Legal
Privacy policy
JR Security handles your personal data carefully and confidentially, in line with the General Data Protection Regulation (GDPR). Below you can read exactly how.
Last updated on [date]. Version 1.0.
Note (TODO for the client): this is a tailored draft that describes the actual data processing of this website. Have it reviewed by a lawyer before publication and complete the placeholders (data protection officer, exact retention periods, signed processor agreements, DPF status of the US parties).
1. Who is responsible?
The controller is JR Security B.V., established in Amsterdam, registered with the Chamber of Commerce under 42007965. See our Imprint for all company details.
- Email: privacy@jrsecurity.nl
- Data protection officer (DPO): [name/contact, or: not formally appointed]
2. What data do we process and why?
a. Contact and quote form
When you complete the contact form, we process: name, optional company name, email address, phone number, chosen service and your message.
- Purpose: to assess and respond to your request.
- Legal basis: legitimate interest (art. 6(1)(f) GDPR) — being able to respond to your request.
- Marketing (optional): only if you tick the separate checkbox do we contact you about relevant services. Legal basis: consent (art. 6(1)(a) GDPR), which you can withdraw at any time.
b. Complaint form
Via the complaints page we process: name, email address, phone number, the date and location of the incident, your description, the desired resolution and any attached file.
- Purpose: to register, handle and resolve your complaint.
- Legal basis: legal obligation (art. 6(1)(c) GDPR) and legitimate interest in careful complaint handling.
- Retention: complaint data is kept for 2 years.
c. Consent and security logs
- When you save your cookie preferences, we record a consent log: time, banner version, chosen categories, a hashed version of your IP address and your browser user agent. Legal basis: legal accountability obligation (art. 5(2)/7 GDPR). Retention: about 13 months.
- For form submissions we keep proof of consent and a counter for abuse prevention (rate-limiting) based on a hashed IP address — without your name, email or message. Legal basis: legitimate interest in security (art. 6(1)(f) GDPR).
We do not store your IP address in readable form; we use an irreversible hash (SHA-256 with salt).
3. With whom do we share data?
We never sell your data. We do engage a few service providers (processors). Some are located outside the European Economic Area (EEA); in that case we base the transfer on an adequacy decision, the EU-US Data Privacy Framework (DPF) or standard contractual clauses (SCCs).
Telegram
- Party/country: Telegram FZ-LLC, Dubai (UAE).
- Data: the content of your contact or complaint message (incl. name, email, phone, message).
- Purpose: fast internal follow-up via our secure channel.
- Transfer: outside the EEA. [TODO: put appropriate safeguards — SCCs — in place]
- Retention: until we delete the message manually.
- Telegram's privacy policy
hCaptcha (anti-spam)
- Party/country: Intuition Machines, Inc., United States.
- Data: IP address, device/browser data and interaction data, to distinguish humans from bots.
- Purpose: to protect forms against abuse and spam.
- Legal basis: legitimate interest (art. 6(1)(f) GDPR) — securing our forms. hCaptcha is strictly necessary and loads on form pages for every visitor; it places no advertising or tracking cookies.
- Transfer: US. [TODO: verify DPF status]
- hCaptcha's privacy policy
Plausible Analytics (optional)
- Party/country: Plausible Insights OÜ, Estonia (EU).
- Data: anonymised, cookieless visitor statistics — no profiling.
- Loading: only after consent to the analytics category. No Google Analytics.
- Plausible's privacy policy
Email delivery (Resend)
- Party/country: Resend, United States.
- Data: the content of your submission, as an email copy to our own address.
- Transfer: US. [TODO: DPF/processor agreement]
Hosting
- Party/country: the website and the processing endpoint run on [Cloudflare Pages + Workers / Vercel] (United States, DPF-certified).
- Data: technical data of each visit (such as IP address) needed to deliver the site securely.
- Fonts are self-hosted; no Google Fonts are loaded.
4. Retention periods (summary)
- Contact requests (proof of consent, without message content): about 90 days.
- Complaints: 2 years.
- Consent logs (cookies): about 13 months.
- Telegram messages: until manual deletion.
- Email in our mailbox: no longer than necessary for handling. [TODO: set a concrete period]
5. Security
We take appropriate technical and organisational measures: traffic only over HTTPS, a strict Content-Security-Policy, server-side validation and sanitisation of input, rate-limiting, and hashing of IP addresses in logs. Access to data is limited to authorised staff.
6. Your rights
You have the right to:
- access to the data we process about you;
- rectification of inaccurate data;
- erasure ("right to be forgotten"), insofar as no legal retention obligation applies;
- restriction of processing;
- object to processing based on legitimate interest;
- data portability;
- withdraw consent previously given, at any time.
Send your request to privacy@jrsecurity.nl. We respond within the legal period of one month.
7. Complaint to the supervisory authority
If you disagree with how we handle your data, you can lodge a complaint with the Dutch Data Protection Authority. We would appreciate the chance to resolve it with you first.
8. Cookies
For the use of cookies and similar techniques, please see our Cookie policy. You can change your choice at any time via Cookie preferences in the footer.
9. Changes
We may amend this privacy policy from time to time. The most recent version is always on this page, with the date of the last change at the top.