PRIVACY POLICY

ForgedCyberSentinel

Version 2.0 — Effective Date: 30 July 2026

ForgedCyberSentinel ("ForgedCyberSentinel", "we", "us", or "our") is committed to protecting the privacy and personal data of individuals who interact with our website at https://www.forgedcybersentinel.com (the "Site") and our cybersecurity advisory and consultancy business.

This Privacy Policy explains how we collect, use, disclose, and safeguard personal data in accordance with Regulation (EU) 2016/679 (the "GDPR"), the Dutch GDPR Implementation Act (Uitvoeringswet Algemene verordening gegevensbescherming, "UAVG"), and other applicable data protection law.

What has changed in this version. ForgedCyberSentinel now offers its Services to individual consumers as well as to business clients. This Policy has been revised to describe how we handle the personal data of consumer clients, which is materially different in kind and sensitivity from the business contact data we previously processed. Sections 5A, 7A, 10, 13, and 21 are the ones most relevant to consumer clients.

This Privacy Policy applies to personal data processed by ForgedCyberSentinel in its capacity as a data controller. It does not apply to personal data that ForgedCyberSentinel may process as a data processor on behalf of a business client under a separate data processing agreement, which is instead governed by the terms of that agreement.

1. Introduction and Purpose

This Privacy Policy describes the types of personal data we collect, why we collect it, how we use and protect it, and the rights available to individuals under applicable data protection law.

It applies to: (a) visitors to the Site; (b) consumer clients — individuals who engage our Services for personal purposes, and prospective consumer clients who enquire about them; (c) prospective and existing business clients and their representatives; and (d) any other individual who corresponds with ForgedCyberSentinel.

Where a distinction matters, this Policy identifies whether a provision concerns consumer clients or business contacts.

2. Data Controller Identity and Contact Details

The data controller responsible for personal data processed in connection with the Site and ForgedCyberSentinel's business activities is:

  • ForgedCyberSentinel, a sole proprietorship (eenmanszaak) operating under Dutch law

  • Chamber of Commerce (KvK) number: 82033560

  • Email for privacy enquiries: Privacy@ForgedCyberSentinel.com

Individuals may exercise any of the rights described in Section 16 by contacting us at the email address above, free of charge.

3. Scope of this Policy

This Policy applies to personal data collected: (a) through the Site, including via contact and enquiry forms; (b) in the course of enquiries, consultations, and engagements with individual consumers; (c) in the course of pre-contractual discussions and proposal preparation with prospective business clients; (d) in the course of managing and administering existing engagements; and (e) through general business correspondence.

This Policy does not govern personal data belonging to a business client's own customers, employees, or end users that ForgedCyberSentinel might, in an exceptional and separately scoped engagement, process as a data processor on that client's behalf under Article 28 GDPR. Such processing is governed exclusively by the applicable data processing agreement.

4. Definitions

For the purposes of this Policy, terms such as "personal data", "processing", "controller", "processor", "data subject", and "third party" have the meanings given to them in Article 4 GDPR.

"Personal data" means any information relating to an identified or identifiable natural person. "Processing" means any operation performed on personal data, whether or not by automated means, such as collection, storage, use, disclosure, or erasure.

"Consumer client" means a natural person who engages our Services for purposes wholly or mainly outside that person's trade, business, craft, or profession.

5. Categories of Personal Data We Collect — General

Depending on your interaction with ForgedCyberSentinel, we may collect:

  • Identity and contact data: name, job title, employer or company name, email address, telephone number, and, for consumer clients, home or correspondence address.

  • Correspondence data: the content of enquiries, consultations, proposal discussions, and email or messaging correspondence with us.

  • Engagement administration data: contact details of the persons involved in an engagement, invoicing and billing details, and, where relevant to contracting, business registration details.

  • Payment data: the payment method used, the amount, the date, and a transaction reference. We do not store full card numbers or bank credentials; payments are handled by our payment or banking providers.

  • Technical and usage data: IP address, browser type, device information, pages visited, and similar data collected automatically via the Site and cookies, as described in our Cookie Policy.

  • Marketing preference data: your preferences regarding newsletters, updates, or marketing communications.

