Privacy Policy

The website sets no cookies and uses no analytics or advertising technologies. Personal data is processed when you send a request, take part in the bug bounty platform or write to us, and only in order to answer you, to conclude and perform a contract and to meet the obligations the law places on us.

1.Controller and scope

1.1

The controller of the personal data described in this Policy is Osaühing Ida Portal, a private limited company registered in the Commercial Register of the Republic of Estonia under registry code 10970449, registered office: Kivilinna tn 18-49, 20604 Narva, Ida-Viru maakond, Estonia (the “Operator”, “we”). The Operator provides its services under the name Security Test Team.

1.2

Questions and requests that concern personal data are sent to info@securitytest.team. The Operator has not designated a data protection officer.

1.3

This Policy applies to the website securitytest.team in all its language versions (the “Website”), to the forms of the Website, to the bug bounty platform the Operator runs on the Website (the “Platform”) and to correspondence with the Operator.

1.4

This Policy does not apply to personal data that the Operator may encounter in the systems of a client while it performs a security check or a security assessment, or that a report of a researcher contains. Such data is processed on behalf of the client or of the owner of a program, who is its controller, under the contract and the data processing terms of the Terms of the Free Website Security Check and of the Terms of the Bug Bounty Platform for Owners.

1.5

The Operator processes personal data in accordance with Regulation (EU) 2016/679 (the “GDPR”) and the Personal Data Protection Act of the Republic of Estonia. The Acts named in this Policy without a State are Acts of the Republic of Estonia.

2.Personal data we process

2.1

Visiting the Website. The Operator itself collects no personal data about a visitor who reads the Website: the Website sets no cookies, keeps no visitor logs of its own, builds no profiles and contains no analytics or advertising technologies. The hosting provider, Cloudflare, Inc., processes the IP address and the technical data of each request to the extent necessary to deliver the pages and to protect the service against attacks.

2.2

Forms of the Website. When you send a request for a service, an application for a program or an application of a researcher, the Operator processes:

  1. (a)identification and contact data: name, email address, organisation, role, the preferred channel of communication and the account or number in that channel;
  2. (b)the content of the request: the services of interest, the address of the website or the system, the desired start, the rewards and the visibility of a program, and the text of the request;
  3. (c)the data of a researcher: the country of residence, the link to a public profile and the description of experience;
  4. (d)your confirmations: that you are entitled to commission the testing of the systems named in the request and act in the course of your business or profession, that you are of age and that you accept the terms of the Platform, together with the version of the terms you accepted and the version of this Policy shown next to the form;
  5. (e)technical data of the request: the time, the language of the page, the page the form was sent from, the campaign parameters contained in the address of that page, the country derived from the IP address, and the beginning of the identification string of the browser;
  6. (f)a keyed hash of the IP address. The IP address itself is not stored by the Operator and cannot be restored from the hash without a key that is kept separately from the data.

2.3

Correspondence. When you write to the Operator by email or through a messenger, the Operator processes your address or account, the content of the messages and the time they were sent.

2.4

Contract. When a contract is concluded, the Operator processes the names, positions and contact data of the signatories and contact persons of the client, the data contained in the authorisation to test and in the documents that confirm the ownership of a system, and the data of invoices and payments.

2.5

Platform, researchers. When a researcher takes part in the programs, the Operator processes the reports of the researcher, the correspondence about them and the name the researcher has chosen. Before the first payment it also processes the information listed in Section 4, the declarations of the researcher on the State of tax residence, the State in which the research is carried out and the payee, the result of the check of identity and of the checks against the lists of international sanctions, and the data of the payments. Where the payee is a legal person, the Operator also processes the data of its representatives and of the persons who own 50 % or more of it or control it.

2.6

Platform, owners. When the owner of a program is verified, the Operator processes the data of its representatives and of the persons who own 50 % or more of it or control it, the data of the documents that confirm the right to represent it and its control over the systems in the program, the result of the checks against the lists of international sanctions and, for an owner who is a natural person, the result of the check of identity.

