Privacy Policy
Last updated: October 2026
1. Data Collection
WarDek only collects data necessary for the service:
- Email - For authentication and notifications
- Scanned URLs - To generate your security reports
- Billing data - Via Stripe (we don't store your cards)
2. Data Usage
Your data is used exclusively to:
- Provide the security scanning service
- Generate your PDF audit reports
- Contact you about your account
- Improve our services (anonymized data)
3. Recipients and internal access
We never sell your data. Two categories of people or entities may access it.
Internal access — who at OmniRealm can read your scans
Access to the URLs you scan and to their results is restricted to authorised personnel. Given the size of the company, this is currently limited to the director of OmniRealm SASU, who also acts as system administrator and therefore holds direct access to the production database.
That access may only be exercised to: handle an incident or a support request, carry out a request from you (export, deletion), perform a maintenance operation, or comply with a legal obligation. Every authorised person is bound by a duty of confidentiality that survives the end of their engagement. Your data is never accessed for commercial purposes, nor used to train an artificial intelligence model.
The full commitment is set out in our Data Processing Agreement, section 4.
Technical providers
Hostinger International Limited (France datacenter)
Infrastructure and database
Stripe (Ireland (EU))
Payments, PCI-DSS certified
Resend (EU)
Transactional emails
Upstash (EU)
Rate limiting and abuse protection
Sentry (EU)
Application error collection
Mistral AI (France (EU))
Website conversation assistant
Telegram (Outside the EU)
Internal notification of a signup or contact request — email domain and contact message only
Our audience analytics and monitoring tools are self-hosted: no browsing data is sent to an advertising platform. The complete list, with the data shared with each provider, is in the DPA, section 6.
4. Your Rights (GDPR)
Under GDPR, you have the following rights:
Response time: 30 days maximum as per regulations.
5. DPO Contact
To exercise your rights or for any questions about your data:
Other legal documents