Privacy Policy
Last updated: January 11, 2026
This Privacy Policy describes how Vultbase AG ("we," "us," or "our") collects, uses, and protects your personal information when you use our security validation platform and services.
At Vultbase, we take your privacy seriously. We are committed to protecting your personal information and being transparent about our data practices. This policy outlines:
- What information we collect and why
- How we use and protect your information
- Your rights regarding your personal data
- How to contact us with privacy questions
Personal Information
When you use our services, we may collect the following personal information:
- Account Information: Name, email address, company name, job title
- Contact Information: Phone number, mailing address (for invoicing)
- Protocol Information: Smart contract code, deployment addresses, technical documentation
- Payment Information: Billing address, payment method details (processed by third-party providers)
Technical Information
- Usage Data: How you interact with our platform, features used, time spent
- Device Information: IP address, browser type, operating system, device identifiers
- Log Data: Server logs, error reports, performance metrics
- Cookies: Analytics cookies, preference settings, authentication tokens
Smart Contract Data
For security validation services, we collect:
- Source code and bytecode of smart contracts
- Contract deployment information and addresses
- Test results, vulnerability findings, and security reports
- Performance and execution logs from challenge runs
Primary Purposes
- Provide security validation services and generate reports
- Execute challenge tests and analyze smart contract behavior
- Communicate with you about your submissions and results
- Process payments and manage your account
- Provide customer support and technical assistance
Secondary Purposes
- Improve our security challenge algorithms and detection capabilities
- Develop new features and enhance platform performance
- Conduct security research (with anonymized data only)
- Comply with legal obligations and enforce our terms
- Prevent fraud and maintain platform security
We do not sell, trade, or rent your personal information to third parties. We may share information in the following limited circumstances:
- Service Providers: Trusted third parties who help us operate our platform (cloud hosting, payment processing)
- Legal Requirements: When required by law, court order, or to protect our rights
- Business Transfers: In connection with a merger, acquisition, or sale of assets
- With Your Consent: When you explicitly authorize us to share specific information
Your smart contract code and security findings are never shared with other clients or made public without your explicit permission.
We implement industry-standard security measures to protect your information:
- Encryption: Data encrypted in transit (TLS 1.3) and at rest (AES-256)
- Access Controls: Role-based access with multi-factor authentication
- Infrastructure: SOC 2 certified cloud providers with isolated environments
- Code Analysis: Smart contracts analyzed in sandboxed, air-gapped systems
- Regular Audits: Third-party security assessments and penetration testing
- Data Minimization: We only retain data as long as necessary for our services
Depending on your location, you may have the following rights regarding your personal information:
Access & Portability
- • Request access to your personal data
- • Receive a copy of your data in portable format
- • Request information about data processing
Control & Deletion
- • Request correction of inaccurate data
- • Request deletion of your personal data
- • Object to or restrict data processing
To exercise your rights, please contact us at privacy@vultbase.com. We will respond to your request within 30 days.
We use cookies and similar technologies to enhance your experience:
Essential Cookies
Required for platform functionality, authentication, and security.
Analytics Cookies
Help us understand usage patterns and improve our services.
You can control cookies through your browser settings. Disabling essential cookies may affect platform functionality.
We retain your information for the following periods:
- Account Information: While your account is active, plus 7 years after closure
- Smart Contract Code: 3 years after service completion (for vulnerability research)
- Security Reports: 7 years (for compliance and improvement purposes)
- Usage Logs: 2 years (for security monitoring and support)
- Marketing Data: Until you unsubscribe or request deletion
Data is automatically purged after these retention periods unless required by law.
Vultbase AG is based in Switzerland. Your information may be transferred to and processed in countries outside your residence, including:
- Switzerland (our headquarters and primary data center)
- European Union (backup and disaster recovery)
- United States (cloud service providers with adequate safeguards)
All international transfers are protected by appropriate safeguards, including standard contractual clauses and adequacy decisions.
We may update this Privacy Policy periodically to reflect changes in our practices or applicable laws. We will:
- Post the updated policy on our website with a new "Last updated" date
- Notify you via email for material changes that affect your rights
- Provide advance notice for changes that require your consent
Your continued use of our services after policy updates constitutes acceptance of the changes.
Privacy Officer
privacy@vultbase.com
Phone
+41 44 123 4567
Mailing Address
Vultbase AG
Privacy Department
Bahnhofstrasse 123
8001 Zurich, Switzerland