root@hckrt: ~#
Privacy Notice
Hackrate Privacy Notice
Last updated: 13 July 2026
Effective date: 13 July 2026
This Privacy Notice explains how HACKRATE Kft. processes personal data when you visit Hackrate websites, create or use a Hackrate account, participate in or report to an ethical hacking or vulnerability disclosure program, communicate with us, request or receive our services, or otherwise interact with Hackrate.
This Privacy Notice should be read together with the terms that apply to the relevant Website, Platform, Program or Service and, where relevant, the privacy information contained in a specific Program.
Privacy Notice Summary
Who is responsible for your personal data?
The controller is HACKRATE Kft., with registered office at 2890 Tata, Baji út 35. 2. lház. 2. em. 12., Hungary, company registration number Cg. 11-09-028368, tax number 28961200-2-11 and EU VAT number HU28961200 (HACKRATE, Hackrate, we, us or our).
Privacy enquiries and data subject requests may be sent to [email protected].
What does this Notice cover?
This Notice covers personal data processed in connection with:
https://www.hckrt.com/,https://hckrt.com/,https://blog.hckrt.com/and other Hackrate webpages that link to this Notice (Website);- the Hackrate Ethical Hacking Platform, user and business accounts, Bug Bounty Programs, Managed Vulnerability Disclosure Programs, Pentest-as-a-Service and related services (Platform and Services);
- identity verification, Program eligibility, reward administration and fraud prevention;
- requests, forms, surveys, newsletters, events, support and other communications with Hackrate; and
- legal, compliance, security and business-administration activities connected with the above.
A Program Sponsor or mVDP Client may separately act as a controller for personal data contained in a Program, report, communication or decision that it determines. Its own privacy notice may also apply.
What personal data may we process?
Depending on how you interact with us, we may process account and contact data, professional profile and researcher data, Program participation and vulnerability-report data, communication data, payment and tax data, identity-verification data, technical and security data, cookie and analytics data, marketing preferences, and records needed to comply with law or protect legal rights.
Identity verification through ComplyCube
Where identity verification is required, Hackrate uses ComplyCube, a service operated by TEEMO TECHNOLOGY LTD, company number 12392069, registered at Crown House, 27 Old Gloucester Street, London, WC1N 3AX, United Kingdom. Depending on the verification workflow, ComplyCube may process an image of an identity document, information extracted from that document, a selfie or short video, facial-comparison and liveness results, device and network information, and related verification records on Hackrate's behalf.
Where biometric data is used for the purpose of uniquely identifying you, Hackrate will rely on explicit consent only where that consent can be freely given and a genuine choice is available, unless another valid condition under applicable data-protection law has been documented. You may withdraw consent for future processing, but withdrawal does not affect processing already carried out lawfully. Where verification is necessary to access a particular Program, receive a Reward, prevent fraud or meet a legal requirement, Hackrate may be unable to provide that feature if verification cannot be completed through an available lawful method.
Why do we use personal data?
We use personal data to operate and secure the Website and Platform; create and manage accounts; administer Programs and reports; communicate with users and customers; verify identity and eligibility; prevent fraud and abuse; assess, triage and route reports; process Rewards and business payments; provide support; improve the Services; send marketing where permitted; comply with law; and establish, exercise or defend legal claims.
Our legal bases may include performance of a contract, steps requested before entering into a contract, legitimate interests, compliance with legal obligations and consent. The basis depends on the activity and context. Special-category data, including biometric data used for unique identification, is processed only where an additional condition under Article 9 GDPR applies.
Who may receive personal data?
Personal data may be accessed by authorised Hackrate personnel and may be shared, where necessary, with service providers, ComplyCube, Program Sponsors, mVDP Clients, payment and banking providers, professional advisers, insurers, auditors, corporate transaction counterparties, competent authorities and other recipients described in this Notice. Hackrate does not sell personal data.
International transfers
Some recipients may process data outside the European Economic Area. Hackrate uses an adequacy decision or appropriate safeguards where required, such as the European Commission's Standard Contractual Clauses adopted under Implementing Decision (EU) 2021/914, together with supplementary measures where appropriate.
How long do we keep personal data?
We retain personal data only for as long as reasonably necessary for the relevant purpose, including account and Program administration, security, fraud prevention, payment and tax obligations, dispute resolution and legal claims. Identity documents, selfies, videos and biometric material are kept for the shortest period reasonably necessary for verification and related risk review, subject to the configured verification workflow, legal obligations and any active dispute or fraud investigation.
