Last updated: 23 July 2026
Privacy Policy
SecBerg ("SecBerg", "we", "us") operates this website and the SecForge SPLM platform for security product lifecycle management. This policy explains what personal data we process when you visit the website, book a demo, or use the platform — and the rights you have under the EU General Data Protection Regulation (GDPR).
1. Controller
The controller within the meaning of Art. 4(7) GDPR is SecBerg, Friedrichstraße 100, 10117 Berlin, Germany. For all privacy matters, contact privacy@secberg.com.
2. Website server logs
When you visit this website, our hosting provider automatically records technical access data: IP address, browser type and version, operating system, referrer URL, pages requested, HTTP status, and timestamps. We process this data under Art. 6(1)(f) GDPR based on our legitimate interest in operating the site securely and stably. Log data is not merged with other data sources and is deleted automatically after a short period.
3. Cookies and local storage
This website sets no advertising or tracking cookies. We store only functional preferences in your browser — your theme (light/dark) and language choice — which do not identify you. The embedded scheduling widget (section 5) may set technically necessary cookies when you use it.
4. Web analytics
We use Vercel Analytics, a cookieless analytics service that records page views in aggregate, without persistent identifiers or cross-site profiles. Legal basis: Art. 6(1)(f) GDPR — our legitimate interest in understanding how the site is used.
5. Booking a demo
When you book a demo, we use the scheduling service Cal.com to process the details you enter (name, work email, company, selected time slot) in order to arrange the meeting. Legal basis: Art. 6(1)(b) GDPR — steps taken prior to entering into a contract at your request.
6. Contacting us
If you contact us by email, we process your address and the content of your message to handle the inquiry (Art. 6(1)(b) or (f) GDPR). Correspondence is deleted once the matter is closed, unless statutory retention duties apply.
7. Data in SecForge SPLM
For platform accounts we process name, work email, company, and role as controller. All content your team creates in the platform — system models, TARA artifacts, requirements, review records, and other work products — is processed strictly as a processor on your organization's behalf under a Data Processing Agreement. Every query is bound to your tenant; your content is never used to train models and never shared across tenants.
8. Hosting and data residency
Platform data is hosted in the EU (Frankfurt) or the US (Virginia), according to your organization's plan. Data is encrypted in transit (TLS 1.3) and at rest (AES-256). This website is hosted on Vercel.
9. Sub-processors
We use a small number of sub-processors for hosting, scheduling, and analytics. The current list, including processing locations and safeguards, is annexed to our DPA and available at any time from privacy@secberg.com.
10. International transfers
Where personal data is transferred outside the EEA — for example if your organization selects US hosting, or through our scheduling and analytics providers — we rely on the EU Standard Contractual Clauses and additional safeguards.
11. Retention
Website logs are kept only briefly. Account and platform data are retained for the duration of your subscription plus a 90-day wind-down period, after which they are deleted from primary and backup systems within 30 days, unless you request earlier deletion or the law requires longer retention.
12. Your rights
You have the right to access, rectify, erase, and receive a copy of your personal data, to restrict or object to its processing, and to withdraw any consent with effect for the future (Art. 15–21 GDPR). Write to privacy@secberg.com; we respond within one month. You may also lodge a complaint with a supervisory authority — for SecBerg, the Berlin Commissioner for Data Protection and Freedom of Information.
13. Changes to this policy
We will announce material changes on this page and, for platform customers, by email at least 30 days before they take effect.