Skip to Content

Security vulnerability notification

Statement

Cybersecurity remains a fundamental priority for JDU Consulting. We are dedicated to safeguarding all users and customers globally through robust protective measures and continuous vigilance.

JDU Consulting maintains transparency in vulnerability management by collaborating with the global security community to identify, assess, and mitigate potential risks.

JDU Consulting maintains a specialized security team that continuously monitors the cybersecurity of all systems, services, and products. Simultaneously, our Group Cybersecurity Team oversees the external vulnerability management process, handling vulnerability reports, conducting investigations, and coordinating response efforts.

Vulnerability Disclosure Notification Process

How to notify JDU Consulting of a security issue

If you discover a vulnerability in our system, services or product, please notify us as quickly as possible by sending an email to: [email protected]

Please include, as a minimum, the following information:

  • Your preferred contact details (including Contact Phone number)
  • Detailed description of the vulnerability
  • Time and method of its discovery
  • Specification of system, services or product where the vulnerability has been discovered
  • Any other related information (code samples, logs, screenshots, etc)

Resolution process

We will investigate any notification issues and will undertake all required actions and measures to mitigate and/or resolve the notification issue.

Undertakings

By submitting a vulnerability notification, you agree to :-

  • Not disclosing or publishing the vulnerability to others before it has been fixed and before expiration of a mutually agreed time frame;
  • Not taking advantage of the vulnerability, modifying, downloading or deleting any records or data or to launch any type of attack based on the vulnerability;
  • Abide by the laws and regulations related to your location;
  • Comply with applicable data protection legislations, in particular by not disclosing a third party’s personal data without any valid legal ground;
  • Confirm that the elements contained in the notification you are submitting do not infringe intellectual property rights of any third party (i.e. you did not copy elements available on the internet for example).

By submitting a vulnerability notification to JDU Consulting, you agree to grant JDU Consulting an irrevocable, worldwide right to use it, gratuitously and for a period of fifty years.

Processing of your personal data

When submitting your notification, you understand that JDU Consulting will process your personal data. Such processing is carried out in compliance with applicable data protection laws, and in any case your personal data will be processed only in order to follow up on your notification. JDU Consulting undertakes not to process your personal data for any other purpose.

With whom do we share your personal data?

Your personal data will be shared with third parties only to the extent strictly necessary. When relying on such third party, be ensured that JDU Consulting has entered into contractual agreements to ensure that your personal data are processed safely and strictly according to JDU Consulting ’s instructions.

Furthermore, the JDU Consulting affiliates or the third party at stake, may be located outside of the European Economic Area (“EEA”) thus implying a data transfer of your personal data.

→ Where such a transfer takes place between entities of JDU Consulting, it will be covered by JDU Consulting ’s Binding Corporate Rules (“BCR”). For further information on JDU Consulting ’s BCR, please click on the following link: https://83.229.17.65/wp-content/uploads/2017/06/Capgemini-Binding-Corporate-Rules.pdf.

→ Where such transfer takes place between JDU Consulting and the external third-party, JDU Consulting and said third-party have into EU Model Clauses approved by the European Commission, to ensure the security of the personal data.

How long does JDU Consulting keep your personal data?

JDU Consulting shall keep your personal data for no longer than is necessary for the purpose(s) for which they were collected.

JDU Consulting shall keep your personal data for three (3) years from date of collection.

What are your rights and how to exercise them?

You can request to access, rectify or erase your personal data. You may also object to the processing of your personal data, or request that it be restricted. In addition, you can ask for the communication of your personal data in a structured, commonly used and machine-readable format.

If you wish to exercise those rights, please contact our Global Data Protection Office by sending an email to the following address: [email protected]. Where appropriate we will communicate your request and/or complaint to the relevant local data protection officer.

Please note that you also have the right to lodge a complaint before a data protection authority or the competent court of law.