Česky

Breach database — privacy notice

How NoPa IT processes data from publicly available breaches, and how you can have your data removed.

Purpose of processing

NoPa IT operates an internal defensive tool that lets it verify whether login credentials of its clients (organisations it provides IT services to) have appeared in known data breaches, so that compromised accounts can be reset. The legal basis is the legitimate interest of protecting our clients' account security (Art. 6(1)(f) GDPR).

Categories of data

The database holds, for each record: a one-way keyed hash of an e-mail address, a hash of a password, the plaintext e-mail and password where the source provides them, the domain, and metadata about the breach (name, year, source). Passwords and e-mails are stored in two physically separate databases that cannot be joined without a per-breach key held by a third protected service.

Sources

Data is imported only from publicly available research sources (such as Have I Been Pwned and public research repositories). NoPa IT never purchases data, never registers on criminal forums, and never acquires data from offenders.

Retention

Records are automatically deleted 24 months after the breach date. Data older than five years is never imported.

Access and safeguards

Access is limited to a small number of named individuals, requires two-factor authentication, and every query is logged in an append-only audit trail. The database is never exposed via a public API and no bulk export is possible. Plaintext passwords are never displayed except under a two-person forensic procedure required by law.

Your rights

You have the right to object (Art. 21), the right of access (Art. 15) and the right to erasure (Art. 17). You can remove your e-mail from this database and prevent future inclusion using the opt-out form below.

Remove my e-mail (opt-out)

Contact

Data protection contact: zdenek@zpavlas.cz. Supervisory authority: Úřad pro ochranu osobních údajů (uoou.gov.cz).