DFIR Lab is a cybersecurity research blog operated by Giuseppe Paternicola. We believe in transparency and respect your privacy. This policy explains what data we collect, how we use it, and the rights you have over it.
The data controller for this website is:
Giuseppe Paternicola
DFIR Lab
privacy@dfir-lab.ch
We act as the data controller for personal data collected through this website. This means we determine the purposes and means of processing your personal data and are responsible for its protection.
We collect minimal personal data, limited to what is necessary for operating this cybersecurity research blog. We do not collect data for advertising purposes.
We process your personal data for the following purposes:
We operate an anonymous interactive API playground at platform.dfir-lab.ch/docs/playground that allows visitors to try the DFIR Platform API without signing up. To prevent abuse of this free resource and to maintain fair availability for all users, we collect limited technical data when anonymous requests are made through the playground.
We process this data under the lawful basis of legitimate interest (GDPR Art. 6(1)(f)) — specifically, our legitimate interest in preventing fraud, abuse, and denial-of-service against a free public resource. We have assessed that this processing is necessary, minimal in scope, and does not override the fundamental rights of visitors since no directly identifying data (name, email, account) is linked to sandbox activity.
No raw IP addresses collected through the sandbox playground are shared with third parties for marketing purposes. We do not sell, rent, or use this data for advertising. Data may be shared only with the sub-processors that operate the storage layer (e.g., Upstash Redis) strictly for the purpose of enforcing per-IP weekly quotas.
Because sandbox data is anonymous (no account, email, or name is collected), identifying a specific record for deletion requires you to provide the approximate timestamp and IP address used. You can request deletion by emailing privacy@dfir-lab.ch. This is a manual process and we will respond within 30 days.
We use the following third-party services to operate this website. Each has been selected for its reliability and privacy posture.
| Service | Purpose | Location |
|---|---|---|
| Vercel | Website hosting and edge delivery | United States |
| Convex | Database and real-time backend | United States |
| Clerk | Authentication (admin only) | United States |
| Plausible Analytics | Privacy-focused website analytics | European Union |
| Google Analytics | Website analytics (with consent) | United States |
| Resend | Newsletter email delivery | United States |
| Anthropic | AI-assisted features (admin tools only) | United States |
| Hetzner Cloud | VPS infrastructure (malware analysis lab and security tools) | Germany |
All third-party service providers are bound by their own privacy policies and, where applicable, data processing agreements. We do not share your personal data with these services beyond what is necessary for their stated purpose.
We do not sell your personal data. We do not share your personal data with third parties for marketing or advertising purposes.
We may disclose personal data only in these circumstances:
Our VPS infrastructure is hosted by Hetzner Cloud in Nuremberg, Germany, within the European Economic Area.
Some of our service providers (Vercel, Convex, Clerk, Resend, Google) are based in the United States. Where personal data is transferred outside the EEA, we rely on:
We retain personal data only as long as necessary for the purposes described in this policy:
Depending on your location, you may have the following rights regarding your personal data:
If you are a California resident, you have the right to:
To exercise any of these rights, please contact us at privacy@dfir-lab.ch. We will respond to your request within 30 days.
If you believe your data protection rights have been violated, you have the right to lodge a complaint with the relevant supervisory authority in your jurisdiction.
We implement appropriate technical and organizational measures to protect personal data against unauthorized access, alteration, disclosure, or destruction. These include:
No system is 100% secure. If you discover a security vulnerability on this site, please report it responsibly to security@dfir-lab.ch.
This website is not directed at children under the age of 16. We do not knowingly collect personal information from children under 16. If you believe that a child under 16 has provided us with personal data, please contact us at privacy@dfir-lab.ch and we will promptly delete it.
We may update this privacy policy from time to time to reflect changes in our practices, technology, or legal requirements. When we make material changes, we will update the "Last updated" date at the top of this page.
We encourage you to review this policy periodically. Continued use of the site after changes constitutes acceptance of the updated policy.
If you have any questions about this privacy policy, your personal data, or would like to exercise your rights, please contact us:
Giuseppe Paternicola
DFIR Lab
Privacy inquiries: privacy@dfir-lab.ch
Security reports: security@dfir-lab.ch
General: info@dfir-lab.ch
We aim to respond to all privacy-related inquiries within 30 days.