2026-06-06 is live. RBL, certificate, and uptime monitoring — now in public beta.

Privacy Policy

This Privacy Policy describes how we collect, use, and protect your personal data when you use our website at anti-abuse.com. The Anti-Abuse Project is a project of DMS EOOD (DMS Ltd.), a company registered in Bulgaria. We are committed to protecting your privacy and complying with applicable data protection laws, including the EU General Data Protection Regulation (GDPR) and the UK GDPR.

Who is responsible for your data?

The data controller for the personal data we process through this website is DMS EOOD (DMS Ltd.), a company registered in Bulgaria (VAT ID: BG124599822), which operates The Anti-Abuse Project. If you have questions about this policy or your data, you can contact us via our contact page. If you are in Bulgaria or consider that our processing relates to you there, you may also lodge a complaint with the Commission for Personal Data Protection (CPDP), Bulgaria’s supervisory authority for data protection.

What data we collect and why

Contact form
When you submit our contact form, we collect your name, email address, subject, and message. We also store technical data such as your IP address, browser user agent, and referrer URL for security and to prevent abuse. We use this data solely to respond to your enquiry and to manage our relationship with you. The legal basis for this processing is your consent (by submitting the form) and our legitimate interest in operating and securing our website. We retain contact form submissions for as long as necessary to respond and for a limited period thereafter for administrative and legal purposes, unless you request erasure earlier or we are required to retain them by law.

Cookies and similar technologies
We use cookies and similar technologies as described in our Cookie Policy. That policy explains which cookies we use (including WordPress, our own cookie consent banner, and Google reCAPTCHA on the contact form) and how you can manage your preferences.

WordPress and server data
Our website runs on WordPress. If you have an account and log in, WordPress may store session and account-related data. Our hosting environment may also log IP addresses and similar technical data for security and operational purposes. We do not use this data to identify you personally unless necessary for security or legal obligations.

Google reCAPTCHA
Our contact form uses Google reCAPTCHA to reduce spam and abuse. When you use the form, Google may process data (including IP address and behaviour) in accordance with Google’s Privacy Policy and Terms of Service. This processing is necessary for our legitimate interest in securing our site; you cannot use the contact form without reCAPTCHA.

Who we share data with

We do not sell your personal data. We may share data only in the following cases:

  • Service providers: Our hosting provider and Google (reCAPTCHA on the contact form) may process data on our behalf. They are required to protect your data and use it only as we instruct.
  • Legal obligations: We may disclose data if required by law, court order, or to protect our rights, safety, or property.

International transfers

Some of our service providers (e.g. Google) may process data outside the European Economic Area (EEA) or the UK. Where we do so, we rely on adequacy decisions, standard contractual clauses, or other mechanisms approved by the relevant authorities to ensure your data is protected.

Your rights

Depending on where you live, you may have the right to:

  • Access your personal data and receive a copy
  • Rectification of inaccurate or incomplete data
  • Erasure (“right to be forgotten”) in certain circumstances
  • Restrict processing in certain circumstances
  • Data portability - receive your data in a structured, machine-readable format
  • Object to processing based on legitimate interests
  • Withdraw consent where processing is based on consent (without affecting the lawfulness of processing before withdrawal)
  • Lodge a complaint with a supervisory authority (e.g. in your country of residence or where we are established)

To exercise any of these rights, please contact us via our contact page. We will respond within the time required by applicable law (e.g. one month under GDPR).

Security

We take appropriate technical and organisational measures to protect your personal data against unauthorised access, loss, or alteration. No method of transmission over the internet or electronic storage is 100% secure; we cannot guarantee absolute security.

Changes to this policy

We may update this Privacy Policy from time to time to reflect changes in our practices or in the law. We will post the updated policy on this page and revise the “last updated” date. We encourage you to review this page periodically.

Contact

For any questions about this Privacy Policy or our use of your personal data, please contact us via our contact page.

Last updated: February 2026