1. Who we are
Chain Cybersecurity is the controller for the personal data described in this statement. We are a sole proprietorship registered in the Netherlands and provide advice and training on cybersecurity culture and behaviour, alongside technical security services.
- Trade name: Chain Cybersecurity
- Address: Setheweg 8, 7942 LB Meppel, Netherlands
- Chamber of Commerce (KvK): 96165278
- Branch number: 000061509515
- Email: support@chainsecurities.org
We are not legally required to appoint a Data Protection Officer. Privacy questions, including requests to exercise your rights, go to the email address above.
2. What personal data we process
Website visitors
- Technical data recorded automatically by our web server: IP address, browser and device type, referring page, pages viewed and timestamps.
- Cookie data, but only in the categories you have agreed to. See section 4.
People who contact us
- Name, work email address, organisation and job context.
- The content of your enquiry and any later correspondence.
- The topic you selected and the date of your enquiry.
Clients and their staff
- Contact and role details of the people we work with during an engagement.
- Data generated by the services themselves — for example participation and results in security awareness training and simulated phishing campaigns, findings from technical testing, and information gathered during incident response.
- Billing and administrative records.
Training and simulation results. Where we run awareness programmes or simulations, results are reported to the client at group or department level by default. Individual-level reporting only happens where the client instructs it and has its own lawful basis and staff communication in place. For this data the client is the controller and we act as processor under a data processing agreement.
3. Why we process it, and our legal basis
| Purpose | Legal basis (GDPR Art. 6) |
|---|---|
| Responding to enquiries and preparing quotes | Steps prior to a contract (b), or our legitimate interest in answering you (f) |
| Delivering the services we have agreed | Performance of a contract (b) |
| Keeping our website secure, available and free of abuse | Legitimate interest (f) |
| Advertising cookies and measuring our campaigns (Meta Pixel, only if you accept advertising cookies) | Your consent (a) |
| Invoicing, accounting and statutory record keeping | Legal obligation (c) |
| Sending occasional service updates to existing clients | Legitimate interest (f) — you can opt out in any message |
Providing your data is voluntary. If you do not give us the details in the enquiry form we cannot respond to you, and if you do not consent to optional cookies the site still works normally.
4. Cookies and similar technologies
We place strictly necessary cookies to make the site work and to remember your cookie choice. Analytics and advertising cookies are only placed after you agree to them, and nothing in those categories loads before you do. You can change or withdraw your choice at any time using the cookie preferences panel, which is also linked in the footer of every page.
The full list of cookies, what each one does and how long it lasts is in our cookie policy.
5. Advertising on Facebook and Instagram
We advertise our services on Facebook and Instagram, which are operated by Meta Platforms Ireland Limited. To measure whether those ads work, we use the Meta Pixel on this website.
The pixel does not load unless you accept advertising cookies. If you do accept, the pixel sends Meta a record of certain actions you take here — for example viewing a page or submitting the enquiry form — together with your IP address and cookie identifiers. Meta uses this to report on our campaigns in aggregate and may use it to build audiences of people who resemble our visitors. We never send Meta the content of your enquiry, and we do not upload contact lists to Meta.
For the collection of this data through the pixel, we and Meta act as joint controllers, and we have entered into Meta's controller addendum. Meta is solely responsible for what it does with the data afterwards. You can read Meta's privacy policy and control how your data is used for ads in your Meta ad preferences.
If you contact us through a Facebook or Instagram lead form rather than this website, Meta collects your details first and passes them to us. Meta's own terms and privacy policy apply to that collection; once we receive your details, this statement applies.
6. Who we share data with
We do not sell personal data. We share it only with suppliers who process it on our behalf under a data processing agreement, and only as far as they need it:
| Category | Supplier | Purpose |
|---|---|---|
| Website hosting | Our VPS hosting provider (details on request) | Serving this website and server logs |
| The mailbox for support@chainsecurities.org | Correspondence and document handling | |
| Enquiry form | Email to support@chainsecurities.org | Receiving and storing enquiries from this website |
| Advertising | Meta Platforms Ireland Limited | Campaign measurement (only with consent) |
| Accounting | Our accountant, under professional confidentiality | Administration and statutory records |
We may also disclose data where we are legally obliged to, for example to a supervisory authority or in response to a valid order, and to our advisers where necessary to establish or defend a legal claim.
7. Transfers outside the EEA
We keep personal data in the European Economic Area wherever we can. Some suppliers, including Meta, are part of groups based in the United States. Where data is transferred outside the EEA we rely on an adequacy decision such as the EU–US Data Privacy Framework, or on the European Commission's standard contractual clauses combined with additional safeguards. You can ask us for details of the mechanism used for a specific supplier.
8. How long we keep data
| Data | Retention period |
|---|---|
| Enquiries that do not lead to an engagement | 12 months after our last contact |
| Client records and correspondence | 2 years after the engagement ends |
| Accounting and invoicing records | 7 years, as required by Dutch tax law |
| Assessment findings and technical evidence | Deleted 90 days after delivery unless the engagement agreement says otherwise |
| Web server logs | 12 months |
| Your cookie choice | 6 months, then we ask again |
9. How we protect data
We apply the measures we would advise a client to apply: multi-factor authentication on all business accounts, encryption of data at rest and in transit, least-privilege access, hardened endpoints, logging, backups, and deletion on a schedule. Findings and evidence from engagements are stored separately with access limited to the people working on that engagement. Everyone working on our behalf is bound by confidentiality obligations.
No set of measures makes a breach impossible. If a personal data breach occurs that is likely to result in a risk to your rights and freedoms, we will notify the Dutch Data Protection Authority within 72 hours and inform you where the law requires it.
10. Your rights
Under the GDPR you have the right to:
- ask what personal data we hold about you and receive a copy;
- have inaccurate data corrected;
- have your data erased where there is no longer a lawful reason for us to keep it;
- ask us to restrict processing while a dispute is resolved;
- object to processing based on our legitimate interests, including direct marketing;
- receive data you gave us in a portable format, or have it sent to another provider;
- withdraw consent at any time, which does not affect processing that already happened.
Write to support@chainsecurities.org and we will respond within one month. We may ask you to confirm your identity first, so that we do not disclose someone else's data to the wrong person. Exercising your rights is free unless a request is manifestly unfounded or excessive.
Where we act as a processor for a client — for example on training results or incident data belonging to your employer — we will forward your request to that client and support them in answering it, rather than acting on it ourselves.
We do not carry out automated decision-making or profiling that produces legal effects for you.
11. Complaints
If you are not satisfied with how we handle your data, please tell us first so we can put it right. You also have the right to complain to the Dutch Data Protection Authority:
- Autoriteit Persoonsgegevens, Postbus 93374, 2509 AJ Den Haag, Netherlands
- autoriteitpersoonsgegevens.nl
If you live in another EU country you may also complain to your local supervisory authority.
12. Changes to this statement
We update this statement when our services, suppliers or obligations change. The version number and date at the top of the page always show the current version. Material changes will be announced on this page before they take effect.