Third Party Index

Snapshot 20813

Document
Privacy policy
URL
https://otnos.com/privacy
Fetched
HTTP status
200
Content type
text/html; charset=utf-8
Fetch mode
static
Size
27747 bytes
SHA-256 (raw)
0a171f29ebfb1e8d5e430430e49deacfa65bde153ff807633b865a9f17bfc6d2
SHA-256 (normalized text)
ed2b467bdc8fcaba688dfeeca638fbec07caef81be963be172d89740bc49b6fe

Normalized text

Scripts and page chrome removed; this is what change detection compares.

Back to Home
Privacy Policy
Effective date: 12 August 2026
1. Who we are
OTNOS ("OTNOS", "we", "our", or "us") provides an OT/ICS security intelligence platform. This policy explains how we handle personal data under the EU General Data Protection Regulation (GDPR) and applicable data-protection law.
Controller: [LEGAL ENTITY NAME], [REGISTERED ADDRESS], Germany. For any privacy question or to exercise your rights, contact us at [email protected].
Two roles. We are the controller for the account, billing, and security data we hold about our users. For data our customers upload or forward into the platform (asset inventories, network captures, forwarded advisory emails), the customer is the controller and OTNOS acts as their processor under a Data Processing Agreement.
2. What we collect and why
We collect only what we need to provide and secure the service. For each purpose, the GDPR "lawful basis" is shown.
Data	Purpose	Lawful basis
Name, email, organisation, hashed password, MFA settings	Create and secure your account; authenticate you	Contract (Art. 6(1)(b)); legitimate interest in security (Art. 6(1)(f))
IP address, browser/user-agent, login timestamps, session tokens	Maintain sessions; detect and prevent abuse	Legitimate interest in security (Art. 6(1)(f))
Billing contact and subscription identifiers (card data is held by our payment processor, not by us)	Manage subscriptions and invoicing	Contract (Art. 6(1)(b)); legal obligation for accounting (Art. 6(1)(c))
Security/audit logs (actor email, IP, action, time)	Security monitoring, incident investigation, accountability	Legitimate interest / legal obligation (Art. 6(1)(f), 32)
Name, email, company on access/demo requests; alert-subscription email	Respond to requests; send updates/alerts you ask for	Steps prior to contract / legitimate interest; consent for marketing (Art. 6(1)(a))
Customer-uploaded content (asset inventory, PCAP, forwarded emails)	Provide the service to the customer (we process on their behalf)	Processed as processor on the customer's instructions (Art. 28)
We do not collect special-category data (e.g. health, biometrics), and we do not knowingly collect data from children.
3. Who we share data with
We do not sell personal data. We share it only with service providers ("sub-processors") who process it on our behalf under contract, and where required by law. By category, these are:
Cloud hosting and infrastructure providers
Content-delivery and edge-security providers
Identity / single sign-on providers
Payment processors
Email delivery and receiving providers
AI processing providers (used to parse vendor advisories)
A current list of the specific sub-processors we use is available to customers on request. We may also disclose data where legally required, or in connection with a merger or acquisition (with notice).
4. International data transfers
The core of your personal data is stored within the EU. Some of our service providers process limited personal data outside the EEA, including in the United States. Where that happens, we rely on appropriate safeguards — the EU–US Data Privacy Framework where the provider is certified, and/or the European Commission's Standard Contractual Clauses. Details of specific providers and their safeguards are available to customers on request.
5. How long we keep data
Account data: for as long as your account is active, then deleted or anonymised [CONFIRM: within 30–90 days of closure].
Security/audit logs: 365 days, then automatically purged.
Access (server) logs: 365 days, then deleted.
Backups: retained on a 30-day rolling basis.
Billing records: as required by law (German accounting-retention rules).
Customer-uploaded content: controlled by the customer; deleted on their request or account closure.
6. How we protect data
We apply security measures appropriate to the risk (GDPR Art. 32), including encryption in transit (TLS) and at rest, multi-factor authentication and SSO, role-based access control with tenant isolation, signed webhooks, audit logging, regular security review, and encrypted backups.
7. Your rights
Subject to conditions in the GDPR, you have the right to:
Access your personal data
Rectify inaccurate data
Erase your data ("right to be forgotten")
Restrict or object to certain processing
Data portability — receive your data in a portable format
Withdraw consent at any time, where processing is based on consent
To exercise any of these, contact [email protected]. We respond within one month.
You also have the right to lodge a complaint with a data protection supervisory authority. In Germany, this is the authority for the state (Bundesland) of our registered office [CONFIRM which]. You may also contact the authority in your own EU country of residence.
8. Cookies and tracking
We use only essential cookies needed to keep you signed in and remember your preferences. We do not use advertising or tracking cookies, and we do not track you across other websites. (Our public pages include structured data for search engines, which does not track visitors.)
To understand which pages are useful, we measure aggregate traffic on our public pages using Umami, open-source analytics that we run on our own servers in the EU: no third party receives any of this data. It sets no cookies, stores no personal data, keeps no IP addresses (a visit is recognised only through a short-lived, non-reversible hash that is discarded daily), and cannot follow you across sites. Because it collects no personal data, this requires no consent and there is nothing for you to opt out of. We see counts — page views, referrers, countries, and which buttons or forms were used — never individuals. Cloudflare, our content delivery network, additionally reports page-view totals and page-speed metrics to us from its edge, likewise without cookies.
9. Automated decision-making
We use AI to extract and enrich vulnerability information from vendor advisories. This processes technical/product content, not decisions about individuals. We do not carry out automated decision-making that produces legal or similarly significant effects on you (GDPR Art. 22).
10. Data we receive indirectly
When you use SSO, we receive basic profile information (name, email) from your single sign-on (SSO) identity provider solely to authenticate you. Separately, when customers forward advisory emails into the platform, those emails may contain personal data of third parties chosen by the customer; we process that content only to provide the service to that customer, as their processor.
11. Changes to this policy
We may update this policy from time to time. Material changes will be reflected here with an updated effective date.
12. Contact us
Questions about this policy or our data practices? [email protected]