Privacy Policy

Version 1.1 · Last updated: July 29, 2026

This policy explains what personal data Yazoul Security collects when you use this site, why we collect it, how long we keep it, and what rights you have under the EU General Data Protection Regulation (GDPR) and the ePrivacy Directive. It applies to yazoul.net and all of its sub-sections (/advisory, /breaches, /news, /learn, /intel, /research, /malware, /web-security).

For /web-security that covers the enquiry you send us through the contact form, and nothing more. The Yazoul Web Security product itself — what the browser extension observes, what the console stores, and how long detection data is kept — is governed by a separate document, the product privacy policy. The two do not overlap: this one is about the publication, that one is about the product.

1. Data controller

The data controller is Yazoul Security, established in the United States. Postal address and registration details for data-subject requests are available on request to the contact below — please include "Privacy request" in the subject line.

Contact for privacy matters: Enable JavaScript to see email. We have not appointed a Data Protection Officer because our processing does not meet the thresholds in GDPR Article 37; the contact above is the single point of contact for all data-subject and supervisory matters.

2. What we collect

The site processes four categories of personal data:

  • Newsletter subscription data. When you subscribe to the newsletter we store your email address, the timestamp of your consent, the version of the consent text you saw, and a one-way hash (SHA-256) of your IP address as proof of where the consent originated. We do not store the raw IP address.
  • Sales enquiry data. When you contact us about Yazoul Web Security we store the name, work email address, company and approximate seat count you provide, any message you write, the timestamp, and a one-way hash (SHA-256) of your IP address. We do not store the raw IP address. These details are also delivered to our internal Slack channel so the enquiry reaches us.
  • Analytics data (Google Analytics 4). Only loaded if you accept analytics cookies. GA4 collects pseudonymous identifiers, page views, referrer, approximate location (country/region level), and device/browser information. IP addresses are anonymized by Google before storage.
  • Server access logs. Cloudflare automatically records standard HTTP request metadata (IP, user agent, requested URL, timestamp, response code) for security and abuse-prevention purposes. These are processed by Cloudflare and not directly retained by us.

We do not run advertising, behavioral profiling, A/B testing, or fingerprinting.

3. Lawful bases (GDPR Article 6)

  • Newsletter — Article 6(1)(a): your explicit consent, given by ticking the consent box on the subscription form.
  • Sales enquiries — Article 6(1)(b): processing necessary to take steps at your request before entering into a contract. If we contact you about the product for any reason other than answering your enquiry, that is Article 6(1)(f) legitimate interest, and you may object at any time.
  • Analytics cookies — Article 6(1)(a): your consent given through the cookie banner. Required by ePrivacy Directive Article 5(3).
  • Server logs — Article 6(1)(f): legitimate interest in operating the service securely and detecting abuse.

4. Recipients and processors

The following third-party processors handle personal data on our behalf under data processing agreements:

  • Cloudflare, Inc. — site hosting (Pages), Workers runtime, D1 database (newsletter subscribers and sales enquiries), DNS, CDN, and edge logging. Data may be processed in the US under Standard Contractual Clauses.
  • Resend — transactional and newsletter email delivery (US-based, SCCs).
  • Google LLC — Google Analytics 4 (US-based, SCCs and EU-US Data Privacy Framework).
  • Slack Technologies, LLC (a Salesforce company) — internal notification of sales enquiries to our team channel (US-based, SCCs and EU-US Data Privacy Framework).

We do not sell or rent your personal data, and we share it only with the processors listed above. Newsletter email addresses go to Resend solely to deliver the newsletter you subscribed to. Sales enquiry details go to Slack solely to notify us of your enquiry. We do not use either for any other purpose.

5. Retention

  • Newsletter subscriber data — kept until you unsubscribe. Unsubscribed records are retained for 30 days as proof of opt-in/opt-out, then deleted.
  • Sales enquiry data — kept for 24 months from the date you send it, then deleted. Copies in our internal Slack channel are deleted after 90 days under our Slack retention settings. If you become a customer, your data is retained under the agreement covering that relationship.
  • Analytics data — 14 months (Google Analytics 4 default), after which it is automatically deleted by Google.
  • Cloudflare access logs — short-term (typically up to 30 days), per Cloudflare's standard retention.

6. Your rights

Under the GDPR you have the following rights regarding your personal data:

  • Access (Art. 15) — request a copy of the data we hold about you.
  • Rectification (Art. 16) — correct inaccurate data.
  • Erasure (Art. 17) — request deletion of your data.
  • Restriction (Art. 18) — limit how we process your data.
  • Portability (Art. 20) — receive your data in a machine-readable format.
  • Objection (Art. 21) — object to processing based on legitimate interest.
  • Withdraw consent (Art. 7) — at any time, with no effect on prior lawful processing.

The fastest ways to exercise these rights:

You also have the right to lodge a complaint with a supervisory authority (Art. 77). Complain to the authority in the EU or EEA country where you live or work — the European Data Protection Board publishes the current list. We are not established in the EU, so no single national authority acts as a lead for us; your own is the right one to approach.

7. Cookies and similar technologies

We only set cookies after you explicitly accept them through the cookie banner. Until you make a choice, no analytics cookies are set and Google Analytics runs in Consent Mode v2 with all consent signals defaulted to "denied".

The site may set the following cookies:

Cookie / storage Purpose Duration Controller
yz_consent (localStorage) Stores your cookie banner choice so we don't ask again 12 months Yazoul Security (essential, no consent required)
newsletter-popup-dismissed (localStorage) Suppresses the newsletter popup after dismissal 7 days Yazoul Security (essential)
yz_views (sessionStorage) Counts pages viewed in the current browsing session Until tab is closed Yazoul Security (essential)
_ga, _ga_* Google Analytics — distinguish users, measure usage Up to 2 years Google (analytics, consent required)

You can change your cookie preferences at any time: .

8. International data transfers

Cloudflare, Resend, Google, and Slack process data on servers located outside the European Economic Area, primarily in the United States. Transfers rely on the European Commission's Standard Contractual Clauses and, where applicable, the EU-US Data Privacy Framework as the legal basis under GDPR Article 46. Copies of the relevant agreements are available from each processor at the links in section 4.

9. Updates to this policy

We may update this policy to reflect changes in our processing or applicable law. The version number and last updated date at the top of the page change with every revision. If a change materially affects how we use your data — for example, adding a new processor or a new processing purpose — we will request renewed consent before the change applies to you.

10. Contact

For any privacy question, request, or complaint, email Enable JavaScript to see email with "Privacy request" in the subject line. We respond within 30 days as required by GDPR Article 12.

Never Miss a Critical Alert

CVE advisories, breach reports, and threat intel — delivered daily to your inbox.