SciScope OÜ — legal

SciScope — Privacy Notice

Last updated: 22 July 2026

1. Who is responsible for your data

SciScope OÜ ("SciScope", "we"), registry code 16731450, VAT (KMKR) EE103007175, registered office Pärnu mnt 105, 11312 Tallinn, Estonia, is the controller of the personal data described in this notice.

Contact for any privacy matter, including the delisting requests described in section 9: hello@sciscope.ee

We have not appointed a Data Protection Officer — we are not required to. Write to the address above and it reaches the people who decide.

2. What this notice covers

This notice covers three distinct groups of people. They are very different, so please read the section that applies to you:

SectionWho
3Visitors to our websites (sciscope.ee, feed.sciscope.ee)
4People who contact us, request a trial, or are a customer contact
5People whose IP address appears in the SciScope Scanner Feed

3. Website visitors

3.1. Our websites are static pages. They set no cookies, run no analytics or tracking, embed no third-party resources, and contain no forms. We do not build visitor profiles and we cannot recognise you across visits.

3.2. The sites are delivered through a content delivery network (Cloudflare), which processes visitors' IP addresses and basic technical request data (timestamp, requested URL, user agent, approximate location) in order to serve the pages and to protect them against attack. Cloudflare acts as our processor under a data processing agreement. Legal basis: our legitimate interest in delivering and securing our website (Art 6(1)(f) GDPR).

3.3. We do not receive individual-level visitor data from this and do not use it to identify you.

4. Enquiries, trials and customer contacts

4.1. If you email us — for example to request a trial — we process the data you choose to send: your name, email address, employer/organization, and the content of your message, plus what we record about the resulting relationship (which API key was issued, its tier and expiry, the use case you described).

4.2. Purposes and legal bases:

PurposeLegal basis
Answering your enquiry, issuing and managing trial or subscription accessPerformance of a contract or steps prior to it (Art 6(1)(b)), or our legitimate interest in responding to business enquiries (Art 6(1)(f))
Invoicing, accounting and tax recordsLegal obligation (Art 6(1)(c)) — Estonian accounting and tax law
Security of the Service (logging key use, abuse prevention)Legitimate interest (Art 6(1)(f))

4.3. Providing this data is voluntary, but without an email address we cannot issue access or reply.

4.4. We do not send marketing to people who merely contacted us, and we do not sell or rent contact data.

5. IP addresses in the SciScope Scanner Feed

This is the section that matters if you have been told your IP address appears in our feed. Please also read section 9 — there is a direct route to ask us to remove it.

5.1 What we do

We operate our own network sensors — servers we control, which are not advertised for public use. When an IP address sends unsolicited traffic to them (port scans, blocked connection attempts, authentication attacks, web exploit probes and similar), our sensors record that fact. We score and curate these observations into a threat-intelligence feed that our subscribers use to defend their own networks.

We do not go looking for people. We record what arrives, uninvited, at our own machines.

5.2 What we record

5.3 What we do NOT record

We do not capture the content or payload of communications. We do not intercept anyone's browsing. We do not track individuals across services, we do not attempt to identify the natural person behind an IP address, and we do not seek out special categories of data (Art 9 GDPR). We do not combine this data with data from data brokers or social media.

5.4 Legal basis

Our legal basis is legitimate interests (Art 6(1)(f) GDPR). Recital 49 of the GDPR expressly recognises that processing personal data to the extent strictly necessary and proportionate for ensuring network and information security — including preventing unauthorised access, stopping attacks and resisting malicious code — constitutes a legitimate interest.

Our legitimate interest is defending our own infrastructure and enabling our subscribers to defend theirs. We have carried out and documented a legitimate-interests assessment weighing this against the rights of the people affected; you can request a summary of it at hello@sciscope.ee.

5.5 Why we did not contact you individually

Where personal data is not obtained from the data subject, Art 14 GDPR normally requires us to inform them. We rely on the exception in Art 14(5)(b): individual notification would involve disproportionate effort and would in practice be impossible. We hold no contact details for the holder of an IP address, and obtaining them would require systematically researching the people behind millions of addresses — which would be more intrusive than the processing itself, not less. This public notice is the safeguard we provide instead, together with the removal route in section 9.

5.6 If your device was compromised

An IP address can appear in our feed because a device behind it was taken over and used to attack others without the owner's knowledge. If that is your situation, you are as much a victim as our sensors are. Our scoring decays continuously (see section 8), so once the activity stops the address fades out by itself — and you can also ask us directly (section 9) to remove it.

