← Trust Center
Statement

Data Handling & Privacy Statement

Exactly what SafeToOpen products see, what leaves your browser, what we store — and for how long.

Audience: Security and privacy reviewers, DPOs, procurement · Classification: Public · Version: 1.0 — July 2026

What our products see, what leaves your browser, what we store — and for how long

This statement complements (does not replace) the SafeToOpen Privacy Policy and DPA.

The short version

SafeToOpen analyzes web pages, links, downloads, and reported emails to detect zero-day phishing. We are designed around data minimization: analysis happens in the browser first, and only when a page requires VisionAI analysis do its visual elements and URL leave the device. Browsing-history checks use one-way hashes, so your actual browsing history is never exposed to us. Our models are not trained on customer data. All customer data is hosted in New Zealand. We never sell data or use it for advertising. We are ISO/IEC 27001:2022 certified and GDPR compliant.

Products covered

SafeToOpen browser extension (Chrome, Edge, Firefox), Email Verification, Customer Email Verification, Brand & Customer Protection, and the SafeToOpen API.

What the extension can access, and what actually leaves the browser

The browser stores require us to declare our permissions and data practices; our declared categories are website content, personally identifiable information, and location data, with binding commitments that data is not sold to third parties and not used for purposes unrelated to the product's core function. The table below explains why each category is needed and what actually happens with it.

Data categoryWhy the product needs itWhat leaves the browserStored by SafeToOpen?Retention
Page code & structure (DOM, scripts)X-Ray inspects page structure for hidden threatsNothing — X-Ray analysis runs locally in the browserNo
Page visual appearanceVisionAI compares what the user sees — logos, branding, login forms — against impersonation patternsVisual elements of the page, only when the page cannot be cleared locally and requires VisionAI analysisYes, pending analysisDeleted within 30 days; confirmed-malicious pages retained as threat intelligence
URL of the analyzed pageAnalysis context and threat lookupThe URL, only alongside a VisionAI submissionYes, with the submissionSame as above
Browsing history (Security Checkup)Detect past exposure to compromised sitesOne-way hashes of URLs only — actual browsing history is never exposed to SafeToOpenNo — hashes are checked and discardedTransient
Form input / paste events (Paste Guard)Prevent credentials being entered into untrusted pagesNothing — evaluated locally; the sensitive value itself is never transmittedNo
DownloadsBlock malicious installers, malware, ransomwareFiles are not uploaded; checks use the source URL and threat intelligenceNo
Email address (breach checkup)Check against known breach databasesThe email address, for the check onlyNot retained beyond performing the checkTransient
Reported emails (Email Verification products)Analyze employee/customer-reported suspicious emails, links, and attachmentsThe reported message, submitted by the customer for analysisYes — for analysis and audit trail90 days, then deleted; confirmed-malicious indicators retained as threat intelligence
Installed extensions list (Security Checkup)Flag known-malicious extensionsChecked against threat dataNoTransient
Account & licensing data (name, email, plan)Provide and bill the serviceStandard account dataYesLife of account + 30 days (billing records kept 7 years per NZ tax law)
Product telemetry / interaction dataReliability and product improvementOptional technical data, as declared in the browser store listingYes12 months

What we never do: sell or rent data; use browsing data for advertising or profiling; read or store form values, passwords, or keystrokes; upload users' files.

Where processing happens

First-pass analysis (X-Ray, Paste Guard, local checks) runs in the user's browser. When a page requires VisionAI analysis, its visual elements and URL are transmitted over TLS to the SafeToOpen cloud, hosted in New Zealand data centres operated by SiteHost. Customer data submitted for analysis is processed and stored in New Zealand. A data-flow diagram is included in the SafeToOpen Security Overview.

AI/ML and your data

SafeToOpen's detection models (VisionAI and X-Ray) are trained on data we gather ourselves — publicly reachable phishing and legitimate pages collected by our own systems and confirmed threat intelligence. Customer data is not used to train or improve our models. Confirmed phishing pages we discover may be shared with the security community (e.g., blocklist operators) to protect the wider public; this concerns attacker infrastructure, not customer data. See the SafeToOpen AI & Machine Learning Transparency Statement for detail.

Enterprise deployment controls

Business customers can contact us to configure deployment to their policy needs, including exclusion of internal domains from analysis so internal applications are never submitted for cloud analysis, and alert visibility for administrators. Contact [email protected] to discuss deployment configuration for your environment.

Legal bases, rights and applicable law

SafeToOpen Ltd (Auckland, New Zealand) acts as processor for customer-submitted content under our DPA and as controller for account data under our Privacy Policy. We support data subject rights (access, correction, deletion, portability) under the NZ Privacy Act 2020, GDPR, and the Australian Privacy Principles. Data is hosted in New Zealand, which holds a European Commission adequacy decision, meaning transfers from the EU/EEA to New Zealand are lawful without additional safeguards. Requests: [email protected].

Sub-processors

The current list, locations, and purposes are published in the SafeToOpen Sub-Processor List on our Trust Center. Customers are notified at least 30 days before a new sub-processor processes customer data.

Security of the data we hold

Controls protecting stored data — encryption in transit (TLS 1.2+) and at rest (AES-256), least-privilege access with MFA, monitoring, incident response, and breach notification within 72 hours of confirmation — are described in the SafeToOpen Security Overview and certified under our ISO/IEC 27001:2022 ISMS.

Questions

Privacy: [email protected] · Security: [email protected] · General: [email protected]

Document control: v1.0 · Approved by the Managing Director · Next review: July 2027. Related: Security Overview · AI Transparency Statement · Privacy Policy · DPA · Terms of Service.

Questions from your security team?

We answer reviewer questions directly and provide the full security review pack under NDA — typical turnaround one business day.

Contact [email protected]