Skip to content
Book a call

Home / Privacy policy

The formal part

Privacy policy

This policy covers this website — what we collect when you visit it or contact us through it. Personal data we handle while carrying out a penetration test for you is governed by your engagement contract and the NDA, not by this page; how we treat your systems and data during an engagement is described on our trust page.

Who we are

AppSec Application Security Ltd., trading as AppSec Labs, of Kfar Saba, Israel. We are the controller of the personal data described here. Our full registered address is available on request.

For anything in this policy — including a request to see or delete your data — write to info@appsec-labs.com.

What we collect, and why

When you use a form on this site. Our forms ask for your name and work email, what you would like tested, and a description of the system in your own words. Some also take a company name and a phone number, and one asks — optionally — how you heard about us. Everything beyond the name and email is optional, and the free-text field contains only what you choose to put in it.

We use it to answer you and, if it goes further, to scope an engagement. The legal basis is our legitimate interest in responding to business enquiries, and, once you ask us for a proposal, taking steps at your request before entering a contract.

When you book a call. Our booking page embeds Google Appointment Schedules. What you type into it goes to Google and into our calendar; it does not pass through this website. Google’s own terms apply to that transfer.

When you request a quote or buy. The quote wizard sends what you enter to our back-office system so we can produce a proposal. Where a card payment is offered it is handled by our payment provider — card details never reach this website or our servers.

Automatically. Standard web-server logs, security logging, and the analytics described below.

Where form submissions go, and how long we keep them

This is the part most privacy policies leave out, so it is worth being exact. A submission is:

  • emailed to info@appsec-labs.com;
  • stored in this website’s own database, which keeps a copy of every submission: name, email address and message;
  • recorded in our mail-delivery log;
  • used within our own business systems where we need it to respond to you or to work with you — where that happens under an agreement between us, that agreement governs it rather than this policy.

We keep enquiries only for as long as we have a reason to — to answer you, to pick up a conversation you started, and to keep our own records straight — and we remove them when that reason has passed. We do not keep them indefinitely, and we do not use them for anything other than what is described here.

If you would like us to delete an enquiry, write to info@appsec-labs.com and we will deal with it — see Your rights below.

Analytics

We use Cloudflare Web Analytics, which measures page views and referrers without cookies and without fingerprinting visitors. A second analytics service also reports page views and referrers to Automattic.

We do not use Google Analytics or Google Tag Manager. We do not run advertising or remarketing tags, and we do not sell or share personal data with advertisers.

Other services that receive data

  • Google reCAPTCHA protects our forms from automated abuse. It receives your IP address and interaction signals when a form is submitted.
  • A spam-filtering service operated by Automattic scores form submissions, so we are not spending our time answering bots.
  • Our security layer logs IP addresses and request details in order to detect and block abuse.
  • Cloudflare sits in front of the site and processes requests in transit, including IP addresses, to serve and protect it.
  • Our mail provider carries enquiry emails and retains a send log.

Where your data is held

This website is hosted in the European Union, so for visitors in the EU or the UK the site and its database sit inside the EU. Our company and our staff are in Israel, which the European Commission recognises as providing an adequate level of data protection — so an enquiry you send is read in Israel.

Cookies

We use the cookies needed to make the site work, and the consent banner lets you control anything beyond that. Cloudflare Web Analytics sets no cookies. If a category in the banner does not match what is described here, the description here is what we intend — please tell us so we can fix the banner.

Your rights

Depending on where you live, you may have the right to ask us for a copy of the personal data we hold about you, to ask us to correct or delete it, or to object to our using it — and where we rely on your consent, to withdraw it. Write to info@appsec-labs.com and we will handle your request as the applicable law requires.

We may need to confirm who you are before we act, so that we are not acting on someone else’s behalf without their knowledge. Some material we have to keep — where a contract, an accounting duty or another legal obligation requires it — and where that applies we will tell you.

Israeli privacy law applies to us. If you are in the EU or the UK, the rights the GDPR gives you apply to the same processing, and you may also complain to your national supervisory authority.

Security

Traffic to this site is encrypted in transit. Administrative access requires two-factor authentication, and access to enquiry data is limited to the people who need it. Our hardening is verified automatically on a schedule, so it cannot quietly regress.

If you think you have found a security problem here, please tell us at info@appsec-labs.com. We will not send a lawyer at anyone acting in good faith.

Changes

We update this policy when what we do changes. We do not email past enquirers about it, so if this matters to you, it is worth re-reading before you send us anything sensitive.