What are your rights?
Subject to applicable law, you may have rights of access, rectification, erasure, restriction, portability and objection, the right to withdraw consent, and rights concerning solely automated decisions. You may also lodge a complaint with the Hungarian National Authority for Data Protection and Freedom of Information or another competent supervisory authority.
Full Privacy Notice
1. Scope and Who This Notice Covers
1.1 This Privacy Notice applies to individuals whose personal data HACKRATE processes in connection with the Website, Platform and Services, including:
- Website visitors;
- people who contact Hackrate, submit a form, join a mailing list, attend an event, answer a survey or request a demonstration;
- Bounty Hunters, ethical hackers, security researchers and mVDP reporters;
- representatives, employees and contractors of Program Sponsors, mVDP Clients, customers, prospects, suppliers and partners;
- people whose data appears in a vulnerability report, Program communication, support request, security log or legal record; and
- other individuals who interact with Hackrate in a business or professional capacity.
1.2 This Notice does not replace a privacy notice provided by a Program Sponsor, mVDP Client or other third party. A Program Sponsor or mVDP Client may independently determine why and how it processes report content, researcher details, communications, testing evidence and decisions relating to its systems. In that case it acts as a separate controller or, where expressly agreed and legally appropriate, in another role described in the relevant agreement.
1.3 Where HACKRATE processes personal data solely on documented instructions from a business customer under a data processing agreement, the customer is responsible for the relevant controller obligations and requests should normally be directed to that customer. HACKRATE will assist the customer as required by the applicable agreement and law.
2. Controller and Contact Details
2.1 Unless this Notice or a specific agreement states otherwise, the controller is:
HACKRATE Kft.
Registered office: 2890 Tata, Baji út 35. 2. lház. 2. em. 12., Hungary
Company registration number: Cg. 11-09-028368
Tax number: 28961200-2-11
EU VAT number: HU28961200
Telephone: +36 20 310 8651
General email: [email protected]
Privacy email: [email protected]
2.2 Please use [email protected] for privacy questions, objections, consent withdrawals and data subject requests. To protect personal data, we may ask for information reasonably necessary to verify your identity and authority before responding.
3. Personal Data We May Process
The data processed depends on the features and Services you use.
3.1 Website, device and security data
This may include:
- IP address, browser type and version, operating system, device type and identifiers;
- requested pages, referrer URL, date, time, duration and navigation events;
- cookie identifiers, consent preferences, local-storage and session-storage data;
- authentication events, login history and account-security events;
- server, application, audit, fraud-prevention and security logs; and
- information about suspected misuse, malicious activity, technical errors or incidents.
3.2 Account and contact data
This may include:
- name, username, email address, telephone number and country;
- account identifiers, password hash, authentication settings and recovery information;
- employer, organisation, role, job title and business contact details;
- language, time zone, communication preferences and profile image; and
- acceptance records for terms, notices, consents and Program rules.
3.3 Researcher, professional profile and eligibility data
For Bounty Hunters, ethical hackers and security researchers, this may include:
- biography, skills, areas of expertise, experience and publicly shared professional profiles;
- Platform activity, Program applications, invitations, participation history and status;
- report quality, responsiveness, ranking, reputation, badges and performance metrics;
- eligibility, suspension, restriction and appeal records; and
- conflict-of-interest, sanctions, fraud-risk or Program-specific screening information where required.
3.4 Program, testing and vulnerability-report data
This may include:
- Program scope, invitations, authorisations, testing windows and access information;
- Finding and vulnerability details, affected assets, severity, technical evidence and reproduction steps;
- proof-of-concept code, screenshots, files, HTTP requests and responses, logs and other Finding Materials;
- comments, triage notes, validation results, remediation status and disclosure decisions;
- activity and audit records associated with a Program or report; and
- personal data inadvertently encountered or included in a report.
You must minimise personal data in reports and must not intentionally access, copy, retain or disclose personal data beyond what is strictly necessary to demonstrate an in-scope Finding and comply with the applicable Program rules.
