Bugloud · Data Protection
Privacy Policy
How Bugloud collects, uses, shares and protects the personal data of security researchers and companies, under the UAE Personal Data Protection Law.
Version 3.1 · Effective 2023 · Last updated 2026
1. Who We Are
This Policy is issued by Exordium ("Exordium", "we", "us"), the legal owner and operator of the Bugloud platform (a product of Exordium), registered at Al Hadi 3 St, Al MZEER’AH, Abu Dhabi, UAE (licence no. CN-4658519). Exordium is the data controller for the personal data described here.
It applies to personal data we process through bugloud.com, our applications and APIs, and related communications, for two groups of data subjects: Researchers and Company users.
Data Protection Officer. You can reach our DPO at [email protected].
2. Personal Data We Collect
We collect the following categories, by role.
2.1 From all users
- Identity data — name, username, and (where required) date of birth, gender.
- Contact data — email, telephone, billing/postal address.
- Account & profile data — credentials (hashed), preferences, country, profile content.
- Usage & technical data — IP address, device and browser type, operating system, pages viewed, and activity logs.
- Cookies & identifiers — see Section 9.
2.2 From Researchers
- Verification (KYC) data — government ID (Emirates ID or passport), residential address, nationality, and image where required.
- Payout & tax data — payout method and any tax/registration details, processed with Stripe.
- Reputation data — submission history, points, rank and leaderboard standing (which may involve profiling).
2.3 From Company users
- Business & billing data — company details, trade-licence and authorised-representative information, subscription and payment records.
- Program data — program configuration and report/triage activity (which may contain personal data within a report).
3. How and Why We Use It — Purposes & Legal Basis
We process personal data for the purposes below. Under the PDPL, processing needs the data subject’s consent unless an Article 4 exception applies (such as performance of a contract or compliance with a legal obligation); the PDPL has no open-ended "legitimate interests" basis.
| Purpose | Legal basis (PDPL) |
|---|---|
| Create and manage your account; provide the Platform | Performance of a contract (Art. 4) |
| Process Rewards, subscriptions and Setup Fees (via Stripe) | Performance of a contract (Art. 4) |
| Identity verification / KYC; AML and sanctions screening | Legal obligation (Art. 4) |
| Reputation scoring, leaderboard and fraud/risk checks (profiling) | Contract performance / consent (Arts. 4, 6) |
| Security, logging and abuse prevention | Legal obligation / contract (Art. 4) |
| Service messages and support | Performance of a contract (Art. 4) |
| Marketing emails, newsletters and non-essential cookies | Consent (Art. 6) |
| Product analytics and improvement (aggregated/de-identified where possible) | Consent / contract (Arts. 4, 6) |
Automated decision-making. We use automated processing for reputation scoring, leaderboard ranking and fraud/risk checks. You may object to a decision based solely on automated processing that produces a legal or similarly significant effect, and request human review.
We process personal data only for the purposes for which it was collected, and keep it accurate and minimised.
4. Who We Share It With
We share personal data only as needed and with recipients bound by confidentiality and data-protection obligations. We do not sell personal data.
- Stripe — payment processing and payout (Stripe handles card data directly under PCI-DSS; see Section 5).
- Identity / KYC and AML-screening providers — to verify Users and meet legal obligations.
- Cloud hosting, email and analytics providers — to operate the Platform.
- A Company and a Researcher — with each other, to the extent needed to run a Program (e.g. a report and its author’s chosen handle).
- Authorities and advisers — where required by law, to establish or defend legal claims, or in a merger or sale of business.
5. International Data Transfers
Some recipients, including Stripe, process personal data outside the UAE (for example in the United States or the European Union).
Because the UAE Data Office has not yet published an adequacy list, we rely on the PDPL Article 23 safeguards for these transfers: (a) a binding data-processing agreement / standard contractual clauses with the recipient imposing PDPL-equivalent protections; (b) the transfer being necessary to perform our contract with you (for example, to process a payment); and (c) your explicit consent where relied upon.
Card data is processed directly by Stripe under PCI-DSS, which limits our own handling of raw card data.
6. How Long We Keep It
We keep personal data only as long as needed for the purpose collected, then delete or anonymise it. Indicative periods: account data is kept for the duration of the account plus 1 year; transaction and tax records for 5 years to meet UAE record-keeping law; KYC and AML records for 5 years after the relationship ends; marketing data until consent is withdrawn or after 2 years of inactivity; and analytics for 24 months.
We may retain data longer where required by law or to establish or defend legal claims.
7. Your Rights
Subject to the PDPL, you have the rights below. To exercise any of them, contact our DPO (Section 1). We will respond within a reasonable period (working expectation: one month, extendable where a request is complex).
- Access & information — to be told what we process and to obtain a copy, free of charge (Art. 13).
- Portability — to receive your data in a structured, machine-readable format (Art. 14).
- Correction & erasure — to correct inaccurate data or have data deleted (Art. 15).
- Restriction — to restrict processing in certain cases (Art. 16).
- Objection / stop processing — including to direct marketing and to profiling (Arts. 17, 18).
- Withdraw consent — at any time, without affecting prior lawful processing (Art. 6).
- Complain — to the UAE Data Office if you are unhappy with how we handle your data (Art. 24).
8. Security & Data Breaches
We apply appropriate technical and organisational measures to protect personal data against loss, misuse and unauthorised access, including encryption in transit, access controls and logging.
If a personal-data breach occurs, we will notify the UAE Data Office without undue delay after becoming aware, and affected data subjects where the breach may prejudice their privacy or rights, including the nature and likely consequences of the breach and the measures taken. We target notification within 72 hours as best practice.
9. Cookies & Tracking
We use strictly-necessary cookies to run the Platform, and, only with your consent, functional, analytics and marketing cookies. Cookies that identify a person are personal data.
You can accept or reject non-essential cookies through our cookie banner (reject is as easy as accept; no pre-ticked boxes) and change your choice at any time. Our separate Cookie Policy lists each cookie, its purpose, provider and duration.
10. Children
The Platform is not directed to children. You must be at least 18 to hold a paid Researcher account or receive a Payout. We do not knowingly collect data from children and will delete it if we learn we have.
11. Changes & Contact
We will post changes to this Policy on this page and, for material changes, notify you by email or a Platform notice. We keep a version history.
Contact. Exordium Data Management Cyber Security Services L.L.C, Al Hadi 3 St, Al MZEER’AH, Abu Dhabi, UAE. Email [email protected]. General inquiries: [email protected].