Terms & Conditions
Welcome to Exploitsynth.com platform (the “Platform”), owned by Lajos Muzsai (address: Hungary, 5400 Mezőtúr Batsányi János utca 5) (the “Provider”). The Platform is available exclusively via our website at scan.exploitsynth.com. Throughout these Terms and Conditions (“T&C”), the terms “ExploitSynth”, “our”, “us”, and/or “we” refer to the Provider. These T&C govern your access to the Platform (and, if the case, use of the Products) and shall apply to all agreements concluded by the Provider with you through the Platform, including the underlying orders and declarations of acceptance by the Provider, as well as any ancillary agreements. For clarity purposes, these T&C will apply to you in both capacities as User and/or Customer, as the case may be, as defined below. These T&C shall apply exclusively. Any terms and conditions of the Customer that conflict with, deviate from, or supplement these T&C shall not apply unless the Provider has expressly agreed to their application in writing. Notwithstanding any statutory provisions concerning conflicting standard terms under Act V of 2013 on the Civil Code of Hungary, these T&C shall prevail over and exclude any conflicting, deviating, or supplementary terms and conditions of the Customer. To the extent not governed by these T&C, the provisions of Hungarian law shall apply. The Provider may, without notice, at any time amend these T&C and any other information contained on this Platform at any time. The latest version of the T&C will be available on the Platform, and you should review the T&C prior to any use of the Platform. Your continued use of the Platform will be considered acceptance of any version available on the Platform during the time of use. YOU ACKNOWLEDGE AND AGREE THAT BY CONFIRMING THESE T&C OR BY ACCESSING OR USING THE PLATFORM, WHICH CONSTITUTE DIGITAL CONTENT NOT SUPPLIED ON A TANGIBLE MEDIUM, AND BY PROVIDING PRIOR EXPRESS CONSENT FOR THE COMMENCEMENT OF THE PERFORMANCE OF THE CONTRACT DURING THE WITHDRAWAL PERIOD, THE CUSTOMER WILL LOSE ANY STATUTORY RIGHT OF WITHDRAWAL.
1. Definitions
All capitalized terms used herein shall have the meaning ascribed to them below: "Asset" means a network host, which can be a hostname (e.g., example.com), a subdomain (e.g., scan.example.com), or an IP address. Each of these is counted as a separate asset. “Business" means any Customer who enters into a legal transaction with the Provider in the course of its trade, business or profession. "Consumer" means any Customer who is a natural person and who enters into a legal transaction with the Provider for a purpose that cannot be attributed to that person's trade, business or profession. "Credit" means units made available by the Provider that may be consumed through the use of the Products.
"Customer" means any User who has created an account and has access to the Products as per these T&C. The term Customer shall, unless otherwise specified, mean both, Consumers and Businesses. “Customer’s Data” means (i) data related to the Customer which is collected, used, processed, stored, or generated as the result of the use of the Products; and, (ii) personally identifiable information collected, used, processed, stored, or generated as the result of the use of the Products, including, without limitation, any information that identifies an individual. “Product(s)” means any and all cybersecurity and network discovery tools, Software, features, functionalities, and related offerings made available by the Provider through the Platform. This includes, without limitation, AI-powered automated server and network discovery, open port scanning, service identification, and related analysis and reporting functionalities, as well as any updated or additional tools the Provider may provide from time to time via the Platform. "Software" means all the Provider’s computer programs marketed in any form and through any medium via the Platform. "Problem" means a user-defined issue seeking resolution due to and limited to failure of the Products to conform substantially to the specifications provided in these T&C. “Website” means the content accessible via the domain name exploitsynth.com. “Platform” means the scan.exploitsynth.com platform where the Products are made available. "Resolution" means an explanation of probable reasons for the problematic performance of the Products and/or of the Platform together with a recommended solution. “User” means any visitor of the Platform or the Website. For clarity purposes, any reference to Users will include Customers, unless expressly specified herein. "User Content" means any data, content, or materials uploaded, submitted, or otherwise transmitted by the User through the Platform.
