Privacy Policy
Last updated: February 2026
1. Data Controller
Auspex Institute (“we”, “us”) — non-profit OSINT & Cyber Intelligence research collective — is the controller of the personal data collected via auspex.institute. Contact: privacy@auspex.institute.
2. What data we collect
- Account data (email, password hash, role) when you register.
- Author profile (display name, bio, avatar, external links) if you are an analyst.
- Technical logs (IP, user-agent, requested paths) retained for max 30 days for security/anti-abuse.
- Cookies: strictly technical (session, language preference). No third-party marketing cookies.
3. Legal basis (GDPR art. 6)
- Contract performance — account provisioning and content publishing.
- Legitimate interest — platform security, fraud prevention.
- Consent — newsletter subscription (opt-in, revocable at any time).
4. Data retention
Account data retained until account deletion. Technical logs auto-purged after 30 days. Backups kept encrypted for 90 days for disaster recovery.
5. Third-party processors
- Hosting: private VPS EU (no third-party data broker).
- LLM enrichment: assessments summaries generated via Emergent LLM proxy on anonymised text (no PII).
- Social crosspost: Telegram Bot API + X API v2 (public content only).
6. Your rights (GDPR art. 15–22)
You can request access, correction, deletion, portability, or object to processing by writing to privacy@auspex.institute. We respond within 30 days. You have the right to lodge a complaint with your local Data Protection Authority.
7. International transfers
Data is hosted in the European Union. Any transfers outside the EEA occur only under Standard Contractual Clauses or an adequacy decision.
8. Changes
We may update this policy from time to time. Substantial changes will be announced via email or homepage notice at least 14 days before taking effect.