2.7

The Operator also receives personal data from sources other than the person concerned:

  1. (a)from a client or an owner: the names, positions and contact data of its representatives, signatories and contact persons;
  2. (b)from a requester: the data of other persons named in the request;
  3. (c)from a researcher: the data of the representatives of a payee that is a legal person and of the persons who own or control it;
  4. (d)from public registers, which are publicly accessible: the representatives of an owner or of a payee and the persons who own or control it;
  5. (e)from the page a researcher links to in an application, which is publicly accessible: the data of the public profile;
  6. (f)from the public lists of international sanctions: whether a person is listed;
  7. (g)from the electronic interfaces of the European Union and of the Member States: whether a tax identification number or a VAT identification number is valid.

2.8

Where the Operator contacts a person whose data it has received from another source, it refers that person to this Policy in its first communication at the latest.

2.9

The Operator does not request special categories of personal data, data about criminal convictions, passwords or access keys, and asks you not to send them through the forms or by email.

2.10

The provision of personal data through a form is neither a statutory nor a contractual requirement; without the data marked as required, the Operator cannot answer the request. The information a researcher gives before the first payment (Section 4) is required by law and by the Terms of the Bug Bounty Platform for Researchers; without it no reward is paid.

3.Purposes and legal bases

3.1

The Operator processes personal data for the following purposes and on the following legal bases:

PurposeDataLegal basis
Answering a request and preparing a proposalData of the request forms, correspondenceSteps taken at your request prior to entering into a contract, Article 6(1)(b) GDPR; where you write on behalf of an organisation, the legitimate interest of the Operator and of that organisation in answering the enquiry, Article 6(1)(f) GDPR
Conclusion and performance of a contract with a client or with the owner of a programContract data, data of the verification of an owner, correspondencePerformance of a contract, Article 6(1)(b) GDPR; where you act on behalf of an organisation, the legitimate interest of the Operator and of that organisation in concluding and performing the contract, Article 6(1)(f) GDPR
Registration of a researcher, examination of reports, payment of rewardsApplication of a researcher, reports, data of the payee and of the account, payment dataPerformance of the contract with the researcher, Article 6(1)(b) GDPR; where the payee is a legal person, the legitimate interest of the Operator and of that legal person in performing the contract with it, Article 6(1)(f) GDPR
Check of the identity of a researcher and of an owner who is a natural personName, date of birth, the type, the number, the issuing State and the expiry date of the identity document, the date, the method and the result of the checkPerformance of the contract, Article 6(1)(b) GDPR; the legitimate interest of the Operator and of the owners in knowing who researches their systems and to whom a reward is paid, and in preventing fraud, Article 6(1)(f) GDPR. No copy of the identity document is kept
Checking that a reward is paid only where Estonian law requires no tax to be withheld from itState of tax residence, State in which the research is carried out, the payee and its entry in a registerPerformance of the contract, Article 6(1)(b) GDPR; legal obligation to determine whether income tax is to be withheld, Article 6(1)(c) GDPR, under §§ 40 and 41 of the Income Tax Act
Due diligence and reporting on researchers and payees as a platform operatorThe information of Section 4Legal obligation, Article 6(1)(c) GDPR, under Article 8ac of and Annex V to Council Directive 2011/16/EU and §§ 20²⁰–20²⁶ and § 8(3) of the Tax Information Exchange Act
Compliance with international sanctions before a program is published and before every paymentName, date of birth, address, the persons who own or control an owner or a payee, the bank of the account, the result of the checkLegal obligation, Article 6(1)(c) GDPR, under Regulation (EU) No 269/2014 and § 19 of the International Sanctions Act
Protection of the forms against abuse, limitation of the number of requestsHash of the IP address, time of the request, technical signals of the abuse checkLegitimate interest of the Operator in the security and availability of the service, Article 6(1)(f) GDPR
Proof of the confirmations given in a form and of the version of this Policy shown next to itConfirmations, versions of the terms and of this Policy, time of the requestLegitimate interest of the Operator in being able to prove what was confirmed and which information was given, Article 6(1)(f) GDPR
Accounting and tax obligationsInvoices, payment data, contractsLegal obligation, Article 6(1)(c) GDPR, under § 12 of the Accounting Act, § 36 of the Value-Added Tax Act and § 58 of the Taxation Act
Disclosure of the identity of a researcher to an owner, and public acknowledgement of a researcher, at the wish of the researcherName of the researcher, the reports concernedConsent of the researcher, Article 6(1)(a) GDPR
Establishment, exercise and defence of legal claims, including the proof that a test was authorisedData necessary for the claim, confirmations of authority, signed authorisationsLegitimate interest of the Operator in the protection of its rights, and of an owner where a researcher has acted outside a program or the rules of the Platform, Article 6(1)(f) GDPR

