// LEGAL PROTOCOL :: DATA PROTECTION

Privacy & Data Protection Policy

Comprehensive disclosure regarding the collection, processing, telemetry architecture, and international protection of personal data across the TelcoSec security research ecosystem.

LAST UPDATED :: 2026.03.20
GOVERNANCE :: GDPR / CCPA / ePrivacy / Google Consent Mode v2

// 0x01 DATA CONTROLLER & DATA PROTECTION OFFICER

TelcoSec ("TelcoSec", "we", "us", or "our") operates as the Data Controller responsible for the processing of personal information collected through telcosec.net and its associated research subdomains.

We have appointed a designated Data Protection Officer (DPO) to oversee compliance with applicable global data privacy regulations, including the European Union General Data Protection Regulation (GDPR Regulation (EU) 2016/679), the UK Data Protection Act 2018 (UK GDPR), the California Consumer Privacy Act as amended by the California Privacy Rights Act (CCPA/CPRA), and the Brazilian Lei Geral de Proteção de Dados (LGPD).

DATA CONTROLLER: TelcoSec Research Collective
DPO CONTACT: legal@telco-sec.com
SECURITY INCIDENT DESK: support@telco-sec.com

// 0x02 INFORMATION WE COLLECT

In operating an advanced technical research platform, we adhere to the principle of strict data minimization. We collect and process personal data strictly necessary to fulfill technical, research, and communication functions:

  • Technical & Network Telemetry: Anonymized/pseudonymized IP addresses, HTTP request headers, browser user-agent strings, referral URLs, language preferences, operating system metadata, and edge access timestamps collected automatically via edge infrastructure for anti-DDoS mitigation, bot verification, and rate limiting.
  • Voluntarily Provided Contact Data: Name, professional email address, organization/company, job designation, industry sector, and message payload submitted when requesting infrastructure audits, vulnerability coordination, newsletter subscriptions, or specialized lab access.
  • Account & Authentication Metadata: Cryptographic session tokens, authentication IDs, and user preferences when authenticating across the TelcoSec platform.
  • Aggregated Usage & Analytics Data: Page interaction paths, scroll depths, dwell times, and technical error logs collected via privacy-preserving telemetry nodes when authorized under consent frameworks.

// 0x04 GOOGLE ANALYTICS & GOOGLE CONSENT MODE V2

Our platform implements Google Consent Mode v2 in accordance with European Union ePrivacy and Google Publisher policies.

By default, all advertising and analytics storage states (analytics_storage, ad_storage, ad_user_data, ad_personalization) are set to denied until you provide explicit affirmative consent via our interactive consent protocol.

When consent is granted, Google Analytics 4 (GA4) processes pseudonymized traffic indicators with IP anonymization enabled. No personally identifiable information (PII) is transmitted to Google. Google may process this data under the EU-U.S. Data Privacy Framework. You can opt out of Google Analytics tracking globally by installing the Google Analytics Opt-out Browser Add-on.

// 0x05 COOKIE POLICY & TELEMETRY MATRIX

Cookies and local storage items are small data fragments stored on your device. We categorize them as follows:

Category Provider / Name Purpose Duration Default State
Strictly Necessary __cf_bm, cf_clearance, cf-turnstile Cloudflare DDoS protection, bot verification, and challenge tokens. Session / 30m Always Active
Strictly Necessary telcosec_consent Stores user cookie preference choices and Consent Mode v2 states. 365 days Always Active
Performance / Analytics _ga, _ga_*, _clck, _clsk Google Analytics 4 & Microsoft Clarity traffic metrics and behavioral loops. 14m - 2 yrs Consent Required
Marketing / Attribution bcookie, lidc, UserMatchHistory LinkedIn Insight Tag conversion measurement for enterprise outreach. 30 - 90 days Consent Required
Functional / CRM __hstc, hubspotutk, __hssrc HubSpot visitor identification when interacting with contact forms. 180 days Consent Required

You can modify your preferences at any time by clearing your browser cookies to trigger the consent banner or by using browser-level cookie controls. You may also opt out of personalized interest-based advertising via the Digital Advertising Alliance, the European Interactive Digital Advertising Alliance, or the Network Advertising Initiative.

// 0x06 THIRD-PARTY SERVICE PROVIDERS & SUB-PROCESSORS

We engage selected infrastructure and SaaS vendors who process data strictly under Data Processing Agreements (DPAs) with Standard Contractual Clauses:

  • Cloudflare, Inc. (USA / Global): Edge CDN, DDoS mitigation, DNS resolution, and Cloudflare Turnstile bot verification.
  • Google LLC (USA): Web analytics (Google Analytics 4) and search indexing (Google Search Console).
  • HubSpot, Inc. (USA): Customer relationship management (CRM) and newsletter delivery infrastructure.
  • Microsoft Corporation (USA): Session usability insights (Microsoft Clarity).
  • LinkedIn Corporation (USA / EU): Professional audience attribution (LinkedIn Insight Tag).

