Privacy & Data Protection Policy
Comprehensive disclosure regarding the collection, processing, telemetry architecture, and international protection of personal data across the TelcoSec security research ecosystem.
// 0x01 DATA CONTROLLER & DATA PROTECTION OFFICER
TelcoSec ("TelcoSec", "we", "us", or "our") operates as the Data Controller responsible for the processing of personal information collected through telcosec.net and its associated research subdomains.
We have appointed a designated Data Protection Officer (DPO) to oversee compliance with applicable global data privacy regulations, including the European Union General Data Protection Regulation (GDPR Regulation (EU) 2016/679), the UK Data Protection Act 2018 (UK GDPR), the California Consumer Privacy Act as amended by the California Privacy Rights Act (CCPA/CPRA), and the Brazilian Lei Geral de Proteção de Dados (LGPD).
// 0x02 INFORMATION WE COLLECT
In operating an advanced technical research platform, we adhere to the principle of strict data minimization. We collect and process personal data strictly necessary to fulfill technical, research, and communication functions:
- Technical & Network Telemetry: Anonymized/pseudonymized IP addresses, HTTP request headers, browser user-agent strings, referral URLs, language preferences, operating system metadata, and edge access timestamps collected automatically via edge infrastructure for anti-DDoS mitigation, bot verification, and rate limiting.
- Voluntarily Provided Contact Data: Name, professional email address, organization/company, job designation, industry sector, and message payload submitted when requesting infrastructure audits, vulnerability coordination, newsletter subscriptions, or specialized lab access.
- Account & Authentication Metadata: Cryptographic session tokens, authentication IDs, and user preferences when authenticating across the TelcoSec platform.
- Aggregated Usage & Analytics Data: Page interaction paths, scroll depths, dwell times, and technical error logs collected via privacy-preserving telemetry nodes when authorized under consent frameworks.
// 0x03 LEGAL BASES FOR DATA PROCESSING (GDPR ART. 6)
We only process personal data when we have a valid lawful basis under Article 6 of the GDPR:
- Consent (Art. 6(1)(a)): For non-essential analytics cookies, advertising optimization tags, and email newsletter communications. You have the absolute right to withdraw consent at any time via our consent manager.
- Contractual Performance (Art. 6(1)(b)): To deliver requested security audits, dedicated lab access, training credentials, and support services.
- Legitimate Interests (Art. 6(1)(f)): To safeguard platform integrity, detect malicious cyber threats, prevent automated bot attacks via Cloudflare Turnstile, improve protocol tools, and maintain network resilience.
- Legal Obligations (Art. 6(1)(c)): To comply with mandatory statutory obligations, export regulations, or lawful court orders.
// 0x04 GOOGLE ANALYTICS & GOOGLE CONSENT MODE V2
Our platform implements Google Consent Mode v2 in accordance with European Union ePrivacy and Google Publisher policies.
By default, all advertising and analytics storage states (analytics_storage, ad_storage, ad_user_data, ad_personalization) are set to denied until you provide explicit affirmative consent via our interactive consent protocol.
When consent is granted, Google Analytics 4 (GA4) processes pseudonymized traffic indicators with IP anonymization enabled. No personally identifiable information (PII) is transmitted to Google. Google may process this data under the EU-U.S. Data Privacy Framework. You can opt out of Google Analytics tracking globally by installing the Google Analytics Opt-out Browser Add-on.
// 0x06 THIRD-PARTY SERVICE PROVIDERS & SUB-PROCESSORS
We engage selected infrastructure and SaaS vendors who process data strictly under Data Processing Agreements (DPAs) with Standard Contractual Clauses:
- Cloudflare, Inc. (USA / Global): Edge CDN, DDoS mitigation, DNS resolution, and Cloudflare Turnstile bot verification.
- Google LLC (USA): Web analytics (Google Analytics 4) and search indexing (Google Search Console).
- HubSpot, Inc. (USA): Customer relationship management (CRM) and newsletter delivery infrastructure.
- Microsoft Corporation (USA): Session usability insights (Microsoft Clarity).
