Privacy policy
Last updated: 2026-08-10
1. Who runs this site #
Phoenix Offensive Security is a personal offensive security blog operated from Greece. The data controller is reachable at info@cyberphoenix.gr.
2. What this site collects #
From browsing: nothing. There are no analytics scripts, no advertising trackers, no third-party telemetry, and no cookies. Nothing is stored in your browser — no localStorage, no sessionStorage.
The site is served through Cloudflare, whose standard server logs may record IP address, user-agent, and request path for short-term abuse prevention and availability. Those logs are not used for marketing or profiling.
Web fonts are loaded from Bunny Fonts, a GDPR-focused font host that does not set cookies or log IP addresses for tracking purposes.
From email: if you write to me, I receive whatever you put in the message. It is used to answer you and kept only as long as that conversation is useful.
3. Legal basis (GDPR) #
Server logs are processed under Article 6(1)(f) — legitimate interest in keeping the site available and secure. Email correspondence is processed under Article 6(1)(f) as well, to respond to a message you chose to send.
4. Sharing #
Nothing is sold, rented, or shared for marketing. The only third parties involved are the hosting provider (Cloudflare), the font host (Bunny Fonts), and the mail provider that delivers email you send to the address above.
5. Your rights #
Under GDPR you can request access to, rectification of, deletion of, restriction of, or portability of your personal data, and you can object to its processing. Email info@cyberphoenix.gr to do so. You may also complain to the Hellenic Data Protection Authority at dpa.gr.
6. Security #
The site is served over HTTPS only, with HSTS and a strict Content Security Policy. To report a vulnerability in this site's infrastructure, see the disclosure policy or security.txt.
7. Changes #
If this policy changes materially, the date above changes with it.