Official Documentation · Terms & Compliance
Legal notice, privacy & terms
This document governs the legal notice, personal data processing under the General Data Protection Regulation (GDPR), and general service conditions provided by dendritc.
We operate under strict data minimization: this site sets no advertising cookies, includes zero third-party analytics trackers, and strictly processes information voluntarily submitted via our contact form.
1. Service identification and scope
This website and associated technical services are operated directly by the dendritc engineering team. All formal communications, security disclosures, and privacy inquiries are managed directly through the contact form on this site.
Our principal activity involves cybersecurity advisory, source code security auditing, cloud architecture review, and hands-on vulnerability remediation support.
All security reviews and code evaluations are governed by bilateral non-disclosure agreements (NDAs) prior to accessing any repositories or client infrastructure.
2. Personal data processing and legal basis
Pursuant to GDPR (EU 2016/679), information collected via the contact form (name, work email, company, engineering team size, and technical notes) is processed solely to evaluate project scope and deliver requested technical proposals.
Processing is legitimized under pre-contractual measures taken at the request of the data subject (Article 6.1.b GDPR) and mutual legitimate interest in professional technical dialogue (Article 6.1.f GDPR).
We perform zero automated profiling and make no automated decisions regarding personal data.
3. Data processors and third-party infrastructure
Form submissions are processed by infrastructure vendors acting as verified data processors under signed Data Processing Agreements (DPAs) compliant with European data protection standards.
Transactional emails are dispatched via Resend Technologies, while web application traffic is routed through Vercel Inc. All communication utilizes end-to-end TLS 1.3 encryption with secure key management.
dendritc never sells, rents, or shares commercial contact details with third parties for marketing purposes.
4. Data retention and custody periods
Contact information for exploratory conversations that do not lead to a formal engagement is retained for a maximum of twelve months from the last contact before permanent deletion.
For formal security auditing or technical remediation engagements, contractual and financial records are maintained for statutory periods required by commercial and tax legislation (five years).
5. User rights and regulatory complaints
You may exercise your statutory rights of access, rectification, erasure (right to be forgotten), restriction of processing, data portability, and objection at any time by submitting a request through the contact form on this website.
You also retain the right to lodge a complaint with your competent supervisory authority (including the Spanish Data Protection Agency, AEPD, at www.aepd.es, or European Data Protection Board) if you believe your data has been processed unlawfully.
6. Confidentiality and audits under NDA
All technical reviews, source code repository inspection, database schemas, and read-only cloud environment access operate under a bilateral Non-Disclosure Agreement (NDA) executed prior to any analysis.
dendritc operates by default under least-privilege principles and non-destructive read-only access, ensuring operational continuity and protecting client trade secrets.
7. Intellectual property and responsible disclosure
All remediation code, security patches, verification scripts, and custom pull requests created specifically during an engagement are transferred exclusively and perpetually to the client upon settlement of agreed fees.
This site enforces strict security controls (strict Content-Security-Policy, forced HSTS, and per-connection rate limits). We maintain a Safe Harbor policy for security researchers who identify and report vulnerabilities in good faith through the contact form on this website.