2. Description of the products
- The Platform provides Users with access to a suite of cybersecurity tools designed to assist in the discovery, identification, and analysis of digital assets and network services, including open ports, exposed services, and related system information using AI-based agents and automated analysis techniques, subject to these T&C.2. If any User wishes to access any of the Products available on the Platform, it may request access to the respective Products. During the beta testing phase, Users may request credits for the purpose of testing the Products. Once access is granted, the Products will be made available immediately through both a web-based interface and an API.3. The Products are tools that may perform automated network reconnaissance, open port scanning, service identification, and related security analysis and reporting functionalities, with scans originating from the Costumer’s own servers and infrastructure rather than from the Providers's systems, as well as any related features or functionalities that may be introduced or updated from time to time on the Platform. The Provider may, at its sole discretion, modify, enhance, or discontinue any part of the Products without prior notice. Scans, checks, and analysis performed by the Products may also be modified, removed, or updated by the Provider at any time without notice.Use of the service is subject to the establishment of a reverse SOCKS5 tunnel between the Provider's infrastructure and the Customer-designated scanning host. All communications and interactions initiated by the agent with the target environment shall be conducted exclusively through this tunnel. In this way scans originating from the Costumer’s own servers and infrastructure rather than from the Providers's systems.
- Access to and use of the Products is intended solely for lawful cybersecurity testing purposes, in accordance with all applicable laws and regulations, and subject to these Terms and Conditions. Users are responsible for ensuring they have the necessary authorization to conduct any security testing activities using the Platform. The Provider reserves the right to request, at any time, proof of such authorization from the Customer, and may suspend or terminate access to the Platform if satisfactory proof is not provided.5. The Provider may request that Users provide information or documentation necessary to verify their eligibility to access certain Products, where required by applicable law. In this case, the Provider shall only be obliged to deliver access to the Platform only after you have provided the appropriate evidence.
3. Access to the products
- The Provider is bound to use commercially reasonable efforts to make the Products available on the Platform.
- The Provider is entitled to make any amendments necessary to make available the Products without informing the Customer thereof, to the extent that such amendments do not lead to any material changes in the Products made available to the Customer.
- The Provider will make all reasonable efforts to meet all deadlines as they may be set from time to time in these T&C, on the Platform or any of the agreements concluded between the Parties.
- The Provider shall grant access to the Products solely after the Customer or any person appointed by the Customer has provided all required data and information through the Platform.
- Customers are responsible for ensuring that their use of the Products is lawful and that they have obtained all necessary authorizations and consents for any cybersecurity testing activities performed through the Platform. The Provider does not warrant that the Products will be uninterrupted, error-free, or capable of identifying all vulnerabilities or threats. The Products are provided on an "as is" and "as available" basis, and the Provider disclaims all liability for any loss or damage arising from the use or inability to use the Products, except as expressly provided in these T&C.
- The Provider may, in certain cases, allow the Customer to connect to or otherwise interact with one or more third-party service providers for purposes permitted by the Platform. Because the Provider does not control such third-party service providers, access to any such third parties through the Platform may be implemented, suspended or terminated by the Provider from time to time in its sole discretion, including as may be necessary for security or maintenance purposes or as required by the applicable law. The Customer acknowledges and agrees that such third parties are not agents of the Provider, that the Provider is not responsible for their services, compliance, accuracy, actions or omissions or for their maintenance or treatment of User Content, that the Provider will not be liable for and specifically disclaim liability for any damage or loss caused thereby and that access to such third party via the Platform does not imply any endorsement by the Provider.
- The Platform may contain links to websites controlled by third parties other than the Provider. Access to any other website linked to the Platform is at your own risk. The Provider is not responsible for and does not endorse or accept any responsibility for the contents or use of these third-party websites.
4. Ineligible use
- To the extent permitted by applicable law, you are not eligible to access, register for, or use the Platform if: a) You or any of your employees, agents, or representatives have been convicted of any computer-related or internet-related crimes, including, but not limited to, offenses involving unauthorized access, fraud, or misuse of computer systems or data; b) You are located in, a resident of, or otherwise subject to the jurisdiction of any country, territory, or region where use of the Products is prohibited by law, regulation, or applicable sanctions; c) You did not provide the Provider proof of authorisation to use the Products on the targeted sites, promptly upon request; d) You have previously been denied access to or had your right to use the Products revoked or terminated by the Provider for any reason, and the situation that led to or justified the refusal has not been remedied.