5A. Additional Categories Collected from Consumer Clients

To advise an individual on a cybersecurity problem, we usually need to know what happened. Depending on the matter, a consumer client may provide, and we may therefore process:

  • A description of the incident: what occurred, when, which accounts, devices, or services were affected, and what the individual has already done about it.

  • Account and device information: email addresses, usernames, account identifiers, device types and operating systems, router or network details, and screenshots or logs the individual chooses to send us.

  • Evidence supplied by the individual: message and email screenshots, phishing messages, ransom or extortion demands, transaction records, and police or bank reference numbers.

  • Financial loss information: amounts lost, the institutions involved, and the status of any claim or report.

  • Household context, where relevant: for example that a family member's device is on the same network.

We ask consumer clients to send us only what is necessary. In particular, we do not need and ask you not to send us passwords, PINs, one-time codes, recovery phrases, banking credentials, or full payment card numbers. If you send them anyway, we will delete them promptly and tell you.

Special category and criminal offence data. A cybersecurity incident affecting an individual can involve information that is sensitive under Article 9 GDPR (for example data revealing health, sexual life, or religious or political views appearing in leaked material) or that relates to criminal offences under Article 10 GDPR (for example fraud, extortion, stalking, harassment, or the non-consensual sharing of intimate images).

Where such information is unavoidably part of what you tell us, we process it only so far as strictly necessary to provide the Services, on the basis of your explicit consent (Article 9(2)(a) GDPR) or because it is necessary for the establishment, exercise, or defence of legal claims (Article 9(2)(f) GDPR). Processing of criminal offence data is carried out only within the limits permitted by Article 10 GDPR and Article 32 UAVG. We apply enhanced access restrictions to such data, keep it strictly separate from marketing systems, and will delete it at your request unless a legal obligation requires us to retain it.

6. Sources of Personal Data

We collect personal data directly from individuals who contact us via the Site, email, telephone, Fiverr, Upwork, LinkedIn, or other platforms, and from individuals acting on behalf of prospective or existing client organisations.

We may also receive limited business contact data from publicly available professional sources where reasonably necessary for legitimate B2B outreach. We do not carry out unsolicited outreach to private individuals on the basis of publicly available data.

7. Purposes and Legal Bases for Processing

We process personal data for the following purposes, on the corresponding legal bases under Article 6(1) GDPR:

  • To respond to enquiries and prepare proposals — legitimate interests (Article 6(1)(f)) in pursuing pre-contractual discussions, and/or steps necessary prior to entering into a contract at the individual's request (Article 6(1)(b)).

  • To perform, administer, and invoice an engagement — performance of a contract (Article 6(1)(b)); for business clients, performance of the contract with the client organisation together with legitimate interests in managing the relationship with individual representatives.

  • To comply with tax, accounting, and other statutory record-keeping obligations — legal obligation (Article 6(1)(c)).

  • To operate, secure, and improve the Site, including through analytics cookies — consent (Article 6(1)(a)) where required for non-essential cookies, and legitimate interests for strictly necessary cookies.

  • To handle complaints and comply with consumer protection law, including the right of withdrawal — legal obligation (Article 6(1)(c)) and performance of a contract (Article 6(1)(b)).

  • To send marketing or informational communications — see Section 21.

  • To establish, exercise, or defend legal claims — legitimate interests (Article 6(1)(f)).

7A. Consumer Clients — Specific Points on Legal Basis

Where you are a consumer client, the primary legal basis for processing the information you give us about your incident is performance of the contract between you and us (Article 6(1)(b) GDPR), together with your explicit consent where the information falls within Article 9 GDPR.

We do not rely on legitimate interests to process the substance of a consumer client's incident information, and we do not use it for any purpose other than delivering the Services you asked for, meeting our legal obligations, and defending or bringing legal claims.

Where processing is based on consent, you may withdraw that consent at any time, free of charge, with effect for the future. Withdrawing consent does not affect the lawfulness of processing carried out before withdrawal. If withdrawing consent means we can no longer deliver the Services, we will tell you and refund anything paid for work not done.

8. Business Contact and Correspondence Data

Most personal data we process about business clients consists of business contact details of individuals acting in a professional capacity. We process such data solely to establish, manage, and administer the business relationship.

