$/fsec/friendsOffSec aus Leidenschaft ♥
ServicesApproachReportWhy usDE/ENIncident support
Legal

Privacy Policy

Last updated: 07/2026

This is a courtesy translation. The legally binding version is the German Datenschutzerklärung.

Website privacy policy

SecFriends GmbH i.G. (“sec/friends”), as the operator of these pages, takes the protection of your personal data very seriously. We treat your personal data confidentially and in accordance with statutory data protection regulations and this privacy policy. When you use this website, various items of personal data are collected. Personal data is data that can be used to identify you personally. This privacy policy explains what data we collect and what we use it for. It also explains how and for what purpose this happens. We would like to point out that data transmission over the internet (for example when communicating by email) can have security gaps. Complete protection of data against access by third parties is not possible.

General information

Details of the controller

Company
SecFriends GmbH i.G.
Represented by
Andrej Schwab
Address
Friedrich-Ebert-Str. 26, 34346 Hann. Münden, Germany
Contact
hallo@secfriends.com

General information on data processing

Scope of the processing of personal data

As a matter of principle, we process our users’ personal data only to the extent necessary to provide a functioning website together with our content and services. Processing takes place on the basis of (pre-)contractual necessity. In individual cases we also base it on our legitimate interests or on the consent of the data subject concerned. In such cases, users are specifically informed about the processing and about their rights to object or to withdraw consent.

Legal basis for the processing of personal data

Visiting the website constitutes a free-of-charge usage agreement, which means that Art. 6(1)(b) GDPR generally serves as the legal basis. This also applies to processing operations that are necessary in order to carry out pre-contractual measures.

Where processing is necessary to safeguard a legitimate interest of our company or of a third party, and where the interests, fundamental rights and freedoms of the data subject do not override that interest, Art. 6(1)(f) GDPR serves as the legal basis for the processing. In this case the data subject has a right to object pursuant to Art. 21 GDPR.

Where processing takes place on the basis of consent, Art. 6(1)(a) GDPR is the applicable legal basis. Consent is always voluntary and may be withdrawn at any time, without giving reasons, with effect for the future.

Erasure of data and storage period

We erase a data subject’s personal data as soon as the purpose of storage no longer applies and any applicable retention periods have expired. Data may be stored beyond this point where provided for by the European or national legislator in Union regulations, laws or other provisions to which we are subject. Where erasure is not yet legally possible, we can and will restrict the data in the individual case. Such a restriction reduces access to the data and its processing to an absolute minimum, for example archiving for potential legal disputes or statutory retention periods for official audits.

Provision of the website and creation of log files

Each time our website is accessed, our system automatically collects data and information from the computer system of the accessing device. The following data is collected in this context:

  • Information about the browser type and version used
  • The user’s operating system
  • The user’s IP address
  • Date and time of access
  • Websites from which the user’s system reaches our website

The data is stored in our system’s log files in order to ensure the proper and secure operation of our pages and to be able to investigate any malfunctions. This data is not stored together with other personal data of the user. The log files are automatically deleted after 30 days.

The legal basis for the temporary storage of the data and the log files is Art. 6(1)(b) in conjunction with Art. 32 GDPR.

Temporary storage of the IP address by the system is necessary in order to deliver the website to the user’s device. For this purpose, the user’s IP address must remain stored for the duration of the session. Subsequent storage in log files takes place in order to ensure the functionality of the website. The data also serves to ensure the security of our systems. No further evaluation of the data for marketing purposes takes place in this context.

Users’ personal data is processed and stored in log files for a maximum of 30 days and is then deleted automatically. Storage beyond this period is possible only in special individual cases where there are concrete indications of incidents requiring investigation. In such cases, users’ IP addresses are deleted or obfuscated wherever possible, so that the accessing client can no longer be identified.

Cookies

This website does not use cookies.

Hosting

We host the content of our website with IONOS SE, Elgendorfer Str. 57, 56410 Montabaur, Germany (hereinafter IONOS). When you visit our website, IONOS records log files including your IP addresses. This processing is carried out exclusively on our behalf and is safeguarded by a data processing agreement pursuant to Art. 28 GDPR.

