// ACTA_SECURITY

// LEGAL

Privacy Policy

Last updated: 21 June 2026.

Who we are

Acta Security ("we", "us") is the data controller for personal data processed through this website and our client services. Contact: hello@actasecurity.eu or via our contact form.

What we collect

We do not use advertising, profiling or third-party analytics/tracking.

Why we process it (legal bases)

Who processes data for us

We work with EU/EEA-resident providers wherever possible:

We never sell personal data. Where a provider may process data outside the EEA, it is done under appropriate safeguards (Standard Contractual Clauses or an adequacy decision).

How long we keep it

Your rights

Under the GDPR you may request access, rectification, erasure, restriction, portability, or object to processing, and you may withdraw consent at any time. To exercise these rights, contact privacy@actasecurity.eu. You also have the right to lodge a complaint with your local EU supervisory authority.

How we protect it

Our infrastructure is operated within the EU. Key measures include: TLS 1.2+ encryption in transit; access-controlled, encrypted-at-rest report and attachment storage; passwordless OTP authentication (no stored passwords); all credentials stored in a dedicated secrets management service (OpenStack Barbican), not in configuration files; network-level firewalling (UFW) with Gcore CDN CIDR allowlists; web application firewall and DDoS protection (Gcore WAAP); host-based intrusion detection and automated blocking (CrowdSec); 24/7 security event monitoring via a dedicated SIEM (Wazuh); daily container vulnerability scanning (Trivy); automated encrypted database backups (AES-256) to EU object storage; and a 90-day log retention and purge policy. See our Cookie Policy for cookie details.

Changes & contact

We may update this policy; the "last updated" date will change. Questions: privacy@actasecurity.eu or the contact form.