Clear criteria. Traceable evidence.Atlant Security
Cyber/AuditBY ATLANT SECURITY
Build your scope Audit brief builder

LEGAL & PRIVACY

Privacy notice

How Atlant Security handles personal information when you visit cybersecurityaudit.services or enquire about a cybersecurity engagement.

Who is responsible

Atlant Security, Svoboda 27-69, Sofia 1231, Bulgaria, VAT BG205426422, is the controller of personal data processed for this website and its business enquiries. Contact alexander@atlantsecurity.com for privacy matters or write to the address above.

This notice covers the public website and initial enquiries. A cybersecurity engagement requires its own contractual confidentiality, evidence-handling and, where applicable, data-processing arrangements.

What we process and why

PurposeInformationLegal basis
Responding to business enquiriesName, work email, organisation, optional timeframe, message, optional NDA or RFP attachment and subsequent correspondence.Legitimate interests in responding to professional enquiries and developing business relationships (GDPR Article 6(1)(f)). Where you personally request steps toward a contract with you, Article 6(1)(b) may apply.
Fulfilling sample audit report requestsName, work email, organisation, optional role and related correspondence. A signed access cookie enables the requested browser download for 15 minutes.Legitimate interests in responding to professional resource requests and discussing related security service requirements (Article 6(1)(f)).
Delivering and protecting the siteIP address and request/security metadata processed by the hosting infrastructure; limited temporary rate-limit information.Legitimate interests in operating a secure, available website and preventing abuse (Article 6(1)(f)).
Legal obligations and claimsRelevant correspondence and records where necessary.Compliance with legal obligations (Article 6(1)(c)) and legitimate interests in establishing, exercising or defending claims (Article 6(1)(f)).

Name, email, organisation and message are required to submit the enquiry form; the timeframe is optional. The sample report form requires name, work email and organisation; your role is optional. We use these details to fulfil the resource request and may follow up about it and your security service requirements. Providing them is not a statutory obligation. You can contact us directly by email instead. Without contact information, we may be unable to respond.

Do not send passwords, sensitive personal data, vulnerability details or confidential production information through the public form. We do not use enquiry details to subscribe you to newsletters. We do not conduct automated decision-making with legal or similarly significant effects through this site.

Enquiry assistance and service providers

Atlant Security uses Cloudflare to host the website, route and send email, and store enquiry records and uploaded documents. Authorised Atlant Security staff and our business mailbox provider process correspondence. Where automated qualification is enabled, OpenAI processes high-level enquiry text after you reply to confirm your email address, to extract facts already supplied and identify missing scoping information. It does not choose email recipients, approve commercial terms or sign NDAs.

The assistant identifies itself as automated. It asks limited questions about company country, objectives, scope, timing, operational constraints and NDA preferences, then prepares a brief for human review. You may ask for a person or reply “stop”. No newsletter subscription is created. Attachments and detected sensitive material are routed to a person without sending those documents to OpenAI. Please avoid sending passwords, patient/payment information or confidential technical evidence.

We store your submitted details, correspondence, evidence-linked scoping facts, delivery status and workflow events in a private enquiry database. Uploaded RFPs and original reply documents are stored privately for delivery to the team. These records are used to answer your request and prepare a possible engagement, not advertising profiles. There are no automated decisions with legal or similarly significant effects. Professional advisers or authorities may receive information where necessary for legal obligations or claims.

International processing

The enquiry database is configured with Cloudflare's EU jurisdiction. This does not make all processing EU-only: Cloudflare's network, email delivery, OpenAI processing and support may involve processing outside the European Economic Area.

For restricted transfers, applicable GDPR Chapter V safeguards are required. Provider commitments are described in the Cloudflare Customer Data Processing Addendum and OpenAI Data Processing Addendum. We use the OpenAI API with response storage disabled; this does not eliminate provider security or abuse-monitoring retention. See OpenAI API data controls. Contact us for information about safeguards relevant to your enquiry.

How long information is kept

Enquiry database records are removed after 180 days without activity unless retained under a documented hold for a continuing engagement, legal obligation or claim. Privately stored reply documents and RFPs are removed after 30 days once delivery to the team has been accepted; a failed document handover remains available for recovery until the enquiry record expires or a hold is applied. Hashed email suppression records are kept for 180 days to honour requests to stop automated correspondence.

Email copies in the business mailbox follow the business relationship and applicable legal recordkeeping needs. Provider security logs have their own retention arrangements. OpenAI API response storage is disabled, but default abuse-monitoring logs may be retained for up to 30 days, subject to the provider's documented exceptions. Contact us to request erasure or information about the retention applicable to your enquiry.

Your rights

Subject to the applicable conditions, you may request access, correction, erasure, restriction and data portability. You may object to processing based on legitimate interests, including by explaining your particular situation. Where processing relies on consent, you may withdraw it without affecting earlier lawful processing; the enquiry form does not rely on marketing consent.

Send requests to alexander@atlantsecurity.com. We may need proportionate information to confirm identity. We aim to handle rights requests within the GDPR time limits, normally one month; lawful extensions or limitations will be explained.

You may complain to a supervisory authority, including the authority in the country where you live or work. The Bulgarian authority is the Commission for Personal Data Protection (CPDP).

Changes and contact

We will update this notice when the site’s processing changes and revise the effective date. Privacy questions can be sent to alexander@atlantsecurity.com.

IP addresses in form notifications

When you submit a contact enquiry, a reviewed scoping brief or a sample-report request, we include the IP address supplied by Cloudflare in the internal notification to Atlant Security. We use it to assess spam and investigate misuse of the forms. It may identify a shared network or VPN rather than an individual.

Where the enquiry workflow stores this information, it is kept as private security metadata alongside the enquiry and follows the enquiry retention period described in this notice. Email copies follow our business mailbox retention arrangements. This IP metadata is not included in automated replies to you or sent to the AI assistant.

AI-assisted scoping briefs

The optional scoping assistant sends the high-level project answers you choose to provide to OpenAI through our Cloudflare server to draft and refine a proposed scope. You can use expert scoping without AI instead. Do not enter credentials, confidential technical details, customer, patient or payment data. No attachment is sent to the model.

Drafts are held in the open page, without browser storage. Our generation endpoint does not save the answers or generated brief in our enquiry database; it records a daily request count for capacity control. We request that OpenAI does not store the response for later retrieval; provider security and abuse-monitoring retention may still apply. Generation alone does not send a sales enquiry. When you submit the contact form, your reviewed brief, contact details, message and optional document are handled under the enquiry purposes, retention, recipients and rights described in this notice.

Form security checks

Cloudflare Turnstile checks your browser when you submit an enquiry, request a report or generate a scoping brief. Cloudflare processes technical browser and network information, including your IP address, to prevent automated abuse. We verify the resulting token before processing the submission and use short-lived request limits. The verification request does not include your message, brief or uploaded document.

This security feature requires JavaScript. If you cannot complete the check, email sales@cybersecurityaudit.services. See the Cloudflare Turnstile Privacy Addendum.