LEGAL

Privacy Policy

Effective date: 2026-07-26

We run offensive.technology and we try to practice the data minimization we preach. This policy explains what personal data we collect, why, and what rights you have. It applies to visitors of this website and to customers of our services.

Who we are

The data controller is Offensive Technology, operated from Poland. For anything in this policy, contact us at [email protected].

What we collect and why

Visiting the site. This website sets no cookies and runs no third-party analytics. Fonts and other assets are served from our own infrastructure. Our server keeps standard access logs: your IP address, browser user agent, the pages requested, and timestamps. We keep these for server security and abuse prevention, based on our legitimate interest in protecting our infrastructure (Article 6(1)(f) GDPR).

Requesting a check or engagement. If you use our intake form, we collect your name, work email, company, the target domain you want tested, and any notes you add. We use this to verify that you are authorized to have the target tested, to scope the work, and to deliver it. The legal basis is performance of a contract, or steps you request before entering one (Article 6(1)(b) GDPR). This data is stored in our own database on a server hosted in the EU (Google Cloud, europe-central2 region, Warsaw, Poland).

Payments. Payments are handled by a third-party payment processor. Your card details go directly to that processor and never touch our systems. We receive only confirmation of payment and basic billing details. The processor's own privacy policy governs its processing.

Scheduling a readout call. When you book a call with us, our scheduling provider processes your name, email, and chosen time slot so the booking works. The legal basis is performance of our contract with you.

Email. If you email us, we keep the correspondence as long as needed to handle your request and any follow-up.

We do not sell personal data, and we do not use it for advertising.

How long we keep data

Who else sees your data

We share personal data only with service providers who help us operate: our EU hosting provider (Google Cloud), a payment processor, and our scheduling provider. Each acts under a data processing agreement or equivalent terms. We disclose data to authorities only where the law requires it.

International transfers

Our team operates from Ukraine and Poland. Ukraine is outside the EU and has no adequacy decision from the European Commission, so where personal data is accessed from Ukraine we rely on appropriate safeguards such as the European Commission's Standard Contractual Clauses. Some providers may process data in the United States under recognized transfer mechanisms. You can ask us at [email protected] for details of the safeguards used.

Your rights

If you are in the EU or EEA, you can ask us to access, correct, delete, or export your personal data, to restrict or object to processing, and, where processing rests on consent, to withdraw that consent at any time without affecting earlier processing. Write to [email protected] and we will respond within one month. You also have the right to complain to a data protection supervisory authority, in particular in the EU country where you live or work.

If you are in the United States, you can make the same requests and we will honor them wherever we reasonably can.

Security

We are a security company, and we treat your data accordingly: encrypted transport, access limited to people who need it, and minimal collection in the first place.

Changes

We will post any changes to this policy on this page with a new effective date. If a change is significant and we have your email, we will tell you directly.