- The Provider reserves the right, at its sole discretion, to refuse, suspend, or terminate access to the Products and the Platform to any individual or entity at any time, if the Provider determines that such action is necessary to protect its interests, ensure compliance with applicable laws and regulations, or safeguard the security and integrity of the Provider or the Platform.
5. Beta Access and Credits
- During the beta testing phase, access to the Products may be granted through credits made available by the Provider. Users may request credits for the purpose of testing the Products.
- The Provider may determine, at its sole discretion, the amount of credits allocated to Users and may modify, suspend, or discontinue the availability of such credits at any time.
- The Provider reserves the right to introduce paid subscriptions, usage-based fees, or other pricing models in the future. Any such fees will be communicated to Users in advance and will be subject to the terms applicable at that time.
- Credits provided for beta testing purposes have no monetary value, are non-transferable, and may not be redeemed for cash or any other form of compensation.
6. Indemnifications and limitation of liability
- You agree to indemnify, defend, and hold harmless the Provider, its affiliates, officers, directors, employees, and agents from and against any and all claims, damages, losses, liabilities, costs, and expenses, including reasonable attorneys’ fees, arising out of or relating to: a) your use or misuse of the Products or the Platform; b) your violation of the T&C or any other applicable document between the parties; c) your breach of any applicable law or regulation; d) any content or data you submit, transmit, or process through the Platform; or e) any unauthorized testing or activity conducted using the Products, including without limitation any claim by a third party alleging unauthorized access or damage to their systems or data.
- To the maximum extent permitted by applicable law, the Provider’s total aggregate liability to you for any and all claims, losses, or damages arising out of or in connection with your use of the Products, whether in contract, tort (including negligence), statutory duty, or otherwise, shall not exceed the total fees paid by you to the Provider for the Products during the twelve (12) months preceding the event giving rise to the claim.
- In no event shall the Provider be liable for any indirect, incidental or consequential damages, including but not limited to loss of profits, loss of revenue, loss of data, business interruption or loss of business opportunity, even if the Provider has been advised of the possibility of such damages or such damages were reasonably foreseeable.
- The Provider shall not be liable for any failure or delay in performance resulting from causes beyond its reasonable control, including but not limited to acts of God, war, terrorism, labour disputes, supply shortages, or failures of third-party service providers.
- Nothing in these T&C shall limit or exclude the Provider’s liability for death or personal injury caused by its negligence, fraud or fraudulent misrepresentation, or any other liability that cannot be limited or excluded under applicable law.
7. Intellectual property
- All content, software, tools, features, data, designs, text, graphics, logos, images, audio, video, and other materials provided on or through the Platform (collectively, "Platform Content") are the exclusive property of the Provider or its licensors and are protected by applicable intellectual property rights, including but not limited to copyright, trademark, trade secret, and patent laws, whether registered or unregistered.
- Any User Content remains the property of the respective User. By submitting User Content, the User grants the Provider a non-exclusive, irrevocable, perpetual, worldwide, royalty-free license to use, reproduce, process, store, display, and transmit such User Content solely as necessary to provide and improve the Products and the Platform.
- Subject to the Customer’s compliance with these T&C, the Provider grants the Customer a limited, non-exclusive, non-transferable, non-sublicensable, revocable license to access and use the Products, including the Platform Content, solely for lawful internal cybersecurity testing and evaluation purposes, and strictly in accordance with all applicable laws and regulations. The Customer may not use, copy, modify, distribute, sell, lease, sublicense, reverse engineer, decompile, disassemble, or create derivative works from the Platform or any Platform Content.
- Notwithstanding Article 7.3, in certain cases, the Customer may be permitted to modify reports generated through the Platform solely for the purpose of customizing badges, logos, and such references to names, e-mail addresses, or similar identifying information. All reports generated through the Platform shall remain property the of the Provider. Under no circumstances may the Customer alter, modify, or misrepresent the substantive results, findings, or technical content of the reports. The Customer shall be entitled to use the reports for authorised purposes within the limits of these T&C and the Acceptable Use Policy. Any modification beyond those expressly permitted herein is strictly prohibited.