3.2

The Operator makes no decisions based solely on automated processing that produce legal effects for you or similarly significantly affect you, performs no profiling, does not use personal data for advertising and does not sell personal data.

3.3

The Operator does not process personal data for a purpose incompatible with the purposes listed in this section.

4.Reporting on researchers to the tax authority

4.1

The Operator is a reporting platform operator under Council Directive 2011/16/EU, as amended by Council Directive (EU) 2021/514, and under Chapter 2⁴ of the Tax Information Exchange Act. This section informs each researcher and each payee that information about them is collected and reported, as Article 25(4) of that Directive requires.

4.2

Before the first payment the Operator collects the following information about each researcher and each payee who is a natural person, and it records the rewards paid to them:

  1. (a)the first and the last name, the primary address and the date of birth;
  2. (b)every tax identification number and the State that issued it or, where none has been issued, the place of birth;
  3. (c)the VAT identification number, where one has been issued;
  4. (d)for a sole proprietor, the register in which the business is entered and its registry code;
  5. (e)the identifier of the account to which rewards are paid and the name of its holder;
  6. (f)the rewards paid in each quarter and the number of the reports for which they were paid.

4.3

The Operator verifies the information against the documents it receives, against public registers and against the electronic interfaces that the European Union and the Member States make available free of charge for checking tax identification numbers and VAT identification numbers.

4.4

Each year, by 31 January of the following year, the Operator reports this information about the researchers and the payees who are resident in a Member State of the European Union, or in a jurisdiction listed by the Estonian Tax and Customs Board, to the Estonian Tax and Customs Board. The Board exchanges it with the tax authorities of the State or the States of residence.

4.5

Before the information is reported, and by 31 January at the latest, the Operator gives each person the information about him or her that it will report, so that the person can exercise the rights of Section 9 in time.

4.6

The information is required by law and by the Terms of the Bug Bounty Platform for Researchers. A reward is paid only after the information has been given and checked.

5.Recipients

5.1

Within the Operator, personal data is accessible to the managers who answer requests and to the specialists who prepare proposals, examine reports and perform contracts, to the extent their duties require.

5.2

The owner of a program receives the reports about its systems under the name the researcher has chosen. The Operator does not disclose the identity of a researcher to an owner without the consent of the researcher, unless the researcher has acted outside the program or the rules of the Platform and the owner needs the identity to establish, exercise or defend legal claims, or the law requires the disclosure.

5.3

The Operator discloses personal data to the following recipients:

RecipientRoleData
Cloudflare, Inc., United StatesProcessor. Hosting of the Website, reception of the forms, storage of requests in a database located in the European Union, the abuse check of the forms, and forwarding of the email sent to the addresses of the domain securitytest.team to the mailbox of the Operator (Cloudflare Email Routing)Request data, IP address, the signals of the abuse check, email sent to the Operator
Cloudflare, Inc., United States (Cloudflare Email Service)Processor. Sending of each request by email from an address of the domain securitytest.team to the mailbox of the OperatorRequest data
Cloudflare, Inc., United StatesIndependent controller of the signals of the abuse check that it uses to improve its detection of automated traffic, as described in its Turnstile Privacy AddendumIP address, characteristics of the browser, of the device and of the connection
Google Ireland Limited, Ireland (Gmail)Independent controller of the mailbox of the Operator, in which the Operator receives email and from which it replies. Google processes the content of the mailbox under its own privacy policy and is not a processor of the OperatorRequest data, correspondence
Telegram Messenger Inc., outside the European Economic AreaIndependent controller of its messenger. Delivers to the closed chat of the managers the notice that a request has arrivedNo personal data of the requester. The notice states the reference number and the kind of the request, the services and the timeline or the range of rewards and the visibility of a program, the language of the page and the time of receipt
The provider of the messenger you choose for correspondenceIndependent controller of its messenger, under its own terms. Receives the messages only if you ask to be answered through itYour account in the messenger, the messages
Estonian Tax and Customs Board (Maksu- ja Tolliamet), EstoniaReceives the information the Operator reports as a platform operator, as described in Section 4, and exchanges it with the tax authorities of the States of residence; receives accounting and tax documents in a tax auditThe information of Section 4, accounting and tax documents
Financial Intelligence Unit, EstoniaReceives a notification where a person is subject to financial sanctions or where that cannot be excluded (§ 19 of the International Sanctions Act)The data of that person and of the payment concerned
The bank that keeps the account of the OperatorExecutes the payments of rewards and receives the payments to the OperatorName of the payer or of the payee, account, amount, reference of the payment
Accounting, audit and legal advisersAccounting, audit, protection of the rights of the OperatorContract and payment data, to the extent the task requires

