Privacy & Data Disclosure Policy
Version 1.0 · 13 July 2026
This Privacy Policy describes how Porta Regulus B.V. (trading as CVD Portal, "we", "us", or "our") collects, uses, encrypts, and strictly limits the disclosure of sensitive vulnerability and personal data. Because the platform facilitates high-stakes cybersecurity workflows aligned with the EU Cyber Resilience Act, our data-handling procedures adhere to strict "need-to-know" operational security (OPSEC) parameters.
1. Who we are (controller identity)
The controller responsible for the personal data described in this notice is:
- Porta Regulus B.V., trading as CVD Portal
- WTC Amsterdam, Strawinskylaan 1, 1077 XW Amsterdam, Netherlands
- Commercial register (KvK) 42062307 · VAT NL869534208B01
- Data-protection contact: [email protected]
We act as the controller for account, billing, marketing, and website data that we determine the purposes and means for. For vulnerability submissions and other personal data processed on behalf of a tenant manufacturer, we act as a processor and the tenant is the controller. Those roles are set out in our Data Processing Agreement.
2. Legal bases for processing (Art. 6 GDPR)
- Contract (Art. 6(1)(b)) — creating and operating your account and providing the service you signed up for.
- Legal obligation (Art. 6(1)(c)) — retaining CRA Article 14 evidence records and billing/tax records required by law.
- Legitimate interests (Art. 6(1)(f)) — securing the platform, preventing abuse, and understanding product usage. We balance these against your rights and you may object (see Section 5).
- Consent (Art. 6(1)(a)) — non-essential cookies and any optional marketing communications. You can withdraw consent at any time.
3. Data We Collect & Process
We process two categories of data on behalf of our Tenants (Manufacturers):
- Tenant Operations Data: Administrative accounts, SBOMs (Software Bill of Materials), hardware identifiers, configuration metadata, and operational audit logs.
- Vulnerability Incident Data: Encrypted/unencrypted submission payloads generated by external cybersecurity researchers, including zero-day proofs-of-concept, exploitation steps, impact assessments, and PGP public keys.
4. The "Shared Responsibility" Security Model
We assume the role of the structural Data Processor holding logs and orchestrating workflows. Sensitive payloads (such as reproduction steps) are only decrypted by authorized Tenant staff holding valid RBAC (Role-Based Access Control) clearance. We do not inspect, monetize, or index the internal content of unpatched vulnerabilities for marketing or external distribution.
5. Mandatory Authority Disclosures (CSIRT / ENISA)
Unlike traditional platforms that never disclose private communications, the CVD Portal is specifically engineered to fulfill Cyber Resilience Act regulatory reporting requirements. If a Tenant actively triages an exploit and flags it as having "CRITICAL" or "HIGH" societal risk, the Platform allows the generation of specialized 24-hr Notification Export files. By using the platform to generate these files, the Tenant explicitly authorizes the compilation of PII and security details into National CSIRT and ENISA-compatible formats for escalated transmission.
6. Researcher Anonymity & Protection
Under the Cyber Resilience Act, cybersecurity researchers submitting vulnerabilities in good faith must be protected. The CVD Portal permits anonymous reporting. When contact emails or PGP identifiers are provided by researchers, they are strictly locked to the relevant Tenant’s workspace to coordinate remediation. The Platform does not aggregate researcher profiles across different, competing tenants.
7. Data Retention & Immutable Logging
Because the Cyber Resilience Act requires rigorous proof of response times (e.g., verifying that a submission was acknowledged within exactly 48 hours), the CVD Portal writes every state-changing action to a tamper-evident audit log. Each entry is linked into a per-tenant SHA-256 hash chain, database-level controls reject any update or deletion of stored entries, and an automated job re-verifies every chain daily. Entries cannot be altered or deleted by Tenant administration staff.
Operational entries (logins, page views, API calls) are retained for 12 months and then purged. Entries forming the CRA Article 14 evidence chain (vulnerability classification, notification, and remediation decisions) are retained permanently. If an account is deleted under GDPR Article 17, those evidence entries are preserved in pseudonymised form, with personal identifiers removed, so the compliance record survives the erasure of personal data. Details are on our Trust page.
8. Your Rights and How to Exercise Them
Where we act as controller, you have the right to access, rectify, erase, restrict, and port your personal data, to object to processing based on legitimate interests, and to withdraw consent at any time without affecting processing that already took place. To exercise any of these rights, email [email protected]. We respond within one month, as required by Article 12(3) GDPR, and may extend this by two further months for complex requests, telling you why. Where a request concerns data we process on behalf of a tenant (for example a vulnerability submission), we will refer you to the tenant manufacturer, who is the controller for that data, and assist them in responding.
9. International Transfers
The platform, its database, and its backups are hosted with Hetzner in Germany, and submission data is not transferred outside the EU/EEA by default. Where a subprocessor processes data outside the EEA (for example optional AI features or edge network traffic), those transfers rely on the European Commission's Standard Contractual Clauses. The current subprocessor list, with the region and transfer mechanism for each, is on our Trust page and in Annex III of our Data Processing Agreement.
10. Cookies
We keep cookies to a minimum. This is the Cookie Policy referenced by our cookie banner.
| Cookie | Purpose | Type | Retention |
|---|---|---|---|
| Session / auth | Keeps you signed in and secures the session. | Strictly necessary | Session / up to 30 days |
| Cookie consent | Remembers your cookie choice. | Strictly necessary | Up to 12 months |
| PostHog (EU) | Privacy-friendly product analytics, hosted in the EU. Set only with your consent. | Analytics (consent) | Up to 12 months |
| cvd_affiliate | Set only if you arrive through an affiliate referral link, so we can credit that affiliate if you later create an account. First-party, HTTP-only, holds a single referral code and nothing about you. Not shared with anyone and not used for profiling or advertising. Cleared as soon as you sign up. | Functional | Up to 90 days |
Strictly necessary cookies are required for the service to work and cannot be switched off. You can accept or decline analytics cookies through the banner and change your choice at any time, and you can also block or delete cookies in your browser settings.
11. Supervisory Authority, DPO, and EU Representative
You have the right to lodge a complaint with a supervisory authority. Our lead authority is the Dutch Autoriteit Persoonsgegevens (autoriteitpersoonsgegevens.nl), and you may also complain to the authority in your country of residence.
We are established in the EU (Netherlands), so an Article 27 EU representative is not required. We have not appointed a statutory Data Protection Officer because our processing does not meet the Article 37 thresholds. Data-protection questions and requests are handled by our privacy contact at [email protected].