- Unless the User becomes a Customer under the conditions provided hereunder, nothing in these T&C shall be construed to confer any license to the User. Any unauthorized use of any Platform Content may violate intellectual property laws, the laws of privacy and publicity, communications regulations and statutes, or other applicable laws.
- The User agrees that any suggestions, improvements, comments, feedback, or other input provided by the User to the Provider regarding the Products, the Platform or the Platform Content ("Feedback") should be deemed entirely voluntary. The User hereby grants to the Provider a perpetual, irrevocable, worldwide, exclusive license to use, reproduce, modify, distribute, and otherwise exploit such Feedback for any purpose without any obligation or payment to the User.
- Nothing in these T&C shall be construed as transferring any ownership rights in the Products, the Platform or in the Platform Content to the User. All rights not expressly granted to the User under these T&C are reserved by the Provider.
8. Confidentiality and permitted disclosures
- Confidential information means and refers to any document and information relating to parties’ business (as well as their subsidiaries or other legal entities controlled by them) including, but not limited to (i) information regarding the parties’ business, operations, financial condition, vendors, sales representatives and other employees, (ii) projections, budgets and business plans regarding the parties; (iii) information regarding the parties’ planned or pending acquisitions, divestitures or other business combinations, (iv) the parties’ trade secrets and proprietary information and (v) technical information, discoveries, improvements, techniques, processes, business methods, equipment, algorithms, software programs, software source documents and formulae, and databases, in each case regarding the parties’ current, future or proposed commercial activities, strategies, products or services (the "Confidential Information").
- Confidential Information shall not include information which (i) is or becomes part of the public domain other than as a result of disclosure by either of the parties, (ii) becomes available to a party on a non-confidential basis from a source other than the disclosing party, provided that this disclosing source is not bound – with respect to the information or document at issue – by a confidentiality agreement concluded with the receiving party, (iii) can be proven by the receiving party (pursuant to written evidence) to have been in the possession of such party prior to disclosure of the same by the disclosing party or (iv) is disclosed with the disclosing party’s prior written consent.
- The parties agree that they will not in any manner, directly or indirectly, use or otherwise employ all or any portion of the Confidential Information except in furtherance of the Products to be provided under these T&C and specifically, without limiting the generality of the foregoing, that they shall not use or otherwise employ all or any portion of the Confidential Information for any purpose which would be independent of the Products.
- Except as required by law or court order, the parties are obliged to keep the Confidential Information strictly confidential. This confidentiality obligation will survive the termination or expiry of these T&C’s applicability for a period of three (3) years. In the case of trade secrets, they shall remain confidential for as long as they qualify as trade secrets under the applicable law.
- The Customer specifically agrees that the Provider may (i) publicly disclose that it makes Products available to the Customer and (ii) use the Customer’s name and/or trademark in promotional materials, including press releases to identify the Customer as a beneficiary of the Products.
9. Obligations of the users
- The User understands, acknowledges, and agrees that it shall use the Platform solely in connection with its scope of business and under the terms and conditions specified herein.
- The Customer must use the Products in accordance with these T&C, all applicable laws and regulations, and any additional policies, guidelines, or instructions provided by the Provider. The Customer is solely responsible for obtaining all necessary authorizations, consents, and permissions for any cybersecurity testing or activities performed using the Platform and the Products.
- The Customer shall provide complete, accurate, and up-to-date information as required for account registration, service access, and during the course of using the Products. The Customer must promptly update any information that becomes inaccurate or outdated.
- The Customer shall not assign, transfer, or otherwise convey any rights under the T&C to any third party, without the prior written consent of the Provider.
- Any subsequent alteration, modification, or change in the Customer’s use of the Products must be reviewed and explicitly authorized by the Provider prior to any such alteration, modification or change in use.
- The Customer undertakes to provide access to the Platform only to its employees and affiliates who are trained to use the Platform and who have priorly read and agreed to these T&C.
