Privacy information for the CVD process
The controller pursuant to Art. 4(7) of the EU General Data Protection Regulation (GDPR) is:
DIAL GmbH
Bahnhofsallee 18
58507 Lüdenscheid, Germany
Tel +49 (0) 2351 5674 0
E-mail: dialog@dial.de
Our data protection officer can be reached at:
progressorg GmbH
Höveler Weg 2
58553 Halver, Germany
Tel +49 (0) 2353 9096 31
E-mail:
datenschutz@progressorg.de
1. Purpose and scope
This privacy information for the CVD process informs you about the processing of your personal data when reporting security vulnerabilities to DIAL GmbH (Coordinated Vulnerability Disclosure – CVD). It supplements the general privacy policy of DIAL GmbH at https://www.dial.de/en-GB/data-protection-policy and applies to all persons who report vulnerabilities or communicate with our security team.
Our CVD process is described in the CVD policy at /en/cvd-policy.html .
2. Data processing when reporting security vulnerabilities
Purposes of processing
- Receipt, categorisation and validation of vulnerability reports
- Communication with you – queries, status updates, coordination of disclosure
- Technical analysis and reproduction of the reported vulnerability
- Development and provision of security updates
- Compliance with statutory reporting obligations (CRA Art. 14, GDPR Art. 33)
- Coordinated disclosure in the European Vulnerability Database (EUVD)
- Documentation and evidence (CRA Annex I Part II No. 5)
- Quality assurance and product improvement (in anonymised form)
Categories of data processed
- Contact data: e-mail address, optionally name, organisation
- Communication data: e-mail correspondence, message history, timestamps
- Metadata: date and time of the report
- Technical data: product and version numbers, system configurations, log data, proof-of-concept code, network traces, screenshots, error messages, CWE numbers
- Process data: incident ID, status, deadlines, decision notes
- PGP key data (if transmitted): public key, fingerprint
Legal bases
- Art. 6(1)(f) GDPR (legitimate interest) for processing, communication, analysis and documentation. Our legitimate interest is ensuring product and system security.
- Art. 6(1)(c) GDPR (legal obligation) for statutory reporting obligations under CRA Art. 14 and GDPR Art. 33 and for coordinated disclosure in the EUVD.
- Art. 6(1)(a) GDPR (consent) when forwarding your data to external security researchers. You may withdraw consent at any time with effect for the future, without affecting the lawfulness of processing prior to withdrawal. Submit withdrawal informally to datenschutz@progressorg.de or psirt@dial.de.
Recipients / categories of recipients
- Internal: security team (PSIRT/CSIRT), data protection officer, legal department, development (only as required)
- CERT-Bund / BSI (reporting actively exploited vulnerabilities, CRA Art. 14)
- ENISA (reporting actively exploited vulnerabilities, CRA Art. 14)
- European Vulnerability Database (EUVD) (coordinated disclosure)
- CVE numbering authorities (e.g. MITRE) – technical vulnerability data only
- Hosting service providers for e-mail, web form and security.txt (data processing, Art. 28 GDPR)
- External security researchers – only with your consent
Storage periods
- Report data and correspondence: 3 years after conclusion of the CVD process
- Technical data: 2 years after conclusion (quality assurance)
- Metadata: 30 days, maximum 90 days
- Data relating to statutory reports (CRA, GDPR): 10 years (statutory retention)
- Data for legal defence: until final conclusion + 3 years
Upon expiry of the periods, data is deleted or anonymised.
Consequences of not providing contact information
Without a contact channel, we cannot submit queries, provide status updates or coordinate disclosure with you. All other information is voluntary.
Third-party data
If your report material (e.g. proof-of-concept, log data, screenshots) contains personal data of third parties, we request that you limit such data to what is indispensable for understanding the vulnerability and anonymise it where possible prior to transmission. If we nevertheless process third-party data, this is done on the basis of Art. 6(1)(f) GDPR for the purpose of remediating the vulnerability. Separate notification of such persons is provided only insofar as possible with reasonable effort (Art. 14(5)(b) GDPR).
