1.Subject of this Policy
1.1
This Policy describes which information the website securitytest.team (the “Website”) stores on the device of a visitor or reads from it. The Website is operated by Osaühing Ida Portal, registry code 10970449 (the “Operator”, “we”).
1.2
In this Policy, “cookies” means cookies and every technology of a similar effect: the local and the session storage of the browser, databases of the browser, tracking pixels and the identification of a device by its characteristics.
1.3
The processing of personal data is described in the Privacy Policy.
2.What the Website stores on your device
2.1
The Website sets no cookies.
2.2
The Website writes nothing to the local storage, the session storage or the databases of the browser.
2.3
The Website contains no analytics, no advertising technologies, no tracking pixels, no components of social networks and no embedded content of third parties. Fonts, styles and scripts are delivered from the domain of the Website.
2.4
The campaign parameters contained in the address of a page are passed on to the links of that page and are sent together with a request, if you send one. They are not stored on your device.
2.5
The Operator keeps turned off the functions of Cloudflare that would set cookies in the domain of the Website: Bot Fight Mode, which sets the cookie __cf_bm; Turnstile pre-clearance and managed challenges, which set the cookie cf_clearance; and the unique-visitor option of rate limiting, which sets the cookie _cfuvid. The statement that the Website sets no cookies depends on these functions staying turned off.
3.Abuse check of the forms
3.1
The forms of the Website are protected against automated submissions by Turnstile, a service of Cloudflare, Inc. The service is not loaded when a page opens. It is loaded from the domain challenges.cloudflare.com only when you first move into a form, by selecting one of its fields or controls, or send the form, and it runs in a frame that is isolated from the Website.
3.2
In order to tell a person from a program, the service runs checks in the browser and reads technical signals of the browser, of the device and of the connection: the IP address, the characteristics of the browser and of the encrypted connection, and the results of the checks of the programming interfaces and of the behaviour of the browser. These signals are sent to Cloudflare. The service returns a one-time token to the Website; the Website sends the token together with the request, and the Operator has it verified by Cloudflare and does not store it.
3.3
The Operator establishes what the service stores by inspecting the storage of a browser, that is the cookies, the local and the session storage and the databases, for the domain of the Website and for the domain of the frame of the service, after a form has been filled in and sent. The Operator repeats the measurement after every change of the forms or of the configuration of Cloudflare and updates this Policy with its result.
3.4
According to the measurements of the Operator, the service stores the following on the device:
| Name | Type and location | Set by | Purpose | Storage period |
|---|---|---|---|---|
| cf.turnstile.u | Entry in the local storage of the domain challenges.cloudflare.com | Cloudflare, Inc. | Operation of the abuse check | Until the data of that domain is deleted in the browser |
3.5
The entry belongs to the domain of Cloudflare. The Website can neither read nor change it. The service sets no cookies in the domain of the Website.
3.6
The abuse check is strictly necessary to provide the service you explicitly request, the sending of a request, and to protect that service, and it starts only when you begin to use a form. For this reason its use does not require consent under Article 5(3) of Directive 2002/58/EC. As far as personal data is processed in the course of the check, the legal basis is the legitimate interest of the Operator in the security of the service, Article 6(1)(f) of Regulation (EU) 2016/679.
3.7
For the abuse check of the Website, Cloudflare, Inc. processes the signals on behalf of the Operator, as its processor. Cloudflare, Inc. also uses the signals as an independent controller to improve its detection of automated traffic, as described in its Turnstile Privacy Addendum and its Privacy Policy.
4.How to control the storage
4.1
You can delete the stored data and block the storage of data in the settings of your browser, for all websites or for a particular domain.
4.2
If the abuse check is blocked, the forms cannot be sent. In that case a request can be sent by email to info@securitytest.team.
4.3
All pages of the Website can be read with cookies, storage and scripts disabled.
5.Changes to this Policy
5.1
Before a technology that requires consent is introduced on the Website, the Operator will change this Policy and will ask for the consent of the visitor before that technology is used.
5.2
The version in force is the one published on this page, with the date from which it applies.