- The Customer shall: (i) ensure that its network and systems comply with the relevant specifications provided by the Provider (ii) be solely responsible for procuring and maintaining its network connections and telecommunications links from its systems to the Provider’s data centres, and (iii) take responsibility for all problems, conditions, delays, delivery failures and all other loss or damage arising from or relating to the Customer's network connections or telecommunications links or caused by the internet connection.
- The Customer specifically agrees to (i) use reasonable security precautions, in line with latest security practice, in connection with the use of the Platform; to (ii) cooperate with Provider’s reasonable investigation of service outages, security problems, and any suspected breach of the T&C; and (iii) immediately notify the Provider of any unauthorized use of the Customer’s account(s) or any other breach of security.
- The Customer is responsible for maintaining the confidentiality and security of all account credentials, passwords, API keys, and other access details associated with the Platform, which will only be disclosed by the Customer on a need-to-know basis. The Customer is liable and responsible for all activities conducted through their account, whether authorized or unauthorized, except where such activities result from breaches beyond the Customer’s reasonable control.
- In addition to all the obligations set forth herein, the Customer shall strictly respect the condition of usage of the Products and the Platform, in accordance with the Acceptable Use Policy.
- You acknowledge and agree that we may engage third-party service providers and subcontractors to support the provision of the Products and the Platform. The use of such third parties is essential for delivering a modern, secure, and reliable service.
10. Prohibited Uses
- The User must not use the Products to: (i) Create Unreasonable Load: Generate excessive traffic, bandwidth consumption, or processing load on any networks, servers, websites, or IPs or on the Provider’s infrastructure that could disrupt normal operations or degrade performance. (ii) Conduct Unlawful Activities: Perform any unlawful activity including but not limited to computer crimes, transmission or storage of illegal content, or activities that violate intellectual property and copyright laws. (iii) Damages to the Provider: Use the Products in a way to cause damage to the Product, or would otherwise impact the Provider, or the Provider’s reputation, brand, or operations.
11. Compliance Obligations and Enforcement
- The Customer’s are solely responsible for ensuring that their use of the Product complies with all applicable laws, regulations, and industry standards in your jurisdiction, including but not limited to data protection laws, computer crime statutes, and cybersecurity regulations. You acknowledge that security testing regulations vary by jurisdiction and that you must obtain all necessary approvals, notifications, or permissions required by applicable law before conducting any security testing.
- The Provider reserves the right to investigate any suspected violations of this T&C and to take immediate action, including but not limited to suspending or terminating your access to the Products, removing or disabling any offending content, and reporting violations to law enforcement authorities. Any violation of this T&C will result in immediate termination of your account and this Agreement, and may result in referral to law enforcement authorities.
12. Obligations of the Provider
- The Provider warrants its commercially reasonable efforts to make the Products available continually, excluding downtime due to maintenance and Software updates.
- The Provider shall perform maintenance on the Software on a regularly scheduled basis and may also perform unscheduled emergency maintenance if needed to address new security threats or other non-routine events, as provided in article 13 herein.
- The Provider shall always attempt to perform maintenance at a time convenient to the Customer, but the Provider does not warrant the Customer in this respect. For the avoidance of any doubt, the Provider does not warrant that Products shall be uninterrupted, error-free, or completely secure.
- The Provider undertakes to provide the Customer with access to the Provider’s technical support team via e-mail, Monday through Friday any time between 9.00 – 16.00 CET for questions about the Products or for submission of any Problem.
- For the avoidance of any doubt, the Provider does not appoint a dedicated person to provide customer support services for or in connection with the Products.
- The Provider, in its sole discretion, may suspend the access to the Products in case: (i) the Provider reasonably believes that the Products are being used in breach of the T&C or the applicable law; (ii) the Customer does not cooperate with Provider’s reasonable investigation of any suspected violation of the T&C; (iii)there is an external attack on the Platform or aimed at the Platform or the Platform is being accessed or manipulated by a third party without the Customer's consent; (iv) of a specific request from a public authority or government body; (v) of a period of at least 12 months of inactivity; (vi) any other events occur and the Provider reasonably believes that the suspension of Products is necessary to protect the Platform or its business, the performance of the Products, the system’s infrastructure or third parties’ rights. Should any of the above events occur, the Provider shall notify in writing the Customer in respect to the suspension of the access and the reason.
