Privacy
Last updated 9 September 2026. This page describes how ReconSec processes personal data on this website and when you request a security check.
Controller
The controller is JoshJess UG (Haftungsbeschränkt), Am Stollenweg 20, 50226 Frechen, NRW, Germany. Represented by Babajide M. Moibi. Provider contact: info@joshjess.de. For ReconSec product requests and data-subject rights: team@reconsec.io.
Lead-form data
When you request a security check we process website/domain, first and last name, company, business email, optional role and free text, language, timestamps, versions of Scan Scope, Security Testing Terms and privacy notice, the authorization confirmation, and optional marketing consent. For abuse prevention we may store a day-rotating hash of the request IP, not the raw IP indefinitely.
Purpose
Attributing and reviewing the request, assessing authorization, performing the agreed limited check, and sending confirmation, next steps, and requested results.
Findings and personal data
If personal data is identifiable within the agreed scope, ReconSec documents the exposure — not the people behind the data. Such details are masked or redacted in findings and reports where technically possible. ReconSec is not designed to maintain a permanent archive of sensitive assessment results. That is separate from necessary operational records of the request (authorization, scope version, delivery).
Legal bases
For the requested service: GDPR Art. 6(1)(b) (steps prior to a contract). For abuse prevention — including Cloudflare Turnstile on the request form — and auditability: Art. 6(1)(f). For optional marketing email: Art. 6(1)(a), withdrawable at any time. Transactional email about the requested check does not depend on marketing consent.
Bot protection (Cloudflare Turnstile)
The request form uses Cloudflare Turnstile in invisible mode to distinguish people from automated abuse. Cloudflare processes technical signals such as IP address, TLS fingerprint, user-agent, and the site key for that check. Cloudflare, Inc. is a processor for this purpose and a controller when it uses those signals to improve Turnstile. Cloudflare's Turnstile Privacy Addendum applies to that processing and is part of this notice by reference.
Email delivery
Production email may be sent with Resend when that provider is configured. In local development, email is logged only and not sent.
Hosting
The website is served via Vercel. The host may keep ordinary technical logs (time, path, user agent) to deliver and secure the site. The processor agreement and storage region must be confirmed before production.
Retention
Assessment results are processed only for as long as required to prepare and deliver the requested result. Request data (authorization, scope, contact) is kept for handling, auditability, and as long as commercial or tax rules require. Concrete erasure periods still need to be set with German legal counsel.
Recipients / processors
Access is limited to people who operate ReconSec and technical processors for hosting, bot protection (Cloudflare Turnstile), and — if configured — email delivery. No sharing for advertising. No sale of findings or contacts.
Cookies and tracking
We do not use marketing tracking, analytics pixels, or non-essential cookies. There is no decorative cookie banner. A strictly necessary cookie (reconsec_locale) remembers the language after the first visit so a manual language switch is not overwritten. Cloudflare Turnstile may use strictly necessary technical storage for bot protection. The browser may keep ordinary HTTPS state (HSTS, cache).
Data-subject rights
You may request access, rectification, erasure, restriction, objection, portability, and may complain to a German or other EU supervisory authority. Write to team@reconsec.io. No automated decision-making under GDPR Art. 22.
This text is a development draft and must be reviewed by qualified German legal counsel before production use. It is not legal advice.