Legal
Privacy Policy
Last updated: July 23, 2026
This policy explains how Rightsignal handles personal data when someone visits the website, submits a case, communicates with the team, purchases or receives services, or uses the client portal. It also explains the choices and rights available to individuals under applicable law.
1. Scope and roles
Rightsignal determines how personal data is used for website operation, case intake, service delivery, client support, security, and business administration. When a client provides data about another person for an authorized enforcement matter, Rightsignal may also process that information on the client's documented instructions and only for the requested work.
This policy applies to the public website, case-request forms, service correspondence, case workspaces, reports, and authenticated client-portal features. Third-party websites and platforms reached through external links are governed by their own privacy notices.
2. Personal data we collect
- Identity and contact data: name, email address, and an optional Telegram, WhatsApp, or other messaging handle.
- Case and authorization data: target URLs, original-source URLs, account names, platform identifiers, urgency, requested action, ownership context, authorization statements, and case notes.
- Evidence data: screenshots, timestamps, correspondence, notices, hashes, source records, reports, verification results, and other materials submitted or generated for a case.
- Portal data: account identifier, assigned cases, case status, target lists, work notes, reports, subscription status, access records, and session information.
- Commercial and communication data: selected service, quote history, invoice and payment status, transaction references, and service correspondence. Rightsignal does not request or store full payment-card numbers.
- Technical and usage data: IP address, browser and device information, request time, pages viewed, security events, routing data, approximate country, and aggregated website analytics.
Please do not submit passwords, private keys, full payment-card details, or personal data that is not necessary for the case.
3. Sensitive and sexually explicit material
Some enforcement requests may concern intimate imagery, nudity, sexual content, identity documents, private account information, or data about a person's sex life or sexual orientation. Rightsignal treats this material as restricted evidence and processes it only where it is necessary, authorized, and permitted by applicable law.
- Clients should provide URLs, timestamps, hashes, and redacted screenshots instead of full media files whenever possible.
- Clients should not upload, forward, or resend illegal files or intimate material involving anyone under 18.
- Access is limited to personnel and service providers who need the material for intake, evidence review, reporting, escalation, or verification.
- Explicit material is not used for advertising, public promotion, or general-purpose artificial-intelligence training.
- Public proof assets are anonymized and redact client identity, private handles, and sensitive media.
- Where special-category data rules apply, processing is based on explicit consent, the establishment, exercise, or defence of legal claims, or another exception permitted by law.
A submission may be restricted, declined, or deleted if the sender cannot demonstrate lawful authority to provide the material.
4. Why we process data and the legal bases
Where data-protection law requires a legal basis, Rightsignal relies on one or more of the following:
- Contract and pre-contract steps: to review a request, prepare a quote, open and manage a case, provide portal access, deliver reports, and communicate about services.
- Legitimate interests: to operate and secure the website and portal, prevent fraud and abusive submissions, maintain case history, improve workflows, protect rights, and manage the service efficiently.
- Consent: for optional communications and for specific evidence or sensitive-data processing where consent is required. Consent may be withdrawn at any time.
- Legal obligations: to maintain required financial records, respond to valid legal process, and comply with applicable laws.
- Legal claims: to establish, exercise, or defend legal claims and preserve relevant dispute records.
When processing is based on legitimate interests, Rightsignal considers the necessity of the processing and the impact on the individuals concerned. Rightsignal does not make decisions producing legal or similarly significant effects solely through automated processing.
5. How we use personal data
- Assess whether a request is suitable, authorized, and supported by sufficient evidence.
- Map targets and select platform, host, registrar, CDN, search, app-store, social-network, or other appropriate routes.
- Prepare and send reports, notices, escalation packages, follow-ups, and verification requests.
- Operate the client portal and show case status, active work, target history, reports, and subscription information.
- Communicate about quotes, payments, requests for additional proof, status changes, and support.
- Detect fraud, prevent false or bad-faith claims, secure accounts, troubleshoot errors, and enforce service terms.
- Produce anonymized operational statistics and improve service quality.
6. Client portal and server sessions
The client portal uses a strictly necessary, signed server-session cookie named
rs_portal_session. It is marked HttpOnly, Secure, and
SameSite=Strict, expires after 12 hours, and is cleared when the user logs out.
The cookie contains a signed account identifier and expiry information; it does not contain
the account password.
Authenticated portal responses are marked not to be stored by shared browser caches. Portal pages may display case information from an approved case workspace, including Notion where configured. Users should keep credentials confidential and log out when using a shared device.
7. Local storage, cookies, and analytics
Case-request details are kept in the open form only while the user prepares and submits the request. Rightsignal does not save the full form payload, target URLs, contact details, evidence context, or case description in persistent browser local storage.
A message or free-scan request is stored securely on the server before email delivery is attempted. This prevents a temporary email-provider or network failure from losing the enquiry. Incomplete details may be retained with an internal manual-review flag. No enforcement work begins until Rightsignal verifies authority and agrees the scope. The browser does not retain a copy after the server confirms receipt.
After the server confirms receipt, the case ID and selected plan may be placed temporarily in
sessionStorage solely to display the confirmation page. That one-time summary is
removed when the confirmation page reads it and is also cleared when the browser tab closes.
Rightsignal uses strictly necessary session technology for authenticated features. Cloudflare may process network and request information to deliver, secure, and measure the website. Rightsignal does not sell personal data and does not use the website data described in this policy for third-party behavioural advertising.
