Legal

Privacy Policy

Last updated: July 14, 2025

1. Who we are

VictimCheck ("we", "us") operates victimcheck.com (the "Service"). The controller responsible for your personal data under the GDPR is: VictimCheck GmbH, Mainzer Landstraße 150, 60327 Frankfurt am Main, Germany. Email: privacy@victimcheck.com. VAT number DE876543210.

2. What this policy covers

This policy explains what personal data we collect when you use VictimCheck to check whether your information appears in records of reported scams, why we collect it, how long we keep it, and what rights you have.

3. What data we collect

Data you give us when running a check:

  • Search identifiers you enter — an email address, phone number, wallet address, username, or transaction reference.
  • Details you voluntarily add when submitting a report (description, dates, amounts, uploads).
  • Contact details, if you ask to be notified of future matches.

Data collected automatically:

  • IP address, browser type and version, device type, operating system, language settings.
  • Pages viewed, time spent, referring URL.
  • Cookie and similar identifiers — see our Cookie Policy.

Data we do not want:

Please do not send us passwords, full payment card numbers, banking credentials, seed phrases, or identity documents unless we have specifically asked. If you send us data we did not request, we will delete it.

4. Special category data

Fraud reports can reveal sensitive information — health circumstances, financial vulnerability, or details implying criminal offences by a third party. Where you include such details, we process them on the basis of your explicit consent (Art. 9(2)(a) GDPR), only to handle your report. You can withdraw that consent at any time.

5. Why we process your data, and our legal basis

PurposeLegal basis (GDPR Art. 6)
Running a check and returning a resultContract (Art. 6(1)(b))
Handling reports you submitConsent (Art. 6(1)(a)) and legitimate interests (Art. 6(1)(f))
Notifying you if your identifier appears in future recordsConsent (Art. 6(1)(a))
Keeping the Service secure and preventing abuseLegitimate interests (Art. 6(1)(f))
Analytics to improve the ServiceConsent (Art. 6(1)(a)) where cookies are involved
Meeting legal, accounting and regulatory obligationsLegal obligation (Art. 6(1)(c))
Responding to lawful requests from law enforcementLegal obligation (Art. 6(1)(c))

Where we rely on legitimate interests, we have weighed those interests against your rights and will explain that assessment on request.

6. Where our records come from

Our records consist of reports submitted by users of the Service and the case files our team creates and maintains from them.

We do not compile a register of accused individuals for publication, and a search result reflects only what appears in the sources described above.

7. Who we share data with

  • Service providers (processors) acting on our instructions — hosting, email delivery, error monitoring, analytics — each bound by an Art. 28 GDPR data processing agreement.
  • Law enforcement or regulators, where legally required or necessary to establish, exercise or defend legal claims.
  • A successor entity, if the business is sold or reorganised.

We do not sell your personal data, and do not share it with advertisers or data brokers for their own marketing.

8. International transfers

Where a provider processes data outside the EEA, we rely on European Commission adequacy decisions, or Standard Contractual Clauses with supplementary safeguards. You can request a copy using the contact details above.

9. How long we keep data

  • Submitted reports: until you ask us to delete them
  • Notification subscriptions: until you unsubscribe
  • Records needed for accounting or legal defence: the applicable statutory period

10. Your rights

Under the GDPR you have the right to: access your data and receive a copy; rectification of inaccurate data; erasure under Art. 17; restriction of processing under Art. 18; data portability; to object to processing based on legitimate interests; to withdraw consent at any time without affecting prior lawfulness; and not to be subject to a decision based solely on automated processing producing legal or similarly significant effects.

To exercise these, contact privacy@victimcheck.com. We respond within one month, and will tell you if we need an extension.

You may also lodge a complaint with a supervisory authority: the Hessian Commissioner for Data Protection and Freedom of Information, Gustav-Stresemann-Ring 1, 65189 Wiesbaden, Germany.

11. Security

We use TLS in transit, encryption at rest, access controls, logging and regular review of our providers. No system is completely secure, but we will notify you and the competent supervisory authority of a personal data breach where the GDPR requires it.

12. Children

The Service is not directed at anyone under 18. We do not knowingly collect data from children. Contact us if you believe a child has provided us with personal data.

13. Changes

We may update this policy. Material changes appear here with a revised date, and where required we will seek fresh consent.

14. Contact

VictimCheck GmbH, Mainzer Landstraße 150, 60327 Frankfurt am Main, Germany — privacy@victimcheck.com