- The Provider is not responsible for any unauthorized access to the Platform or the unauthorized use of the Products unless the unauthorized access or use is a result of the Provider’s failure to meet its obligations as provided for in these T&C.
- The Provider will implement appropriate technical and organizational measures to safeguard the security, confidentiality, and integrity of Customer Data processed through the Platform, in accordance with the Provider’s Privacy Policy and applicable data protection laws.
- The Provider shall provide support in connection with the Products only for properly reported Problems. To this end the Customer must provide the Provider with the following (in the following order): (i) a description of the functionality desired to be achieved; (ii) a description of the incorrect behaviour of the Platform or any of the Products; (iii) a step-by-step process reproducing a singular undesired event; (iv) any and all exact error messages occurred; (v) any necessary contact information.
- In case of any Problems related to the Products, the Customer undertakes to duly notify the Provider in accordance with the provisions above. The Provider shall use its best efforts to provide the Customer with a Resolution in accordance with the terms provided in these T&C.
14. Customer's data
- Customer’s Data shall be known and treated by the Provider as Confidential Information.
- The Provider is provided a limited license to use the Customer’s Data for the sole and exclusive purpose of providing the Products, including a license to collect, process, store, generate, and display Customer’s Data only to the extent necessary in the provision of the Products. The Provider shall: (i) keep and maintain Customer’s Data in strict confidence, using such degree of care as is appropriate and consistent with its obligations as further described in these T&C and applicable law to avoid unauthorized access, use, disclosure, or loss; (ii) use and disclose Customer’s Data solely and exclusively for the purpose of providing the Products, such use and disclosure being in accordance with these T&C, and applicable law; and (iii) not use, sell, rent, transfer, distribute, or otherwise disclose or make available Customer’s Data for Provider’s own purposes or for the benefit of anyone other than Customer without Customer’s prior written consent, excepting as otherwise stated in these T&C.
- The Customer acknowledges and agrees that the Customer’s Data may be transferred or stored outside the EEA or the country where the Customer is located in order for the Products to be made available and in compliance with the Provider’s other obligations under these T&C.
15. Privacy Policy
- This Privacy Policy explains how the Provider uses the personal data and other data it collects from you when you use the Platform and the Products, and supplements the provisions of article 14 above. This Privacy Policy forms an integral part of these T&C and applies to Users and Customers alike.
- In connection with the provision of the Products, the Provider collects and processes the following data: a) e-mail address; b) password hash; c) credit balance; d) for each scan: the IP address of the target, the port numbers scanned, the complete results of the scan, and the AI agent’s interactions with the scanned ports, including the commands executed by the agent, the responses received, and any websites accessed by the agent for contextual purposes; e) the names given by Customers to their projects on the Platform; f) API keys generated through the Platform, together with the names assigned to such API keys; g) coupon codes redeemed by the Customer, together with the identity of the redeeming Customer and the date and time of redemption; and h) any .nessus or .nmap files uploaded by the Customer through the Platform, together with their content. The Customer is solely responsible for ensuring that no special categories of personal data, as referred to in article 15.11 below, are contained in any scan data or uploaded files submitted through the Platform.
- The Customer directly provide the Provider with most of the data described above in article 15.2. The Provider collects and processes data when you: a) register on the Platform b) use or view the Platform via your browser's cookies c) email to our team e) upload a file through the Platform f) otherwise use the Products The Provider may also receive your data, if necessary, for resolving specific Problems that can affect the usability of the Platform, or your user experience. The Provider considers any one of the above listed actions to be a clear affirmative action which is freely given, specific, informed, and unambiguous, and which therefore signifies consent to process your data hereunder.
- The Provider collects your data so that it can: a) provide the Products and enable Customers to manage their accounts; b) view and analyze your data to troubleshoot and improve the Products for internal purposes only; c) upload your data to the third-party service providers listed below as part of providing the Products. The Provider maintains, where applicable, a Data Processing Agreement (DPA) with each such provider; and d) divulge your data to law enforcement if the Provider receives a valid legal request — the Provider will notify you if this happens, unless legally prohibited from doing so.
- The third-party service providers engaged by the Provider in connection with the Products are the following: a) OpenAI, L.L.C., which processes the information reviewed and generated by the Provider’s AI agents in the course of performing scans; b) Supabase, Inc., which hosts the Provider’s database and, accordingly, stores substantially all of the data described above; c) Railway Corp., which provides hosting infrastructure for the Provider’s static landing page; this provider does not store any of your data; d) Resend, which handles the transmission of e-mails sent by or on behalf of the Provider; and e) Hetzner Online GmbH, which provides the server infrastructure on which the Provider’s containerized agents run; all scanning activity is processed through this infrastructure, but no data is stored thereon. The Provider may update the list of third-party service providers from time to time; the Provider will keep this Privacy Policy reasonably up to date to reflect any such changes. Independent of the third parties that the Provider uses to manage your data, you can pursue the following rights over your personal data at any time: access, rectification, erasure, restriction of processing, data portability, object, and be informed. For more information about these rights, please see below.
- The Provider securely stores your data in information systems that are in cloud environments, but are managed by us, using policies and procedures such as the SOC 2 standard. Without limiting the foregoing, the Provider follows the following security policies and procedures: (i) all your data is encrypted in transit, configured to follow industry best practices; (ii) access control lists and firewall rules are designed to grant minimal necessary permissions; and (iii) regular monitoring for potential security vulnerabilities and immediate remediation of any material security vulnerabilities discovered. The Provider stores your personal data using specific security controls, that we manage periodically to avoid disclosure, or unauthorized access. The Provider processes your personal data only to provide the Products in accordance with this Privacy Policy, and for no other purpose. To prevent any use or disclosure of your personal data subject to this Privacy Policy, you may not register an account, subscribe to our newsletter, or send us an email which gets logged in our ticketing system. If you believe we are already storing your personal data, and you want to prevent further use or disclosure of your personal data, please exercise your Right to erasure as described below.
- The Provider will never sell your data to a third party, or send you unsolicited marketing e-mails.
- The Provider would like to make sure you are fully aware of all of your data protection rights. These data protection rights are the following: (i) Right to access: You have the right to request copies of your personal data. (ii) Right to rectification: You have the right to request that the Provider correct any information you believe is inaccurate. You also have the right to request the Provider to complete the information you believe is incomplete. (iii) Right to erasure: You have the right to request that the Provider erase your personal data, under certain conditions. (iv) Right to restrict processing: You have the right to request that the Provider restrict the processing of your personal data, under certain conditions. (v) Right to object to processing: You have the right to object to the Provider’s processing of your personal data, under certain conditions. (vi) Right to data portability: You have the right to request that the Provider transfer the data it has collected to another organization, or directly to you, under certain conditions. If you make a request, the Provider has 1 month to respond to you, and if you want to exercise any of these rights, you can write to the Provider at: support@exploitsynth.com
- The Website and the Platform may use cookies and similar technologies that are strictly necessary for the operation of the Platform.
- The Website and the Platform can contain links to other websites, but this Privacy Policy applies only to the Website and the Platform. If you click on a link to another website, that website’s own privacy policy will govern the privacy of your data.
- Personal data revealing racial or ethnic origin, political opinions, religious or philosophical beliefs, or trade union membership, and the processing of genetic data, biometric data for the purpose of uniquely identifying a natural person, data concerning health, or data concerning a natural person’s sex life or sexual orientation, is expressly prohibited from being stored or processed by Customers via the Platform in any way, and the Provider will delete immediately any kind of sensitive data that it identifies in its systems.
- The Provider keeps this Privacy Policy under regular review and places any updates within these T&C. This Privacy Policy was last updated on the date listed at the end of these T&C.
