Privacy
Privacy notice
Last updated: 28 May 2026
Controller
NEOSEC GmbH, Parkstraße 30, 41061 Mönchengladbach. Privacy enquiries: datenschutz@neosec.de
Purpose of processing
Operating the vulnerability and threat-intel platform intel.neosec.io: aggregating public security sources, enriching with German analysis, exposing via API, webhook, RSS and web UI.
Lawful basis
Art. 6(1)(f) GDPR (legitimate interest in secure, stable operation) and Art. 6(1)(b) for subscriber and customer relationships.
Data categories
Server log files (IP, user agent, timestamp, path, status, referrer) — max. 7 days hot, then anonymised. Subscriber data (email, newsletter preferences) lives in the separate subscriber schema, never in advisory or enrichment schemas.
Subscriber tier
Sign-up via double-opt-in. Stored: email, timestamp, IP, confirmation token. Self-service erasure propagates in <24 h to all downstream systems. Lawful basis: Art. 6(1)(a)+(b) GDPR.
Customer tier
Contractual provision for XIEM customers. Mandatory TOTP, audit log of every admin action, multi-tenancy via PostgreSQL row-level security.
Hosting
Dedicated Hetzner machine, located in Germany. Data processing agreement with Hetzner Online GmbH in place. Backups encrypted to Backblaze B2 EU-Central (Netherlands), DPA in place.
Log files
Structured JSON logs (request_id, timestamp, level, event, service). Retention: 7 days container logs, 90 days audit DB hot, then S3 archive 2-7 years by data class. IPs anonymised after 7 days.
Cookies
Strictly necessary cookies: theme preference (intel_theme), cookie banner status (intel_consent), subscriber session (NextAuth), admin bearer (intel_admin_token). Tracking cookies (Matomo) only on active opt-in, revocable any time via the cookie banner.
Reach statistics (Matomo)
After active opt-in via the cookie banner we load Matomo Analytics from our own instance (mat.aundb.io, operated by NEOSEC GmbH). Collected: truncated IP address (last octet zeroed), URL, referrer, user agent, viewport size, dwell time. No third-party cookies, no data sharing. 90-day rolling retention. Lawful basis Art. 6(1)(a) GDPR (consent). Revoke any time via the cookie banner ("Essential only").
hCaptcha
On unauthenticated write endpoints (newsletter sign-up, contact) we use hCaptcha by Intuition Machines, Inc. Privacy: https://www.hcaptcha.com/privacy. Lawful basis: Art. 6(1)(f) GDPR.
Third-party sources
We aggregate publicly available security data: NVD, CVE.org, CISA KEV, BSI CERT-Bund, GHSA, abuse.ch, AlienVault OTX. Sources are cited and not 1:1 mirrored.
Retention
Log files 7 days hot, 90 days warm, then anonymised. Audit tables 7 years (Object-Lock bucket) per compliance. Subscriber data until revoked, max. 6 months inactive.
Your rights
Access (Art. 15), rectification (Art. 16), erasure (Art. 17), restriction (Art. 18), portability (Art. 20), objection (Art. 21). Requests to datenschutz@neosec.de — handled within 30 days.
Third-country transfer
By default none. Exception: Backblaze B2 (NL, EU). LLM calls go through a LiteLLM proxy with a guardrail policy that blocks subscriber PII via regex.
Automated decisions
No automated individual decisions with legal effect per Art. 22 GDPR.
Right to complain
You may file a complaint with the North Rhine-Westphalia Commissioner for Data Protection and Freedom of Information (LDI NRW) — https://www.ldi.nrw.de.
Updates
This privacy notice is updated upon material changes. Versioning in Git: git.aundb.io/neosec/neosec-intel.