Terms of Service
These Terms govern access to and use of the SurfaceWatch platform at surfacewatch.io.
Purpose
These Terms of Service ("Terms") govern access to and use of the SurfaceWatch platform (the "Service"), accessible at surfacewatch.io.
SurfaceWatch is an external attack surface monitoring service. It enables organizations to monitor their internet-exposed assets, including DNS changes, leaked credentials, and exposed domains.
Acceptance
By accessing the Service or creating an account, you agree to be bound by these Terms. If you do not agree, you must stop using the Service immediately.
Service Description
SurfaceWatch provides the following features:
Breach data displayed originates from publicly accessible third-party sources. SurfaceWatch does not create these breaches and only aggregates and presents this information for defensive security purposes.
Account Access
Access to the Service requires creating an account with a valid email address. The Service uses passwordless authentication. You are responsible for the security of your email address and any access made through your account.
Acceptable Use
The Service is intended exclusively for lawful and defensive use. It is strictly prohibited to:
Any violation of these terms will result in immediate account suspension without refund.
Subscription and Termination
You may cancel your subscription at any time from your account settings. Cancellation takes effect at the end of the current billing period.
Customers are entitled to a full refund within 30 days of purchase, no questions asked. No exceptions or qualifiers apply.
SurfaceWatch reserves the right to suspend or terminate any account for violation of these Terms, without notice.
Limitation of Liability
The Service is provided "as is" and "as available." SurfaceWatch does not warrant the completeness, accuracy, or continued availability of the data presented.
In no event shall SurfaceWatch be liable for any indirect, consequential, incidental, or punitive damages arising from the use of or inability to use the Service, including decisions made based on the information provided.
SurfaceWatch's total liability is limited to the amount paid by the user in the three (3) months preceding the event giving rise to the claim.
Intellectual Property
All elements of the Service (interface, algorithms, brand, logos) are the exclusive property of SurfaceWatch. Any reproduction or use without authorization is prohibited.
Amendments
SurfaceWatch reserves the right to modify these Terms at any time. Users will be notified by email with 15 days' advance notice. Continued use of the Service after notification constitutes acceptance of the updated Terms.
Governing Law
These Terms are governed by the law of the jurisdiction where the Service operator is established. Any disputes shall be submitted to the competent courts of that jurisdiction.
Privacy Policy
How SurfaceWatch collects, uses and protects your personal data under GDPR.
Data Controller
The data controller for personal data collected through SurfaceWatch is the operator of the Service. For any questions regarding your data, contact:
[email protected]Data Collected
2.1 Data you provide directly
2.2 Automatically collected data
Data we do NOT collect
Purposes and Legal Bases
Retention Periods
Cookies and Analytics
SurfaceWatch uses Google Analytics to measure website traffic. Google Analytics places cookies on your browser and collects anonymized browsing data (pages visited, duration, referral source).
You can refuse these cookies via the consent banner displayed on your first visit, or by installing the Google Analytics opt-out browser add-on at tools.google.com/dlpage/gaoptout.
For more information on Google's privacy practices: policies.google.com/privacy
Sub-processors
International Transfers
The Service is hosted within the European Union (OVH, France). Google Analytics may involve data transfers to the United States, governed by the European Commission's Standard Contractual Clauses.
Your Rights
Under GDPR, you have the following rights:
To exercise these rights: [email protected] — we will respond within 30 days.
Security
SurfaceWatch implements appropriate technical and organizational measures to protect your data: encryption of sensitive data, passwordless authentication, restricted access to production data.
In the event of a data breach likely to result in a risk to your rights and freedoms, we commit to notifying the competent supervisory authority within 72 hours.
Amendments
Any material changes to this policy will be notified to you by email with 15 days' advance notice.