Skip to content

Legal

Privacy Policy

Last Updated: August 10, 2026

1. Introduction

Houdin.io ("we", "us", "our") provides a cloud-based cyber threat intelligence platform (the "Service"), available at app.houdin.io. This policy explains how we collect, use, share, and protect your data in compliance with the EU General Data Protection Regulation (GDPR).

2. Data Controller & Processor

  • Controller: Houdin.io controls the processing of customer data related to your use of the Service.
  • Processor: For Enterprise and MSSP customers we act as a processor when handling personal data on their behalf. A Data Processing Agreement (DPA) covering subprocessors, confidentiality, technical safeguards and data deletion is available on request.

3. Personal Data & Lawful Processing

  • Account data: name, email address and avatar provided by your sign-in method (Google, GitHub, Microsoft or email/password, via our identity provider Auth0)
  • Usage data: scan history, quota and usage counters, plan and subscription status, and your conversations with the Mesmer assistant
  • Submitted observables: the IP addresses, domains, URLs and file hashes you submit for analysis. The Service does not accept file uploads
  • Billing data: payments are processed by Stripe; we store subscription references only and never see or store your card details

We process data under these lawful bases:

  1. Consent: when you opt into data tracking or cookies.
  2. Contractual necessity: to provide and support the Service.
  3. Legitimate interests: for fraud prevention, analytics, security.
  4. Legal obligations: e.g., record‑keeping for compliance.

4. Data Principles & Retention

  • Minimization: only essential data is collected.
  • Purpose limitation: data used only for stated purposes.
  • Accuracy: you can correct your info anytime.
  • Storage limitation: your scan history and assistant conversations are retained until you delete them; deleting your account removes your personal data.
  • Security: encryption, access control, pseudonymization, audits.

5. Transparency & Privacy‑by‑Design

Privacy is built into the Service by default: third‑party connector credentials you configure are stored encrypted, API keys are stored hashed, scanner configurations are stripped of secrets before results are saved, and access to customer data is restricted by role.

6. Consent & Cookies

The Service uses a small number of first‑party cookies: an authentication session cookie, a theme preference, and a 30‑day cookie recording how you first found us. We use PostHog (EU‑hosted) and Vercel Analytics to understand product usage. You can object to analytics at any time at privacy@houdin.io.

7. Subprocessors & International Transfers

We rely on the following subprocessors: Auth0 (authentication), Stripe (payments), Vercel (hosting and analytics), MongoDB Atlas (database), PostHog (EU‑hosted analytics), Upstash (task queue), and AI model providers accessed through Vercel AI Gateway (including Anthropic and Google) for Mesmer analysis features. When you launch a scan, the submitted observable is also sent to the threat‑intelligence sources queried — such as VirusTotal, urlscan.io, AbuseIPDB, AlienVault OTX, Hatching Triage, ThreatFox, MISP and Netlas — which process it under their own privacy policies. Data transferred outside the EU/EEA is protected by Standard Contractual Clauses or equivalent safeguards.

8. Data Subject Rights

Under GDPR, you may:

  • Access, correct, erase, restrict, or object to processing
  • Port your data in a common format
  • Withdraw consent and stop profiling or automated decisions

Requests are processed within one month. Contact us at privacy@houdin.io.

9. Data Breach & Security Measures

  • TLS encryption in transit, encryption at rest
  • Role‑based access controls
  • Hashed API keys & encrypted third‑party connector credentials
  • 72‑hour breach notification to authorities

10. Data Protection Officer (DPO)

We have not designated a formal DPO, as our processing activities do not require one under GDPR. Privacy matters are handled directly by the team at privacy@houdin.io.

11. Updates & Governance

Policy updates are posted on this page with a revision date; significant changes will be highlighted. We maintain records of our processing activities.

12. Contact Information

Email: privacy@houdin.io