1. Data Controller
CLEAREX.MARKET ("we", "our", "the Platform") operates as the data controller for all personal data processed through this website. We are committed to handling your data with full transparency and in strict compliance with the General Data Protection Regulation (EU) 2016/679 (GDPR) and applicable national data protection laws.
For any privacy-related enquiries, please contact our Data Protection Officer at: privacy@clearex.market
2. Data We Collect
We collect only the minimum data necessary to provide our services:
- Account Data: Email address only. All accounts — including admin accounts — use passwordless magic-link authentication. No passwords are created, stored, or processed anywhere on the Platform.
- Password Security Check: The credential you submit for checking is never stored. A service record (order reference, purchase status, and breach result count) is created solely to track your purchase and deliver results. The credential itself is processed in memory only and is never written to any database or log.
- Password Check Queries: When you submit a password for a compromise check, we apply a k-anonymity model — only a 5-character SHA-1 hash prefix is transmitted. The full password or its complete hash never reaches our servers.
- Usage Data: IP address (authentication IPs anonymised within 1 hour of collection; security and fraud-prevention audit-log IPs within 90 days; other usage IPs stored only as a one-way hash), browser type, and page interaction logs collected for security, fraud prevention, and service integrity purposes.
3. Legal Basis for Processing
We process your personal data on the following legal bases under GDPR Article 6:
- Contract Performance (Art. 6(1)(b)): Processing necessary to provide the account security check and platform services you request.
- Legitimate Interests (Art. 6(1)(f)): Security monitoring, fraud prevention, and platform integrity — balanced against your fundamental rights.
- Legal Obligation (Art. 6(1)(c)): Compliance with applicable financial, cybersecurity, and data protection regulations.
- Consent (Art. 6(1)(a)): Where you have explicitly opted in to communications or optional features. You may withdraw consent at any time without affecting prior processing.
4. How We Use Your Data
Your data is used exclusively for the following purposes:
- Providing, operating, and improving the Platform and its security services.
- Verifying that password checks are performed by the legitimate account owner.
- Sending transactional communications (authentication tokens, security alerts).
- Detecting and preventing fraud, abuse, and unauthorised access.
- Complying with our legal and regulatory obligations.
We do not sell, rent, or trade your personal data to third parties for commercial purposes. We use Google Analytics (Google LLC) to measure aggregate traffic; we never send Google your email address or any personal identifier, GA4 does not store your IP address, and ad-personalisation signals are disabled — you can opt out via Google's Analytics Opt-out Browser Add-on. We do not engage in automated decision-making or profiling that produces legal or similarly significant effects.
5. Data Retention
We retain personal data only for as long as necessary to fulfil the purpose for which it was collected:
- Account data: Deleted immediately and permanently upon your request. Cascade deletion removes all associated personal records including forum content, messages, payment records, and uploaded profile images. No account data is retained after deletion.
- Security check query data: Deleted immediately after the check is completed. No persistent record is created.
- Usage logs: authentication IP addresses anonymised within 1 hour of collection, security and fraud-prevention audit-log IP addresses within 90 days, and other usage IPs stored only as a one-way hash; aggregated statistics retained for up to 12 months.
You may request deletion of your account and associated data at any time by contacting privacy@clearex.market.
6. Your Rights Under GDPR
As a data subject, you have the following rights, exercisable free of charge:
- Right of Access (Art. 15): Obtain confirmation of whether we process your data and receive a copy.
- Right to Rectification (Art. 16): Correct inaccurate or incomplete personal data.
- Right to Erasure (Art. 17): Request deletion of your data where processing is no longer justified ("right to be forgotten").
- Right to Restriction (Art. 18): Limit how we use your data in certain circumstances.
- Right to Data Portability (Art. 20): Receive your data in a structured, machine-readable format.
- Right to Object (Art. 21): Object to processing based on legitimate interests.
- Right to Withdraw Consent: Where consent is the legal basis, withdraw it at any time.