3.5 Identity-verification data
Where identity verification is required, this may include:
- legal name, date and place of birth, nationality, residential address and contact details;
- identity-document type, issuing country or authority, document number, issue and expiry dates, document images and machine-readable-zone or barcode data;
- a live photo, selfie or short video;
- facial-comparison, liveness, authenticity and fraud-risk results, confidence scores and reason codes;
- where enabled, biometric templates or measurements used to establish whether the person presenting the document is the same person shown on it;
- IP address, device, network, location indicators and technical metadata associated with the verification; and
- verification status, timestamps, reviewer notes and audit records.
Not every verification uses every category listed above. The data collected depends on the method configured for the relevant account, Program, Reward or risk level.
3.6 Payment, tax and transaction data
This may include:
- payee or billing name, address and contact details;
- bank-account or payment destination details and transaction identifiers;
- Reward amount, currency, status and payment history;
- invoices, purchase orders, subscription and business-payment information;
- tax-residency certificates, tax identifiers and information required for accounting, reporting or withholding; and
- sanctions, anti-fraud and payment-risk review records where applicable.
Hackrate generally receives limited payment information from its banking or payment providers and does not necessarily receive or retain complete card details.
3.7 Communications, support and customer-relationship data
This may include:
- enquiries, support tickets, emails, chat messages, meeting notes and call records;
- demonstration requests, proposals, contracts, order forms and customer-account records;
- survey answers, event registrations, feedback and testimonials;
- newsletter subscriptions, campaign interactions and marketing preferences; and
- records of complaints, disputes, rights requests and their resolution.
3.8 Compliance and legal data
This may include information needed to:
- investigate suspected violations of terms, Program rules or law;
- respond to lawful requests from courts, regulators or authorities;
- conduct audits, security reviews, due diligence or corporate transactions;
- establish, exercise or defend legal claims; and
- maintain records required by accounting, tax, company, employment, sanctions or other applicable laws.
3.9 Special-category and criminal-offence data
Hackrate does not seek special-category data unless it is necessary for a specific, disclosed purpose. Identity verification may involve biometric data used for unique identification. A report or communication may exceptionally contain health, political, religious, trade-union, sexual-orientation or other sensitive data, or information relating to alleged offences. Do not provide such data unless it is strictly necessary and lawful to do so. We will process such data only where an applicable Article 9 GDPR condition applies or, for criminal-offence data, where Article 10 GDPR and applicable Union or Member State law permit the processing.
4. How We Obtain Personal Data
We may obtain personal data:
- directly from you when you visit the Website, register, complete a profile, submit a report, communicate with us, take part in verification or use the Services;
- from your employer, organisation, Program Sponsor, mVDP Client, authorised representative or another Platform user;
- from ComplyCube, payment providers and other service providers acting in connection with the Services;
- from public professional profiles, company registers, sanctions lists and other lawful public sources where relevant to verification, due diligence, security or fraud prevention;
- automatically from devices, browsers, cookies, logs and security systems; and
- from authorities, advisers, insurers, counterparties or other third parties where lawful and necessary.
Where another person provides us with your data, that person is responsible for having a valid basis to disclose it and, where required, for giving you appropriate privacy information.
5. Purposes and Legal Bases
HACKRATE relies on one or more legal bases depending on the processing activity. The examples below are intended to explain the main activities; a different or additional basis may apply where required by law.
5.1 Website operation and essential security
Purposes: deliver webpages and requested functionality; maintain availability; remember essential settings; diagnose errors; prevent attacks, abuse and unauthorised access; and keep technical and security logs.
Main data: Website, device, cookie, log and security data.
Legal bases: legitimate interests under Article 6(1)(f) GDPR in operating and securing the Website and Services; performance of a contract or pre-contractual steps under Article 6(1)(b) where the activity is part of a requested service; and legal obligation under Article 6(1)(c) where applicable.
5.2 Account creation, authentication and administration
Purposes: create and manage accounts; authenticate users; provide account features; communicate service information; enforce applicable terms; and manage access, suspension and closure.
Main data: account, contact, profile, authentication, acceptance and activity data.
Legal bases: Article 6(1)(b) GDPR; Article 6(1)(f) GDPR for account security, auditability and misuse prevention; and Article 6(1)(c) where records are legally required.
5.3 Program administration and ethical hacking services
Purposes: publish or operate Programs; manage applications, invitations and authorisations; route and administer Findings; facilitate communication; support triage and validation; maintain status and audit records; and provide contracted Services to Program Sponsors and mVDP Clients.
Main data: account, professional profile, Program, report, communication and activity data.