5.4

When the Operator processes personal data on behalf of a client or of the owner of a program as described in Section 1, it engages one sub-processor: Cloudflare, Inc., United States, for hosting and for the storage of data in the European Union. The Operator does not send such data by email or through messengers and does not place it in its mailbox: reports and evidence are exchanged through the secure channel named in the contract.

5.5

The Operator discloses personal data to courts, supervisory and law enforcement authorities only where the law obliges it to do so, and only to the extent required.

6.Transfers outside the European Economic Area

6.1

The recipients of Section 5 that are established outside Estonia, and the bases on which personal data is transferred to them outside the European Economic Area, are the following:

RecipientCountryBasis
Cloudflare, Inc.United StatesAdequacy decision on the EU-US Data Privacy Framework, Commission Implementing Decision (EU) 2023/1795, Article 45 GDPR; Cloudflare, Inc. participates in the Framework. If that basis ceases to apply, the standard contractual clauses of Commission Implementing Decision (EU) 2021/914 apply under the data processing addendum of Cloudflare, Article 46(2)(c) GDPR
Google Ireland LimitedIrelandNo transfer: the recipient is established in the European Economic Area. As an independent controller, Google is responsible for its own transfers
Telegram Messenger Inc.Outside the European Economic AreaNo transfer: no personal data of requesters is sent
The provider of the messenger you chooseThe State of that providerWhere the provider is established outside the European Economic Area, the Operator sends its messages there only because you have asked to be answered through that messenger, Article 49(1)(b) GDPR

6.2

The database of requests is stored in the European Union. The Website, the forms, the abuse check and the processing of email run in the global network of Cloudflare, which includes data centres outside the European Economic Area.

6.3

Through a messenger the Operator only arranges the next steps. Credentials, keys and details of vulnerabilities are exchanged only through the secure channel agreed with you.

6.4

A copy of the safeguards that apply to a particular transfer is provided on request sent to info@securitytest.team.

7.Retention periods

7.1

A request sent through a form is stored for 365 days from the day it was received and is then erased automatically. For up to seven days after its erasure it remains in the recovery history of the database, Cloudflare D1 Time Travel, from which it can be restored only by restoring the whole database to an earlier moment. The Operator deletes the copy of a request delivered to its mailbox within the same period; after that, Google may keep the deleted copy for the periods stated in its own privacy policy. The Operator keeps the previews of Cloudflare Email Service turned off; that function would keep a copy of every sent message for about seven days.

7.2

Correspondence that did not lead to a contract is erased no later than 365 days after the last message.

7.3

Where a request leads to a test, the Operator moves the confirmation of authority given in the request to the file of the contract. That confirmation and the signed authorisation to test are kept with the contract until the limitation periods for the claims and the offences related to the test have expired, and in any case for at least five years after the test.

7.4

The data of a researcher and of an owner is kept for the duration of the contract and afterwards for the periods of this section. The Operator keeps no copy of an identity document; it keeps the record of the check of identity with the information of Section 4.

