← Back to home

/ PRIVACY POLICY

Privacy Policy

Version 1.0 | Effective 2026-08-28 | Scope odysec.org and the team's contact channels


1. Where this policy stands

One of the subjects we research is how people obtain information about others without their knowledge. We hold our own data collection to the same standard we apply in that research: collect only what a specific purpose requires, delete it once that purpose is served, and use it for nothing else.

This policy is written in plain language and lists specifics you can check us against. Any collection not described here is something we do not do.

2. Browsing the site

odysec.org is a static site. We use no analytics service, no advertising network, no social widgets and no tracking cookies, and the site sets no cookies in your browser. Fonts, styles and images are served entirely by this site; nothing is loaded from third parties.

The server keeps standard access logs (source IP, time, request path, response code, User-Agent) solely for operations and abuse prevention. They are retained for 14 days and then rotated out. They are not correlated with any other data and are not used to analyse individual behaviour. The server also produces anonymised aggregate traffic statistics from these logs (IPs are anonymised during aggregation), for the team's own use only.

The site sits behind a content delivery network (Cloudflare) for transport security and abuse protection. By the nature of the connection that provider processes your connection data under its own policies.

3. Membership application form

When you submit an application we collect the following from the form:

Item Required Purpose
Name Yes Identifying the applicant, review, follow-up
Email Yes Sending the review result and follow-up
Affiliation and role No Review context
Research lines of interest No Assigning research direction
About you and motivation Yes Basis for review

We also record your source IP and the submission time, used only for abuse prevention (for example, identifying bulk repeat submissions).

This information is used only for reviewing your application and related correspondence. It is not used for marketing and is never disclosed, exchanged or sold to third parties. It is stored on servers the team administers and in the team's mailbox (mail provider: Proton).

4. Retention

  • Application declined or withdrawn: deleted within 90 days of the decision being sent. That window exists so we can answer any follow-up questions from the applicant.
  • Application approved: becomes member data, kept for the duration of membership and for 1 year after it ends, then deleted. Accounting records are kept for the period required by law.
  • Website access logs: 14 days.
  • Form abuse-prevention records (IP and time): 90 days.

5. Your rights

You may at any time ask us to give you access to, a copy of, or an explanation of the personal data we hold about you; to supplement or correct it; or to delete it and stop collecting, processing or using it. Write to contact@odysec.org. We reply within 1–3 business days and act on the request once we have verified your identity.

Exercising these rights is free and will not be held against you. If you disagree with how we have handled your data, you may complain to the competent supervisory authority.

6. Data security

  • The site is HTTPS throughout, with HSTS and a strict Content Security Policy.
  • Applications are stored on a server only the team can reach, with file permissions limited to the service account that needs them.
  • Mail is sent over an encrypted channel (STARTTLS) using a dedicated token that can send mail but cannot access the mailbox.
  • Server access is by key authentication only; password login is disabled.

We do not claim to be perfectly secure — anyone who claims that should not be believed. What we claim is that the measures above are actually in place and can be verified from outside (for instance, by checking this site's transport security and response headers with public tools).

7. Minors

Membership is limited to those aged eighteen or above. We do not knowingly collect personal data from minors.

8. Changes to this policy

When this policy changes we update the version and effective date on this page. Material changes to what we collect or why will additionally be announced on the site.

9. Contact

General matters and data rights: contact@odysec.org

Security reports (PGP encryption preferred): security@odysec.org, key at /pgp-key.txt