We do not rely on consent for anything the service needs to function, which means withdrawing newsletter consent never affects your seat.
- Running your account
- Art. 6(1)(b) — contract
- Invoicing and tax records
- Art. 6(1)(c) — legal obligation
- Abuse prevention and rate limiting
- Art. 6(1)(f) — legitimate interest
- Security and audit logging
- Art. 6(1)(f) — legitimate interest
- Newsletter
- Art. 6(1)(a) — consent, withdrawable
Where we rely on legitimate interest we have balanced it against your rights; you can object and we will reconsider on the facts.
Your rights
- Access — copy of your account data
- Rectification — correct inaccurate profile fields
- Erasure — delete account where legally allowed
- Restriction / objection — where applicable
- Portability — export of account fields we hold
- Complaint — to your supervisory authority
How to request
Email support via the Telegram help desk or a console ticket. For removal of identifiers from research corpora where we control the copy, use Data remover.
We respond within one month of a verified request. Complex requests can extend that by a further two months, and we will tell you if that happens. There is no fee unless a request is manifestly excessive or repetitive.
We need to be confident who is asking before we hand over or delete anything, so expect a verification step proportionate to what you are requesting.
What we cannot always do
Some requests collide with other obligations. Being straight about that up front is more useful than a promise we cannot keep.
- Billing records must be retained for tax and accounting periods even after account deletion.
- Abuse and security logs tied to an investigation may be kept under legitimate interest until it closes.
- Third-party source data is not ours to rewrite. We can delist our copy; we cannot edit the original breach corpus or the upstream provider.
- Another person's request about data you queried is answered by us for our copy, and by you for yours — you are the controller of your case file.
Automated decisions and profiling
We do not make decisions with legal or similarly significant effects about you by automated means, and we do not build marketing profiles from your query history. Automation in the platform is limited to routing, rate limiting, abuse scoring and the query orchestration that picks which sources to hit — none of which decides anything about you as a data subject.
Retention
Account data is kept while your seat is active and for a limited period afterward for abuse prevention and legal compliance. Search logs may be retained per plan and security policy. Category-by-category windows are listed on the Privacy policy.
Transfers
Infrastructure may run in the EU and/or other regions. Where transfers occur, we use appropriate safeguards — an adequacy decision where one exists, otherwise Standard Contractual Clauses with encryption in transit and data minimisation. Details are in the Privacy policy.
Complaints
If you think we have handled your data badly, tell us first — most issues are a misunderstanding we can fix quickly. You do not have to come to us first, though: you can complain directly to the supervisory authority in your country of residence, place of work, or where the alleged infringement happened. Going to a regulator does not cost you any other remedy, including compensation through the courts.
