Privacy Policy

1. Responsible Party

BAS GmbH
Storkower Straße 6, 15749 Mittenwalde OT Gallun
info@bas-on.de | +49 (0) 3376 2514 184

2. Collection and Processing of Personal Data

We collect personal data only if you voluntarily provide it in the context of a contact request (name, email, phone, message). This data is used exclusively to process your inquiry and is not passed on to third parties.

3. Cookies

This website does not use tracking cookies. Only technically necessary session data is processed.

4. External Links

This website contains links to external websites (LinkedIn, netze-on.de, etc.). The operators of these external pages are solely responsible for their content.

5. Vulnerability Reports (Cyber Resilience Act)

Through our vulnerability report form, we collect name, company, and email address as required fields, along with optional information about the affected device (e.g. version, serial number, manufacturer, location), a description of the vulnerability, reproduction steps, and an uploaded file (image or PDF, max. 10 MB). This data is processed to review and handle the report and is stored in a secured, non-public area.

The Cyber Resilience Act (CRA) requires us to report actively exploited vulnerabilities and severe security incidents to the responsible national CSIRT body or ENISA within statutory deadlines. As part of this legal reporting obligation, the information contained in your report — including personal data — may be forwarded to these authorities. Once a coordinated disclosure process has concluded, technical details of a vulnerability may also be published.

6. Your Rights

You have the right to access, rectify, delete, and restrict the processing of your stored data, as well as the right to data portability. For this purpose, contact: info@bas-on.de

Last updated: September 2026