Privacy notice
This notice describes personal data processed by CyberSecLab under KVKK article 10 and, where applicable, the GDPR. The site is in beta.
Controller
Personal data is processed by the operator of CyberSecLab. Contact: the email published on the contact page.
What we collect
For an offline-tool request: name, organization, email and domain, selected platforms and operating systems, optional notes, consent records, locale, and request status. To limit abuse we may store a hash of your IP (not the raw IP). If you email us, we process the message. Site traffic may use cookieless Vercel Analytics; we do not build ad profiles.
Purpose and legal basis
Purpose: review closed field-test requests, send the offline tool when appropriate, coordinate logs and feedback, and limit abuse. Legal basis: your explicit consent (form checkboxes) and legitimate interest (security / spam). Without consent, no request is created.
Transfers and retention
Data is processed on hosting and database providers (Supabase / Vercel; an EU region is preferred). It is not sold or used for third-party marketing. Requests are kept until the program ends or you ask us to delete them, then deleted or anonymized after a reasonable period.
Your rights
You may exercise KVKK article 11 rights (access, correction, deletion, withdraw consent, and others) via the contact email. Withdrawing consent does not make prior processing unlawful.
Logs and feedback
Avoid secrets, passwords, and unnecessary personal data in scan logs you share. We use submitted logs to improve the product and do not publish raw environment configuration.
This notice is general information, not legal advice. Use the contact email for questions.