ISMS DirectoryPrivacy Policy
Last updated: January 26, 2025
Our Commitment to Your Privacy
We believe privacy should be simple. Unlike most websites, we don't track you, collect your data, or sell your information. This page explains exactly what we do (and don't do) with your data when you visit ISMS Directory.
What We DON'T Collect
Here's what we explicitly do NOT collect or use on this website:
- No personal information - We don't collect names, emails, phone numbers, or addresses directly
- No third-party ad tracking - No Google Analytics, Facebook Pixel, advertising pixels, or cross-site tracking (we use privacy-focused first-party analytics, described below)
- No user accounts - No login system or user registration
- No selling or sharing of data - Data is shared only with the processors named on this page, only to operate the site
- No advertising networks - No targeted ads or ad tracking
What We DO Use
We use exactly one cookie for a better user experience:
Cookie: sidebar:state
- Purpose: Remembers whether you've collapsed or expanded the sidebar navigation
- Duration: 7 days
- Type: Functional cookie (UI preference only)
- Storage: Stored locally in your browser
- Data shared: None - this cookie never leaves your device
This is a strictly functional cookie that improves your experience by remembering your UI preferences. No personal data is collected or transmitted.
Your Control & Rights
You have complete control over your data:
- You can clear the sidebar preference cookie at any time through your browser settings
- You can browse our site with all cookies disabled (the sidebar just won't remember your preference)
- For AI search conversations and listing submissions you can request access, correction, deletion, restriction, or object to processing via our contact form; for AI conversations, include the conversation reference shown in the search window so we can locate the data without asking you for identity documents
- You also have the right to lodge a complaint with your data protection supervisory authority
Service Submissions
When you submit a service to be listed in our directory, your information is collected through Google Forms. This includes:
- Company name and service details
- Contact information for verification purposes
- Service descriptions and specializations
This information is used solely for the purpose of reviewing and listing your service in our directory. Google Forms' privacy policy applies to data collected through their platform.
Paid Submissions & Stripe
For paid submission options, payment processing is handled securely by Stripe. When you make a payment:
- Payment details are processed directly by Stripe and never stored on our servers
- We receive only the information necessary to fulfill your order (name, email, transaction confirmation)
- This information is used exclusively for processing your listing and providing customer support
Stripe's privacy policy applies to all payment data. Visit stripe.com/privacy for more details.
Third-Party Services
Beyond the submission process described above, we use the following third-party services:
Contact Form (Tally)
Our contact form is provided by Tally. When you submit a contact request, removal request, or change request, your information is processed by Tally. This may include your name, email, and message content. Tally's privacy policy applies to data collected through their platform. Visit tally.so/help/privacy-policy for more details.
Our standard directory search runs entirely client-side in your browser: those search terms are not sent to us or any third party. The optional AI vendor search works differently and is described in its own section below. External links to tools and resources on other websites are clearly marked, and their privacy policies apply once you leave our site.
Analytics
We measure site usage with a self-hosted Umami instance and Vercel's privacy-friendly analytics: aggregate page views, referrer domains, outbound clicks to vendors, and coarse search-intent categories (for example framework, region, or service type, from a fixed list). No advertising identifiers, no cross-site profiles, no use for advertising. Analytics never contain the content of AI search conversations, only category labels from our own fixed vocabulary.
AI Vendor Search
The AI vendor search is an optional, clearly labelled AI feature (no account needed). When you use it:
- What we process: your messages, the AI's answers, a random conversation reference, your language, and a salted hash of your IP address (never your raw IP).
- AI processing: your messages and the answers are sent to OpenRouter and a restricted set of zero-data-retention model providers, only to generate the answer. Providers may not train on this data.
- Storage: we keep conversations for up to 14 days (up to 90 days if linked to an abuse or safety incident), only to prevent abuse, secure the service, and review the safety and accuracy of answers. Legal basis: our legitimate interests, Art. 6(1)(f) GDPR.
- What we never do: no training on your conversations, no advertising, no vendor rankings from your conversations, no conversation content in analytics, no linking to other visitors.
- Please do not enter personal or confidential information: the assistant only needs your compliance requirement. Detected sensitive data is kept out of our logs.
- Your rights: request access, deletion, restriction, or object via our contact form, quoting the conversation reference shown in the search window. You may also complain to your supervisory authority.
AI answers are generated automatically and can be wrong; verify important details with the vendor. openrouter.ai/privacy.
AI market data chat
The optional AI chat on the GRC trends page answers questions about directory page interest (frameworks, regions, and combinations). It uses the same honesty rules as our public market API: pageviews of directory pages, not market share or adoption.
- What we process: your messages, the AI answers, a random conversation reference, your language, and a salted IP hash. Conversation content is never sent to analytics.
- Storage: up to 14 days (up to 90 days if linked to an abuse or safety incident), for abuse prevention and answer integrity review. Legal basis: legitimate interests, Art. 6(1)(f) GDPR.
- This chat does not recommend vendors. For vendor search, use Ask AI on the homepage.
Questions About This Policy?
If you have any questions about our privacy practices, please feel free to reach out to us. As a GRC-focused resource, we take privacy seriously and are happy to address any concerns.
Please use our contact form to reach out to us directly.
Changes to This Policy
If we ever change this privacy policy, we'll update the "Last updated" date at the top of this page. Given our minimal data collection approach, we don't anticipate significant changes. Any updates will be posted here.