We retain correspondence with prospective and existing clients as necessary to document the scope of engagements, respond to future queries, and satisfy our legal and contractual obligations, subject to the retention periods in Section 13.

9. Cookies and Similar Tracking Technologies

The Site uses cookies and similar tracking technologies to operate correctly, remember preferences, and, where consented to, understand aggregate usage patterns. Full details are set out in our Cookie Policy, available at https://www.forgedcybersentinel.com, which forms part of this Privacy Policy by reference.

Non-essential cookies (such as analytics cookies) are placed only with the visitor's prior consent, obtained via our cookie consent banner, in accordance with Article 11.7a of the Dutch Telecommunications Act (Telecommunicatiewet) and the EU ePrivacy framework. Consent is requested from every visitor on the same terms, whether the visitor is a business contact or a private individual.

10. Processing of Client Customer or End-User Data

Business clients. Consistent with the advisory and consultancy nature of the Services, ForgedCyberSentinel does not, in the ordinary course of business, collect, access, host, or otherwise process personal data belonging to the customers, employees, or end users of its business clients. Where a specific engagement is scoped to require such processing, it will only proceed under a dedicated, signed Article 28 GDPR data processing agreement entered into before that processing begins.

Consumer clients. Where the client is an individual, we act as an independent data controller in respect of all personal data we process about that individual. We are not that individual's processor, and no data processing agreement is required or entered into.

Third parties mentioned by a consumer client. Information a consumer client gives us may incidentally identify other people — a family member sharing a device, a person who sent a phishing message, or a suspected perpetrator. We process such information only so far as necessary to advise our client, do not use it for any other purpose, do not attempt to identify, locate, profile, or investigate any individual, and apply the exemption in Article 14(5) GDPR where providing notice to those individuals would be impossible or involve disproportionate effort. We will not assist any person to identify, locate, monitor, or take action against another individual.

11. Data Sharing and Third-Party Recipients

We do not sell personal data. We may share personal data with the following categories of recipients, strictly as necessary for the purposes described in this Policy:

  • IT and hosting service providers who host the Site and store correspondence and records, acting as our data processors under written data processing agreements.

  • Email, calendar, and communication service providers used to conduct correspondence.

  • Payment and banking service providers, for the purpose of taking and refunding payments.

  • Accounting, invoicing, and professional advisory service providers, where necessary for tax, legal, or financial administration.

  • Freelance marketplace platforms (such as Fiverr and Upwork), to the extent personal data is exchanged through those platforms as part of an engagement initiated there, subject to those platforms' own privacy terms.

  • Competent authorities, courts, or regulators, where disclosure is required by Applicable Law or to establish, exercise, or defend legal claims.

  • Any recipient the individual expressly asks us to share with — for example their own bank, insurer, lawyer, or the police.

We will not report a consumer client's incident to the police or to any other authority without that client's instruction, unless we are legally required to do so or there is a serious and imminent risk to a person's life or safety.

All third-party processors are bound by written agreements imposing data protection obligations consistent with Article 28 GDPR, including confidentiality, security, and sub-processing restrictions.

12. International Data Transfers

Where personal data is transferred outside the European Economic Area (EEA), including to service providers located in the United States or other third countries, ForgedCyberSentinel ensures such transfers are carried out in accordance with Chapter V GDPR.

Depending on the recipient, this may be achieved through: (a) an applicable European Commission adequacy decision under Article 45 GDPR; (b) the EU-U.S. Data Privacy Framework, where the recipient is self-certified with the U.S. Department of Commerce; or (c) the European Commission's Standard Contractual Clauses under Article 46 GDPR, together with a transfer impact assessment where appropriate.

The EU-U.S. Data Privacy Framework has been the subject of legal challenge before the Court of Justice of the European Union. We monitor developments and will, where necessary, implement Standard Contractual Clauses as a supplementary or fallback transfer mechanism to maintain continuity of appropriate safeguards.

Sensitive consumer incident data is, wherever reasonably practicable, stored and processed within the EEA. Where a transfer outside the EEA is unavoidable, we apply the safeguards described above and will tell an individual, on request, which countries are involved and on what basis.

13. Data Retention

We retain personal data only for as long as necessary to fulfil the purposes for which it was collected, including satisfying any legal, accounting, or reporting requirements.