8. Recipients and service providers
Personal data may be disclosed only as needed to the following categories of recipients:
- Cloudflare: website hosting, serverless functions, content delivery, network security, request processing, and analytics. See the Cloudflare Privacy Policy and Data Processing Addendum.
- Resend: transactional delivery of case-request and service emails, which may include sender and recipient addresses, message metadata, and message content. See the Resend Privacy Policy and Data Processing Addendum.
- Notion: case-workspace and portal-data management where that service is configured for the relevant case.
- Enforcement recipients: platforms, hosts, registrars, CDNs, search engines, app stores, social networks, payment services, and abuse or rights-management channels relevant to the requested case.
- Operational recipients: authorized contractors, technical providers, payment or invoicing providers, and professional advisers subject to appropriate confidentiality duties.
- Legal recipients: courts, regulators, supervisory authorities, law enforcement, or other parties when disclosure is required by law or reasonably necessary to protect rights and safety.
- Business-transfer recipients: a prospective buyer, successor, or adviser in a merger, financing, reorganization, or sale, subject to appropriate safeguards.
Some reporting systems require complainant or rights-holder details. Rightsignal will include client-provided identity or authorization information only where it is necessary for the selected route.
9. International data transfers
Rightsignal, its service providers, and enforcement recipients may process data in countries other than the country where the user is located. Those countries may have different data-protection laws.
Where required, transfers are supported by an adequacy decision, the European Commission's Standard Contractual Clauses, the UK International Data Transfer Agreement or UK Addendum, an applicable Data Privacy Framework, or another legally recognized safeguard. Rightsignal also uses vendor data-processing terms, purpose limitations, access controls, and data minimization as appropriate to the transfer.
10. Retention schedule
Rightsignal applies the following retention periods unless a longer period is required by law, an active dispute, or a documented legal hold:
- Unaccepted or declined intake requests: 90 days after the last communication.
- Public contact and free-scan submissions: up to 30 days in the secure delivery store; resulting email correspondence follows the applicable correspondence period.
- Active case records and evidence: for the duration of the engagement.
- Closed case records, notices, correspondence, and reports: 3 years after case closure.
- Unredacted sensitive or sexually explicit evidence: deleted within 30 days after case closure or final verification, unless it is still required for an active dispute or legal obligation. Redacted reports and non-sensitive verification records may follow the 3-year case-record period.
- Portal session cookie: 12 hours, or earlier when the user logs out.
- Browser case-confirmation summary: until the confirmation page reads it, or earlier when the browser tab closes.
- Portal account and access-administration records: while the service is active and for 90 days after account closure; underlying case records follow the case-retention periods above.
- Raw security and operational logs controlled by Rightsignal: up to 30 days. Aggregated, non-identifying analytics may be retained for up to 24 months.
- Invoices, payment status, and accounting records: 7 years where required for tax, accounting, or audit obligations.
- Privacy requests and consent records: 3 years after the request is completed or consent is withdrawn.
- Residual encrypted backups: up to 90 days after deletion from active systems, after which they expire through the backup cycle.
Service providers may retain limited security, delivery, and compliance records under their own documented schedules and legal obligations. Data is anonymized or deleted when its applicable retention period ends.
11. Security
Rightsignal uses proportionate technical and organizational safeguards, including encrypted transport, restricted access, signed secure sessions, no-store controls for authenticated API responses, data minimization, and redaction of public proof materials. No internet transmission or storage system can be guaranteed to be completely secure.
12. Privacy rights
Depending on location and applicable law, an individual may have the right to:
- request access to personal data and information about how it is processed;
- correct inaccurate or incomplete personal data;
- request deletion of personal data;
- request restriction of processing;
- receive eligible data in a structured, commonly used, machine-readable format and request portability;
- object to processing based on legitimate interests;
- withdraw consent at any time where consent is the legal basis;
- complain to the data-protection supervisory authority in the country or region of residence, work, or the alleged infringement; and
- receive equal service and pricing without unlawful discrimination for exercising a privacy right.
Withdrawal of consent does not affect processing that was lawful before withdrawal. Rights are not absolute and may be limited by legal obligations, legal claims, security needs, or the rights of others. If required data is deleted or consent is withdrawn, Rightsignal may be unable to continue the relevant case or portal service.
13. How to submit a privacy or deletion request
Submit a request through the website contact form or reply to existing Rightsignal service correspondence. Start the message with Privacy Request and identify the request as Access, Correction, Deletion, Restriction, Portability, Objection, or Consent Withdrawal. Include the email address used for the case, the case ID if known, and the data or time period covered by the request.
Rightsignal may request proportionate information to verify identity and authority before disclosing or deleting data. Valid requests are answered within one month where required by applicable law. That period may be extended where the request is complex or numerous, with notice as required by law. Deletion is applied to active systems and then to backups through the retention cycle described above.
14. Minors
The service is intended only for persons aged 18 or older. Rightsignal does not knowingly accept clients or collect personal data directly from children. A person under 18 should act through a parent, guardian, attorney, agency, or other lawful representative. Users must not submit sexual or intimate material involving any person under 18.
If Rightsignal identifies or reasonably suspects that submitted material involves sexual exploitation of a minor, ordinary case processing may be suspended, access will be restricted, and the material may be preserved, deleted, or reported to competent authorities as required by applicable law and safety procedures.
15. Changes to this policy
This policy may be updated when services, providers, legal requirements, or data practices change. The revised version will be posted on this page with a new “Last updated” date. Material changes may also be communicated through the website, portal, or service correspondence.