- LinkedIn Corporation (USA / EU): Professional audience attribution (LinkedIn Insight Tag).
// 0x07 INTERNATIONAL DATA TRANSFERS
Personal data collected by TelcoSec may be stored and processed in data centers located in the European Union, the United Kingdom, and the United States. Where cross-border data transfers occur from the European Economic Area (EEA) or the UK to third countries not covered by an adequacy decision, we rely on the European Commission's Standard Contractual Clauses (SCCs) and the EU-U.S. Data Privacy Framework (DPF) to guarantee equivalent standards of protection.
// 0x08 DATA RETENTION & RESEARCH SEGREGATION
We retain personal data only for as long as necessary to fulfill the purposes outlined in this policy:
- Edge Security Logs: Retained for a maximum of 90 days, then purged automatically.
- Contact & Inquiry Records: Retained for 24 months after last contact, or until deletion is requested.
- Analytics Telemetry: Retained for 14 months within Google Analytics data retention bounds.
Technical data generated through the use of our signaling calculators, 3GPP explorers, and simulation tools is executed client-side or in segregated ephemeral environments. Any research packet captures (PCAPs) uploaded for collaborative analysis are scrubbed of live IMSIs, MSISDNs, and private network routing keys prior to publication.
// 0x09 YOUR DATA PROTECTION RIGHTS (GDPR & UK GDPR)
Under European and UK data protection laws, you possess the following enforceable statutory rights:
To exercise any of these rights, email our Data Protection Officer at legal@telco-sec.com. We process all verified requests within thirty (30) calendar days without charge. You also maintain the right to lodge a formal complaint with your local EU/EEA supervisory authority (e.g., CNIL, BfDI, DPC) or the UK Information Commissioner's Office (ICO).
// 0x10 CALIFORNIA & US STATE PRIVACY DISCLOSURES (CCPA / CPRA)
This section applies to residents of California, Virginia, Colorado, Connecticut, and other US states with comprehensive privacy legislation:
- No Sale or Sharing of Personal Information: TelcoSec has not sold or shared personal information to third parties for monetary consideration in the preceding twelve (12) months.
- Right to Know & Access: You may request disclosure of categories of data collected, sources, and commercial purposes.
- Right to Delete & Correct: You may request erasure or correction of inaccurate personal data.
- Non-Discrimination: We will never discriminate, deny services, or alter pricing because you exercised your statutory privacy rights.
// 0x11 GLOBAL PRIVACY CONTROL (GPC) & DO NOT TRACK
TelcoSec recognizes and honors the Global Privacy Control (GPC) browser signal. When our infrastructure detects an active GPC signal transmitted by your browser, our consent engine automatically sets third-party marketing tags and analytics telemetry to a restricted state.
// 0x12 CHILDREN'S ONLINE PRIVACY (COPPA)
TelcoSec is an enterprise telecommunications security research and engineering platform intended strictly for cybersecurity professionals, network engineers, and academic researchers aged 18 and older. We do not knowingly solicit, collect, or process information from individuals under 18 years of age. If we become aware that personal data of a minor has been received without verified parental consent, we will delete that data immediately.
// 0x13 TECHNICAL & ORGANIZATIONAL SECURITY MEASURES
We enforce strict administrative, technical, and physical safeguards to secure user data and platform communications:
- All web traffic is forced over Transport Layer Security (TLS 1.3) with HTTP Strict Transport Security (HSTS) and modern cipher suites.
- Restricted database access governed by Zero Trust principles, role-based access controls (RBAC), and multi-factor authentication (MFA).
- Continuous vulnerability scanning, automated edge DDoS mitigation, and encrypted rest storage utilizing AES-256-GCM.
// 0x14 POLICY AMENDMENTS & CONTACT DESK
We reserve the right to revise this Privacy Policy periodically to reflect technological updates, legal developments, or operational modifications. When updates occur, the "LAST UPDATED" timestamp at the top of this document will be revised accordingly. Continued use of our platform following posted revisions constitutes acceptance of the modified terms.
For any inquiries, data subject access requests (DSARs), or security reporting, contact our legal desk directly: