Legal
Privacy Policy
Last updated 4 August 2026
1. Data controller & contact
For the purposes of the EU General Data Protection Regulation (Regulation (EU) 2016/679, GDPR) and applicable national data-protection law, the controller of your personal data is:
- CraveWave Ltd(HE 465429) — a company registered in the Republic of Cyprus, operating the Services under the GenticOne brand
- Antheon 13, Aradippou, 7103 Larnaca, Cyprus
- Email: privacy [at] genticone.com
Our Data Protection Officer (where appointed) can be reached at dpo [at] genticone.com.
2. Scope
This Privacy Policy explains how we collect, use, disclose and safeguard personal data when you visit our website or use the Services, and describes your rights under the GDPR. It does not apply to third-party sites we do not control.
3. Personal data we collect
Data you provide
- Account data — name, email address, password (hashed), organization and role.
- Billing data — plan, billing contact and transaction identifiers (payments are processed by our payment provider; we do not store full card numbers).
- Communications — messages you send to support, sales or feedback.
Data we collect automatically
- Usage data — pages viewed, features used, actions taken and timestamps.
- Device & log data — IP address, browser type, operating system, referring URLs and diagnostic logs.
- Cookies & similar technologies — as described in our Cookies Policy.
Scan data
When you submit a URL, we retrieve and analyse publicly available information from that address to produce a report. Submitted URLs and generated reports are associated with your Account.
4. Purposes & legal bases
We process personal data only where we have a lawful basis under Article 6 GDPR:
- To provide the Services (create your account, run scans, deliver reports) — performance of a contract (Art. 6(1)(b)).
- To operate, secure and improve the Services, prevent abuse and ensure network security — legitimate interests (Art. 6(1)(f)).
- To send service and, where permitted, marketing communications — consent (Art. 6(1)(a)) or legitimate interests, which you may object to at any time.
- To handle billing and comply with legal, tax and accounting obligations — legal obligation (Art. 6(1)(c)) and contract.
- Cookies and analytics that are not strictly necessary — consent (Art. 6(1)(a)).
- Cookieless aggregate traffic measurement — legitimate interests (Art. 6(1)(f)) in understanding how the site performs. This sets no cookies and no identifiers, so it does not depend on your cookie choices; you may object at any time.
5. Cookies & similar technologies
We use cookies and similar technologies to run the site, remember preferences and, with your consent, measure usage. See our Cookies Policy for details and to manage your choices.
6. Recipients & sharing
We do not sell your personal data. We share it only with:
- Processors acting on our instructions (cloud hosting, analytics, email delivery, payment processing, customer support), bound by data-processing agreements. Our website analytics processor is Google Analytics 4 (Google Ireland Limited); it is loaded only if you allow analytics cookies, and we do not enable its advertising or personalisation features. We additionally use Cloudflare Web Analytics (Cloudflare, Inc.), which is cookieless: it records aggregate page views, referrer, approximate country, device type and page-timing measurements, and does not set cookies or build a profile of you. Because it is injected by our CDN before the page reaches you, it is not governed by the cookie banner;
- professional advisers, auditors and authorities where required by law;
- a successor entity in the context of a merger, acquisition or reorganization, subject to this Policy.
7. International transfers
Where personal data is transferred outside the European Economic Area, we rely on an adequacy decision or on appropriate safeguards such as the European Commission’s Standard Contractual Clauses, together with supplementary measures where needed. A copy of the relevant safeguards is available on request.
In practice this applies to our use of Google Analytics, where data may be processed by Google LLC in the United States. You can prevent this entirely by declining analytics cookies — the Analytics tag is never loaded without your consent, and you can withdraw it at any time via Cookie settings.
It also applies to Cloudflare Web Analytics (Cloudflare, Inc., United States), which we rely on Standard Contractual Clauses for. Because it is cookieless and injected by our CDN, declining cookies does not switch it off; if you wish to object to it, contact us using the details below.
8. Data retention
We keep personal data only as long as necessary for the purposes set out above: for the life of your Account and a limited period thereafter, or longer where required to comply with legal obligations, resolve disputes or enforce agreements. Scan reports are retained with your Account until you delete them or close your Account.
9. Data security
We implement appropriate technical and organizational measures to protect personal data, including encryption in transit, access controls, and logging. No method of transmission or storage is completely secure; we cannot guarantee absolute security but work to protect your data and to notify you and the relevant authority of a breach where legally required.
10. Your rights
Subject to conditions in the GDPR, you have the right to:
- Access — obtain confirmation and a copy of your personal data (Art. 15).
- Rectification — correct inaccurate or incomplete data (Art. 16).
- Erasure — request deletion in certain circumstances (Art. 17).
- Restriction — limit processing in certain circumstances (Art. 18).
- Portability — receive your data in a structured, machine-readable format (Art. 20).
- Objection — object to processing based on legitimate interests or to direct marketing (Art. 21).
- Withdraw consent — at any time, without affecting prior lawful processing (Art. 7(3)).
To exercise any right, contact privacy [at] genticone.com. We will respond within one month, as required by law. Exercising your rights is free unless requests are manifestly unfounded or excessive.
11. Automated decision-making
We do not make decisions that produce legal or similarly significant effects about you based solely on automated processing within the meaning of Article 22 GDPR. Scan scores are automated assessments of websites, not decisions about individuals.
12. Children
The Services are not directed to children under 16, and we do not knowingly collect their personal data. If you believe a child has provided us data, contact us and we will delete it.
13. Changes to this Policy
We may update this Policy from time to time. The “Last updated” date reflects the latest version; material changes will be communicated through the Services or by email where appropriate.
14. Complaints & supervisory authority
If you have concerns, please contact us first at privacy [at] genticone.com. You also have the right to lodge a complaint with a supervisory authority, in particular in the EU Member State of your residence, place of work or the alleged infringement. Our lead supervisory authority is the Office of the Commissioner for Personal Data Protection in Cyprus (dataprotection.gov.cy).