Skip to main content
Get support →
Back to Home

Privacy

Last updated: August 3, 2026

1. Introduction

Ransom-ISAC ("we", "our", or "us") is committed to protecting the privacy and personal data of our members, website visitors, newsletter subscribers, and anyone who interacts with our services. This policy explains how we collect, use, store, and protect your personal data in accordance with the General Data Protection Regulation (EU) 2016/679 ("GDPR"), the UK General Data Protection Regulation, and other applicable data protection legislation.

This policy applies to all personal data processed through our website (ransom-isac.org), membership platform, communication channels, newsletter services, and any related services we operate.

2. Data Controller

The data controller responsible for your personal data is:

Ransom-ISAC UG (haftungsbeschränkt)
Registered at the Amtsgericht München, HRB 312071
Contact: contact@ransom-isac.org

3. What Data We Collect

Website Visitors. When you visit our website, we may collect technical data such as your IP address, browser type and version, operating system, referring URL, pages visited, time and date of access, and approximate geographic location derived from your IP address.

Newsletter Subscribers. When you subscribe to our newsletter, we collect your email address, name (if provided), organisation (if provided), and the date and time of subscription. We also record your consent to receive communications and may track whether emails are opened or links are clicked for the purpose of improving our communications.

Members and Applicants. When you apply for or maintain membership, we may collect your full name, professional email address, organisation name and role, professional background information, contact details, and any correspondence exchanged during the membership process. As part of membership vetting, we also process identity verification and related data, including where applicable biometric and identity-document data.

Event Attendees. If you register for events, webinars, or conferences, we collect your name, email address, organisation, and any dietary or accessibility requirements you provide.

Intelligence Platform. In operating our threat-intelligence community, we process information shared through the platform. Where such information contains personal data, it is handled in accordance with this policy and applicable data protection law.

4. How We Use Your Data

PurposeData UsedLegal Basis (GDPR Art. 6)
Website operation and securityTechnical/server log dataLegitimate interest (Art. 6(1)(f))
Sending newsletters and updatesEmail, name, organisationConsent (Art. 6(1)(a))
Membership administrationContact details, professional infoContract performance (Art. 6(1)(b))
Membership vetting and verificationIdentity, verification and (where applicable) biometric dataExplicit consent (Art. 9(2)(a)); legitimate interest (Art. 6(1)(f)); legal obligation (Art. 6(1)(c))
Operating the intelligence communityPlatform and shared dataLegitimate interest (Art. 6(1)(f)); contract (Art. 6(1)(b))
Event registration and deliveryName, email, dietary/access needsContract performance (Art. 6(1)(b))
Website analytics (where consent given)Cookies, usage dataConsent (Art. 6(1)(a))
Responding to enquiriesContact details, message contentLegitimate interest (Art. 6(1)(f))
Legal compliance and fraud preventionAs required by lawLegal obligation (Art. 6(1)(c))

5. Cookies and Similar Technologies

Our website uses cookies. Strictly necessary cookies are required for the website to function and cannot be switched off. Analytics cookies help us understand how visitors interact with our website and are only placed with your consent.

You can manage your cookie preferences through your browser settings or our cookie consent banner. Refusing non-essential cookies will not affect the core functionality of our website.

6. Newsletter and Email Communications

We send newsletters and updates only to individuals who have provided explicit consent (opt-in). Each email includes an unsubscribe link. You may withdraw your consent at any time by clicking the unsubscribe link in any email.

We use a third-party email service provider to deliver our communications. Your data is shared with this provider solely for that purpose, under a contract that complies with GDPR Article 28.

We may track email open rates and link clicks in aggregate to improve the relevance of our communications. This newsletter tracking does not involve profiling or automated decision-making. For automated processing on our incident hotline, see section 7 below.

7. Incident Hotline and Automated (AI) Call Handling

When you call our cyber incident response hotline, your call is answered initially by an automated assistant — an artificial intelligence system rather than a human. You are informed of this at the start of every call. Full terms are set out in our Incident Hotline Terms of Service.

What we collect. Your telephone number, the date, time and duration of the call, an audio recording and transcript of the call, and the details you provide about your organisation and the incident — typically your name, role, organisation, contact details, country, and a description of what has happened.

How it is processed. Audio from the automated portion of the call may be recorded, transcribed and analysed by artificial intelligence systems, including systems operated by third-party providers acting as processors on our behalf under GDPR Article 28 contracts. This is done to triage your call and route it to an appropriate human responder.

Provider retention and model improvement. Our voice platform provider may retain call recordings and transcripts, and depending on their configuration this data may be used to improve their artificial intelligence models. Processing may take place outside the European Economic Area, including in the United States, under the safeguards described in section 9. If your organisation requires that call data is not handled in this way, please contact us in advance and we will arrange an alternative intake route.

