Legal
Privacy Policy
Last updated:
1. Controller and Contact
The controller responsible for processing personal data on this website is:
ResponsibleDisclosure
Website: https://responsibledisclosure.io
Email: [email protected]
If you have questions about this policy or wish to exercise your rights, contact us via the email above.
2. Overview and Key Principles
- Your data, not ours: we design for data minimization and exportability.
- Zero‑knowledge for report content: client‑side encryption; no plaintext at rest.
- No AI training: we do not train models on your data or share it with AI providers.
- No trackers by default: only essential cookies and logs for security/operation.
3. Categories of Personal Data We Process
- Account and onboarding data: organization name, domain, contact email, username, password (hashed), email verification tokens, two‑factor (TOTP) configuration and backup codes.
- Program and report metadata: program configuration, report identifiers, timestamps, status, labels/tags, attachment counts. Report content itself is end‑to‑end encrypted and not accessible to us.
- Communication data: emails we send (e.g., invitations, verifications) and your responses.
- Technical and log data: IP address, user‑agent, timestamps, request paths, error logs for security and abuse prevention.
- Cookies: essential session and CSRF cookies required to operate the service. No marketing or cross‑site tracking cookies.
4. Purposes and Legal Bases
- Service provision and onboarding (Art. 6(1)(b) GDPR): create and manage organizational accounts, program setup, authentication, email verification, two‑factor security.
- Security and abuse prevention (Art. 6(1)(f) GDPR): protect accounts, detect abuse, maintain availability, and ensure integrity; our legitimate interest in a secure service.
- Legal compliance (Art. 6(1)(c) GDPR): comply with legal obligations, respond to lawful requests.
- Communications (Art. 6(1)(b) or (f) GDPR): send transactional emails related to your use of the service. We do not send marketing without your consent.
- Consent‑based features (Art. 6(1)(a) GDPR): if we offer optional features that require consent, we will ask you explicitly and provide a way to withdraw.
5. Recipients and Processors
We use carefully selected service providers (processors) for hosting, email delivery, and infrastructure operations. These providers are contractually bound to process personal data only on our instructions and under appropriate safeguards. We do not sell personal data.
6. International Data Transfers
Where personal data is transferred outside the European Economic Area, we ensure appropriate safeguards (e.g., EU Standard Contractual Clauses) and implement additional measures where necessary. You can contact us for details about current processors and transfer mechanisms.
7. Retention
- Account and onboarding data: kept while the account is active and as required by law or to resolve disputes.
- Program and report metadata: retained as long as your organization maintains the program or as required by law. Encrypted report content remains encrypted; we cannot access the plaintext.
- Logs: typically up to 12 months, unless a longer period is needed for security or legal reasons.
- Backups: held for limited periods and rolled over on a schedule.
8. Your Rights (EU/EEA)
You have the right to request access, rectification, erasure, restriction, and data portability, and to object to processing based on legitimate interests. Where we rely on consent, you may withdraw it at any time (without affecting prior processing). You also have the right to lodge a complaint with a supervisory authority in the EEA member state of your residence or place of work.
To exercise your rights, contact: [email protected]. We will respond within the time periods required by law.
9. Children
Our service is intended for organizations and professionals. We do not knowingly collect personal data from children. If you believe a child has provided us personal data, contact us and we will take appropriate steps.
10. Security Measures
We use industry‑standard security measures including transport encryption, client‑side encryption of report content, two‑factor authentication, access controls, and regular updates. No system is perfectly secure; we continuously improve our defenses.
11. Changes
We may update this policy to reflect legal, technical, or business developments. The "Last updated" date indicates the latest revision. Significant changes will be communicated where appropriate.