Privacy Policy
Last updated: 23 July 2026
This Policy describes how Lunar j.d.o.o. handles personal data in connection with the website majhenlabs.com and the free checks at scan.majhenlabs.com, in accordance with Regulation (EU) 2016/679 (GDPR).
It covers four checks — the legitimacy check, the website vulnerability check, the email source check and the GDPR check — which differ in the data they process, so they are described separately below.
1. Controller
Bana Jelačića 14, 42230 Ludbreg, Croatia
Company ID (OIB): 47232633853
Email: privacy@majhenlabs.com
2. What we don't do
This comes first because it's shorter than the list of what we do.
We have no Google Analytics or any other third-party analytics. We have no tracking cookies, pixels, advertising identifiers or profiling. We do not sell or hand over data to anyone. We use no automated decision-making with legal effect.
We read traffic from our own server logs.
We never store the body of a message you submit to the email check, whatever the outcome. The raw source exists only in working memory while that single request is processed.
3. Data we process
3.1 When you run the website check or the GDPR check
Both are started by entering a domain and both require confirmation of a code.
- The email address you enter to confirm the code.
- The domain you submitted for checking.
- The findings the check produced.
- IP address and timestamp of the request, to limit the number of checks and prevent abuse.
There is no registration. We don't ask for your name, company or phone number. If you write those into a message yourself, we'll process them in order to reply to that message.
3.2 When you submit a message to the email check
That check requires no email address and no confirmation code. Processing happens at two levels:
- For every check we record only the time, the IP address and the number of signals found — for rate limiting and the public counter. That record contains no part of the message content.
- Only when the outcome is “very likely fraud” or “suspicious” do we additionally record the sender, the subject line, the list of signals found, the domains from links, attachment names, and the result of the SPF, DKIM and DMARC checks. Without this we cannot maintain the list of frauds in circulation, and whether the check recognises the next one depends on it.
- When the outcome is “no obvious alarms” or “cannot judge”, nothing remains beyond the count in the first point.
The message you submit may contain personal data of third parties — the sender's name and address, recipient addresses. We process these only to the extent described above and never use them to contact those people.
Attachment contents never leave your computer. Attachments are stripped in your browser before sending; only their name and size reach us. Attachments are not opened, not decoded, and not examined for malicious content.
3.3 When you run the legitimacy check
This check requires no email address and no code confirmation — it concerns someone else's, publicly available site that you are checking. We process:
- the address (URL) and domain you enter for checking;
- the findings the check produced — which signals are present and their assessment;
- your IP address and the time, to limit the number of checks and for the public counter.
To run it, we fetch that page as an ordinary visitor and ask public registries about the domain (domain registration data, a public archive). As a result, the name of the domain you are checking also reaches those external services. We read the page's content, but do not change or store it.
3.4 When you only visit the site
- Server logs: IP address, timestamp, requested path, response code, browser type and the page you came from. This is the standard record every web server keeps.
- The
ml_langcookie, if you pick a language by hand. It contains onlyhroren, lasts a year, and exists solely so we don't send you to the wrong language next time. It is not a tracking cookie, which is why we don't ask for consent for it.
4. Why we process it, and on what basis
- Running the check and delivering the findings — performance of a contract at your request, Art. 6(1)(b) GDPR. Without an email address we cannot confirm that you are authorised to request a check for that domain.
- Limiting the number of checks and preventing abuse — our legitimate interest, Art. 6(1)(f), in keeping the server available and in the Service not being used to reconnoitre other people's systems.
- Maintaining the list of recognised frauds — our legitimate interest, Art. 6(1)(f). Without a record of messages recognised as fraud we cannot maintain the signals by which the check recognises them, and the service would gradually stop working. The record is created only for a recognised fraud and contains no message body.
- Replying to your question about the findings — legitimate interest, Art. 6(1)(f), or pre-contractual steps at your request.
- Legal obligations — Art. 6(1)(c), where we are required to act on a request from a competent authority.
We don't use your email address for a newsletter or for offers unrelated to the check you ran yourself. That would require separate consent.
5. Where data is processed
- All four checks run on a server we rent from Hetzner Online GmbH, in a data centre in Nuremberg, Germany.