Legal bases: Article 6(1)(b) GDPR where processing is necessary for an agreement with you or pre-contractual steps requested by you; Article 6(1)(f) GDPR in operating reliable, auditable and secure Programs and supporting customers; and Article 6(1)(c) where a legal obligation applies.
5.4 Identity verification, eligibility and fraud prevention
Purposes: confirm that an account is linked to a real and eligible person; reduce impersonation, duplicate or fraudulent accounts; protect Programs and payments; apply Program participation conditions; support sanctions, payment or legal checks where applicable; investigate inconsistencies; and maintain evidence of verification.
Main data: account, contact, identity-document, selfie or video, facial-comparison, liveness, device, risk and audit data.
Legal bases for personal data: Article 6(1)(b) GDPR where verification is objectively necessary for a requested account, Program or Reward; Article 6(1)(f) GDPR in preventing fraud, protecting customers and users, maintaining Program integrity and securing payments; and Article 6(1)(c) GDPR where a specific legal obligation requires verification or screening.
Additional condition for biometric data: where facial images or measurements are processed as biometric data for the purpose of uniquely identifying you, Hackrate relies on your explicit consent under Article 9(2)(a) GDPR unless another applicable Article 9 condition has been identified and documented for the specific processing.
5.5 Report quality, safety and Platform integrity
Purposes: evaluate report completeness and quality; detect duplicates, spam, abuse, unsafe testing or rule violations; protect Program assets and other users; investigate incidents; apply restrictions; and permit fair review of contested decisions.
Main data: report, Program, communication, activity, security, reputation and review data.
Legal bases: Article 6(1)(b) GDPR where necessary to administer the applicable terms and Program; Article 6(1)(f) GDPR in maintaining the security, quality, fairness and integrity of the Platform and Programs; and Article 6(1)(c) where required by law.
5.6 Rewards, billing, accounting and tax
Purposes: approve and process Rewards; issue and receive invoices; administer subscriptions and fees; verify payment destination; prevent payment fraud; keep accounting and tax records; and resolve payment disputes.
Main data: identity, contact, transaction, bank, invoice, tax, Program and communication data.
Legal bases: Article 6(1)(b) GDPR; Article 6(1)(c) GDPR for accounting, tax, reporting and other legal obligations; and Article 6(1)(f) GDPR for fraud prevention, audit and dispute management.
5.7 Contact, support and relationship management
Purposes: answer questions; provide support; manage demonstrations, proposals and contracts; administer customer and partner relationships; collect feedback; and keep a record of communications.
Main data: contact, organisation, communication, support and account data.
Legal bases: Article 6(1)(b) GDPR where the communication concerns a contract or requested pre-contractual steps; Article 6(1)(f) GDPR in responding to enquiries and managing professional relationships; and Article 6(1)(a) where consent is the appropriate basis.
5.8 Analytics and service improvement
Purposes: understand Website and feature use; measure performance; troubleshoot; improve usability, reliability and security; and develop aggregate statistics and service insights.
Main data: cookie, device, usage, account and aggregate data.
Legal bases: consent under Article 6(1)(a) GDPR for non-essential analytics cookies or similar technologies where required; and Article 6(1)(f) GDPR for limited first-party operational measurement, security analytics and de-identified or aggregate analysis that does not require consent.
5.9 Marketing and events
Purposes: send newsletters, product and service information, invitations and relevant business communications; administer events; measure engagement; and maintain suppression records so that opt-out preferences are respected.
Main data: name, business contact details, organisation, role, preferences, subscription and engagement data.
Legal bases: consent under Article 6(1)(a) GDPR where required; Article 6(1)(f) GDPR for proportionate business-to-business relationship communications where permitted by applicable direct-marketing law; and Article 6(1)(c) GDPR to maintain evidence of consent or objection.
You may unsubscribe using the link in a message or by contacting [email protected]. We may retain a minimal suppression record after an opt-out to avoid contacting you again for the same marketing purpose.
5.10 Legal, regulatory and corporate purposes
Purposes: comply with law and lawful requests; keep required records; conduct audits and due diligence; protect rights, safety and property; investigate and defend claims; enforce agreements; and support a merger, financing, reorganisation or sale of all or part of a business.
Main data: any data reasonably necessary for the relevant matter.
