← opensecuritymetrics.org

Legal notice

Service provider (Art. 5 Directive 2000/31/EC — e-commerce; implemented in Portugal by Decreto-Lei n.º 7/2004):

Nico Wiegand
Rua Conde de Carvalhal 56a
9060-012 Funchal, Madeira
Portugal

Contact: info@opensecuritymetrics.org

Trademark and licensing

"OSMS" is the subject of EU trade mark application No. 019380729 (Nice classes 9, 41, 42). The OSMS specification and metric catalog are licensed under CC BY 4.0; the validator and schema under MIT. The open licenses do not grant trademark rights. Web fonts bundled with this site (Fraunces, Public Sans, IBM Plex Mono) are used under the SIL Open Font License 1.1.

Privacy notice

Controller

Nico Wiegand, address as above, info@opensecuritymetrics.org.

Hosting

This website is served from a classic web-hosting environment operated by GoDaddy.com, LLC (14455 N. Hayden Rd., Ste. 226, Scottsdale, AZ 85260, USA). When you access the site, the web server processes technically necessary access data (IP address, timestamp, requested resource, user agent) in server log files to ensure secure and stable operation (Art. 6(1)(f) GDPR). Log files are deleted according to the hosting provider's retention configuration. As the provider is a US company, technically necessary access data may be transferred to or accessed from the United States; such transfers rely on the EU–US Data Privacy Framework, under which GoDaddy is certified (European Commission adequacy decision of 10 July 2023), with the EU Standard Contractual Clauses as an additional safeguard. A data processing agreement pursuant to Art. 28 GDPR is in place with the provider. In addition, the site keeps anonymous aggregate counters (page views and download counts) without cookies, IP addresses or any other personal data.

Web analytics (GoatCounter)

To understand how many people visit this site and which pages they read, we use the privacy-focused analytics service GoatCounter (goatcounter.com). GoatCounter sets no cookies, stores nothing on your device and uses no persistent identifiers. It records only aggregate statistics: pages visited (including a counter for clicks on the GitHub repository link), the referring site, browser and operating system family, screen size, and the country derived from the IP address. The IP address itself and the full user-agent string are not stored; visits are grouped using a short-lived, non-reversible hash and cannot be linked to a person. Processing is based on our legitimate interest in measuring the reach of the project (Art. 6(1)(f) GDPR). Data is stored on GoatCounter's servers at Hetzner Online GmbH in Germany and Finland (EU) and is not shared with third parties. Details: GoatCounter privacy policy.

No cookies, no tracking profiles

This website sets no cookies and uses no advertising networks. Apart from a single optional language preference (a small localStorage entry that stays in your browser, contains no identifier and is never transmitted), it stores nothing on your device. All fonts are served from this domain — no requests go to font providers.

Contact by email

If you contact us at info@opensecuritymetrics.org, we process your details to handle the request (Art. 6(1)(b) or (f) GDPR) and delete them once they are no longer needed for the review process.

Newsletter (Brevo)

If you subscribe to updates about the OSMS project and its ecosystem (standard releases, review milestones, the book, the KPI platform, and the academy), your email address and the consent timestamp are processed by our newsletter provider Brevo (Sendinblue GmbH, Germany / Brevo SAS, France) on the basis of your consent (Art. 6(1)(a) GDPR). Subscription uses double opt-in; your consent is logged. Every message contains an unsubscribe link, and you can withdraw your consent at any time with effect for the future. A data processing agreement pursuant to Art. 28 GDPR is in place with the provider. The subscription form is hosted by Brevo — this website itself continues to set no cookies.

Your rights

Under the GDPR you have the rights of access, rectification, erasure, restriction of processing, data portability and objection (Art. 15–21 GDPR), and the right to lodge a complaint with a supervisory authority — in Portugal the CNPD (Comissão Nacional de Proteção de Dados).