Privacy Policy and Legal Notice

Welcome to Wireshark Labs. We appreciate your interest in our self-paced PCAP labs and services offered under the Wireshark brand. Protecting your personal data is of the utmost importance to us. Our website can generally be used without providing any personal information. However, if you wish to access certain services, the processing of personal data may become necessary. If processing personal data is required and there is no legal basis for such processing, we will seek your explicit consent.

The processing of personal data, such as your name, address, email address, or phone number, is always carried out in accordance with the General Data Protection Regulation (GDPR) and other applicable international data protection laws. This privacy policy aims to inform you about the nature, scope, and purpose of the personal data we collect, use, and process, as well as your rights regarding your personal data.

Wireshark Labs has implemented numerous technical and organizational measures to ensure the most complete protection of personal data processed through this website. However, internet-based data transmissions may have security gaps, so absolute protection cannot be guaranteed. Therefore, you are free to transmit personal data to us via alternative means, such as by telephone.

1. Definitions

This privacy policy is based on the terminology used by the GDPR and other internationally recognized privacy standards. We aim to make our privacy policy easy to read and understand for the public, our customers, and business partners. To ensure this, we explain the terminology used in advance.

We use, among others, the following terms in this privacy policy:

a) Personal Data

Personal data means any information relating to an identified or identifiable natural person ("data subject"). An identifiable natural person is one who can be identified, directly or indirectly, in particular by reference to an identifier such as a name, an identification number, location data, an online identifier, or to one or more factors specific to the physical, physiological, genetic, mental, economic, cultural, or social identity of that natural person.

b) Data Subject

Data subject is any identified or identifiable natural person whose personal data is processed by the controller responsible for the processing.

c) Processing

Processing means any operation or set of operations which is performed on personal data or on sets of personal data, whether or not by automated means, such as collection, recording, organization, structuring, storage, adaptation or alteration, retrieval, consultation, use, disclosure by transmission, dissemination or otherwise making available, alignment or combination, restriction, erasure, or destruction.

d) Restriction of Processing

Restriction of processing is the marking of stored personal data with the aim of limiting their processing in the future.

e) Profiling

Profiling means any form of automated processing of personal data consisting of the use of personal data to evaluate certain personal aspects relating to a natural person, in particular to analyze or predict aspects concerning that natural person's performance at work, economic situation, health, personal preferences, interests, reliability, behavior, location, or movements.

f) Pseudonymization

Pseudonymization is the processing of personal data in such a manner that the personal data can no longer be attributed to a specific data subject without the use of additional information, provided that such additional information is kept separately and is subject to technical and organizational measures to ensure that the personal data are not attributed to an identified or identifiable natural person.

g) Controller

Controller or data controller means the natural or legal person, public authority, agency, or other body which, alone or jointly with others, determines the purposes and means of the processing of personal data.

h) Processor

Processor means a natural or legal person, public authority, agency, or other body which processes personal data on behalf of the controller.

i) Recipient

Recipient means a natural or legal person, public authority, agency, or another body, to which the personal data are disclosed, whether a third party or not.

j) Third Party

Third party means a natural or legal person, public authority, agency, or body other than the data subject, controller, processor, and persons who, under the direct authority of the controller or processor, are authorized to process personal data.

Consent of the data subject means any freely given, specific, informed, and unambiguous indication of the data subject's wishes by which he or she, by a statement or by a clear affirmative action, signifies agreement to the processing of personal data relating to him or her.

2. Name and Address of the Controller

The controller for the purposes of the GDPR and other applicable data protection laws is:

Wireshark Labs  
Self-paced PCAP Labs  
[Address Placeholder]  
[City, Country Placeholder]  
Email: [[email protected]]  

3. Collection of General Data and Information

The website of Wireshark Labs collects a series of general data and information when you or an automated system accesses the website. This general data and information are stored in the server log files. The following may be collected: (1) browser types and versions used, (2) the operating system used by the accessing system, (3) the website from which an accessing system reaches our website (referrer), (4) the sub-websites, (5) the date and time of access, (6) an Internet Protocol address (IP address), (7) the internet service provider of the accessing system, and (8) any other similar data and information that may be used in the event of attacks on our information technology systems.

Wireshark Labs does not draw any conclusions about the data subject from this general data and information. Rather, this information is needed to (1) deliver the content of our website correctly, (2) optimize the content of our website as well as its advertising, (3) ensure the long-term viability of our information technology systems and website technology, and (4) provide law enforcement authorities with the information necessary for criminal prosecution in case of a cyber-attack. The anonymously collected data and information are evaluated by Wireshark Labs statistically and with the aim of increasing the data protection and data security of our enterprise, and ultimately to ensure an optimal level of protection for the personal data we process. The anonymous data of the server log files are stored separately from any personal data provided by a data subject.

4. Subscription to Comments in the Blog

Comments made in the Wireshark Labs blog may be subscribed to by third parties. In particular, there is the possibility that a commenter may subscribe to follow-up comments on a particular blog post.

If a data subject chooses to subscribe to comments, the controller will send an automatic confirmation email to verify, using the double opt-in procedure, whether the owner of the specified email address has indeed chosen this option. The option to subscribe to comments can be terminated at any time.

5. Routine Deletion and Blocking of Personal Data

The controller shall process and store the personal data of the data subject only for the period necessary to achieve the purpose of storage, or as far as this is granted by the applicable laws or regulations.

If the storage purpose is not applicable, or if a storage period prescribed by applicable laws expires, the personal data are routinely blocked or erased in accordance with legal requirements.

6. Rights of the Data Subject

a) Right to Confirmation

You have the right to obtain confirmation from the controller as to whether or not personal data concerning you is being processed. If you wish to exercise this right, you may contact our data protection officer or another employee of the controller at any time.

b) Right to Access

You have the right to obtain free information about your stored personal data at any time and a copy of this information. Furthermore, you have the right to obtain information regarding:

  • the purposes of processing
  • the categories of personal data concerned
  • the recipients or categories of recipients to whom the personal data have been or will be disclosed, in particular recipients in third countries or international organizations
  • where possible, the envisaged period for which the personal data will be stored, or, if not possible, the criteria used to determine that period
  • the existence of the right to request rectification or erasure of personal data or restriction of processing of personal data concerning you, or to object to such processing
  • the right to lodge a complaint with a supervisory authority
  • where the personal data are not collected from you, any available information as to their source
  • the existence of automated decision-making, including profiling, and, at least in those cases, meaningful information about the logic involved, as well as the significance and envisaged consequences of such processing for you

You also have the right to know whether personal data are transferred to a third country or to an international organization. Where this is the case, you have the right to be informed of the appropriate safeguards relating to the transfer.

If you wish to exercise this right, you may contact our data protection officer or another employee of the controller at any time.

c) Right to Rectification

You have the right to obtain the rectification of inaccurate personal data concerning you without undue delay. Taking into account the purposes of the processing, you have the right to have incomplete personal data completed, including by means of providing a supplementary statement.

If you wish to exercise this right, you may contact our data protection officer or another employee of the controller at any time.

d) Right to Erasure (“Right to be Forgotten”)

You have the right to request the erasure of personal data concerning you without undue delay where one of the following grounds applies and as long as the processing is not necessary:

  • The personal data are no longer necessary in relation to the purposes for which they were collected or otherwise processed.
  • You withdraw consent on which the processing is based and there is no other legal ground for the processing.
  • You object to the processing and there are no overriding legitimate grounds for the processing.
  • The personal data have been unlawfully processed.
  • The personal data must be erased for compliance with a legal obligation.
  • The personal data have been collected in relation to the offer of information society services.

If one of the above reasons applies and you wish to request the erasure of personal data stored by Wireshark Labs, you may contact our data protection officer or another employee of the controller at any time. The data protection officer or another employee will promptly ensure that the erasure request is complied with.

e) Right to Restriction of Processing

You have the right to request the restriction of processing where one of the following applies:

  • The accuracy of the personal data is contested by you, for a period enabling the controller to verify the accuracy of the personal data.
  • The processing is unlawful and you oppose the erasure of the personal data and request the restriction of their use instead.
  • The controller no longer needs the personal data for the purposes of the processing, but they are required by you for the establishment, exercise, or defense of legal claims.
  • You have objected to processing pending the verification whether the legitimate grounds of the controller override those of you.

If one of the above conditions is met and you wish to request the restriction of personal data stored by Wireshark Labs, you may contact our data protection officer or another employee of the controller at any time.

f) Right to Data Portability

You have the right to receive the personal data concerning you, which you have provided to a controller, in a structured, commonly used, and machine-readable format. You also have the right to transmit those data to another controller without hindrance, as long as the processing is based on consent or on a contract and the processing is carried out by automated means, unless the processing is necessary for the performance of a task carried out in the public interest or in the exercise of official authority.

In exercising your right to data portability, you have the right to have the personal data transmitted directly from one controller to another, where technically feasible and as long as this does not adversely affect the rights and freedoms of others.

To assert the right to data portability, you may contact the data protection officer appointed by Wireshark Labs or another employee at any time.

g) Right to Object

You have the right to object, on grounds relating to your particular situation, at any time to processing of personal data concerning you which is based on legitimate interests. This also applies to profiling based on these provisions.

Wireshark Labs will no longer process the personal data in the event of the objection, unless we can demonstrate compelling legitimate grounds for the processing which override your interests, rights, and freedoms, or for the establishment, exercise, or defense of legal claims.

Where Wireshark Labs processes personal data for direct marketing purposes, you have the right to object at any time to processing of personal data concerning you for such marketing. This applies to profiling to the extent that it is related to such direct marketing. If you object to Wireshark Labs to the processing for direct marketing purposes, Wireshark Labs will no longer process the personal data for these purposes.

You also have the right, on grounds relating to your particular situation, to object to processing of personal data concerning you for scientific or historical research purposes, or for statistical purposes, unless the processing is necessary for the performance of a task carried out for reasons of public interest.

To exercise the right to object, you may contact the data protection officer of Wireshark Labs or another employee directly. You are also free, in the context of the use of information society services, to exercise your right to object by automated means using technical specifications.

h) Automated Individual Decision-Making, Including Profiling

You have the right not to be subject to a decision based solely on automated processing, including profiling, which produces legal effects concerning you or similarly significantly affects you, unless the decision (1) is necessary for entering into, or the performance of, a contract between you and a data controller, or (2) is authorized by applicable law and which also lays down suitable measures to safeguard your rights and freedoms and legitimate interests, or (3) is based on your explicit consent.

If the decision (1) is necessary for entering into or the performance of a contract between you and a data controller, or (2) it is based on your explicit consent, Wireshark Labs shall implement suitable measures to safeguard your rights and freedoms and legitimate interests, at least the right to obtain human intervention on the part of the controller, to express your point of view, and to contest the decision.

If you wish to exercise rights concerning automated individual decision-making, you may contact our data protection officer or another employee of the controller at any time.

You have the right to withdraw your consent to processing of your personal data at any time.

If you wish to exercise the right to withdraw consent, you may contact our data protection officer or another employee of the controller at any time.

7. Data Protection Provisions about the Application and Use of LinkedIn

The controller has integrated components of the LinkedIn Corporation on this website. LinkedIn is an internet-based social network that enables users to connect with existing business contacts and make new business contacts. More than 400 million registered people use LinkedIn in over 200 countries.

When you access a page on our website that contains a LinkedIn component (LinkedIn plug-in), your browser is automatically prompted to download a display of the corresponding LinkedIn component. Further information about LinkedIn plug-ins may be obtained at https://developer.linkedin.com/plugins. In the course of this technical procedure, LinkedIn gains knowledge of what specific sub-page of our website was visited by you.

If you are logged in at LinkedIn at the same time, LinkedIn recognizes with each visit to our website by you—and for the entire duration of your stay on our website—which specific sub-page of our website you visited. This information is collected by the LinkedIn component and associated with your LinkedIn account. If you click on a LinkedIn button integrated on our website, LinkedIn assigns this information to your personal LinkedIn user account and stores the personal data.

LinkedIn receives information via the LinkedIn component that you have visited our website, provided that you are logged in at LinkedIn at the time of the call-up to our website. This occurs regardless of whether you click on the LinkedIn component or not. If such a transmission of information to LinkedIn is not desirable, you may prevent this by logging out of your LinkedIn account before visiting our website.

LinkedIn provides options to manage email messages, SMS messages, and targeted ads at https://www.linkedin.com/psettings/guest-controls and to manage ad settings. LinkedIn uses partners who may set cookies. Such cookies can be refused at https://www.linkedin.com/legal/cookie-policy. The applicable privacy policy of LinkedIn is available at https://www.linkedin.com/privacy-policy. The LinkedIn cookie policy is available at https://www.linkedin.com/legal/cookie-policy.

8. Data Protection Provisions about the Application and Use of Xing

The controller has integrated components from Xing on this website. Xing is an internet-based social network that enables users to connect with existing business contacts and make new business contacts. Users may create a personal profile on Xing. Companies may create company profiles or post job offers on Xing.

When you access a page on our website that contains a Xing component (Xing plug-in), your browser is automatically prompted to download a display of the corresponding Xing component. Further information about Xing plug-ins may be obtained at https://dev.xing.com/plugins. In the course of this technical procedure, Xing gains knowledge of what specific sub-page of our website was visited by you.

If you are logged in at Xing at the same time, Xing recognizes with each visit to our website by you—and for the entire duration of your stay on our website—which specific sub-page of our website you visited. This information is collected by the Xing component and associated with your Xing account. If you click on a Xing button integrated on our website, such as the "Share" button, Xing assigns this information to your personal Xing user account and stores the personal data.

Xing receives information via the Xing component that you have visited our website, provided that you are logged in at Xing at the time of the call-up to our website. This occurs regardless of whether you click on the Xing component or not. If such a transmission of information to Xing is not desirable, you may prevent this by logging out of your Xing account before visiting our website.

The data protection provisions published by Xing, available at https://www.xing.com/privacy, provide information about the collection, processing, and use of personal data by Xing. Xing has also published data protection information for the Xing Share button at https://www.xing.com/app/share?op=data_protection.

The legal basis for processing operations for which we obtain consent for a specific processing purpose is Art. 6(1)(a) GDPR. If the processing of personal data is necessary for the performance of a contract to which you are party, as is the case, for example, with processing operations necessary for the supply of goods or to provide any other service, the processing is based on Art. 6(1)(b) GDPR. The same applies to such processing operations necessary for carrying out pre-contractual measures. If our company is subject to a legal obligation by which processing of personal data is required, such as for the fulfillment of tax obligations, the processing is based on Art. 6(1)(c) GDPR. In rare cases, processing of personal data may be necessary to protect the vital interests of you or another natural person. Then the processing would be based on Art. 6(1)(d) GDPR.

Ultimately, processing operations could be based on Art. 6(1)(f) GDPR. This legal basis is used for processing operations which are not covered by any of the aforementioned legal grounds, if processing is necessary for the purposes of the legitimate interests pursued by our company or by a third party, except where such interests are overridden by your interests or fundamental rights and freedoms.

10. Legitimate Interests Pursued by the Controller or a Third Party

Where the processing of personal data is based on Article 6(1)(f) GDPR, our legitimate interest is the conduct of our business in favor of the well-being of all our employees and shareholders.

11. Duration for Which Personal Data Will Be Stored

The criterion used to determine the period of storage of personal data is the respective statutory retention period. After expiration of that period, the corresponding data are routinely deleted, as long as they are no longer necessary for the fulfillment of the contract or the initiation of a contract.

We inform you that the provision of personal data is partly required by law (e.g., tax regulations) or can also result from contractual provisions (e.g., information on the contractual partner). Sometimes it may be necessary to conclude a contract that you provide us with personal data, which must subsequently be processed by us. For example, you are obliged to provide us with personal data when our company signs a contract with you. The non-provision of personal data would have the consequence that the contract with you could not be concluded.

Before personal data is provided by you, you may contact our data protection officer. Our data protection officer will clarify on a case-by-case basis whether the provision of the personal data is required by law or contract or is necessary for the conclusion of the contract, whether there is an obligation to provide the personal data, and the consequences of non-provision of the personal data.

13. Existence of Automated Decision-Making

As a responsible company, we do not use automatic decision-making or profiling.

§ 1 Limitation of Liability

The contents of this website are created with the utmost care. However, Wireshark Labs does not guarantee the accuracy, completeness, or timeliness of the information provided. The use of the website content is at your own risk. Named contributions reflect the opinion of the respective author and not always the opinion of Wireshark Labs. Merely using the website does not create any contractual relationship between the user and Wireshark Labs.

This website contains links to third-party websites ("external links"). These websites are the responsibility of the respective operators. At the time the external links were first linked, no legal violations were apparent. Wireshark Labs has no influence on the current and future design and content of the linked pages. Setting external links does not mean that Wireshark Labs adopts the content behind the reference or link as its own. Continuous control of external links is not reasonable for Wireshark Labs without concrete evidence of legal violations. If legal violations become known, such external links will be deleted immediately.

The content published on this website is subject to international copyright and intellectual property laws. Any use not permitted by copyright law requires the prior written consent of Wireshark Labs or the respective rights holder. This applies in particular to reproduction, editing, translation, storage, processing, or reproduction of content in databases or other electronic media and systems. Content and rights of third parties are indicated as such. Unauthorized reproduction or distribution of individual content or complete pages is not permitted and is punishable by law. Only the production of copies and downloads for personal, private, and non-commercial use is allowed.

The presentation of this website in external frames is only permitted with written permission.

§ 4 Special Terms of Use

Where special conditions for individual uses of this website deviate from the above paragraphs, this will be expressly indicated at the appropriate place. In such cases, the special terms of use apply in each individual case.