No automated decision-making. The automated assistant collects information and routes calls. It does not make decisions producing legal or similarly significant effects concerning you within the meaning of Article 22 GDPR. Assessment of your incident and any advice given is carried out by human responders.

Lawful basis. We process this data on the basis of our legitimate interests (Article 6(1)(f) GDPR) in operating an incident response service and in taking steps at your request prior to any engagement (Article 6(1)(b) GDPR). Where recording requires consent under the law of your jurisdiction, we rely on the consent indicated by your continued participation after the introductory notice.

Your choice. You may decline automated handling at any point during the call and ask to be transferred to a human responder, or contact us in writing instead. Declining does not affect the assistance available to you.

Retention. Call recordings and transcripts are deleted after 14 days, unless a call is flagged — for example in connection with misuse of the service or an ongoing investigation — in which case it is kept only for as long as that purpose requires.

Coordination with DFIR partners. We operate a vetted network of regional digital forensics and incident response partners. Based on your location and the nature of the incident, we coordinate with the appropriate partner and share your enquiry so they can engage with you directly. Partners are independent controllers in respect of any subsequent engagement.

8. Data Sharing and Third Parties

We do not sell, rent, or trade your personal data. We may share your data only in the following circumstances:

Service providers: Trusted third-party providers for functions including website hosting, threat-intelligence platform services, identity verification and vetting, payment processing, email delivery, and analytics. These providers process data only on our behalf, under contracts that comply with GDPR Article 28.

Partners: Where relevant to an incident or intelligence-sharing arrangement, and subject to authorisation and applicable law, we may share information with our vetted partner organisations, under written agreements.

Legal obligations: Where required by law, regulation, or legal process.

With your consent: Where you have given specific, informed consent.

9. International Data Transfers

Some of our service providers and partners are located outside the European Economic Area (EEA) and the United Kingdom, including in the United States. This means your personal data may be transferred to, and processed in, countries that have not received an adequacy decision from the European Commission or the UK.

Where we transfer personal data outside the EEA or the UK, we put in place appropriate safeguards required under applicable data protection law, which may include:

  • transfers to countries or frameworks covered by an adequacy decision (such as the EU–US Data Privacy Framework, where the recipient is certified);
  • the European Commission’s Standard Contractual Clauses (SCCs), together with a transfer impact assessment where required; or
  • other lawful transfer mechanisms permitted under Chapter V of the GDPR.

In particular, our threat-intelligence platform and certain service providers may process data on infrastructure located in the United States, subject to these safeguards. You may request further information about the specific safeguards applied to a given transfer by contacting us using the details in Section 14.

10. Data Retention

We retain personal data only for as long as necessary to fulfil the purposes for which it was collected, or as required by law.

Data CategoryRetention PeriodNotes
Website server logs90 daysAutomatically deleted
Newsletter subscriber dataUntil consent is withdrawnDeleted within 30 days of unsubscribe
Member dataDuration of membership + 12 monthsFor continuity purposes
Vetting and verification dataDuration of membership + 12 monthsBiometric data deleted promptly after verification
Event registration data12 months after the eventFor follow-up and feedback
Enquiry/contact data12 months after last interactionUnless ongoing relationship exists
Cookie dataMax 12 monthsConfigurable via cookie preferences

When personal data is no longer required, it is securely deleted or anonymised.

11. Data Security

We implement appropriate technical and organisational measures to protect personal data against unauthorised access, alteration, disclosure, or destruction, including encryption in transit and at rest, access controls, and regular review of security practices.

12. Your Rights

Under the GDPR, individuals have rights regarding their personal data, including access, rectification, erasure, restriction of processing, data portability, and the right to object. Where processing is based on consent, consent may be withdrawn at any time without affecting the lawfulness of prior processing.

Requests may be directed to us at contact@ransom-isac.org and will be handled in accordance with applicable legal requirements.

You also have the right to lodge a complaint with a supervisory authority. The competent authority for us is the Bavarian State Office for Data Protection Supervision (Bayerisches Landesamt für Datenschutzaufsicht — BayLDA), based in Ansbach.

13. Children's Privacy

Our services are not directed at individuals under the age of 18. We do not knowingly collect personal data from children.

14. Changes to This Policy

We may update this policy from time to time. Material changes will be communicated via our website and, where appropriate, by email at least 30 days before taking effect. The "Last updated" date at the top indicates the most recent revision.

15. Contact

For any privacy queries, or to exercise any of the rights described above, please contact us at contact@ransom-isac.org.