What the policy must cover

Do not treat a captured application like an ordinary newsletter lead.

  • names, work email addresses, organizations, roles, and intake responses;
  • ownership and authorization statements;
  • application URLs or artifacts submitted during an assessment intake;
  • server and analytics data, including whether Cloudflare Web Analytics is enabled;
  • purpose and legal basis;
  • processors, security measures, cross-border processing, user rights, retention, and deletion;
  • the privacy contact and policy-change process.

Public form warning

Do not submit code, credentials, HAR files, private URLs with tokens, or confidential materials through the public form.