To exercise any right, you can:
- Use self-service endpoints: DELETE /api/user (account erasure) and GET /api/user/export (data portability — downloads a JSON file of all data we hold).
- Contact our DPO: privacy@clearex.market for requests we cannot automate (e.g. rectification, restriction, objection).
We will respond to all requests within 30 days. If you are unsatisfied with our response, you have the right to lodge a complaint with your national supervisory authority.
7. Third-Party Processors
We engage the following sub-processors, each bound by Data Processing Agreements (DPAs) ensuring GDPR-equivalent protection:
- Amazon Web Services EMEA SARL (AWS) — Cloud infrastructure, compute, and managed database hosting. Region: eu-north-1 (Stockholm, Sweden, EEA). DPA: aws.amazon.com/agreement. AWS is covered by the EU-US Data Privacy Framework adequacy decision.
- Resend Inc. — Transactional email delivery (magic-link authentication emails only). Data processed: recipient email address and email content. DPA available at resend.com/legal/dpa.
- NOWPayments — Cryptocurrency payment processing for membership subscriptions and donations. Data processed: payment amount, cryptocurrency wallet address, transaction status. NOWPayments does not receive personal identification data beyond what is necessary to process the transaction.
- Stripe (Stripe, Inc. / Stripe Payments Europe, Ltd.) — Card payment processing for membership subscriptions, where enabled. Data processed: payment card details (entered directly with Stripe; CLEAREX.MARKET never receives or stores full card numbers), billing status. Stripe is a PCI-DSS Level 1 certified service provider. DPA available at stripe.com/legal/dpa.
A full and current list of sub-processors is available upon request at privacy@clearex.market. We notify users of material changes to our sub-processor list with at least 30 days' notice.
We do not transfer personal data to countries outside the EEA without appropriate safeguards (adequacy decision or Standard Contractual Clauses) in place.
8. Cookies & Tracking
We use strictly-necessary cookies for authentication and session management, and — only with your consent — privacy-friendly analytics. We do not use advertising cookies or cross-site tracking pixels.
Strictly-necessary cookies (no consent required under GDPR Recital 25 and ePrivacy Directive Article 5(3)):
- session / __Host-session: Encrypted authentication token. HttpOnly, Secure, SameSite=Lax (required to receive the cookie when following a magic-link from email — a cross-site top-level navigation). Expires after 24 hours by default.
- __Host-admin / admin-session: Admin authentication token. HttpOnly, Secure, SameSite=Lax. Expires after 2 hours.
SameSite=Lax still blocks all cross-site non-GET requests (POST, PATCH, DELETE), providing CSRF protection. An additional explicit CSRF-token check is applied as defence-in-depth.
Analytics (consent-based, opt-in): On your first visit a Cookie Consent Banner asks whether to enable analytics. Only if you choose "Accept" do we load Google Analytics 4 — privacy-hardened: no email or personal identifier is sent, IP addresses are not stored (used only momentarily for approximate country, then discarded), and Google Signals + ad personalisation are off. Choosing "Reject" means no analytics is loaded at all. We also run cookieless first-party analytics that stores no personal data and needs no consent. You can change your choice at any time by clearing the cx_consent cookie. You may disable cookies in your browser, but core platform functionality will not be available.
9. Changes to This Policy
We may update this Privacy Policy to reflect changes in our practices or legal requirements. Material changes will be communicated via email (if you have an account) and by updating the "Last Updated" date below. Continued use of the Platform after notification constitutes acceptance of the revised policy.
10. Contact
Data Protection Officer: privacy@clearex.market General Enquiries: contact@clearex.market Registered correspondence: Clearex Market, LLC, c/o Data Protection Officer, privacy@clearex.market
For postal correspondence requests, please email privacy@clearex.market to receive our current registered address. We will respond within 5 business days.
You also have the right to lodge a complaint with your local data protection authority at any time.