LEGAL · GDPR

Privacy & GDPR

CSAEC — How this product website handles personal information.

Privacy principles for cybersecurity information

Cybersecurity findings can become sensitive even when they do not directly name an individual. A report may disclose device names, account references, network addresses, open services, software versions, vulnerabilities or details about security controls. Organisations should classify this information, limit access and use secure channels when external review is genuinely necessary.

The local-first design of CSAEC helps reduce automatic external disclosure, but it does not remove user responsibility. Saving a report to a shared folder, attaching it to ordinary email, copying it into a ticketing system or using an optional third-party component can create additional processing. Before doing so, identify the recipient, purpose, legal basis, retention period and appropriate protection.

Data minimisation

Share only the information needed for the defined support or licensing purpose. An initial commercial enquiry usually does not require a full scan report. Where technical assistance is requested, consider whether identifiers can be removed, whether a summary is sufficient and whether the recipient needs every finding. Data minimisation supports both GDPR compliance and sound security practice.

Organisational responsibilities

Customers remain responsible for identifying their own role under data-protection law, providing employee notices where required, establishing internal access rights and selecting appropriate service providers. The presence of a privacy notice on this website is not a substitute for the customer’s own records, risk assessment or professional legal advice.

Incident and rights requests

Privacy or personal-data enquiries should be sent to info@connext-world.com with enough information to identify the request. Do not include unnecessary identity documents in the first email. If a security incident is suspected, use the authorised company contact channel and provide sensitive technical evidence only after a suitable exchange method has been confirmed.