Privacy Policy
On this page
- 1.Controller and contact
- 2.Principles and legal bases
- 3.Website visits, consent and analytics
- 4.Cookie and preference data
- 5.Contact requests
- 6.Free licenses and license records
- 7.License validation, heartbeat and integrity
- 8.Cookie Scanner
- 9.Recipients and service providers
- 10.Retention summary
- 11.Your rights
- 12.Complaints
- 13.Security and changes
1. Controller and contact
The data controller is Andrei Angel Țîru, trading as Tyrus, based in Vamdrup, Denmark. Privacy requests can be sent to angel@tyrus.dk.
This Policy covers the Tyrus website, public Demo, free-license requests, contact, Cookie Scanner and software-licensing flows described below. A distinct service may publish additional terms or a dedicated notice where its processing differs.
2. Principles and legal bases
Tyrus processes only data that is reasonably needed for a stated purpose. Depending on the flow, processing is based on one or more of the following GDPR bases:
- Consent (Article 6(1)(a)) for optional full analytics and optional persistent interface preferences.
- Contract or steps before a contract (Article 6(1)(b)) for free-license requests, license activation/validation and service enquiries where processing is needed to provide what you request.
- Legitimate interests (Article 6(1)(f)) for site security, abuse prevention, license enforcement, limited operational statistics, handling non-contractual enquiries and protecting the service against fraud or misuse.
- Legal obligations (Article 6(1)(c)) where records must be retained or disclosed because applicable law requires it.
3. Website visits, consent and analytics
Before you make a consent choice, Tyrus does not write optional analytics measurements. The essential consent cookie records the choice itself. If you reject optional analytics, the site may keep minimal aggregate operational counts such as day/hour, page, referrer host, country and broad device type. The raw IP address and user-agent are not written to the essential aggregate table.
If you consent to Analytics, Tyrus stores first-party visit data locally, including IP address and a hashed form of the IP, page, referrer, user-agent, device/browser/OS, country/city, ISP/connection classification, download flag and visit time. This is used to understand site reliability and usage trends, not for advertising or cross-site profiling.
GeoIP enrichment uses the local MaxMind database when available. There is intentionally no external GeoIP network fallback; visitor IP addresses are not sent to a third-party GeoIP API for this purpose. A local GeoIP cache uses a SHA-256-derived filename and is purged after approximately seven days during subsequent lookups.
Public Demo: the interactive Demo creates a temporary per-session sandbox and processes operational analytics separately from the optional main-site Analytics category. To provide the requested Demo, prevent abuse and understand reliability, Tyrus may record the session/sandbox identifier, raw and hashed IP address, browser/OS, language, broad device and screen information, timezone, referrer domain, timestamps, feature-use counters and local GeoIP results. Raw search text and full referrer URLs are intentionally not collected. The sandbox expires after about 30 minutes of inactivity or is deleted on logout. Demo analytics are automatically deleted after 12 months; raw IP and sandbox-path fields are cleared from records older than 30 days. This processing is based on providing the requested Demo service and Tyrus' legitimate interests in security, abuse prevention and limited operational statistics.
4. Cookie and preference data
The essential tyrus_consent cookie stores the time and category choices for up to one year. Tyrus also keeps a server-side consent receipt containing the timestamp/day, consent choice, a SHA-256 IP hash, a shortened user-agent and referrer. Consent receipts are automatically purged after 12 months.
If you enable Preferences, the language preference may be stored in the site_lang cookie for up to one year, and interface preferences may use localStorage/sessionStorage. If Preferences are refused, the persistent language cookie is removed. Full details are in the Cookie Policy.
5. Contact requests
When you use the contact form, Tyrus may receive your name, email address, company, website, preferred contact method, selected service/project information, message, whether you requested a copy, a SHA-256 IP hash and a limited user-agent string. The data is used to answer the request, prevent abuse and maintain the correspondence needed to handle the enquiry.
Contact records are kept while the enquiry is active and afterwards only for as long as reasonably necessary for follow-up, dispute handling, security, accounting or other applicable legal requirements. Individual requests can be deleted administratively when they are no longer needed.
