Data protection
Privacy Policy
We take your privacy seriously. This policy explains how we collect, use, and protect your personal data in accordance with the GDPR.
Last updated: August 2026
This is a convenience translation; the Danish version is legally binding.
Who is responsible for your data?
Hosting.gl ApS is the data controller for the processing of the personal data we receive about you. We ensure that your personal data is processed in accordance with applicable data protection legislation.
Contact details:
Hosting.gl ApS
Greenland
If you have questions about our processing of your personal data, please feel free to contact us.
Your rights
As a data subject, you have several rights under the GDPR:
- Right of access to your data
- Right to rectification
- Right to erasure
- Right to data portability
- Right to object
What information do we collect?
We only collect the information necessary to provide our services:
- Contact details: Name, email, and organisation when you create an account, report vulnerabilities, or contact us.
- Report data: Technical details about submitted vulnerability reports, including descriptions, screenshots, and proof of concept.
- Payment information: Bank details for paying out bounties. We do not store card details.
- Technical data: IP address, browser type, and device information for security and troubleshooting.
- Communication: Correspondence between you and us, or between you and companies on the platform.
- Activity log: Timestamps of actions on the platform for security and documentation purposes.
Why do we process your data?
We process your personal data for the following purposes:
- Provision of services: To operate our bug bounty platform and facilitate communication between researchers and companies.
- Paying out bounties: To be able to pay rewards to security researchers.
- Communication: To respond to enquiries and send relevant updates.
- Security: To protect the platform against misuse and ensure the integrity of our systems.
- Legal obligations: To comply with legal requirements, e.g. bookkeeping rules.
- Improvement: To analyse and improve our services (anonymised).
Legal basis
We process your data based on:
- Contract: Necessary to provide our services
- Consent: When you actively give permission
- Legitimate interest: Security and improvement of services
- Legal obligation: Statutory requirements
Who do we share data with?
We only share data in the following cases:
Companies on the platform:
When you report a vulnerability, relevant information is shared with the affected company. You can choose to report anonymously.
Service providers:
We use selected service providers for hosting, email, and payments. All providers are subject to data processing agreements.
Authorities:
We only disclose data to authorities if we are legally obliged to do so, or to protect our rights.
With your consent:
In other cases, we only share data with your express consent.
Anonymous reporting
You can choose to report vulnerabilities anonymously. In that case, we do not share your contact details with the company. Note: anonymous reporting may affect your ability to receive a bounty.
No sale of data
We never sell your personal data to third parties. Your data is not a commodity to us.
How long do we keep your data?
We retain your personal data for as long as necessary for the purposes for which it was collected:
- Account data: For as long as you have an active account, plus 2 years after deletion
- Vulnerability reports: 5 years for documentation and legal reasons
- Payment data: 5 years pursuant to bookkeeping legislation
- Communication: 2 years after the dialogue has ended
- Technical logs: 12 months
After the retention period, your data is deleted or anonymised.
Deleting your account
You can request deletion of your account at any time via our contact form. Certain data may need to be retained for legal reasons, even after account deletion.
What can you do with your data?
Under the GDPR, you have the following rights regarding your personal data:
- Right of access: You have the right to have confirmed whether we process your data and, if so, to access that information.
- Right to rectification: You have the right to have inaccurate information about you corrected and incomplete information completed.
- Right to erasure: You have the right to have your personal data deleted, unless we have a lawful reason to retain it.
- Right to data portability: You have the right to receive your data in a structured, machine-readable format and transfer it to another service.
How do we protect your data?
As a cybersecurity platform, we take data security very seriously. We implement appropriate technical and organisational measures:
- Encryption of data in transit (TLS/HTTPS)
- Encryption of sensitive data at rest
- Access control and authentication
- Regular security testing of our own systems
- Staff training in data protection
- Incident response procedures
No system is 100% secure, but we work continuously to protect your data as well as possible.
Data breach
In the event of a data breach affecting your rights, we will notify you and the relevant authorities in accordance with the GDPR.
Questions or complaints?
If you have questions about this privacy policy or wish to exercise your rights, you can contact us.
Complaints:
You have the right to lodge a complaint with the Danish Data Protection Agency (Datatilsynet) if you believe that we are processing your personal data in violation of the law.
Changes:
We may update this privacy policy from time to time. In the event of material changes, we will inform you via the platform or email.
Datatilsynet
The Danish data protection authority can be contacted at:
Datatilsynet
Carl Jacobsens Vej 35
2500 Valby
www.datatilsynet.dk
Contact us about your data
Do you have questions about our processing of your personal data, or wish to exercise your rights?