Privacy notice
We process as little data as possible and pass nothing to third-party advertising or analytics services.
Controller
The provider named in the legal notice is responsible for the processing. Privacy questions are answered via the contact address given there.
What we process
- Account data: your email address and a password hash. The password itself is never stored.
- Your questionnaire answers and, if you upload them, your evidence. These belong to your organisation and are isolated from other organisations.
- Technically necessary data such as a session cookie, plus short-lived counters used to prevent abuse (for example login attempts).
Cookies
Only strictly necessary cookies are set: a session cookie after login, a cookie for an assessment you started, and your language choice. There are no tracking or advertising cookies -- which is why you will not find a cookie banner here.
Usage measurement
We count, server-side, how often steps such as 'quick check started' or 'result viewed' occur. Only the event, a coarse category (for example country), the date and a count are stored -- no IP address, no identifier, nothing that could recognise you again. No third-party analytics scripts are loaded.
Hosting and delivery
The application runs on a server operated by the provider in the Netherlands (EU). Public delivery goes through Cloudflare as an upstream reverse proxy; Cloudflare processes technically necessary connection data such as IP address and requested URL in order to establish the connection and fend off attacks. Nothing is transferred for advertising purposes.
Outbound email
Transactional email (address verification, password reset, team invitation, security notices) is sent from the provider's own mail server; no external email service is involved. We do not send marketing newsletters.
Payments
No payment provider is currently connected and no payment data is processed. This notice will be extended before any paid feature is offered.
Logs
Server logs contain the time, the requested path, the status code and technical error messages. Questionnaire answers, evidence and credentials do not appear in them. Security-relevant events are logged separately.
Retention
- An assessment started without an account is deleted after 24 hours.
- Account data and assessments are kept while the account exists; we delete them on request.
- Records of security-relevant actions (for example role changes) are kept separately and for a shorter period, and contain no questionnaire content.
The database is backed up regularly and the backups are kept on the same EU infrastructure. After a deletion, data may still be present in backups until the retention period expires; it is not restored into live operation.
Export and deletion
Signed-in users can export their data as a machine-readable file at any time, delete individual cases and delete their own account. Deleting the account ends all sessions; ownership of an organisation must first be transferred, or the organisation deleted with the account.
Your rights
You may request access, rectification, erasure, restriction and data portability, and object to processing. The contact address is above.