Skip to main content
Back to Home

Privacy

Last updated: August 3, 2026

1. Introduction

Ransom-ISAC ("we", "our", or "us") is committed to protecting the privacy and personal data of our members, website visitors, newsletter subscribers, and anyone who interacts with our services. This policy explains how we collect, use, store, and protect your personal data in accordance with the General Data Protection Regulation (EU) 2016/679 ("GDPR"), the UK General Data Protection Regulation, and other applicable data protection legislation.

This policy applies to all personal data processed through our website (ransom-isac.org), membership platform, communication channels, newsletter services, and any related services we operate.

2. Data Controller

The data controller responsible for your personal data is:

Ransom-ISAC UG (haftungsbeschränkt)
Registered at the Amtsgericht München, HRB 312071
Contact: contact@ransom-isac.org

3. What Data We Collect

Website Visitors. When you visit our website, we may collect technical data such as your IP address, browser type and version, operating system, referring URL, pages visited, time and date of access, and approximate geographic location derived from your IP address.

Newsletter Subscribers. When you subscribe to our newsletter, we collect your email address, name (if provided), organisation (if provided), and the date and time of subscription. We also record your consent to receive communications and may track whether emails are opened or links are clicked for the purpose of improving our communications.

Members and Applicants. When you apply for or maintain membership, we may collect your full name, professional email address, organisation name and role, professional background information, contact details, and any correspondence exchanged during the membership process. As part of membership vetting, we also process identity verification and related data, including where applicable biometric and identity-document data.

Event Attendees. If you register for events, webinars, or conferences, we collect your name, email address, organisation, and any dietary or accessibility requirements you provide.

Intelligence Platform. In operating our threat-intelligence community, we process information shared through the platform. Where such information contains personal data, it is handled in accordance with this policy and applicable data protection law.

4. How We Use Your Data

PurposeData UsedLegal Basis (GDPR Art. 6)
Website operation and securityTechnical/server log dataLegitimate interest (Art. 6(1)(f))
Sending newsletters and updatesEmail, name, organisationConsent (Art. 6(1)(a))
Membership administrationContact details, professional infoContract performance (Art. 6(1)(b))
Membership vetting and verificationIdentity, verification and (where applicable) biometric dataExplicit consent (Art. 9(2)(a)); legitimate interest (Art. 6(1)(f)); legal obligation (Art. 6(1)(c))
Operating the intelligence communityPlatform and shared dataLegitimate interest (Art. 6(1)(f)); contract (Art. 6(1)(b))
Event registration and deliveryName, email, dietary/access needsContract performance (Art. 6(1)(b))
Website analytics (where consent given)Cookies, usage dataConsent (Art. 6(1)(a))
Responding to enquiriesContact details, message contentLegitimate interest (Art. 6(1)(f))
Legal compliance and fraud preventionAs required by lawLegal obligation (Art. 6(1)(c))

5. Cookies and Similar Technologies

Our website uses cookies. Strictly necessary cookies are required for the website to function and cannot be switched off. Analytics cookies help us understand how visitors interact with our website and are only placed with your consent.

You can manage your cookie preferences through your browser settings or our cookie consent banner. Refusing non-essential cookies will not affect the core functionality of our website.

6. Newsletter and Email Communications

We send newsletters and updates only to individuals who have provided explicit consent (opt-in). Each email includes an unsubscribe link. You may withdraw your consent at any time by clicking the unsubscribe link in any email.

We use a third-party email service provider to deliver our communications. Your data is shared with this provider solely for that purpose, under a contract that complies with GDPR Article 28.

We may track email open rates and link clicks in aggregate to improve the relevance of our communications. This does not involve profiling or automated decision-making.

7. Data Sharing and Third Parties

We do not sell, rent, or trade your personal data. We may share your data only in the following circumstances:

Service providers: Trusted third-party providers for functions including website hosting, threat-intelligence platform services, identity verification and vetting, payment processing, email delivery, and analytics. These providers process data only on our behalf, under contracts that comply with GDPR Article 28.

Partners: Where relevant to an incident or intelligence-sharing arrangement, and subject to authorisation and applicable law, we may share information with our vetted partner organisations, under written agreements.

Legal obligations: Where required by law, regulation, or legal process.

With your consent: Where you have given specific, informed consent.

8. International Data Transfers

Some of our service providers and partners are located outside the European Economic Area (EEA) and the United Kingdom, including in the United States. This means your personal data may be transferred to, and processed in, countries that have not received an adequacy decision from the European Commission or the UK.

Where we transfer personal data outside the EEA or the UK, we put in place appropriate safeguards required under applicable data protection law, which may include:

  • transfers to countries or frameworks covered by an adequacy decision (such as the EU–US Data Privacy Framework, where the recipient is certified);
  • the European Commission’s Standard Contractual Clauses (SCCs), together with a transfer impact assessment where required; or
  • other lawful transfer mechanisms permitted under Chapter V of the GDPR.

In particular, our threat-intelligence platform and certain service providers may process data on infrastructure located in the United States, subject to these safeguards. You may request further information about the specific safeguards applied to a given transfer by contacting us using the details in Section 14.

9. Data Retention

We retain personal data only for as long as necessary to fulfil the purposes for which it was collected, or as required by law.

Data CategoryRetention PeriodNotes
Website server logs90 daysAutomatically deleted
Newsletter subscriber dataUntil consent is withdrawnDeleted within 30 days of unsubscribe
Member dataDuration of membership + 12 monthsFor continuity purposes
Vetting and verification dataDuration of membership + 12 monthsBiometric data deleted promptly after verification
Event registration data12 months after the eventFor follow-up and feedback
Enquiry/contact data12 months after last interactionUnless ongoing relationship exists
Cookie dataMax 12 monthsConfigurable via cookie preferences

When personal data is no longer required, it is securely deleted or anonymised.

10. Data Security

We implement appropriate technical and organisational measures to protect personal data against unauthorised access, alteration, disclosure, or destruction, including encryption in transit and at rest, access controls, and regular review of security practices.

11. Your Rights

Under the GDPR, individuals have rights regarding their personal data, including access, rectification, erasure, restriction of processing, data portability, and the right to object. Where processing is based on consent, consent may be withdrawn at any time without affecting the lawfulness of prior processing.

Requests may be directed to us at contact@ransom-isac.org and will be handled in accordance with applicable legal requirements.

You also have the right to lodge a complaint with a supervisory authority. The competent authority for us is the Bavarian State Office for Data Protection Supervision (Bayerisches Landesamt für Datenschutzaufsicht — BayLDA), based in Ansbach.

12. Children's Privacy

Our services are not directed at individuals under the age of 18. We do not knowingly collect personal data from children.

13. Changes to This Policy

We may update this policy from time to time. Material changes will be communicated via our website and, where appropriate, by email at least 30 days before taking effect. The "Last updated" date at the top indicates the most recent revision.

14. Contact

For any privacy queries, or to exercise any of the rights described above, please contact us at contact@ransom-isac.org.