6. Free licenses and license records
When you request a free license, Tyrus processes your email address, domain, optional name, originating IP address, product, EULA version and acceptance state. The six-digit verification code expires after 10 minutes and is stored only as a one-way password hash, not as the readable code. Expired, unverified free-license requests are automatically eligible for deletion after 30 days.
After verification, Tyrus keeps the request and license information needed to issue and administer the domain-bound license and to prove the EULA version and acceptance associated with that license. These records are retained while the license remains relevant and afterwards only as reasonably necessary to establish, exercise or defend legal claims, maintain security and resolve licensing disputes.
7. License validation, heartbeat and integrity
Tyrus software may communicate with Tyrus servers for license activation/validation, heartbeat and integrity checks. Depending on the event, records can include the license key, licensed or attempted domain, manager/software version, PHP version, originating/server IP address, timestamps, ping counts, violation type and limited user-agent data.
This processing supports performance of the license agreement and Tyrus' legitimate interests in preventing unauthorized use and tampering. Managed file contents are not transmitted as part of license validation. Domain mismatch or integrity failures can result in automated technical suspension under the EULA; if you believe a result is incorrect, contact Tyrus for review.
8. Cookie Scanner
The Cookie Scanner processes the public HTTPS URL you submit and technical response data needed to produce the scan. Final reports are temporary and expire after approximately one hour; queued job data is purged after approximately two hours, progress data after approximately 10 minutes, and pseudonymous daily rate-limit counters after no more than approximately two days. The scanner does not require your email address.
You should submit only targets you own or are authorized to assess. The scanner's technical findings are diagnostic information, not legal advice.
9. Recipients and service providers
Tyrus does not sell personal data and does not use third-party advertising or third-party analytics providers for Tyrus first-party analytics. Data may be processed by infrastructure providers that are necessary to operate the service, including hosting and outbound email infrastructure (currently Hostinger services), and by professional advisers or authorities where disclosure is lawfully required.
MaxMind GeoLite data is used from a local database for GeoIP enrichment; routine visitor lookups are not sent to MaxMind. If a processor handles data outside the EEA, Tyrus relies on an applicable GDPR transfer mechanism and safeguards where required.
10. Retention summary
- Consent cookie: up to 1 year.
- Consent receipts: 12 months.
- Full first-party analytics: automatically purged after 12 months.
- Essential aggregate analytics: automatically purged after 12 months.
- Local GeoIP cache: approximately 7 days, purged during subsequent lookups.
- Public Demo analytics: raw IP and sandbox-path fields are cleared after 30 days; the remaining visit row is deleted after 12 months; the active sandbox itself expires after about 30 minutes of inactivity or on logout.
- Unverified free-license requests: eligible for automatic deletion after 30 days; verification codes themselves expire after 10 minutes.
- Verified license/EULA records: while required to administer the license and afterwards as reasonably necessary for legal proof, security and dispute handling.
- Cookie Scanner: report ~1 hour, job ~2 hours, progress ~10 minutes, rate counter up to ~2 days.
- Contact requests: for the active enquiry and then only while reasonably necessary for follow-up, security, legal or administrative purposes.
11. Your rights
Subject to the conditions and exceptions in the GDPR, you may request access, rectification, erasure, restriction or data portability, and you may object to processing based on legitimate interests. Where processing relies on consent, you may withdraw that consent at any time without affecting the lawfulness of processing before withdrawal.
Cookie consent can be changed from the persistent Cookie settings control on the site. For other privacy requests, email angel@tyrus.dk. Tyrus may ask for information reasonably necessary to verify your identity before acting on a request.
12. Complaints
You have the right to lodge a complaint with a competent supervisory authority. In Denmark, the supervisory authority is Datatilsynet. You are welcome to contact Tyrus first so the concern can be investigated directly.
13. Security and changes
Tyrus uses technical and organizational measures intended to protect personal data, including access controls, rate limiting, hashing where appropriate, local-only GeoIP enrichment and restricted writable storage. No system can guarantee absolute security.
This Policy may be updated when processing changes or legal requirements develop. The effective date above identifies the current version. Material changes will be reflected on this page before they apply where practicable.