- If you have any questions about this Privacy Policy, the data the Provider holds on you, or you would like to exercise one of your data protection rights, please do not hesitate to contact the Provider at: support@exploitsynth.com
- The Provider commits to resolving complaints about its collection or use of personal data. Individuals or companies with inquiries or complaints regarding this Privacy Policy may contact the Provider at the e-mail address above, or may lodge a complaint with the competent data protection authority, in Hungary, the National Authority for Data Protection and Freedom of Information (NAIH)
16. Term and termination
- These T&C shall remain in effect from the date you first access the Platform and continue until terminated in accordance with this section.
- You may terminate your account and cease use of the Products at any time by submitting a request for account termination to the Provider’s support team at support@exploitsynth.com . The request shall be handled within 5 working days. unless otherwise required by law or expressly stated herein or in a separate agreement, no refunds will be issued for any prepaid fees upon such termination.
- The Provider may terminate your access to the Platform and Products, in whole or in part, at any time and for any reason, upon written notice, including but not limited to the reasons for suspending the access to the Products listed under article 12.6.
- Where possible, the Provider will provide you with prior notice of termination and an opportunity to remedy any breach, except where immediate action is deemed necessary to protect the Platform, the Provider, or other users.
- Upon termination of your access to the Platform and/or the Products for any reason: a) all rights and licenses granted to you under these T&C will immediately cease; b) your access to the Platform will be discontinued; c) any outstanding fees or charges incurred prior to the effective date of termination become immediately due and payable; d) the Provider may, but is not obligated to, provide you with a limited period (not exceeding thirty (30) days) to access, export, or retrieve your data, after which all data may be permanently deleted, except as otherwise required by law.
- Any provisions of the T&C that by their nature should survive termination, including but not limited to those relating to intellectual property, confidentiality, indemnification, limitation of liability, and payment obligations, shall survive the termination of your access to the Platform and/or the Products.
17. Force majeure
- A party whose activity in performing the obligations hereunder is impeded due to a force majeure event (as it is defined in the Hungarian Civil Code) may suspend the performance of its obligations during the period of time while the force majeure lasts and shall notify accordingly the other party, as soon as practicable, in writing. A force majeure event shall not relieve the parties from the obligation to use their best efforts to mitigate the damages caused by the failure to perform or default performance due to the force majeure event.
- In case of force majeure event lasting for more than 60 days, parties may terminate the agreement, by written notice submitted to the other party, without any formality or court intervention and without any further payment of damages. For the avoidance of doubt, any outstanding debts shall be promptly paid by the parties.
18. Governing law and jurisdiction
- These T&C, as well as any use of the Platform and/or Products, shall be governed by and construed in accordance with the laws of Hungary.
- In the event of any dispute arising out of or in connection with these T&C, the parties shall attempt, in good faith, to resolve the dispute amicably. If an amicable settlement cannot be reached within fifteen (15) calendar days from the date one party notifies the other of the dispute, the dispute shall be submitted to the competent courts, as per article 18.3 below.
- By accepting these T&C, you agree that any matters relating to the validity, interpretation, performance, or termination of these T&C, or any dispute arising out of or in connection with them, including non-contractual obligations, shall be subject to the exclusive jurisdiction of the competent courts of Budapest, Hungary.
19. No waiver
- No single or partial exercise of any right or remedy under these T&C shall constitute a waiver of that or any other right or remedy. A waiver of any breach of any provision shall not be deemed a waiver of any subsequent breach.
20. Miscellaneous
- The Customer may not assign or transfer any of its rights or obligations under these T&C without the prior written consent of the Provider, such consent not to be unreasonably withheld or delayed. This restriction shall not apply to assignments or transfers to legal successors in the event of a merger, acquisition, or sale of substantially all assets.
- The invalidity or unenforceability of any provision or part of a provision of these T&C shall not affect the validity or enforceability of the remaining provisions. The parties agree to replace any invalid or unenforceable provision with a valid and enforceable provision that most closely reflects the original intent and economic effect.
- The United Nations Convention on Contracts for the International Sale of Goods (CISG) shall not apply.
21. Reporting Violations
If you believe someone is using the Provider’s Products to scan your systems without authorization, please contact us immediately at: Email: abuse@exploitsynth.com Subject line: "Unauthorized Scanning Report" Include: Target details, scan timestamps, and any evidence of unauthorized activity Last update of T&C on: 25.06.2026.