Privacy policy

Information about the processing of personal data in accordance with the General Data Protection Regulation (GDPR).
The protection of your personal data is important to us. Below, we inform you about how your data is processed in the context of this Security Hub.

1. Controller

iFD GmbH
Schulstraße 44
09125 Chemnitz
Germany

2. Data Protection Officer

DataCo GmbH
Sandstr. 33
80335 München
Germany

3. General information on data processing

The protection of your personal data is important to us. We process personal data exclusively within the framework of the applicable data protection regulations, in particular the General Data Protection Regulation (GDPR).

4. Access to the website

When you visit this website, technically necessary information is processed by the web server. This includes in particular:

  • IP address
  • Date and time of access
  • Requested URL
  • Browser type and browser version
  • Operating system
  • HTTP status code
  • Referrer URL (if transmitted)

The processing is carried out to ensure the secure and stable operation of the website.

5. Contact form and security reports

Security incidents, vulnerability reports and general security enquiries can be submitted through this Security Hub.

The following data may be processed in this context:

  • Name
  • Organisation or company
  • Email address
  • Phone number (optional)
  • Description of the vulnerability
  • Affected products or systems
  • File attachments and technical evidence
  • Time of the report
  • IP address for abuse prevention

The data is used exclusively to process the report, to communicate with reporters and to improve the security of our products and services.

6. Coordinated Vulnerability Disclosure (CVD)

As part of our vulnerability disclosure programme, we store the information required to process a security report. A reporter's name is only published with their explicit consent.

7. Disclosure of data

Personal data is only disclosed to the extent required to process the report or where legal obligations exist.

8. Storage duration

Personal data is stored only for as long as is necessary for processing security reports, documentation, evidencing or statutory retention obligations.

9. Technical and organisational measures

To protect your data, we employ appropriate technical and organisational security measures, in particular:

  • HTTPS/TLS encryption
  • Access restrictions
  • Regular security updates
  • Logging of security-relevant events

10. Cookies

This website uses only technically necessary cookies and local storage mechanisms, for example for language settings or the light/dark mode display.

11. Your rights

You have the following rights under the GDPR:

  • Access
  • Rectification
  • Erasure
  • Restriction of processing
  • Data portability
  • Objection to processing

Please send requests to:ifd@ifd-gmbh.com

12. Right to lodge a complaint

You have the right to lodge a complaint with a data protection supervisory authority.

Saxon Data Protection and Transparency Officer (SDTB)
Devrientstraße 5
01067 Dresden
www.datenschutz.sachsen.de

As of: July 2026