We’re a security firm. We are not in the data-broker business. Specifically:
What we collect
On this website. Nothing. We run no analytics, set no cookies, and do not fingerprint visitors. The site is static and serves its own fonts, so your visit isn’t measured or shared with anyone.
Through contact forms. Whatever you put in the form. We store it in our inbox until the engagement (if any) ends, then we archive and encrypt it.
During engagements. A great deal, but it’s covered by a separate contractual agreement with the customer (typically a Master Services Agreement and Statement of Work). That agreement governs handling, retention, and destruction of all engagement artifacts. Findings and code samples never leave our infrastructure.
What we don’t collect
- We don’t run third-party analytics (Google, Meta, Hotjar, etc.)
- We serve our fonts from our own server, with no Google Fonts or other third-party CDNs
- We don’t use marketing pixels
- We don’t sell or rent any data, ever
- We don’t share customer engagement details across customer boundaries
Retention
- Contact-form submissions: 12 months, then deleted
- Engagement artifacts: per the contract, typically 12 months post-engagement, then cryptographically destroyed
Cookies
We use no cookies on this site. If your browser shows one, it isn’t us.
Your rights
Whether you’re in the EU, California, or anywhere else, you can ask us to:
- Show you what we have about you
- Correct anything wrong
- Delete it
Email [email protected]. We aim to respond inside one business day; the statutory deadline under the GDPR is one month.
Changes
We’ll update this page if our practices change. The date at the top reflects the last edit. Material changes go in our journal.
Contact
- General privacy or GDPR questions at [email protected]
- Legal address: Yeti.Security, Prague, Czech Republic