DE Vulnerability Disclosure Policy

This English version is provided for convenience. The German version is legally binding.

Glen Dimplex B.V. and its affiliated companies are committed to protecting the confidentiality of consumers' and employees' personal data, the availability of websites/information systems and the security of internet-connected devices, including compliance with applicable IoT security requirements.

This policy gives security researchers guidelines for vulnerability discovery activities and for reporting vulnerabilities they find.

Research carried out in good faith under this policy is considered authorised, provided it stays within the defined scope; Glen Dimplex B.V. will then not take legal action, provided the scope has not been exceeded, there was no malicious intent and no applicable law has been broken.

Glen Dimplex B.V. does NOT run a bug bounty programme and offers no reward/compensation for reports.

Guidelines for researchers

As part of legitimate research you should:

  • notify Glen Dimplex B.V. as soon as possible after discovering an actual or potential security issue
  • make every effort to avoid privacy breaches, degrading the user experience, disrupting production systems and destroying/manipulating data
  • use exploits only to the extent needed to confirm the vulnerability
  • not use an exploit to compromise/exfiltrate data, establish persistent unauthorised access or move to other systems
  • give Glen Dimplex B.V. a reasonable period to fix the issue before any public disclosure

If you find a vulnerability or access sensitive data (personal data, financial data, proprietary information, trade secrets): stop testing immediately, notify Glen Dimplex B.V. without delay, do not disclose the data to anyone else, permanently delete/destroy all sensitive data as soon as possible after notifying us and confirm its destruction on request. Keep all details of the vulnerability confidential until the fix has been confirmed or Glen Dimplex B.V. has approved disclosure in writing.

Reporting a vulnerability

Report by email (address Cloudflare-encrypted on the original page, available directly via the website).

Recommended report content:

  • when the vulnerability/issue was found
  • description of the affected system or product
  • description of the steps to reproduce the vulnerability
  • suggestions/ideas for a fix

Glen Dimplex B.V. acknowledges all reports within 3 working days. For IoT products: regular updates until the reported vulnerability has been fixed.

Scope

Included: all Glen Dimplex B.V. websites (owned or licensed), all internet-connected business systems, internet-connected products and related mobile applications.

Not included:

  • social engineering or phishing campaigns against Glen Dimplex B.V. employees
  • denial-of-service (DoS) attacks on websites/business applications
  • all other unauthorised activity with malicious intent

Questions about the programme or reporting a vulnerability: contact us by email via the website.