Legal
Privacy Notice
What personal data this platform holds about you, who processes it, how long it is kept, and the rights you have over it.
- Version
- 1
- Effective
- 2026-09-21
1. Who is responsible for your data
Prop Firm Match Global - FZCO, whose registered office is at IFZA Business Park, DDP, PO Box 342001, Dubai, United Arab Emirates, is the controller of the personal data described here.
The controller is the same company that operates https://propfirmmatch.com; this platform is its security program on a subdomain. The Prop Firm Match Privacy Policy at https://propfirmmatch.com/privacy describes how we handle personal data generally. This notice describes the processing that is specific to the bug bounty program — your researcher account, the reports you submit, and what we do to pay you — and it prevails over the general policy on those points.
Privacy requests and questions go to security@propfirmmatch.com. We answer within 30 days, and we will tell you if we need longer and why.
We have not appointed a Data Protection Officer. One is required where an organisation is a public authority, where its core activities involve large-scale regular and systematic monitoring of individuals, or where they involve large-scale processing of special-category data. None of those describes this platform: it holds a small number of voluntary researcher accounts, monitors nobody, and processes no special-category data. We keep this under review and will appoint one if the position changes.
Where we are established outside the European Union and continue to offer this program to researchers in the EU, we appoint a representative under Article 27 GDPR and name them here. Our representative's details, when one is appointed, are published at this address and are available on request from security@propfirmmatch.com.
2. What we collect
Account data: your name, email address, and a salted, hashed password.
Report data: the findings you submit — titles, descriptions, reproduction steps, CVSS vectors, attachments, and the conversation thread with our triage team.
Platform activity: report state changes, reputation, and the audit trail of administrative actions.
Acceptance records: which version of the Terms of Service and Researcher Agreement you accepted, and when. This is the record that establishes what you agreed to.
Payment and screening data, where a monetary reward is due: identity and tax documentation, and the result of sanctions screening. Collected only at that point, not at sign-up.
Technical logs: standard server logs held by our hosting provider (requests, timestamps, IP addresses) for security and availability.
3. Why we hold it, and on what basis
To run the program — receiving, triaging and resolving reports, and crediting you for them. Basis: our legitimate interest in securing our systems, and performance of the agreements you accepted.
To pay rewards and meet the obligations that come with paying them, including sanctions, anti-money-laundering and tax rules. Basis: legal obligation, and performance of our agreement with you.
To keep an audit trail of administrative actions. Basis: our legitimate interest in an accountable process — it is also the record that protects researchers.
To secure the platform itself. Basis: legitimate interest.
Where we rely on legitimate interest we have weighed it against your interests and rights. The balance is straightforward here: you chose to take part, everything we hold you gave us or generated by using the platform, none of it is sensitive, and the processing is what makes the program work at all. You can object at any time — section 7.
We do not rely on consent for any of the processing above, which is why you are not asked to consent to this notice. The one place consent does apply is public credit in the hall of fame: that is opt-in, and you can withdraw it at any time without affecting anything else.
4. Who processes it for us
Database hosting: all platform data lives in a managed PostgreSQL database operated for us in the European Union (Frankfurt).
Application hosting: the application runs on a managed hosting platform, which holds standard access logs under its own security programme.
Transactional email: verification, password reset and report notifications are delivered through a managed email service on our behalf.
Sanctions and identity screening, where a monetary reward is due: a third-party screening provider may process your identity and residence data for that purpose only.
We name categories rather than vendors so this notice does not go stale the day a contract changes. The current list of named processors is available on request.
5. How long we keep it
Account data: while the account is open, and for 12 months after it is closed so that a re-registration or a dispute can be dealt with. Then deleted.
Reports and their threads: 6 years from the date the report is closed. A vulnerability report is the record of a security decision, and 6 years matches the period in which a claim arising from it could be brought.
Acceptance records: 7 years from the date of acceptance, and they survive the deletion of the account in pseudonymised form — see below. They exist to evidence what was agreed, which is worth nothing if they disappear at the moment a disagreement starts.
Audit trail of administrative actions: 6 years. It is the record that protects researchers from us, so it is not ours to shorten.
Payment and screening records: 5 years after the last payment, which is the period anti-money-laundering rules require, and as long as tax law requires where that is longer.
Technical logs: 90 days.
Attachments: deleted with the report they belong to. Drafts never attached to a submitted report are swept after 7 days.
When a period ends we delete, except where a specific law requires us to keep something longer, in which case we keep only that and only for that long.
7. Your rights
Access and correction: ask us what we hold about you and correct it.
Deletion: ask us to delete your account and personal data, and we will, subject to the retention periods in section 5. Two things outlive the account deliberately. Reports with live triage value are kept until the underlying issue is resolved, because a vulnerability does not stop existing when its reporter leaves. And the audit trail and your acceptance records are kept in pseudonymised form — your name, email and account are removed, and what remains is a record that a given version of a given document was accepted on a given date, tied to a one-way cryptographic digest instead of to you. To be precise about what that is: it is pseudonymisation, not anonymisation. We could confirm that a particular address had accepted by recomputing the digest for it, and that is the whole point — it is what makes the record usable if you or we ever dispute what was agreed. It cannot be reversed into an address, it identifies nobody on its face, and it is used for nothing else. We rely on Article 17(3)(e) GDPR for keeping it: the establishment, exercise and defence of legal claims. It is also the record that protects you, not only us.
Objection and restriction: where we rely on legitimate interest, you can object and we will reconsider.
Portability: ask for a copy of what you gave us, in a machine-readable form.
Hall of fame: public credit lists only your chosen name and reputation, and only with your agreement. Ask and we will list you anonymously or remove you.
Withdrawal: you can stop participating at any time; reports you already submitted remain governed by the program policy.
To exercise any of these, write to security@propfirmmatch.com. You also have the right to complain to your data protection authority.
8. International transfers
Platform data is stored in the European Union (Frankfurt).
Some of our processors, and our own staff, may access it from outside the European Economic Area — including from the United States. Where that happens we rely, in this order: on an adequacy decision covering the destination where one applies; otherwise on the EU Standard Contractual Clauses (Commission Implementing Decision (EU) 2021/914), with a transfer risk assessment on file; and, for a recipient in the United States that is certified under the EU–US Data Privacy Framework, on that certification.
For transfers out of the United Kingdom we rely on the UK Addendum to those clauses, or the UK International Data Transfer Agreement.
A copy of the clauses we rely on for a specific transfer is available on request from security@propfirmmatch.com.
9. Changes to this notice
This notice carries a version number and an effective date. When it changes materially we will tell you; the previous version remains the one that described how your data was handled at the time.
This is a notice, not a contract: you are not asked to accept it, and nothing here reduces the rights you have under data protection law.