1. Introduction Welcome to Rastros. Our mission is to protect your digital identity by discovering your digital footprint and forcing data brokers to delete your personal information. Because our service requires handling your most sensitive data to hunt for exposures, privacy and data minimization are the core of our architecture.
2. Information We Collect To successfully locate your data across the surface web, dark web, and Spanish state bulletins (Boletines Oficiales), we collect "seed data" directly from you. This includes:
Contact & Identity Data: Full name, current and historical physical addresses, email addresses, phone numbers, and date of birth.
Verification Documents: To legally compel Spanish data brokers to erase your records, we collect and securely store a watermarked scan of your national identity document (DNI or NIE).
Digital Identifiers: Known social media usernames and historical account handles.
Authorization: A digital Letter of Authority (LOA) granting us limited power of attorney to act on your behalf.
3. Lawful Basis for Processing Under the General Data Protection Regulation (GDPR), we process your data strictly under the following lawful bases:
Performance of a Contract (Article 6(1)(b)): Processing your seed data is necessary to deliver the continuous scanning and removal services you requested.
Consent (Article 6(1)(a)): For the handling of sensitive identification documents (DNI/NIE) and specific automated authorizations. You may withdraw this consent at any time.
4. How We Use and Share Your Data We use your data exclusively to find and remove your digital footprint. We never sell, rent, or trade your personal data to advertisers or third-party marketers. We only share your data in the following operational capacities:
Data Brokers & Directories: We transmit your details (and your LOA/DNI) directly to Spanish and international data brokers solely to verify your identity and force the deletion of your records under GDPR Article 17.
Threat Intelligence APIs: When querying dark web monitoring systems, we transmit cryptographically hashed identifiers (such as SHA-256 hashes of your email) wherever possible to prevent exposing your plaintext data in transit.
Regulatory Escalations: If a data broker ignores a valid deletion request, we may share the dispute record with the Spanish Data Protection Authority (AEPD) to file a formal complaint on your behalf.
5. Data Retention and Deletion We retain your active profile data only for as long as your account remains active, which is necessary to facilitate our continuous 90-day rescanning and automated removal loops.
If you choose to delete your account, your profile data, stored identity documents, and historical scanning logs will be cryptographically wiped from our live systems within 24 hours.
Encrypted automated server backups will expire and roll off within 35 days.
6. Security Architecture Your seed data is guarded by rigorous security protocols. We utilize client-side encryption and operate on a framework designed to minimize internal access to your raw personal data. When conducting open-source intelligence (OSINT) sweeps, we route traffic through ephemeral proxy networks to protect your anonymity during the reconnaissance phase.
7. Your GDPR Privacy Rights As a resident of the European Union, you maintain absolute control over your data. You have the right to:
Right of Access (Article 15): Request a complete copy of the personal data we hold about you.
Right to Erasure (Article 17): Request the immediate deletion of your account and all associated seed data.
Right to Rectification (Article 16): Update or correct inaccurate information in your profile.
Right to Object (Article 21): Object to specific types of processing.
To exercise these rights, please contact our Data Protection Officer at mashuesitos@gmail.com. If you believe we have violated your data protection rights, you have the right to lodge a complaint directly with the Agencia Española de Protección de Datos (AEPD) at www.aepd.es.