// 0x07 INTERNATIONAL DATA TRANSFERS

Personal data collected by TelcoSec may be stored and processed in data centers located in the European Union, the United Kingdom, and the United States. Where cross-border data transfers occur from the European Economic Area (EEA) or the UK to third countries not covered by an adequacy decision, we rely on the European Commission's Standard Contractual Clauses (SCCs) and the EU-U.S. Data Privacy Framework (DPF) to guarantee equivalent standards of protection.

// 0x08 DATA RETENTION & RESEARCH SEGREGATION

We retain personal data only for as long as necessary to fulfill the purposes outlined in this policy:

  • Edge Security Logs: Retained for a maximum of 90 days, then purged automatically.
  • Contact & Inquiry Records: Retained for 24 months after last contact, or until deletion is requested.
  • Analytics Telemetry: Retained for 14 months within Google Analytics data retention bounds.

Technical data generated through the use of our signaling calculators, 3GPP explorers, and simulation tools is executed client-side or in segregated ephemeral environments. Any research packet captures (PCAPs) uploaded for collaborative analysis are scrubbed of live IMSIs, MSISDNs, and private network routing keys prior to publication.

// 0x09 YOUR DATA PROTECTION RIGHTS (GDPR & UK GDPR)

Under European and UK data protection laws, you possess the following enforceable statutory rights:

Right of Access (Art. 15) Request confirmation and copies of all personal data held about you.
Right to Rectification (Art. 16) Request correction of inaccurate, incomplete, or outdated information.
Right to Erasure (Art. 17) Request immediate deletion ("right to be forgotten") of your personal data.
Right to Restriction (Art. 18) Request temporary restriction of processing during verification or dispute.
Right to Portability (Art. 20) Receive personal data in a structured, commonly used, machine-readable format.
Right to Object (Art. 21) Object at any time to processing based on legitimate interest or direct marketing.

To exercise any of these rights, email our Data Protection Officer at legal@telco-sec.com. We process all verified requests within thirty (30) calendar days without charge. You also maintain the right to lodge a formal complaint with your local EU/EEA supervisory authority (e.g., CNIL, BfDI, DPC) or the UK Information Commissioner's Office (ICO).

// 0x10 CALIFORNIA & US STATE PRIVACY DISCLOSURES (CCPA / CPRA)

This section applies to residents of California, Virginia, Colorado, Connecticut, and other US states with comprehensive privacy legislation:

  • No Sale or Sharing of Personal Information: TelcoSec has not sold or shared personal information to third parties for monetary consideration in the preceding twelve (12) months.
  • Right to Know & Access: You may request disclosure of categories of data collected, sources, and commercial purposes.
  • Right to Delete & Correct: You may request erasure or correction of inaccurate personal data.
  • Non-Discrimination: We will never discriminate, deny services, or alter pricing because you exercised your statutory privacy rights.

// 0x11 GLOBAL PRIVACY CONTROL (GPC) & DO NOT TRACK

TelcoSec recognizes and honors the Global Privacy Control (GPC) browser signal. When our infrastructure detects an active GPC signal transmitted by your browser, our consent engine automatically sets third-party marketing tags and analytics telemetry to a restricted state.

// 0x12 CHILDREN'S ONLINE PRIVACY (COPPA)

TelcoSec is an enterprise telecommunications security research and engineering platform intended strictly for cybersecurity professionals, network engineers, and academic researchers aged 18 and older. We do not knowingly solicit, collect, or process information from individuals under 18 years of age. If we become aware that personal data of a minor has been received without verified parental consent, we will delete that data immediately.

// 0x13 TECHNICAL & ORGANIZATIONAL SECURITY MEASURES

We enforce strict administrative, technical, and physical safeguards to secure user data and platform communications:

  • All web traffic is forced over Transport Layer Security (TLS 1.3) with HTTP Strict Transport Security (HSTS) and modern cipher suites.
  • Restricted database access governed by Zero Trust principles, role-based access controls (RBAC), and multi-factor authentication (MFA).
  • Continuous vulnerability scanning, automated edge DDoS mitigation, and encrypted rest storage utilizing AES-256-GCM.

// 0x14 POLICY AMENDMENTS & CONTACT DESK

We reserve the right to revise this Privacy Policy periodically to reflect technological updates, legal developments, or operational modifications. When updates occur, the "LAST UPDATED" timestamp at the top of this document will be revised accordingly. Continued use of our platform following posted revisions constitutes acceptance of the modified terms.

For any inquiries, data subject access requests (DSARs), or security reporting, contact our legal desk directly:

TelcoSec Legal & Compliance Team
PGP Key Fingerprint: B4C9 E2C7 1C4C 5C2B AC2B 2B3C 4D5E 6F7A