Appointment booking via Proton Calendar

To arrange an intro call, we link to a booking form provided by Proton AG, Route de la Galaise 32, 1228 Plan-les-Ouates, Switzerland (hereinafter Proton). The link is only followed when you click it – as long as you do not click it, no data is transmitted from our website to Proton.

If you open the booking form, Proton processes the data you enter there – in particular your name, email address, preferred appointment and an optional message – together with the connection data required for technical reasons. The purpose of the processing is to arrange and carry out the appointment. The legal basis is Art. 6(1)(b) GDPR, as arranging the appointment serves to carry out pre-contractual measures.

On the basis of an adequacy decision by the European Commission, Switzerland is regarded as a third country with an adequate level of data protection within the meaning of Art. 45 GDPR. The processing is carried out on our behalf under a data processing agreement pursuant to Art. 28 GDPR.

We erase the data collected in the course of arranging an appointment as soon as the appointment has been completed and the purpose of storage no longer applies, unless statutory retention periods prevent this. Further information can be found in Proton’s privacy policy: proton.me/legal/privacy.

Reporting security incidents (incident response)

For reporting acute security incidents, we provide the email address secfriends@ir-hotline.com. This address is not operated by us but by an external partner:

Company
Quirso GmbH
Address
August-Bebel-Straße 26-53, 14482 Potsdam, Germany
Server location
Germany

If you write to this address, the data transmitted – in particular your sender address, the content of the message, any attachments and information about the affected system – is received, stored and processed by this partner in order to handle the reported incident. The purpose is to be reliably reachable and to handle security incidents.

The legal basis is Art. 6(1)(b) GDPR insofar as the report serves to initiate or perform a contract, and otherwise Art. 6(1)(f) GDPR on the basis of our legitimate interest in a reliably reachable reporting point for security incidents. The processing is carried out on our behalf and is safeguarded by a data processing agreement pursuant to Art. 28 GDPR.

Where processing takes place outside the European Union or the European Economic Area, we base the transfer on standard contractual clauses.

The data is erased as soon as the reported incident has been dealt with conclusively and the purpose of storage no longer applies, at the latest after 30 Days, unless statutory retention periods prevent this.

For general enquiries that do not concern an acute security incident, please use hallo@secfriends.com.

Rights of the data subject

If your personal data is processed, you are a data subject within the meaning of the GDPR and you have the following rights vis-à-vis the controller:

Right of access, Art. 15 GDPR

You have the right to request confirmation as to whether data concerning you is being processed, to obtain information about that data as well as further information, and to receive a copy of the data in accordance with statutory requirements.

Right to rectification, Art. 16 GDPR

You have a right to rectification and/or completion vis-à-vis us if the processed personal data concerning you is inaccurate or incomplete.

Right to erasure and restriction of processing, Art. 17, 18 GDPR

In accordance with statutory requirements, you have the right to request that data concerning you be erased without undue delay or, alternatively, in accordance with statutory requirements, to request a restriction of the processing of the data.

Right to data portability, Art. 20 GDPR

You have the right to receive the personal data concerning you that you have provided to us in a structured, commonly used and machine-readable format.

Right to object, Art. 21 GDPR

You have the right to object at any time, on grounds relating to your particular situation, to the processing of personal data concerning you which is carried out on the basis of Art. 6(1)(e) or (f) GDPR.

Right to lodge a complaint with a supervisory authority, Art. 77 GDPR

Without prejudice to any other administrative or judicial remedy, you have the right to lodge a complaint with any data protection supervisory authority if you consider that the processing of personal data concerning you infringes the GDPR. The supervisory authority forwards complaints according to its competence.

Changes to our privacy provisions

Our websites and our security and data protection measures may change over time. This may make changes to our privacy information necessary. We therefore always provide the current version of our privacy information.

← Back to the home page
sec/friends — OffSec aus Leidenschaft ♥Legal notice · Privacy · Responsible Disclosure