  • Enquiry and correspondence data relating to prospective clients who do not proceed: up to twenty-four (24) months from last contact, unless deletion is requested earlier. For prospective consumer clients, this is reduced to twelve (12) months.

  • Engagement and invoicing records: retained for the statutory Dutch tax record-keeping period of seven (7) years (Article 52, General Tax Act (Algemene wet inzake rijksbelastingen)), or longer where required to defend potential legal claims within applicable limitation periods.

  • Consumer incident content — the substantive detail, evidence, screenshots, and logs a consumer client provides: retained for twelve (12) months after the engagement ends, and then deleted, unless the individual asks us to delete it sooner (in which case we will do so promptly) or asks us to keep it longer, or unless it is needed for an ongoing legal claim. The minimum invoice and contract record required for tax purposes is kept separately for the statutory seven-year period and does not include the incident detail.

  • Special category and criminal offence data: deleted as soon as it is no longer needed for the engagement, and in any event within twelve (12) months of the engagement ending, unless retention is necessary for a legal claim.

  • Records relating to the exercise of a right of withdrawal or a complaint: retained for the period necessary to demonstrate compliance with consumer protection law, and in any event not more than five (5) years.

  • Cookie and analytics data: as described in our Cookie Policy.

  • Marketing contact preferences: retained until consent is withdrawn or an objection is made, and reasonably thereafter to record the fact of withdrawal.

At the end of the applicable retention period, personal data is securely deleted or anonymised.

14. Data Security Measures

ForgedCyberSentinel implements appropriate technical and organisational measures designed to protect personal data against unauthorised access, alteration, disclosure, or destruction, proportionate to the nature and sensitivity of the personal data processed. These include access controls, encryption of data in transit and at rest where technically available, multi-factor authentication on business accounts, restriction of access on a need-to-know basis, and confidentiality obligations imposed on any third-party processor.

Because we now process sensitive incident information about individuals, our measures for that category are calibrated accordingly, including separate storage, restricted access, and shorter retention as described in Section 13.

Client-facing cybersecurity Services provided to clients regarding their own systems and data are governed separately by the applicable engagement documents and are not a representation of the security measures ForgedCyberSentinel applies to its own systems.

15. Personal Data Breach Notification

In the event of a personal data breach affecting personal data for which ForgedCyberSentinel acts as controller, we will assess the risk to affected individuals and, where required under Articles 33 and 34 GDPR, notify the Dutch Data Protection Authority (Autoriteit Persoonsgegevens) without undue delay and, where feasible, within seventy-two (72) hours of becoming aware of the breach, and will notify affected individuals directly where the breach is likely to result in a high risk to their rights and freedoms.

Given the sensitivity of consumer incident data, we will notify an affected consumer client of any breach involving their incident information, in plain language and without undue delay, even where notification is not strictly required under Article 34 GDPR.

16. Data Subject Rights

Subject to the conditions and exceptions set out in the GDPR, individuals whose personal data we process as controller have the right to:

  • Access their personal data and receive a copy of it (Article 15 GDPR).

  • Request rectification of inaccurate or incomplete personal data (Article 16 GDPR).

  • Request erasure of personal data in certain circumstances (Article 17 GDPR).

  • Request restriction of processing in certain circumstances (Article 18 GDPR).

  • Object to processing based on legitimate interests, including for direct marketing purposes (Article 21 GDPR).

  • Request data portability, where processing is based on consent or contract and carried out by automated means (Article 20 GDPR).

  • Not be subject to a decision based solely on automated processing, including profiling, which produces legal effects or similarly significantly affects them (Article 22 GDPR); we do not engage in such automated decision-making, as noted in Section 19.

To exercise any of these rights, individuals may contact us using the details in Section 2, free of charge. We will respond within one (1) month of a verified request, extendable by a further two (2) months for complex requests, as permitted under Article 12(3) GDPR.

We will verify identity proportionately and will not demand identity documents where the request can reasonably be verified another way — for example where it comes from the email address used throughout the engagement.

