Trust & security

OtoTrak is unwavering in protecting your data and following the best security practices.

Report a security vulnerability

If you have found a cybersecurity issue in any OtoTrak product, including web, mobile app, cloud or hardware module — you can report it to us confidentially and have us address the problem before it is publicly disclosed. Please reach out if you believe you have found vulnerabilities, no matter how small.

Request my data / deletion

If you are an individual in the European Union, GDPR gives you rights over your personal data — including access, correction, transfer, and deletion. We extend these same rights to non-EU individuals and companies as well. Contact us with your request.

How coordinated disclosure works

We take the security of our products and services seriously and welcome responsible disclosure from anyone who identifies a potential vulnerability, whether you are one of our business customers or an individual such as a security researcher. If you believe you have found a security issue, please report it — we will acknowledge your report, investigate promptly, and keep you informed as we work toward a fix, in line with coordinated vulnerability disclosure practices. We ask that you give us reasonable time to resolve the issue before any public disclosure and avoid accessing or modifying data beyond what is necessary to demonstrate the vulnerability.

You report privately

Send us the details using the email address above. Please include in your report as much detail as possible, including the affected component, steps to reproduce, and potential impact.

We'll acknowledge the issue

We may follow up for more detail if needed, and assign you a reference number and a named contact on our security team.

We remediate

Critical issues are patched in the shortest possible timeframe. Firmware fixes for the module may take time to roll out — we'll tell you the target date.

Your rights over your data

In accordance with the General Data Protection Regulation (GDPR), anyone whose personal data we process has the right to access, correct, delete, or request portability of their data, as well as to object to or restrict certain processing. To exercise any of these rights, please contact our Data Protection Officer, providing your name and relevant account details so we can verify and process your request. We aim to respond to all such requests within the timeframes required by law. Please note that though we may not be required to, we try to honor data protection requests from all customers, even if they are not based in the EU.

Access: Get a copy of the data we hold about you.
Correct: Have any details corrected.
Port: Get your data as a machine-readable export (CSV, JSON).
Erase: Have your data deleted where we have no legal ground to keep it.
Restrict: Have us stop processing data.
Object: Dispute our reason for processing your data at any time, such as to legitimate interests or direct marketing.