Privacy Policy

Last updated: July 2026

Compliant with GDPR and applicable data protection laws.

1. Who we are

Breaches.Africa is an independent platform documenting cybersecurity incidents in Africa. Website: https://breaches.africa.

Contact: contact form.

2. Data collected

We collect the strict minimum:

  • Contact form - name, email, message. Retained for up to 90 days.
  • Newsletter - email, subscription date, language. Retained until unsubscription.
  • Technical cookies - admin session only (authentication). No advertising, social media or third-party tracking cookies.
  • Server logs - IP address, user-agent, visited pages, timestamp. Retained 14 days max for security.

We do not collect any compromised personal data from the breaches we document.

3. Legal basis

  • Consent - for the newsletter
  • Legitimate interest - for server logs and contact form
  • Legal obligation - for any data we are required to retain by law

4. Data recipients

Your data is never sold, rented or shared with third parties.

5. Retention period

  • Contact messages: 90 days
  • Newsletter: until unsubscription
  • Server logs: 14 days
  • Session cookies: session duration

6. Your rights

Under GDPR, you have the following rights:

  • Right of access
  • Right to rectification
  • Right to erasure
  • Right to object
  • Right to data portability
  • Right to withdraw consent

To exercise these rights: contact us.

7. Cookies

This site uses only a session cookie for admin authentication. No other cookies are placed.

8. Security

  • Mandatory HTTPS/TLS encryption
  • Restricted database access
  • Hashed passwords (bcrypt)
  • Regular security updates

9. Contact

For any questions: contact form.