Privacy Policy
AXUM SEC collects and processes personal data from companies (clients) and security researchers (hunters) who use our bug bounty and vulnerability management platform. This policy explains what data we collect, why we collect it, how we protect it, and your rights under applicable data protection laws including Ethiopia's Proclamation No. 1321/2024 (Personal Data Protection Proclamation). We are committed to transparency, security, and giving you control over your personal information.
Privacy Policy
Effective Date: May 15, 2026 Version: 1.0 Applicable to: AXUM SEC Platform (www.axumsec.com)
1. Introduction
AXUM SEC PLC ("Company", "we", "us", "our") respects your privacy and is committed to protecting your personal data. This Privacy Policy explains how we collect, use, disclose, and safeguard your information when you use our bug bounty and vulnerability management platform.
We comply with:
- Ethiopia Proclamation No. 1321/2024 (Personal Data Protection Proclamation)
- Applicable international data protection standards where required
By using our platform, you consent to the data practices described in this policy.
2. Data Controller Information
| Field | Details |
|---|---|
| Company Name | AXUM SEC PLC |
| Address | Addis Ababa, Ethiopia |
| privacy@axumsec.com | |
| Phone | +251943733593 |
| Website | www.axumsec.com |
3. What Personal Data We Collect
3.1 For Companies (Clients)
| Data Category | Examples | Purpose |
|---|---|---|
| Company Information | Legal name, registration number, tax ID, address | Account creation, verification, invoicing |
| Contact Information | Name, email, phone number of authorized representatives | Communication, support, program management |
| Billing Information | Payment method details, invoice history | Payment processing, financial records |
| Program Data | Scope assets, reward ranges, program rules | Service delivery |
| Technical Data | IP address, browser type, usage logs | Security, analytics, platform improvement |
3.2 For Security Researchers (Hunters)
| Data Category | Examples | Purpose |
|---|---|---|
| Identity Information | Full name, username, email, phone number | Account creation, verification, communication |
| KYC Data | Government ID, proof of address, date of birth | Identity verification, legal compliance, bounty payments |
| Payment Information | PayPal email, bank account details | Bounty payment processing |
| Professional Information | Skills, certifications, experience | Profile building, program matching |
| Submission Data | Vulnerability reports, proof of concept, comments | Service delivery, program management |
| Technical Data | IP address, browser type, usage logs | Security, analytics, platform improvement |
3.3 For Website Visitors
| Data Category | Examples | Purpose |
|---|---|---|
| Technical Data | IP address, browser type, pages visited | Analytics, security, platform improvement |
| Cookies | Session tokens, preference settings | User experience, authentication |
4. How We Collect Your Data
| Method | Description |
|---|---|
| Direct Interactions | You provide data when registering, submitting reports, updating profile, or contacting us |
| Automated Technologies | We collect technical data via cookies, logs, and analytics tools |
| Third Parties | We may receive data from identity verification services, payment processors, or program partners |
5. Legal Basis for Processing
Under Proclamation No. 1321/2024, we process your personal data on the following legal bases:
| Legal Basis | When Applied |
|---|---|
| Consent | When you voluntarily provide data and agree to our processing (e.g., marketing communications) |
| Contractual Necessity | When processing is required to provide our services (e.g., program management, bounty payments) |
| Legal Obligation | When processing is required by law (e.g., KYC, tax reporting, anti-money laundering) |
| Legitimate Interests | When processing is necessary for our legitimate business interests (e.g., security, fraud prevention, platform improvement) |
6. How We Use Your Personal Data
| Purpose | Data Used | Legal Basis |
|---|---|---|
| Account Creation and Management | Identity, contact | Contract |
| Program Delivery | Program data, submissions | Contract |
| Bounty Payments | Payment, identity | Contract |
| Identity Verification (KYC) | Government ID, proof of address | Legal Obligation |
| Customer Support | Contact, account data | Contract, Legitimate Interest |
| Security and Fraud Prevention | Technical, identity | Legitimate Interest, Legal Obligation |
| Platform Improvement | Usage data, technical | Legitimate Interest |
| Marketing and Communications | Contact | Consent (where required) |
| Legal Compliance | Varies | Legal Obligation |
7. Data Sharing and Disclosure
7.1 Who We Share Data With
| Recipient Type | Data Shared | Purpose |
|---|---|---|
| Program Clients | Researcher username, submission details | Program operation |
| Researchers | Program scope, submission status | Program operation |
| Identity Verification Providers | Government ID, personal information | KYC compliance |
| Payment Processors | Payment details | Bounty and invoice processing |
| Cloud Service Providers | Hosting data | Platform operation |
| Legal and Regulatory Authorities | As required by law | Legal compliance |
7.2 International Data Transfers
We may transfer personal data outside Ethiopia only where adequate safeguards are in place, such as:
- Standard Contractual Clauses (SCCs)
- Adequacy decisions by relevant authorities
- Your explicit consent
8. Data Retention
| Data Type | Retention Period | Reason |
|---|---|---|
