Privacy Notice: BitHive Reporting Desk application
Version 3.0 · September 2026 · Replaces version 2.0 (changes: hosting provider STACKIT, processing in the European Union). This notice covers the application at app.bithive-it.com and its API. The privacy policy of our website bithive-it.com applies to the website.
1. Controller
BitHive UG (haftungsbeschränkt), Heisenbergstraße 3, 10587 Berlin, Germany, represented by its managing director Alireza Khalili. E-mail: contact@bithive-it.com.
2. Who is responsible for which data
Our customers use the application to manage their products, software bills of materials, vulnerability cases and report texts, and they decide who in their organisation uses it. For personal data that customers and their users enter into the application, the customer is the controller and we process the data on its behalf under a data processing agreement (Art. 28 GDPR). If you are a user of a customer account, please contact that customer about your rights regarding this data; we support them in answering.
We are the controller for the processing described in Sections 3 to 5.
3. Customer contract and billing
We process the name, business contact details and billing information of our customers' contact persons in order to conclude and perform the contract, issue invoices and communicate about the contract.
Legal basis: Art. 6 (1) (b) GDPR (contract) and, for the contact persons of business customers, Art. 6 (1) (f) GDPR (our legitimate interest in performing contracts with companies); Art. 6 (1) (c) GDPR for statutory retention. Invoices and accounting records are kept for the retention periods required by German commercial and tax law.
4. Security and operation of the application
When the application or the API is used, our servers record technical data: IP address, time, requested address, result status and, for logged-in users, the user ID. We use this data to operate the application, detect and defend against attacks and misuse, and investigate errors.
Legal basis: Art. 6 (1) (f) GDPR (our legitimate interest in the secure and stable operation of the application). The data is deleted after 30 days, unless it is needed longer to investigate a specific security incident.
5. Login and cookies
You log in without a password, using a one-time link sent by e-mail. After login, the application sets a single cookie that keeps you logged in. It is technically necessary for the service you have requested (Section 25 (2) no. 2 TDDDG) and is deleted when you log out or after it expires. We use no analytics, tracking or advertising cookies and load no content from third parties in the application.
Legal basis for processing the login data: Art. 6 (1) (b) GDPR or, for users of customer accounts, Art. 6 (1) (f) GDPR (secure access to the service booked by the customer).
6. Recipients and hosting
The application is operated exclusively in data centres in Germany by our hosting provider Schwarz Digits Cloud GmbH & Co. KG (STACKIT), Bad Friedrichshall, Germany. E-mails (login links and notifications) are delivered by the e-mail service provider Brevo GmbH, Berlin, Germany, with servers in the European Union. Both act on our behalf under data processing agreements.
The data stored in the application remains in Germany; we do not transfer it to countries outside the European Union. Our e-mail service provider uses service providers, some of them US companies, and group companies in the USA and India for hosting, content delivery, support and maintenance. Only the data needed for delivery (e-mail address, name and content of the e-mail) can be affected. Such transfers are safeguarded by the European Commission's standard contractual clauses (Art. 46 (2) (c) GDPR) and, where applicable, the EU-U.S. Data Privacy Framework (Art. 45 GDPR). A copy of these safeguards is available on request at contact@bithive-it.com.
7. Your rights
You have the right of access (Art. 15 GDPR), rectification (Art. 16), erasure (Art. 17), restriction of processing (Art. 18) and data portability (Art. 20). Where we process data on the basis of Art. 6 (1) (f) GDPR, you have the right to object at any time on grounds relating to your particular situation (Art. 21). To exercise your rights, contact contact@bithive-it.com.
You also have the right to lodge a complaint with a data protection supervisory authority. The authority responsible for us is the Berlin Commissioner for Data Protection and Freedom of Information (Berliner Beauftragte für Datenschutz und Informationsfreiheit).
8. No automated decisions
We do not use automated decision-making, including profiling, within the meaning of Art. 22 GDPR.
This notice exists in a German and an English version. In the event of discrepancies, the German version prevails.