GDPR Framework

Privacy Policy

Last updated: October 2026

1. Data Collection

WarDek only collects data necessary for the service:

  • Email - For authentication and notifications
  • Scanned URLs - To generate your security reports
  • Billing data - Via Stripe (we don't store your cards)

2. Data Usage

Your data is used exclusively to:

  • Provide the security scanning service
  • Generate your PDF audit reports
  • Contact you about your account
  • Improve our services (anonymized data)

3. Recipients and internal access

We never sell your data. Two categories of people or entities may access it.

Internal access — who at OmniRealm can read your scans

Access to the URLs you scan and to their results is restricted to authorised personnel. Given the size of the company, this is currently limited to the director of OmniRealm SASU, who also acts as system administrator and therefore holds direct access to the production database.

That access may only be exercised to: handle an incident or a support request, carry out a request from you (export, deletion), perform a maintenance operation, or comply with a legal obligation. Every authorised person is bound by a duty of confidentiality that survives the end of their engagement. Your data is never accessed for commercial purposes, nor used to train an artificial intelligence model.

The full commitment is set out in our Data Processing Agreement, section 4.

Technical providers

Hostinger International Limited (France datacenter)

Infrastructure and database

Stripe (Ireland (EU))

Payments, PCI-DSS certified

Resend (EU)

Transactional emails

Upstash (EU)

Rate limiting and abuse protection

Sentry (EU)

Application error collection

Mistral AI (France (EU))

Website conversation assistant

Telegram (Outside the EU)

Internal notification of a signup or contact request — email domain and contact message only

Our audience analytics and monitoring tools are self-hosted: no browsing data is sent to an advertising platform. The complete list, with the data shared with each provider, is in the DPA, section 6.

4. Your Rights (GDPR)

Under GDPR, you have the following rights:

Access
Rectification
Deletion
Portability
Objection
Restriction

Response time: 30 days maximum as per regulations.

5. DPO Contact

To exercise your rights or for any questions about your data:

Data Protection Officer

[email protected]

OmniRealm SASU — Les Sables d'Olonne, France

Other legal documents