Last updated: 24 July 2026.
PatchBriefing ("we", "us") operates the PatchBriefing security-intelligence website and daily e-mail brief. This policy explains what personal data we process, why, and the rights you have under the EU General Data Protection Regulation (GDPR). For any privacy question, or to exercise a right, contact privacy@patchbriefing.com.
Who is responsible
PatchBriefing is the data controller for the personal data described here. We are based in the European Union and process data in accordance with the GDPR.
What we collect
- Subscription data — when you sign up for the brief we store your e-mail address, chosen language, and your topic and product preferences.
- Proof of consent — the date and time you subscribed, a one-way hashed (irreversible) form of your IP address, your user-agent, and the exact consent text you agreed to. We keep this only to demonstrate that consent was validly given.
- Delivery and engagement data — for each brief we send you we record delivery status and, to measure whether our mails are useful and reaching inboxes, whether the mail was opened and which links were clicked.
- Minimal website analytics — we count page views using a daily-rotating, anonymous session hash. This cannot be linked back to you across days and we build no visitor profiles.
We do not collect special categories of data, and we do not ask for your name.
Why we process it, and our legal basis
- To send the daily brief you asked for and service messages about your subscription — legal basis: your consent (Art. 6(1)(a) GDPR), which you can withdraw at any time.
- To keep our sending reputation healthy and prevent abuse, spam and deliverability problems (open/click/bounce handling) — legal basis: our legitimate interest (Art. 6(1)(f)) in operating a functioning mail service.
- To keep consent records — legal basis: our legal obligation and legitimate interest in being able to prove lawful consent.
Who we share it with
We never sell or rent your data. We share it only with the processors that make the service work, each under a data-processing agreement:
- our e-mail delivery provider, to send the brief and report deliveries, bounces and complaints;
- our hosting and infrastructure provider, which stores the application data.
Where a processor is located outside the European Economic Area, transfers are covered by an adequacy decision or the European Commission's Standard Contractual Clauses.
How we keep it safe
Traffic is encrypted in transit (TLS). Management links use one-way hashed tokens — the plaintext is never stored. Provider API keys and other secrets are stored encrypted. Access to subscriber data is limited to what is needed to run the service.
How long we keep it
- Unconfirmed sign-ups are deleted automatically after 30 days.
- After you unsubscribe, we retain only the suppression record (your address in hashed or plain form and the reason) needed to make sure we do not mail you again.
- Hard bounces and spam complaints automatically add you to that suppression list and stop all future mail, to protect other recipients and our sending reputation.
- Consent records are kept for as long as needed to evidence lawful processing and then deleted.
Your rights
Under the GDPR you have the right to access, rectify, erase, restrict or port your data, and to object to processing. Because we rely on consent for the newsletter, you can withdraw consent at any time — every brief has a one-click unsubscribe and a preferences link, and withdrawal does not affect processing carried out before it.
To exercise any right, mail privacy@patchbriefing.com. You also have the right to lodge a complaint with your national data-protection authority; in the Netherlands this is the Autoriteit Persoonsgegevens.
Cookies
We use a single functional cookie to remember your light/dark theme choice. We set no advertising or cross-site tracking cookies.
Changes
We may update this policy; the "last updated" date above reflects the latest version. Material changes affecting subscribers will be announced in the brief.