Privacy Policy
Last updated: July 2026
Compliant with GDPR and applicable data protection laws.
1. Who we are
Breaches.Africa is an independent platform documenting cybersecurity incidents in Africa. Website: https://breaches.africa.
Contact: contact form.
2. Data collected
We collect the strict minimum:
- Contact form - name, email, message. Retained for up to 90 days.
- Newsletter - email, subscription date, language. Retained until unsubscription.
- Technical cookies - admin session only (authentication). No advertising, social media or third-party tracking cookies.
- Server logs - IP address, user-agent, visited pages, timestamp. Retained 14 days max for security.
We do not collect any compromised personal data from the breaches we document.
3. Legal basis
- Consent - for the newsletter
- Legitimate interest - for server logs and contact form
- Legal obligation - for any data we are required to retain by law
4. Data recipients
Your data is never sold, rented or shared with third parties.
5. Retention period
- Contact messages: 90 days
- Newsletter: until unsubscription
- Server logs: 14 days
- Session cookies: session duration
6. Your rights
Under GDPR, you have the following rights:
- Right of access
- Right to rectification
- Right to erasure
- Right to object
- Right to data portability
- Right to withdraw consent
To exercise these rights: contact us.
7. Cookies
This site uses only a session cookie for admin authentication. No other cookies are placed.
8. Security
- Mandatory HTTPS/TLS encryption
- Restricted database access
- Hashed passwords (bcrypt)
- Regular security updates
9. Contact
For any questions: contact form.