Legal bases: Article 6(1)(c) GDPR; Article 6(1)(f) GDPR in protecting legal rights and conducting responsible business operations; and, where necessary, Article 9(2)(f) GDPR for legal claims involving special-category data.
6. Identity Verification and ComplyCube
6.1 When verification may be required
Hackrate may require identity verification before or during account use, participation in certain private or higher-risk Programs, access to sensitive Program information, receipt of a Reward, restoration of an account, or investigation of suspected impersonation, fraud, duplicate accounts or serious rule violations. The applicable Program or user interface will indicate when verification is required.
6.2 Verification provider
Hackrate uses ComplyCube, operated by TEEMO TECHNOLOGY LTD, company number 12392069, Crown House, 27 Old Gloucester Street, London, WC1N 3AX, United Kingdom, to provide identity-document, facial-comparison, liveness and related verification services.
For verification data submitted by Hackrate or by you through a Hackrate verification flow, Hackrate determines the purpose and essential means of the verification and acts as controller. ComplyCube generally processes that client data on Hackrate's documented instructions as a processor. ComplyCube may separately process limited service, account, security or legally required data for purposes for which it independently determines the means and basis, as explained in its own privacy information.
6.3 How a verification works
Depending on the configured workflow, you may be asked to:
- provide information about yourself;
- photograph or upload an accepted identity document;
- take a live selfie or record a short video;
- permit document-authenticity, facial-similarity, liveness and fraud-risk checks; and
- provide additional information or undergo human review where the automated result is inconclusive or raises a concern.
ComplyCube returns results and supporting information to Hackrate. Hackrate uses those results to decide whether the relevant verification requirement has been met. A clear technical result does not itself guarantee eligibility for every Program or payment, and a non-clear result may be reviewed or corrected where appropriate.
6.4 Biometric data and explicit consent
A live image, selfie or video is not automatically special-category data in every context. It becomes biometric data under the GDPR where it is processed through specific technical means for the purpose of uniquely identifying a person. Where Hackrate's verification workflow uses facial comparison or liveness in that way, Hackrate will rely on explicit consent only if the consent can be freely given and a genuine choice is available. If Hackrate cannot offer that choice, it will not rely on consent and will document another valid Article 9 GDPR condition before carrying out the biometric processing.
Any consent request will be presented separately and in clear language. Where consent is the legal basis, Hackrate will provide a reasonably equivalent non-biometric or human-review route where this is required to preserve genuine choice. You may withdraw consent for future processing by contacting [email protected]. Withdrawal does not affect processing already carried out before withdrawal. After withdrawal, Hackrate will delete or restrict biometric data when no longer required, subject to applicable law, fraud prevention, security, evidence and legal-claim requirements.
6.5 Consequences of not completing verification
Providing identity-verification data is not required merely to browse the public Website. It may, however, be necessary for a specific account function, private Program, sensitive scope, Reward or legally required check. Where verification is necessary and a suitable alternative method is not reasonably available, Hackrate may be unable to activate or continue the relevant feature, permit participation, restore access or process a Reward.
Where reasonably practicable, a person who cannot complete the standard workflow may contact [email protected] or Hackrate support to request assistance or an alternative review. Hackrate does not guarantee that an alternative method will be available in every case.
6.6 Human review and challenges
Verification tools may use automated analysis and rules to identify document, facial, liveness, device or fraud indicators. Hackrate personnel may review results and supporting evidence where necessary. Hackrate does not intend to make a decision producing legal or similarly significant effects solely by automated means unless the decision is permitted by applicable law and appropriate safeguards are provided.
You may contact [email protected] to request correction of inaccurate data, provide additional information, challenge a verification-related decision or request human review where Article 22 GDPR or another applicable rule gives you that right.
6.7 Sharing verification results
Hackrate may share a verification status, confirmed identity attributes or limited supporting information with a Program Sponsor or mVDP Client where this is reasonably necessary for Program access, security, fraud prevention, a Reward, legal compliance or a documented customer requirement, and where a lawful basis exists. Hackrate aims to share the minimum information necessary and, where practicable, a verification outcome rather than a copy of the underlying identity document, selfie, video or biometric material.
Raw identity documents or biometric material will not be disclosed to a Program Sponsor or mVDP Client merely for convenience. Any exceptional disclosure must be necessary, proportionate, legally permitted, subject to appropriate access and security controls, and explained to the individual where required.
7. Program Sponsors, mVDP Clients and Other Platform Users
7.1 When you participate in a Program or submit a report, Hackrate may make relevant profile, identity-status, Program, report and communication data available to the responsible Program Sponsor or mVDP Client. The data shared depends on the Program, your role, the report and the need to administer testing, triage, remediation, disclosure, Reward or legal obligations.
7.2 A Program Sponsor or mVDP Client may act as an independent controller for its decisions about Program scope, invitations, report handling, remediation, disclosure, Rewards, access to its systems and compliance records. It is responsible for providing its own privacy information where required. You may contact it directly about processing for which it is responsible, or contact Hackrate if you need help identifying the relevant organisation.
7.3 Hackrate may act as an independent controller for operating and securing the Platform, managing accounts, enforcing terms, preventing fraud, administering Hackrate's contractual relationship, maintaining audit records and complying with law. Data-protection roles for a specific enterprise service may be further described in an Order Form or data processing agreement.
7.4 Reports may contain personal data relating to employees, customers or other third parties. Program Sponsors, mVDP Clients and researchers must minimise such data, restrict access and use it only as necessary for authorised security testing, verification, remediation, legal compliance and coordinated disclosure.
8. Automated and Rules-Based Processing
8.1 Hackrate and its service providers may use automated tools or rules to support identity verification, fraud detection, account security, duplicate detection, spam and abuse prevention, report routing, severity suggestions, quality indicators, sanctions or payment-risk screening, and service analytics.
8.2 These tools assist human and operational decisions. Results may be incomplete or inaccurate. Where a decision is based on an automated signal and materially affects your account, Program access or Reward, Hackrate will provide human review where required by law or where reasonably appropriate to correct an error.
8.3 Hackrate does not intend to rely on solely automated processing that produces legal effects or similarly significantly affects an individual unless Article 22 GDPR permits it and the required safeguards, information and challenge rights are provided.
9. Cookies and Similar Technologies
9.1 The Website and Platform may use cookies, local storage, session storage, pixels and similar technologies. These may be:
- strictly necessary, for security, authentication, network management, consent choices and requested functionality;
- preference-related, to remember settings;
- analytics-related, to understand use and performance; or
- marketing-related, to measure campaigns or provide relevant communications where enabled.
9.2 Non-essential cookies and similar technologies will be used only where permitted by applicable law and, where required, after consent. You can use the Website's cookie controls and browser settings to manage them. Refusing non-essential cookies should not prevent access to basic Website functions, although some optional features may be affected.
9.3 The Website's cookie banner or cookie settings identify the technologies, providers, purposes and durations applicable to the relevant Website visit. Hackrate will keep that information consistent with the Website's live configuration.
10. Recipients and Service Providers
10.1 Internal access
Authorised Hackrate personnel and contractors may access personal data on a need-to-know basis for their work. Access is subject to confidentiality and appropriate technical and organisational controls.
10.2 Categories of external recipients
Hackrate may disclose personal data, where necessary and lawful, to:
- Program Sponsors, mVDP Clients and their authorised personnel;
- ComplyCube for identity verification and related fraud-prevention checks;
- cloud hosting, content-delivery, security, authentication, communications, support, CRM, survey, analytics and software-development providers;
- banks, payment processors, accountants and tax advisers;
- professional advisers, auditors, insurers and certification bodies;
- authorities, courts, regulators and law-enforcement bodies;
- parties involved in a dispute, investigation or legal claim where disclosure is lawful and necessary;
- potential buyers, investors, lenders and advisers in a proposed corporate transaction, subject to appropriate confidentiality; and
- other recipients you direct us to use or to whom you consent to disclosure.
10.3 Current service-provider categories and examples
Depending on the Services and Website features enabled, providers may include:
- TEEMO TECHNOLOGY LTD (ComplyCube) - identity verification, document checks, facial comparison, liveness and related risk signals;
- Microsoft group companies - cloud hosting, infrastructure, productivity and communications services;
- Cloudflare, Inc. and its affiliates - content delivery, network performance and security services;
- HubSpot group companies - contact forms, customer-relationship management, chat, surveys, events and newsletters where enabled;
- Google group companies - analytics or related Website services where enabled and consented to as required;
- SonarSource SA and related service providers - software quality or security tooling where used; and
- banking, payment, accounting, tax, legal and other professional-service providers used in the ordinary course of business.
This list describes provider categories and material examples and may change as the Services evolve. Hackrate will update public information where a provider change materially affects individuals or where applicable law requires an update.
10.4 No sale of personal data
Hackrate does not sell personal data. Hackrate may create and use statistics or Aggregate Data that no longer identifies an individual and cannot reasonably be used to re-identify one. Such data is not personal data under the GDPR.
11. International Data Transfers
11.1 Hackrate is established in Hungary. Some service providers, group entities or other recipients may process personal data in the United Kingdom, Switzerland, the United States or other countries outside the European Economic Area (EEA).
11.2 Where required, Hackrate relies on an applicable European Commission adequacy decision. Where no adequacy decision applies, Hackrate uses appropriate safeguards under Article 46 GDPR, such as the European Commission's Standard Contractual Clauses adopted by Implementing Decision (EU) 2021/914, and supplementary technical, contractual or organisational measures where appropriate. For transfers from the EEA to the United Kingdom, Hackrate may rely on the applicable European Commission adequacy decision while it remains in force. Other transfer directions or recipients may require a separate lawful transfer mechanism.
11.3 Transfer arrangements depend on the recipient, service configuration and data location. You may request information about the safeguards relevant to your data by contacting [email protected]. We may redact confidential or security-sensitive information from copies where permitted by law.
12. Retention
12.1 General principle
Hackrate keeps personal data only for as long as reasonably necessary for the purposes described in this Notice, taking account of the nature and sensitivity of the data, the relationship and Program status, security and fraud risks, contractual and legal requirements, limitation periods and active disputes or investigations. Data may be retained for longer where required by law, a preservation obligation or a legal hold.
12.2 Indicative retention approach
Unless a more specific period is communicated or required, Hackrate applies the following criteria:
- Website and security logs: for a period proportionate to operational troubleshooting, security monitoring, incident investigation and abuse prevention;
- analytics and cookie data: according to the cookie configuration, consent choice and provider settings, and no longer than necessary for the stated analytics purpose;
- account and profile data: while the account is active and for a reasonable period afterwards for reactivation, security, audit, dispute and legal purposes;
- Program and report data: for the duration of the Program and afterwards for remediation history, coordinated disclosure, audit, security, contractual obligations, dispute resolution and legal claims;
- identity documents, selfies, live photos, videos and biometric material: for the shortest period reasonably necessary to complete verification, investigate a relevant inconsistency or fraud concern, satisfy a documented legal requirement, and resolve an active dispute; the precise period may depend on Hackrate's configured ComplyCube workflow and is reviewed regularly;
- verification outcomes and audit records: for as long as reasonably necessary to evidence that verification was performed, maintain Program and payment integrity, prevent repeat fraud and meet contractual or legal requirements;
- Reward, invoice, accounting and tax records: for the period required by applicable accounting, tax and other financial-record laws;
- support and business communications: for the relationship and a reasonable follow-up period, or longer where relevant to an agreement, complaint, security matter or legal claim;
- marketing data: until consent is withdrawn, an objection is made or the data is no longer needed, subject to periodic review; and
- suppression records: for as long as needed to respect an opt-out or objection.
12.3 Deletion and backups
When a retention period ends, Hackrate will delete or anonymise the data unless continued retention is lawful and necessary. Data removed from active systems may remain temporarily in restricted backups until overwritten under normal backup cycles. Where immediate deletion from a backup is not reasonably possible, Hackrate will protect the data from further use and delete it when the backup is restored or expires.
13. Security
13.1 Hackrate uses appropriate technical and organisational measures designed to protect personal data against accidental or unlawful destruction, loss, alteration, unauthorised disclosure or access. Measures may include access controls, authentication, encryption in transit and where appropriate at rest, logging, secure development and change management, vulnerability management, backups, incident response, staff confidentiality and supplier controls.
13.2 Access to identity-verification and report data is limited to personnel and customer users with a documented need. Program Sponsors and mVDP Clients are responsible for securing data within systems and accounts under their control.
13.3 No online service can guarantee absolute security. You are responsible for using a strong, unique password, protecting authentication credentials, keeping devices secure, following Program rules and notifying Hackrate promptly of suspected account compromise or unauthorised disclosure.
14. Your Data-Protection Rights
Subject to the GDPR and other applicable law, you may have the following rights:
14.1 Access
You may request confirmation whether Hackrate processes your personal data and receive a copy and information about the processing.
