Legal
Privacy Policy
How SecNode handles the personal data you share through this website, who receives it, how long we keep it, and the rights you have under the GDPR.
Last updated September 2026
Who we are and what this policy covers
This website is operated by the entity identified in our Imprint (SecNode GmbH (in Gründung), Michaelkirchstraße 21, 10179 Berlin, Germany), which is the controller for the personal data described here.
This policy covers this website: the pages you read, the contact and demo forms, the vulnerability-disclosure form, and the analytics you can accept or decline. It does not cover the SecNode platform. Data that customers connect to the platform, such as code, cloud configuration, documentation, and findings, is processed on their instructions under the customer agreement and a data processing agreement, with SecNode acting as processor.
How to reach us about privacy
Write to sales@secnode.ai or to the postal address in the Imprint. For anything concerning a security vulnerability, use security@secnode.ai.
When you contact us or book a demo
The contact and demo forms ask for your first and last name, work email address, company, and an optional message. We use these to answer your request, arrange and hold the demo, and follow up on the conversation you started. The legal basis is the steps taken at your request before entering into a contract (Art. 6(1)(b) GDPR).
Your submission is delivered to our team by email through Resend and recorded in our internal lead register so that the right engineer follows up. When our anti-bot check has verified the submission, you also receive a copy by email. We do not sell personal data and we do not add you to a newsletter because you contacted us.
When you report a vulnerability
The disclosure form on our Security page asks for a title, the affected target, a description, the steps to reproduce, and an email address so we can acknowledge and coordinate with you. The report is sent from your browser to SecNode's own disclosure platform and handled by our security team under the program terms on that page. The legal basis is our legitimate interest in receiving and fixing reports about our systems (Art. 6(1)(f) GDPR) and, where you ask to be credited, your consent.
What we collect automatically
Like every website, ours receives technical data with each request: your IP address, browser and device type, the page requested, and the time. Our hosting provider records this in short-lived server logs to deliver the site and keep it secure.
Our forms use Cloudflare Turnstile to tell people from bots. Turnstile evaluates signals from your browser and returns a token to us; we verify that token and use your IP address to limit how often forms can be submitted. This protects the forms from abuse and is based on our legitimate interest in running a secure site (Art. 6(1)(f) GDPR).
Cookies, local storage, and analytics
We do not use advertising cookies or cross-site tracking. The site stores one value in your browser's local storage to remember your cookie choice, and Cloudflare Turnstile may store what it needs to complete its check; both are strictly necessary and need no consent.
Analytics runs only if you accept it through the consent banner. If you do, we use Vercel Web Analytics to understand which pages are read and how the site performs. The legal basis is your consent (Art. 6(1)(a) GDPR), which you can withdraw at any time by clearing this site's data in your browser; the banner will ask you again.
Who receives your data
We use a small number of service providers to run this website, each bound by a data processing agreement: Vercel (hosting and, with your consent, analytics), Resend (email delivery for form submissions), and Cloudflare (bot protection for the forms and the network in front of our disclosure platform). Vulnerability reports go to SecNode's own disclosure platform.
Within SecNode, your data is seen only by the people who need it to respond to you. We may also share personal data with professional advisers, or with public authorities where the law requires it, and it would transfer with the business in the event of a merger or acquisition.
Transfers outside the EU
SecNode is based in Germany and hosts its platform in the EU. Some of the website providers named above are headquartered in the United States and may process data there. Where that happens, the transfer is protected by safeguards under Chapter V of the GDPR, such as the European Commission's Standard Contractual Clauses or the provider's certification under the EU-US Data Privacy Framework.
How long we keep it
Contact and demo requests are kept for as long as we are in conversation with you and for no more than [24 months] after our last exchange, unless a contract with your company follows, in which case the customer agreement governs. Vulnerability reports are kept for as long as needed to resolve the issue and keep a record of the program. Server logs are kept for a short period by our hosting provider. Analytics data is aggregated and does not identify you.
How we protect it
Data in transit is encrypted, access within SecNode is limited to the people who need it, every form is protected against automated abuse, and we hold our own systems to the standard we test everyone else's, including a public disclosure program for anyone who finds a weakness.
Your rights
Under the GDPR you may ask us for access to the personal data we hold about you, have it corrected or deleted, restrict or object to its processing, receive it in a portable format, and withdraw any consent you have given. We do not make automated decisions about you that have legal or similarly significant effects.
To exercise a right, write to sales@secnode.ai. We answer within one month and do not charge a fee unless a request is manifestly unfounded or excessive.
Complaints
If you believe we have handled your data unlawfully, we would like to hear from you first. You also have the right to lodge a complaint with a supervisory authority, in particular the Berlin Commissioner for Data Protection and Freedom of Information (Berliner Beauftragte für Datenschutz und Informationsfreiheit) or the authority where you live or work.
Links to other websites
This site links to third-party sites such as LinkedIn and GitHub. Their privacy practices are their own, and this policy does not apply to them.
Changes to this policy
We update this policy when the site, the law, or our providers change. The version published here, with its "last updated" date, is the one in force.