Clinical continuity. Technical evidence.Atlant Security
Hospital/PentestBY ATLANT SECURITY

LEGAL & PRIVACY

Privacy notice

How Atlant Security handles personal information when you visit hospitalpentest.com or enquire about a penetration testing engagement.

Who is responsible

Atlant Security, Svoboda 27-69, Sofia 1231, Bulgaria, VAT BG205426422, is the controller of personal data processed for this website and its business enquiries. Contact alexander@atlantsecurity.com for privacy matters or write to the address above.

This notice covers the public website and initial enquiries. A penetration testing engagement requires its own contractual confidentiality, evidence-handling and, where applicable, data-processing arrangements.

What we process and why

PurposeInformationLegal basis
Responding to business enquiriesName, work email, organisation, optional timeframe, message and subsequent correspondence.Legitimate interests in responding to professional enquiries and developing business relationships (GDPR Article 6(1)(f)). Where you personally request steps toward a contract with you, Article 6(1)(b) may apply.
Fulfilling sample report requestsName, work email, organisation, optional role and related correspondence. A signed access cookie enables the requested browser download for 15 minutes.Legitimate interests in responding to professional resource requests and discussing related testing requirements (Article 6(1)(f)).
Delivering and protecting the siteIP address and request/security metadata processed by the hosting infrastructure; limited temporary rate-limit information.Legitimate interests in operating a secure, available website and preventing abuse (Article 6(1)(f)).
Legal obligations and claimsRelevant correspondence and records where necessary.Compliance with legal obligations (Article 6(1)(c)) and legitimate interests in establishing, exercising or defending claims (Article 6(1)(f)).

Name, email, organisation and message are required to submit the enquiry form; the timeframe is optional. The sample-report form requires name, work email and organisation; your role is optional. We use these details to fulfil the resource request and may follow up about it and your testing requirements. Providing them is not a statutory obligation. You can contact us directly by email instead. Without contact information, we may be unable to respond.

Do not send passwords, sensitive personal data, vulnerability details or confidential production information through the public form. We do not use enquiry details to subscribe you to newsletters. We do not conduct automated decision-making with legal or similarly significant effects through this site.

Who may receive information

Authorised people handling enquiries at Atlant Security can access relevant correspondence. Cloudflare provides hosting, security and delivery of form notifications to our business mailbox. The mailbox service processes the resulting email in the ordinary course of email delivery and storage. Professional advisers or public authorities may receive information where necessary for advice, legal obligations or claims.

The website does not sell personal data or load advertising networks. We do not retain form submissions in a separate website database. Messages are forwarded to our business mailbox, where subsequent correspondence is handled.

International processing

Cloudflare operates a global network; email delivery and support may also involve processing outside the European Economic Area. We do not represent this service as EU-only hosting.

Where a restricted transfer occurs, an appropriate GDPR Chapter V safeguard is required, such as an applicable adequacy decision or standard contractual clauses. Cloudflare describes its processor commitments and transfer provisions in its Customer Data Processing Addendum. Contact us for information about safeguards relevant to your data and how to obtain a copy, subject to necessary redactions.

How long information is kept

Enquiry correspondence is kept for as long as reasonably needed to respond, manage the resulting business relationship and address related questions. Retention also considers whether a contract follows, applicable legal recordkeeping duties and the period reasonably necessary for claims. Information no longer needed for these purposes should be deleted.

The website does not create an application-level archive of submissions or a marketing profile. Infrastructure security data is subject to the relevant provider’s processing and retention arrangements. You can ask for information about retention applicable to your enquiry or request erasure where the legal conditions are met.

Your rights

Subject to the applicable conditions, you may request access, correction, erasure, restriction and data portability. You may object to processing based on legitimate interests, including by explaining your particular situation. Where processing relies on consent, you may withdraw it without affecting earlier lawful processing; the enquiry form does not rely on marketing consent.

Send requests to alexander@atlantsecurity.com. We may need proportionate information to confirm identity. We aim to handle rights requests within the GDPR time limits, normally one month; lawful extensions or limitations will be explained.

You may complain to a supervisory authority, including the authority in the country where you live or work. The Bulgarian authority is the Commission for Personal Data Protection (CPDP).

Changes and contact

We will update this notice when the site’s processing changes and revise the effective date. Privacy questions can be sent to alexander@atlantsecurity.com.