3. Anonymous reports
We expressly permit anonymous reports. You are not obliged to provide your name or other identifying information. For anonymous reports, we recommend using a disposable e-mail address and encrypting communication with our PGP key (
https://security.dial.de/psirt-pgp-key.asc
, fingerprint: 8C29 895A 9F6B 1A11 7703 BDAD 7AC5 2306 FD2F FCF3).
Anonymous reports are assessed by the same criteria as identified reports. However, we cannot provide status updates unless you provide a suitable anonymous communication channel.
4. Data processing at security contact points
E-mail (PSIRT / CSIRT)
When communicating with psirt@dial.de or csirt@dial.de , we process your e-mail address, message content and attachments as well as metadata (timestamp, subject). We recommend PGP encryption. Our PGP key is available at https://security.dial.de/psirt-pgp-key.asc . The legal basis is Art. 6(1)(f) GDPR (legitimate interest in receiving and processing vulnerability reports and in IT security).
Web form
If you use the web form at /en/vulnerability-report-form.html , we process the data you enter and your IP address for a maximum of 7 days for misuse prevention. The web form uses exclusively technically necessary session cookies. Storage of technically necessary session cookies occurs without consent pursuant to § 25(2) No. 2 TDDDG.
security.txt (RFC 9116)
Our security.txt document at https://security.dial.de/.well-known/security.txt contains exclusively functional contact data. Personal data of natural persons is not published there. Access is logged in anonymised logs for a maximum of 7 days. The legal basis for access logging is Art. 6(1)(f) GDPR (legitimate interest in the security and functionality of our systems).
5. Your rights in the CVD process
Your general data subject rights (access, rectification, erasure, restriction, data portability, objection, complaint) are described in the general privacy policy of DIAL GmbH at https://www.dial.de/en-GB/data-protection-policy . The following particularities apply in the CVD process:
- Anonymous reports: For anonymous reports, we cannot provide information about your data as we cannot identify you. We will endeavour to fulfil your request if you provide a suitable communication channel.
- Objection: You have the right, on grounds relating to your particular situation, to object at any time to processing of your personal data based on our legitimate interest (Art. 6(1)(f) GDPR). Upon objection, we will cease processing your personal data unless we demonstrate compelling legitimate grounds for processing that override your interests, rights and freedoms, or processing serves the establishment, exercise or defence of legal claims. Submit objections informally to datenschutz@progressorg.de or psirt@dial.de .
- Erasure during ongoing proceedings: During an ongoing CVD process, erasure of your data is only possible to a limited extent, as processing is necessary for handling the report.
- Automated decisions: No automated decision-making (Art. 22 GDPR) occurs in the CVD process. Every decision is made by at least two authorised persons (four-eyes principle).
- Right to lodge complaint: Without prejudice to other remedies, you have the right to lodge a complaint with a supervisory authority (Art. 77 GDPR). The competent authority for DIAL GmbH is the State Commissioner for Data Protection and Freedom of Information of North Rhine-Westphalia, Kavalleriestraße 2–4, 40213 Düsseldorf, www.ldi.nrw.de .
6. References
This privacy information is embedded in the following framework:
- CVD policy: /en/cvd-policy.html
- General privacy policy: https://www.dial.de/en-GB/data-protection-policy
- Legal notice: https://www.dialux.com/en-GB/legal-notice
- Cyber Resilience Act (EU 2024/2847): Art. 13, 14 and Annex I Part II No. 5
| Version | Date | Change |
|---|---|---|
1.0.0 | 12.08.2026 | Initial publication |
This privacy information supplements the general privacy policy of DIAL GmbH and fulfils the requirements of the GDPR (Art. 13, 14) and the Cyber Resilience Act (Art. 13(6), Annex I Part II No. 5).