14.2 Rectification
You may request correction of inaccurate personal data and completion of incomplete data.
14.3 Erasure
You may request deletion in circumstances provided by law. The right is not absolute; Hackrate may retain data where processing remains necessary for a legal obligation, security, fraud prevention, freedom of expression and information, public-interest grounds or legal claims.
14.4 Restriction
You may request restriction of processing in the circumstances provided by Article 18 GDPR.
14.5 Portability
Where processing is based on consent or contract and carried out by automated means, you may have the right to receive personal data you provided in a structured, commonly used and machine-readable format and, where technically feasible, have it transmitted to another controller.
14.6 Objection
You may object, on grounds relating to your particular situation, to processing based on legitimate interests. Hackrate will stop that processing unless it demonstrates compelling legitimate grounds that override your interests, rights and freedoms or the processing is necessary for legal claims.
You may object at any time to direct marketing. After a valid marketing objection, Hackrate will stop using your data for that purpose.
14.7 Withdraw consent
Where processing is based on consent, you may withdraw it at any time for future processing. Withdrawal does not affect the lawfulness of processing before withdrawal.
14.8 Automated decisions
Where Article 22 GDPR applies, you may have the right not to be subject to a decision based solely on automated processing that produces legal effects or similarly significantly affects you, and the right to obtain human intervention, express your point of view and contest the decision.
14.9 Complaint
You may lodge a complaint with the supervisory authority in the country of your habitual residence, place of work or the alleged infringement. Hackrate encourages you to contact [email protected] first so that we can try to resolve the issue.
14.10 Exercising rights
Send a request to [email protected]. Please describe the request and the relevant account, Program or interaction. Hackrate may request proportionate information to verify identity and authority. Hackrate normally responds within one month, subject to lawful extensions for complex or numerous requests. Requests are generally free, but Hackrate may charge a reasonable fee or refuse to act where a request is manifestly unfounded or excessive, as permitted by law.
Where another controller, such as a Program Sponsor or mVDP Client, is responsible for the requested processing, Hackrate may direct or transmit the request to that organisation as appropriate.
15. Age Requirements and Minors
15.1 A person must be at least 18 years old to register as a Bounty Hunter, enter into the Bounty Hunter Terms of Use or receive Rewards through the Platform, unless Hackrate has expressly approved a legally valid alternative arrangement in advance.
15.2 The public Website is intended primarily for business and professional audiences and is not directed to children. An mVDP report may nevertheless be received from a person under 18. Hackrate and the relevant mVDP Client will handle such a report in light of the person's age, applicable law, safety and the need to validate and remediate the reported vulnerability.
15.3 If you believe a child has provided personal data contrary to this Notice or without required authorisation, contact [email protected].
16. Changes to This Privacy Notice
16.1 Hackrate may update this Notice to reflect changes to the Website, Platform, Services, providers, law or processing practices. The current version will be published with a revised “Last updated” date.
16.2 Material changes will apply prospectively. Where required by law, Hackrate will provide additional notice or request renewed consent before the change takes effect.
16.3 Earlier versions may be retained for legal, audit and transparency purposes.
17. Supervisory Authority and Contact
Questions, requests and complaints may be sent to:
HACKRATE Kft.
Email: [email protected]
Postal address: 2890 Tata, Baji út 35. 2. lház. 2. em. 12., Hungary
The Hungarian supervisory authority is:
Hungarian National Authority for Data Protection and Freedom of Information
(Nemzeti Adatvédelmi és Információszabadság Hatóság - NAIH)
Address: 1055 Budapest, Falk Miksa utca 9-11, Hungary
Postal address: 1363 Budapest, P.O. Box 9, Hungary
Telephone: +36 1 391 1400
Email: [email protected]
You may also contact another competent supervisory authority where applicable.
Hackrate
Our platform helps companies to identify software vulnerabilities in a cost-efficient way. It provides a secure and centralized view of ethical hacking projects for your company.
US Patent Applied for HackGATE #63/645,845
Products
From the Blog
-
Hackrate Ranked 1st in Hungary and 22nd Globally at Hack The Box’s Global Cyber Skills Benchmark 2026
May 29 • 13 min read
-
Press release: Hackrate becomes Hungary’s first CVE Numbering Authority
Jan 13 • 5 min read ★
-
Let 2026 be the year bug bounty becomes part of how you build and operate
Jan 05 • 4 min read