Privacy Notice for Reports to our PSIRT

Controller

Freiberg Instruments GmbH 
Delfter Straße 6, 09599 Freiberg, Germany 
Phone +49 3731 41954-0 
Email privacy@freiberginstruments.com 
Data protection officer: Thanga Kumar, 
thanga.kumar@freiberginstruments.com

What we process

The information you enter in the form or send by email: name or pseudonym, email address, and the content of your report including any attachments. In addition, the time of receipt and the technical data about your access to the form (IP address, timestamp). Any further information is provided voluntarily. If your report contains personal data of other people, for example in log extracts or screenshots, we process it only as far as necessary to assess and remediate the issue, and delete it as soon as it is no longer needed.

Purposes

Handling and assessing your report, contacting you with follow-up questions, remediating the vulnerability, informing affected customers, documenting our vulnerability handling, and complying with statutory reporting obligations.

Legal bases

Art. 6(1)(f) GDPR – our legitimate interest, and our customers’ interest, in the security of our products. 

Art. 6(1)(c) GDPR – where we are legally required to report, in particular under Article 14 of Regulation (EU) 2024/2847 (Cyber Resilience Act). 

Art. 6(1)(a) GDPR – for crediting you by name in a publication, if you wish. You may withdraw this consent at any time; the withdrawal does not affect the lawfulness of processing carried out before it.

Recipients

Service providers who process the report on our behalf under Article 28 GDPR, in particular our email and hosting providers and our ticketing system, all of them bound by data processing agreements. We will name the specific providers on request.

The competent CSIRT and ENISA via the single reporting platform, where a reporting obligation applies. 

Manufacturers of affected supplied components, where the vulnerability concerns them. 

We share the content of your report only as far as necessary for remediation. We share information about you personally only with your agreement or where we are legally obliged to do so.

Retention

  • The content of the report: for the support period of the affected product plus three years, as evidence of our vulnerability handling.

  • Your contact details: twelve months after the case is closed. If crediting has been agreed, we keep your name for as long as the advisory remains published.

  • Technical access data from the form: three months.

Your rights

You have the right of access, rectification, erasure, restriction of processing, data portability and objection, and the right to withdraw consent at any time. You may also lodge a complaint with a data protection supervisory authority. The authority competent for us is the Saxon Data Protection and Transparency Commissioner (Sächsische Datenschutz- und Transparenzbeauftragte), Postfach 11 01 32, 01330 Dresden, Germany, post@sdtb.sachsen.de.

Right to object

Where we process your data on the basis of Art. 6(1)(f) GDPR, you have the right to object to that processing at any time on grounds relating to your particular situation.

Voluntary provision

Providing your data is voluntary and you may report under a pseudonym. Without a means of contacting you, however, we cannot send you feedback or ask follow-up questions.

Version: August 28, 2026