Effective 29 September 2026
Who is responsible
Atlant Security, Svoboda 27-69, Sofia 1231, Bulgaria, VAT BG205426422, is the controller of personal data processed for this website and its business enquiries. Contact alexander@atlantsecurity.com for privacy matters or write to the address above.
This notice covers the public website and initial enquiries. A penetration testing engagement requires its own contractual confidentiality, evidence-handling and, where applicable, data-processing arrangements.
What we process and why
| Purpose | Information | Legal basis |
|---|---|---|
| Responding to business enquiries | Name, work email, organisation, optional timeframe, message, optional RFP attachment and subsequent correspondence. | Legitimate interests in responding to professional enquiries and developing business relationships (GDPR Article 6(1)(f)). Where you personally request steps toward a contract with you, Article 6(1)(b) may apply. |
| Fulfilling sample report requests | Name, work email, organisation, optional role and related correspondence. A signed access cookie enables the requested browser download for 15 minutes. | Legitimate interests in responding to professional resource requests and discussing related testing requirements (Article 6(1)(f)). |
| Delivering and protecting the site | IP address and request/security metadata processed by the hosting infrastructure; limited temporary rate-limit information. | Legitimate interests in operating a secure, available website and preventing abuse (Article 6(1)(f)). |
| Legal obligations and claims | Relevant correspondence and records where necessary. | Compliance with legal obligations (Article 6(1)(c)) and legitimate interests in establishing, exercising or defending claims (Article 6(1)(f)). |
Name, email, organisation and message are required to submit the enquiry form; the timeframe is optional. The sample-report form requires name, work email and organisation; your role is optional. We use these details to fulfil the resource request and may follow up about it and your testing requirements. Providing them is not a statutory obligation. You can contact us directly by email instead. Without contact information, we may be unable to respond.
Do not send passwords, sensitive personal data, vulnerability details or confidential production information through the public form. We do not use enquiry details to subscribe you to newsletters. We do not conduct automated decision-making with legal or similarly significant effects through this site.
Search and browser storage
Site search matches your query against a public index in your browser. There is no third-party search service or stored search history. Query text is reflected in the page URL and can be included in ordinary request metadata when you load or share that URL. Avoid confidential queries.
The site sets no advertising or analytics cookies and uses no browser storage for profiling. See the cookie notice for information about the necessary report-access cookie and infrastructure cookies.
Enquiry assistance and service providers
Atlant Security uses Cloudflare to host the website, route and send email, and store enquiry records and uploaded documents. Authorised Atlant Security staff and our business mailbox provider process correspondence. OpenAI processes high-level enquiry text after you reply to confirm your email address, to extract facts already supplied and identify missing scoping information. It does not choose email recipients, approve commercial terms or sign NDAs.
The assistant identifies itself as automated. It asks limited questions about company country, objectives, scope, timing, operational constraints and NDA preferences, then prepares a brief for human review. You may ask for a person or reply “stop”. No newsletter subscription is created. Attachments and detected sensitive material are routed to a person without sending those documents to OpenAI. Please avoid sending passwords, patient/payment information or confidential technical evidence.
We store your submitted details, correspondence, evidence-linked scoping facts, delivery status and workflow events in a private enquiry database. Uploaded RFPs and original reply documents are stored privately for delivery to the team. These records are used to answer your request and prepare a possible engagement, not advertising profiles. There are no automated decisions with legal or similarly significant effects. Professional advisers or authorities may receive information where necessary for legal obligations or claims.
International processing
The enquiry database is configured with Cloudflare's EU jurisdiction. This does not make all processing EU-only: Cloudflare's network, email delivery, OpenAI processing and support may involve processing outside the European Economic Area.
For restricted transfers, applicable GDPR Chapter V safeguards are required. Provider commitments are described in the Cloudflare Customer Data Processing Addendum and OpenAI Data Processing Addendum. We use the OpenAI API with response storage disabled; this does not eliminate provider security or abuse-monitoring retention. See OpenAI API data controls. Contact us for information about safeguards relevant to your enquiry.
How long information is kept
Enquiry database records are removed after 180 days without activity unless retained under a documented hold for a continuing engagement, legal obligation or claim. Privately stored reply documents and RFPs are removed after 30 days once delivery to the team has been accepted; a failed document handover remains available for recovery until the enquiry record expires or a hold is applied. Hashed email suppression records are kept for 180 days to honour requests to stop automated correspondence.
Email copies in the business mailbox follow the business relationship and applicable legal recordkeeping needs. Provider security logs have their own retention arrangements. OpenAI API response storage is disabled, but default abuse-monitoring logs may be retained for up to 30 days, subject to the provider's documented exceptions. Contact us to request erasure or information about the retention applicable to your enquiry.
Your rights
Subject to the applicable conditions, you may request access, correction, erasure, restriction and data portability. You may object to processing based on legitimate interests, including by explaining your particular situation. Where processing relies on consent, you may withdraw it without affecting earlier lawful processing; the enquiry form does not rely on marketing consent.
Send requests to alexander@atlantsecurity.com. We may need proportionate information to confirm identity. We aim to handle rights requests within the GDPR time limits, normally one month; lawful extensions or limitations will be explained.
You may complain to a supervisory authority, including the authority in the country where you live or work. The Bulgarian authority is the Commission for Personal Data Protection (CPDP).
Changes and contact
We will update this notice when the site’s processing changes and revise the effective date. Privacy questions can be sent to alexander@atlantsecurity.com.