- The majhenlabs.com site and email are served from a shared server at our hosting provider in Croatia.
Your data — email, IP address, findings — is processed and stored only at those two locations, both within the European Economic Area. The exceptions are the domain name during subdomain discovery (section 6.1) and, for the legitimacy check, the domain name and address you are checking — because we then fetch that page and query public registries about the domain, so that data reaches services that may be outside the EEA. Everything else stays on our servers.
6. Who data is disclosed to
We don't sell data and don't pass it to third parties for their own purposes. Access is limited to:
- Our server provider (Hetzner Online GmbH) and our website and email hosting provider, as processors, to the extent necessary to operate the infrastructure.
- Competent authorities, where we are legally required to comply.
6.1 External sources the check queries for subdomains
This is the section most similar services leave out, and we write it because it is the only honest thing to do. To list your domain's subdomains, the check uses a tool called subfinder, which sends the domain you entered to a range of public services and collects their answers. These are services that publish subdomains publicly anyway — logs of issued TLS certificates, public DNS archives, and the like.
It matters what this means: your domain name leaves our infrastructure during that query and reaches those services. Some are in Europe, some in the United States, and some elsewhere. The query contains the domain name only, and comes from our IP address, never yours. Your email address, your IP address and the findings themselves go nowhere — they stay on our server.
Why it works this way: the domain itself is public data, and the subdomains these services return are already published — anyone can retrieve them the same way. The check simply shows you the same list that already exists about you. If that doesn't suit you, subdomains can be left out of the check by contacting us before the scan.
6.2 Queries made by the email check
To establish whether the server a message arrived from is permitted to send mail on behalf of the sender's domain, the check queries the public domain name system (DNS) — for the sender's domain and its SPF chain, at most ten queries. The query contains only that domain name and comes from our IP address.
Domains found in links are not resolved and no link from the message is ever opened. The subject line, the message body and data about you never leave our server.
6.3 What the site being checked sees
The website check and the GDPR check fetch the page being checked from our server. In that site's logs, inbound traffic appears from our IP address — never from yours. The GDPR check loads the page with an automated browser, as an ordinary visitor, without any action, and changes nothing on it.
6.4 The vulnerability database
The known-vulnerability database (Wordfence Intelligence Community Edition) is held as a local copy on our server and refreshed once a day. The check never queries it over the network, so Wordfence does not learn which domain we checked.
7. How long we keep it
- Findings of the website and GDPR checks, and the link to them — 30 days from creation, then deleted.
- Email address and domain — 12 months from the last check.
- Confirmation code — until confirmed, at most 15 minutes.
- A record of a recognised fraud (sender, subject, signals, link domains, attachment names) — 12 months from the check. A longer period serves no purpose, as fraud patterns change within a year.
- A record that a check was run (time, IP address, type of check, number of signals) — 30 days, then deleted.
- Server logs — 30 days, then deleted.
- Business correspondence — for as long as it is needed for the relationship it concerns, or as tax and accounting rules require if a contract was concluded.
8. Your rights
Under the GDPR you have the right to:
- access — confirmation of whether we process your data, and a copy of it;
- rectification of inaccurate or incomplete data;
- erasure;
- restriction of processing;
- portability in a machine-readable format;
- objection to processing based on legitimate interest;
- complaint to a supervisory authority — in Croatia this is the Personal Data Protection Agency, azop.hr.
Send requests to privacy@majhenlabs.com. We reply within one month. Since we keep no user accounts, we may ask you to send the request from the email address you used to run the check — that's the only way we can connect you to the data.
9. Security
The check runs under a separate unprivileged system user, on a server with restricted access and a firewall. Traffic is encrypted (HTTPS). Logs and findings do not leave that server. No measure is absolute and we don't claim otherwise.
10. Children
The Service is intended for business users — people managing websites or business email. An individual may also find the suspicious-message check useful, but it too is not directed at anyone under 18.
11. Changes
We may update this Policy from time to time. The “Last updated” date shows when it was last changed.
Contact
Bana Jelačića 14, 42230 Ludbreg, Croatia
Company ID (OIB): 47232633853
Email: privacy@majhenlabs.com
See also the Terms of Service.