17. Right to Withdraw Consent

Where processing is based on consent (for example, non-essential cookies, certain marketing communications, or special category incident data), individuals may withdraw consent at any time, free of charge, with effect for future processing. Withdrawal does not affect the lawfulness of processing carried out before withdrawal, and it must be as easy to withdraw consent as it was to give it.

Consent for cookies can be withdrawn or adjusted at any time via the cookie preference mechanism described in our Cookie Policy. Marketing communications include an unsubscribe mechanism in every message.

18. Right to Lodge a Complaint

Without prejudice to any other administrative or judicial remedy, individuals have the right to lodge a complaint with a supervisory authority, in particular in the EU Member State of their habitual residence, place of work, or the place of the alleged infringement.

The Dutch supervisory authority is the Autoriteit Persoonsgegevens (Dutch Data Protection Authority), Bezuidenhoutseweg 30, 2594 AV The Hague, the Netherlands (https://www.autoriteitpersoonsgegevens.nl). Individuals resident elsewhere in the EU may complain to their own national supervisory authority.

19. Automated Decision-Making and Profiling

ForgedCyberSentinel does not use personal data for automated decision-making, including profiling, that produces legal effects concerning individuals or similarly significantly affects them. We do not score, rank, or profile consumer clients, and we do not use their incident data to train any automated or machine-learning system.

20. Children's Privacy

Our Services are offered only to individuals aged eighteen (18) or over, and we do not knowingly contract with minors.

We do not knowingly collect personal data from children. In the Netherlands, the age below which parental consent is required for information society services offered directly to a child is sixteen (16), pursuant to Article 8 GDPR and Article 5 UAVG. If we become aware that we have inadvertently collected personal data from a child, we will take reasonable steps to delete it promptly.

Where a parent or guardian engages our Services in connection with an incident affecting their child, we process the child's data on the parent's or guardian's instruction and with their consent, restrict it to what is strictly necessary, and delete it as soon as the engagement ends unless asked to keep it.

21. Marketing Communications

Business contacts. Where permitted under Applicable Law, we may send business-related communications, updates, or informational content to existing and prospective business contacts, in accordance with Article 11.7 of the Dutch Telecommunications Act governing unsolicited electronic communications to legal entities, with an opt-out in every message.

Individuals. We will not send marketing communications to a private individual without that person's prior, freely given, specific, informed, and unambiguous opt-in consent, as required by Article 11.7 of the Dutch Telecommunications Act for natural persons. The only exception is the limited "soft opt-in": where we have obtained an individual's contact details in the course of providing Services to them, we may send information about our own similar Services, and we will give a clear and free opportunity to object both at the point of collection and in every subsequent message.

We do not use a consumer client's incident information to target, segment, or personalise marketing, and we do not share consumer contact data with any third party for marketing purposes.

Opting out of marketing does not affect service-related or contractual communications relating to an active engagement.

22. Third-Party Links

The Site may contain links to third-party websites, including platforms such as Fiverr or Upwork, or professional networking sites. This Privacy Policy does not apply to such third-party websites, and we encourage individuals to review the privacy policies of any third-party website they visit.

23. Changes to this Privacy Policy

We may update this Privacy Policy from time to time to reflect changes in our practices, the Services, or Applicable Law. The updated version will be posted on the Site with a revised effective date. Material changes will be communicated to active clients and, where feasible, to affected individuals by appropriate means, before the change takes effect.

24. Data Protection Contact

Given the current scale of ForgedCyberSentinel's operations as a sole proprietorship, a formal Data Protection Officer has not been appointed. Our assessment is that appointment is not mandatory under Article 37 GDPR, because our core activities do not consist of processing operations requiring regular and systematic monitoring of data subjects on a large scale, nor of large-scale processing of special categories of data.

We will keep this assessment under active review as the consumer side of the business grows, since the volume and sensitivity of consumer incident data are directly relevant to the Article 37(1)(c) threshold, and we will appoint a Data Protection Officer if that threshold is met.

All privacy-related enquiries should be directed to the contact point in Section 2, which is our designated privacy contact.

25. Contact Information

For any questions, requests, or concerns regarding this Privacy Policy or ForgedCyberSentinel's data processing practices, please contact us using the details in Section 2.

DATA PROTECTION INQUIRIES

Email: Privacy@ForgedCyberSentinel.com