7.5

The information of Section 4 and the records of the steps taken to collect and verify it are kept at least for the current calendar year and the six preceding calendar years, and no longer than ten years (§ 8(3) of the Tax Information Exchange Act). The record of a check against the lists of international sanctions is kept with the documents of the payment it preceded.

7.6

Accounting and tax documents are kept for the following periods; where several periods apply to a document, the longest applies:

  1. (a)accounting source documents, such as invoices and the documents of payments: seven years from the end of the financial year in which the transaction was entered in the books (§ 12(1) of the Accounting Act);
  2. (b)contracts, ledgers, reports and the other business documents necessary to reconstruct transactions: seven years from the end of the financial year they concern (§ 12(2) of the Accounting Act);
  3. (c)documents relating to long-term rights and obligations, such as the contracts with clients, owners and researchers and the licences to reports: seven years after they have expired (§ 12(3) of the Accounting Act);
  4. (d)invoices: seven years from their issue or receipt (§ 36 of the Value-Added Tax Act);
  5. (e)other documents relevant for taxation: seven years from 1 January of the year following their preparation or receipt (§ 58 of the Taxation Act).

7.7

Data necessary for the establishment, exercise or defence of a legal claim is kept until the claim has been finally resolved, and otherwise until the limitation period of the claim has expired.

8.Cookies and similar technologies

8.1

The Website sets no cookies and stores nothing on your device. The automated abuse check of the forms is provided by Cloudflare Turnstile. It starts only when you begin to fill in a form or send it. What it stores and reads on your device is described in the Cookie Policy.

9.Your rights

9.1

To the extent and under the conditions laid down in the GDPR, you have the right:

  1. (a)to obtain confirmation as to whether your personal data is processed, access to the data and a copy of it (Article 15);
  2. (b)to have inaccurate data rectified and incomplete data completed (Article 16);
  3. (c)to have your data erased (Article 17);
  4. (d)to have the processing restricted (Article 18);
  5. (e)to receive the data you have provided in a structured, commonly used and machine-readable format and to transmit it to another controller (Article 20);
  6. (f)to object, on grounds relating to your particular situation, to processing based on a legitimate interest (Article 21);
  7. (g)to withdraw a consent at any time, where the processing is based on it. The withdrawal does not affect the lawfulness of the processing carried out before it (Article 7(3)).

9.2

To exercise a right, write to info@securitytest.team and, if you have sent a request through a form, state its reference. The Operator may ask for the information necessary to confirm your identity. As a rule it confirms your identity through the address or the account known to it from your request or your correspondence, and it does not ask for a copy of an identity document.

9.3

The Operator answers within 28 days of receipt of the request. Where the complexity or the number of requests requires it, the period may be extended by up to two further months in accordance with Article 12(3) GDPR; you are informed of the extension and of its reasons within the initial period. The exercise of the rights is free of charge.

9.4

You have the right to lodge a complaint with a supervisory authority, in particular in the Member State of your habitual residence, of your place of work or of the alleged infringement. The supervisory authority of the Operator is the Estonian Data Protection Inspectorate (Andmekaitse Inspektsioon), Tatari 39, 10134 Tallinn, Estonia, info@aki.ee, www.aki.ee.

10.Security of personal data

10.1

The Operator applies technical and organisational measures appropriate to the risk, including the following:

  1. (a)the Website and the forms are served over encrypted connections only;
  2. (b)the service that stores requests cannot be reached from the internet and accepts data from the Website only;
  3. (c)IP addresses are stored as keyed hashes;
  4. (d)access to stored requests is limited to the persons who answer them;
  5. (e)requests are erased automatically when the retention period expires.

10.2

The measures that protect the information of clients are set out in the Information Security Policy.

11.Children

11.1

The Website is addressed to organisations and to persons who act in the course of their business or profession. The Operator does not knowingly process personal data of children.

12.Changes to this Policy

12.1

The version of this Policy is the date from which it applies. The current version is 2026-09-29.

12.2

A request records the version of this Policy shown next to the form when the request was sent, as evidence of the information the requester was given. The record is not a consent.

12.3

The Operator publishes changes on this page. A change does not apply to processing that was completed before the change took effect.