6. Who we share data with

6.1. Subscribers. The curated feed — including IP addresses, scores, tags and the supporting evidence described in 5.2 — is made available to subscribers who have a licence to it. Each subscriber is an independent controller for what they then do with it. Our Terms of Service contractually bind them to use it only for their own network and information security, and expressly prohibit them from using it for marketing, credit, insurance or eligibility decisions, or from attempting to identify the individual behind an address except when investigating a specific security incident.

6.2. Service providers (processors). Hosting and infrastructure providers, the CDN (Cloudflare) and, for section 4 data, email and accounting providers. They act on our instructions under data processing agreements.

6.3. Authorities, where we are legally obliged to disclose, or where it is necessary to establish, exercise or defend legal claims.

6.4. We do not sell personal data.

7. International transfers

7.1. Our infrastructure is located in the European Economic Area.

7.2. Cloudflare processes website request data and may do so outside the EEA; those transfers are covered by the European Commission's Standard Contractual Clauses and Cloudflare's certification under the EU–US Data Privacy Framework.

7.3. Subscribers outside the EEA. Where we make feed data available to a subscriber established outside the EEA, the transfer is made under an appropriate Chapter V GDPR safeguard — normally the European Commission's Standard Contractual Clauses (controller-to-controller, Module One), which that subscriber undertakes in our Terms of Service (§ 8.6).

8. How long we keep data

Threat data ages out deliberately: an address that stops being seen stops influencing the feed and is then deleted.

DataRetention
Individual event records (each observation)45 days
Reputation score record for an IPdropped 60 days after the last relevant signal
Per-IP aggregate statisticsup to 365 days from the last observation
Reverse-DNS lookup cache365 days
Published feed / score documentsremoved 90 days after they stop being refreshed
Historical monthly event indicesmoved to compressed archive after 18 months, then permanently deleted at 24 months from the date of the events
Operational logs on our own sensor servers (the source records)rotated and deleted within 90 days — most within about 5 weeks
Section 4 contact and customer datafor the relationship, then per Estonian accounting/tax law (7 years for accounting records)

In addition, an address's influence on its score halves every 7 days and scoring uses a rolling 30-day window, so the practical effect of old activity disappears within weeks — well before the storage limits above.

Our sensor servers also keep ordinary operational security logs, as any server operator does; those are the source records from which the above is derived, and none of them is retained longer than 90 days.

Aggregated statistics that contain no IP addresses — for example monthly totals by country, network operator or targeted port, and the trend series we publish — are not personal data, and we keep those indefinitely.

9. Your rights

9.1. Subject to the conditions in the GDPR, you have the right to access your personal data, to have inaccurate data rectified, to request erasure, to restrict or object to processing, and — where applicable — to data portability.

9.2. Objection (Art 21). Because we process on the basis of legitimate interests, you may object at any time on grounds relating to your particular situation. We will then stop unless we can demonstrate compelling legitimate grounds that override your interests, or the data is needed for legal claims.

9.3. Delisting an IP address — the practical route. If an IP address that you are responsible for appears in our feed and you believe it should not, email hello@sciscope.ee with the address and a short explanation (for example: the machine has been cleaned up, the address has been reassigned, or it is legitimate infrastructure such as a crawler, scanner or resolver). We review these promptly. Removals propagate to subscribers as they refresh the feed — our Terms require subscribers to refresh at least every 7 days.

We may ask for enough information to establish that the request is genuine and that you are connected to the address; we will not ask for more identification than necessary, and we will not use anything you send us for any other purpose.

9.4. Complaints. If you are unhappy with how we handled your data, you can lodge a complaint with the Estonian Data Protection Inspectorate (Andmekaitse Inspektsioon, www.aki.ee, info@aki.ee), or with the supervisory authority in your country of residence.

10. Automated decision-making

We do not take decisions producing legal or similarly significant effects about individuals by automated means. Our score is an assessment of network activity, not a decision about a person. Subscribers may configure their own systems to act on the feed; that is their processing, and our Terms prohibit them from using it for decisions about individuals such as eligibility, credit or insurance.

11. Changes to this notice

We may update this notice; the "Last updated" date above always shows the current version. Material changes affecting the people in section 5 will be reflected here, as that is the channel Art 14(5)(b) relies on.


SciScope OÜ · registry code 16731450 · VAT EE103007175 · Pärnu mnt 105, 11312 Tallinn, Estonia · hello@sciscope.ee · IP geolocation data by DB-IP (CC BY 4.0)

Website Terms of Use · Scanner Feed Terms of Service · Back to SciScope