Website Privacy Notice
PWN-ALL Auditing, Reviewing & Testing Cyber Risks CO. L.L.C ("PWN-ALL", "we", "our", "us") is the data controller for the processing described in this Notice. Our registered address is: 145, Al Mustaqbal street, Iris Bay Tower 2101-11, Business Bay, Dubai, United Arab Emirates. For questions or to exercise your rights contact legal@pwn-all.com.
This Notice explains what personal data is processed when you use the pwn-all.com website, why, how long it is kept, and the rights available to you under applicable data protection laws (including EU/UK GDPR, UAE PDPL, and US state laws).
1. Scope of This Notice
This Notice covers personal data processed when you browse or interact with pwn-all.com — including its localized language versions, blog, product marketing pages, public website APIs, and free browser-based tools — or send a pre-contract enquiry using a contact method linked from the Website.
It does not govern:
- Engagement data. Data processed during a contracted professional engagement is governed by the applicable signed Statement of Work and its incorporated confidentiality and data-handling schedules, not by this Notice.
- Product data. Standalone PWN-ALL products (such as Dark Monitor, Bot & Abuse Detection, CheckURL, and DocGuard) run on their own subdomains and are governed by the privacy notice published for each product.
2. Browsing the Website
The Website is served from our own infrastructure, without a third-party CDN, analytics service, or advertising network. When your browser requests a page, standard connection data (your IP address, requested URL, and request headers such as User-Agent) is processed in order to deliver the response and protect the service. Our web server is not configured to write access logs of visitor requests.
One page processes visitor data beyond serving files:
- Bot-detection demo (homepage): your IP address and User-Agent are evaluated in memory to compute the demo verdict shown to you. The result is returned in the page and not stored.
3. No Advertising or Cross-Site Tracking, No Sale/Sharing
- We do not use advertising, analytics, or cross-site behavioural tracking (no advertising cookies, pixels, or tracking beacons).
- We do not sell or share personal data for cross-context behavioural advertising. We honor browser-based opt-out signals such as Global Privacy Control (GPC) where applicable.
4. Free Tools: Local Processing & Browser Storage
The free tools on this Website run in your browser. Files and text you process with them (for example in the archive viewer, email viewer, image tools, or hash generator) are handled locally on your device and are not uploaded to us unless the tool's page states otherwise.
Some tools save your inputs or preferences in your browser's localStorage so they survive a page reload — for example the OTP generator, NDA generator, invoice generator, privacy-policy generator, manforge, and the sitewide theme choice. That data stays on your device and never reaches our servers; you can remove it at any time by clearing site data in your browser.
5. Tools That Contact Third-Party Services
A few tools send requests directly from your browser to third-party APIs when you use them. Those services receive your IP address and the queried data, and process them under their own privacy notices. Nothing is routed through our servers:
- BTC Tracer: queries transaction and address data from mempool.space.
- Wallet Generator (balance check, optional): sends the public address you check to blockstream.info (Bitcoin), ethereum-rpc.publicnode.com (Ethereum), api.trongrid.io (Tron), or api.mainnet-beta.solana.com (Solana). Keys are generated locally and never leave your device.
- Subdomain Checker: sends reachability probes from your browser and network to the hosts you specify.
- Archive Viewer: offers a link that opens virustotal.com with the file's SHA-256 hash (the file itself is never uploaded).
Each tool's page states its network behaviour.
6. Contacting Us (Pre-Contract Enquiries)
When you contact us we process the contact details you provide (name, email address or messenger handle) and the content of your message, in order to reply, answer questions, and scope potential work. The channels we offer are independent third-party services that process your data under their own notices:
- Email: delivered to our mailbox hosted by Proton (Proton Privacy Policy). Standard email is not end-to-end encrypted in transit to us unless you encrypt it with our published PGP key.
- Signal: end-to-end encrypted messenger (Signal Privacy Policy).
- Telegram: operated by Telegram (Telegram Privacy Policy).
- WhatsApp: operated by Meta (WhatsApp Privacy Policy).
Please do not send confidential evidence, credentials, or incident material over Telegram or WhatsApp. For sensitive matters use PGP-encrypted email or Signal; a contracted engagement will define its own secure transfer channel.
7. Lawful Bases for Processing
- Legitimate interests — operating and securing the Website, answering enquiries, and preventing abuse;
- Steps prior to entering a contract — scoping and responding to your enquiry;
- Legal obligation — where retention or disclosure is required by law;
- Consent — where explicitly required by local law.
8. Data Retention
- Website requests: connection data is processed transiently to serve the response; no access logs of visitor requests are kept.
- Enquiries: messages and contact details are deleted within 30 days of the last exchange unless an engagement follows (in which case the engagement's own documents govern) or law requires longer retention.
- Deletion requests: upon a verified request, we take reasonable steps to complete deletion within 30 calendar days, subject to legal exceptions.
9. Security
- All Website traffic is encrypted in transit (TLS with HSTS preload) and the Website enforces a strict Content Security Policy.
- We collect the minimum data needed to run the Website and answer enquiries, and keep no visitor request logs.
- Access to enquiry correspondence is restricted to authorized personnel on a need-to-know basis.
10. International Processing
The Website is served from company-controlled infrastructure. The third-party services named in this Notice (messaging and email providers, and the APIs contacted directly by your browser when you use certain tools) process data in the locations described in their own privacy notices. Where we transfer personal data across borders ourselves, we apply the safeguards required by the law applicable to you (for example EU Standard Contractual Clauses for transfers of EEA data, the UK IDTA/Addendum for UK data, and UAE PDPL transfer requirements).
11. Data Breach Notifications
We maintain procedures to identify, assess, and respond to personal data breaches. Where required by the law applicable to you, we will notify the competent supervisory authority (for example within 72 hours under EU/UK GDPR, or the UAE Data Office under PDPL) and affected individuals, including the nature of the incident, the data affected, likely consequences, and the measures taken.
12. Your Rights & How to Exercise Them
Depending on your jurisdiction, you may have the right to: access, correction, deletion, restriction of processing, objection, portability, and to withdraw consent where processing is based on consent. California and other US state rights (access, deletion, opt-out of sale/sharing) will be honored where applicable; we will not discriminate for exercising any rights.
To exercise your rights, email legal@pwn-all.com. We will verify identity (and the authority of any authorized agent) before responding. We aim to respond within 30 days or within the statutory period applicable to your jurisdiction and will communicate any necessary extension. If your jurisdiction provides a supervisory authority, you may lodge a complaint with that authority (e.g., an EU Supervisory Authority or the UK ICO).
13. Children
The Website is not directed to individuals under 18, and we do not knowingly collect personal data from anyone under 18. In the United States, the Website is not directed to children under 13 and we do not knowingly collect personal data from children under 13 (COPPA).
14. Changes to This Notice
We may update this Notice to reflect legal, regulatory, or operational changes. We will post updates here with a revised Effective Date.
15. Contact Us
PWN-ALL Auditing, Reviewing & Testing Cyber Risks CO. L.L.C
145, Al Mustaqbal street, Iris Bay Tower 2101-11, Business Bay, Dubai, United Arab EmiratesD-U-N-S Number: 571235572
VAT Number: 104633529300001
Email: legal@pwn-all.com