| Account Information | Duration of account + 5 years | Legal compliance, contract enforcement |
| KYC Documents | 5 years after account closure | Regulatory requirement |
| Transaction Records | 10 years | Tax and financial compliance |
| Submission Reports | As agreed with client | Contractual obligation |
| Chat and Communication | 2 years | Service improvement, dispute resolution |
| Technical Logs | 90 days | Security, troubleshooting |
9. Data Security
We implement appropriate technical and organizational measures to protect your personal data:
| Security Measure | Description |
|---|---|
| Encryption | AES-256 for data at rest, TLS 1.3 for data in transit |
| Access Controls | Role-based access, authentication, authorization |
| Monitoring | 24/7 security monitoring and alerting |
| Audit Logs | Comprehensive logging of data access and processing |
| Regular Testing | Vulnerability assessments and penetration testing |
| Staff Training | Regular data protection and security awareness training |
10. Your Rights
Under Proclamation No. 1321/2024, you have the following rights:
| Right | Description | How to Exercise |
|---|---|---|
| Right of Access | Request a copy of your personal data | Email privacy@axumsec.com |
| Right to Rectification | Correct inaccurate or incomplete data | Update profile or contact us |
| Right to Erasure | Request deletion of your data (where applicable) | Email privacy@axumsec.com |
| Right to Object | Object to processing based on legitimate interests | Email privacy@axumsec.com |
| Right to Data Portability | Receive your data in a machine-readable format | Email privacy@axumsec.com |
| Right to Withdraw Consent | Withdraw consent where processing is based on consent | Update preferences or contact us |
| Right to Lodge a Complaint | Complain to the Ethiopian Communications Authority (ECA) | Contact ECA directly |
We will respond to your request within 30 days as required by law.
11. Data Breach Notification
In the event of a personal data breach that poses a risk to your rights and freedoms, we will:
- Notify the Ethiopian Communications Authority (ECA) within 72 hours
- Notify affected data subjects without undue delay where the breach poses a high risk
- Document the breach, its effects, and remedial actions taken
12. Cookies and Tracking Technologies
We use cookies and similar technologies to:
| Cookie Type | Purpose |
|---|---|
| Essential | Authentication, security, platform functionality |
| Preference | Remember your settings and preferences |
| Analytics | Understand how you use our platform |
| Marketing | Deliver relevant advertisements (with consent) |
You can manage cookie preferences through your browser settings.
13. Children's Privacy
Our platform is not directed to individuals under 18 years of age. We do not knowingly collect personal data from minors. If you believe we have collected data from a minor, please contact us immediately.
14. Changes to This Privacy Policy
We may update this Privacy Policy from time to time. Material changes will be notified via:
- Email to registered users
- Platform notification
- Website posting
The "Effective Date" at the top of this policy indicates when it was last revised.
15. Contact Information
| Purpose | Contact |
|---|---|
| Data Protection Inquiries | privacy@axumsec.com |
| Security Concerns | security@axumsec.com |
| General Questions | support@axumsec.com |
| Phone | +251943733593 |
| Address | Addis Ababa, Ethiopia |
16. Complaints
If you believe we have violated your data protection rights, you have the right to lodge a complaint with:
Ethiopian Communications Authority (ECA)
- Website: www.eca.et
- Address: Addis Ababa, Ethiopia
We encourage you to contact us first so we can address your concerns directly.
17. Specific Provisions for Security Researchers (Hunters)
17.1 KYC Verification
As a security researcher, you are required to complete identity verification (KYC) before receiving bounty payments. Your government ID and personal information will be shared with our identity verification provider solely for this purpose.
17.2 Submission Data
Your vulnerability reports, including proof of concept and evidence, will be shared with the relevant program client for remediation purposes. Your personal identity is only shared with clients if you consent or if required by program rules.
17.3 Bounty Payments
Your payment information is processed securely by our payment processors. We do not store full payment credentials on our servers.
18. Specific Provisions for Companies (Clients)
18.1 Program Data
Your program scope, assets, and reward ranges are visible to researchers participating in your program. Confidential information should not be included in public program descriptions.
18.2 Employee Data
If you add team members to your account, their personal data will be processed in accordance with this policy. You are responsible for notifying your team members of this policy.
19. Glossary
| Term | Definition |
|---|---|
| Personal Data | Any information relating to an identified or identifiable natural person |
| Processing | Any operation performed on personal data (collection, storage, use, disclosure, etc.) |
| Data Controller | The entity that determines the purposes and means of processing (AXUM SEC) |
| Data Processor | The entity that processes data on behalf of the controller |
| Data Subject | The individual to whom personal data relates |
| KYC | Know Your Customer - identity verification process |
20. Acknowledgment
By using the AXUM SEC platform, you acknowledge that you have read, understood, and agree to this Privacy Policy.
For questions or concerns, please contact: