Legal / Privacy
Privacy policy.
This site sets no cookies and loads nothing from other companies' servers. We collect personal data only when you write to us: to answer a scoping request, to run an engagement you sign, or to handle a vulnerability report. This page says what we keep, why, for how long, and how to use your rights.
Draft for lawyer review. Not in force. PLACEHOLDER
This page is a working draft. A lawyer reviews it before it applies, and bracketed slots fill in once the company is registered.
Who is responsible for your data.
[LEGAL NAME] is the controller for the personal data this page describes.Note 1
- Company
- [LEGAL NAME]
- KvK
- [KVK NUMBER]
- Address
- [STREET], [CITY], the Netherlands
- Contact
When you only read this site.
No cookies, no analytics, no advertising scripts, no embedded videos or social buttons. Fonts, scripts and images come from our own domain, so no third party is involved in reading a page beyond our host.
Three small preferences stay in your own browser and never reach us: motion in local storage remembers whether you turned motion off, and nav-intro-seen and filing-last in session storage time the page transitions for this visit only. They are not cookies, and you can clear them in your browser at any time.
Like every website, ours is served by a host that sees your IP address and the request when you load a page. Our host, [HOSTING PROVIDER], processes them for us to deliver the site and keep it available, under a processing agreement, and keeps its logs for [LOG RETENTION].Note 2
When you ask us for a scope.
- What
- Your name, work email, company and role, and what you want tested. If you use the scope builder, the deal value you type is used in your browser only and is never sent.
- Why
- To answer you and prepare a quote: steps you asked for before a contract, GDPR Article 6(1)(b).Note 3
- How long
- Who receives it
- Only us, and our email provider, [EMAIL PROVIDER], as our processor.
When you are a client.
Engagement data, from scope documents to test evidence, is governed by the data processing agreement we sign with you, not by this page.
Invoices and the records behind them are kept for seven years, because Dutch tax law requires it: a legal obligation under GDPR Article 6(1)(c).Note 4
When you report a vulnerability.
We keep your report and our correspondence to fix the issue, and to credit you if you ask us to. Our basis is our legitimate interest in keeping our systems secure, GDPR Article 6(1)(f). See our disclosure policy.Note 5
Your rights.
- See the personal data we hold about you, and get a copy.
- Have it corrected, or deleted when we no longer need it.
- Have its use restricted while a question about it is open.
- Receive the data you gave us in a machine-readable format.
- Object to processing based on our legitimate interest.Note 6
Write to us to use any of them. We answer within one month; when a request is complex we may take two more months, and we will tell you why within the first.Note 7
If you believe we handle your data wrongly, you can complain to the Autoriteit Persoonsgegevens, the Dutch data protection authority.Note 8
Changes to this policy.
This is draft version 0.1, dated 2026-10-10. If we change how we handle personal data, we change this page first, with a new version and date.
Read next
- Terms of use
The rules for using this site and its content.
- Disclosure policy
How to report a vulnerability in our systems.
- About
Who we are, and how to check us.