Privacy

Privacy notice

Last updated: 28 May 2026

Controller

NEOSEC GmbH, Parkstraße 30, 41061 Mönchengladbach. Privacy enquiries: datenschutz@neosec.de

Purpose of processing

Operating the vulnerability and threat-intel platform intel.neosec.io: aggregating public security sources, enriching with German analysis, exposing via API, webhook, RSS and web UI.

Lawful basis

Art. 6(1)(f) GDPR (legitimate interest in secure, stable operation) and Art. 6(1)(b) for subscriber and customer relationships.

Data categories

Server log files (IP, user agent, timestamp, path, status, referrer) — max. 7 days hot, then anonymised. Subscriber data (email, newsletter preferences) lives in the separate subscriber schema, never in advisory or enrichment schemas.

Subscriber tier

Sign-up via double-opt-in. Stored: email, timestamp, IP, confirmation token. Self-service erasure propagates in <24 h to all downstream systems. Lawful basis: Art. 6(1)(a)+(b) GDPR.

Customer tier

Contractual provision for XIEM customers. Mandatory TOTP, audit log of every admin action, multi-tenancy via PostgreSQL row-level security.

Hosting

Dedicated Hetzner machine, located in Germany. Data processing agreement with Hetzner Online GmbH in place. Backups encrypted to Backblaze B2 EU-Central (Netherlands), DPA in place.

Log files

Structured JSON logs (request_id, timestamp, level, event, service). Retention: 7 days container logs, 90 days audit DB hot, then S3 archive 2-7 years by data class. IPs anonymised after 7 days.

Cookies

Strictly necessary cookies: theme preference (intel_theme), cookie banner status (intel_consent), subscriber session (NextAuth), admin bearer (intel_admin_token). Tracking cookies (Matomo) only on active opt-in, revocable any time via the cookie banner.

Reach statistics (Matomo)

After active opt-in via the cookie banner we load Matomo Analytics from our own instance (mat.aundb.io, operated by NEOSEC GmbH). Collected: truncated IP address (last octet zeroed), URL, referrer, user agent, viewport size, dwell time. No third-party cookies, no data sharing. 90-day rolling retention. Lawful basis Art. 6(1)(a) GDPR (consent). Revoke any time via the cookie banner ("Essential only").

hCaptcha

On unauthenticated write endpoints (newsletter sign-up, contact) we use hCaptcha by Intuition Machines, Inc. Privacy: https://www.hcaptcha.com/privacy. Lawful basis: Art. 6(1)(f) GDPR.

Third-party sources

We aggregate publicly available security data: NVD, CVE.org, CISA KEV, BSI CERT-Bund, GHSA, abuse.ch, AlienVault OTX. Sources are cited and not 1:1 mirrored.

Retention

Log files 7 days hot, 90 days warm, then anonymised. Audit tables 7 years (Object-Lock bucket) per compliance. Subscriber data until revoked, max. 6 months inactive.

Your rights

Access (Art. 15), rectification (Art. 16), erasure (Art. 17), restriction (Art. 18), portability (Art. 20), objection (Art. 21). Requests to datenschutz@neosec.de — handled within 30 days.

Third-country transfer

By default none. Exception: Backblaze B2 (NL, EU). LLM calls go through a LiteLLM proxy with a guardrail policy that blocks subscriber PII via regex.

Automated decisions

No automated individual decisions with legal effect per Art. 22 GDPR.

Right to complain

You may file a complaint with the North Rhine-Westphalia Commissioner for Data Protection and Freedom of Information (LDI NRW) — https://www.ldi.nrw.de.

Updates

This privacy notice is updated upon material changes. Versioning in Git: git.aundb.io/neosec/neosec-intel.

NEOSEC Intel — NEOSEC Intel