LEGAL / DATA PROTECTION
Privacy Policy
Effective Date: 1 July 2026
ForgedCyberSentinel ("ForgedCyberSentinel", "we", "us", or "our") is committed to protecting the privacy and personal data of individuals who interact with our website at https://www.forgedcybersentinel.com (the "Site") and our cybersecurity advisory and consultancy business. This Privacy Policy explains how we collect, use, disclose, and safeguard personal data in accordance with the GDPR, the Dutch GDPR Implementation Act (UAVG), and other applicable data protection law.
1. Information We Collect
We collect personal data through several channels, limited in each case to what is necessary for the relevant purpose. Data you provide directly: when you contact us, request a consultation, or engage our services, we collect contact details (name, email address, telephone number), company information (organization name, role, sector), and the contents of your communications with us.
Data collected automatically: when you visit the Site, we collect technical information including your IP address, browser type, device and operating system details, and usage and analytics data gathered through cookies and similar technologies.
Data collected during engagements: in the course of delivering security assessments and advisory work, we may process technical findings and related information. Such data is strictly limited to what is required for the agreed assessment scope, handled under confidentiality, and never retained beyond the engagement's defined purpose.
2. How We Use Your Information
We use the personal data we collect to: provide, deliver, and administer our consultancy and advisory services; respond to inquiries and requests for consultation; establish and manage client relationships and contractual arrangements; operate, maintain, and improve the Site and its functionality; comply with our legal, regulatory, and professional obligations; and send service-related communications, such as scheduling, deliverables, and important notices. We do not use your data for automated decision-making or profiling.
3. Legal Basis for Processing
We process personal data only where a lawful basis under Article 6 of the GDPR applies. Depending on the context, we rely on: your consent, for example where you agree to non-essential cookies or optional communications; contractual necessity, where processing is required to perform a consultancy engagement or take steps at your request prior to entering into a contract; our legitimate interests, such as securing and improving our Site and managing client relationships, provided these are not overridden by your rights; and compliance with a legal obligation to which we are subject.
4. Data Sharing and Disclosure
We do not sell, rent, or trade your personal data. We share personal data only where necessary and under appropriate safeguards. This may include vetted subprocessors and service providers — such as secure hosting, communications, and analytics providers — who act on our behalf under binding confidentiality and data processing agreements that restrict their use of the data to our documented instructions.
We may also disclose personal data where required to do so by law, regulation, legal process, or an enforceable governmental request, or where necessary to protect our rights, safety, or the integrity of our services.
5. Data Retention
We retain personal data only for as long as necessary to fulfil the purposes described in this Policy, including to meet the requirements of an active or prospective engagement, or for as long as required by applicable law, regulatory obligations, or contractual commitments. When personal data is no longer required, we securely delete or irreversibly anonymize it in line with our data minimization principles.
6. Your Rights Under GDPR
Subject to applicable law, you have the following rights in relation to your personal data:
the right to access the personal data we hold about you;
the right to rectify inaccurate or incomplete data;
the right to erasure of your data in certain circumstances;
the right to restrict processing of your data;
the right to data portability;
the right to object to processing based on legitimate interests; and
the right to lodge a complaint with the Dutch Data Protection Authority (Autoriteit Persoonsgegevens).
To exercise any of these rights, please contact us using the details set out below. We will respond within the timeframes required by applicable law.
7. Cookies and Tracking Technologies
We use cookies and similar technologies to enable essential Site functionality and to understand how the Site is used through aggregated analytics. Essential cookies are necessary for the Site to operate; analytics and other non-essential cookies are used only with your consent. You can manage or withdraw your cookie preferences at any time through your browser settings, which allow you to block or delete cookies. Disabling certain cookies may affect the functionality of the Site.
8. Data Security
As a cybersecurity practice, the protection of data is central to how we operate. We implement appropriate technical and organizational measures to safeguard personal data against unauthorized access, alteration, disclosure, or destruction. These measures include encryption in transit and at rest, strict role-based access controls and least-privilege principles, network segmentation, monitoring, and binding confidentiality agreements with all personnel and subprocessors. While no method of transmission or storage is completely secure, we continually review and strengthen our controls in line with recognized industry standards.
9. International Data Transfers
We primarily process personal data within the European Economic Area (EEA). Where personal data is transferred to a country outside the EEA, we ensure that appropriate safeguards are in place as required by the GDPR — such as the European Commission's Standard Contractual Clauses (SCCs) and, where relevant, supplementary technical and organizational measures — so that your data continues to receive an equivalent level of protection.
10. Changes to This Policy
We may update this Privacy Policy from time to time to reflect changes in our practices, technology, legal requirements, or other operational factors. When we make material changes, we will revise the effective date shown at the top of this Policy, and, where required by law, provide additional notice. We encourage you to review this Policy periodically to stay informed about how we protect your personal data.
12. Children's Privacy
Our Site and services are intended for organizations and professional clients, and are not directed at children. We do not knowingly collect personal data from individuals under the age of 16. If we become aware that we have inadvertently collected personal data from a child without appropriate parental or guardian consent, we will delete that data promptly and securely. If you believe a child has provided us with personal data, please contact us using the details set out below so we can take appropriate action.
13. Third-Party Links and Services
The Site may contain links to third-party websites, tools, or resources that are not operated or controlled by us. This Privacy Policy applies only to our own processing activities and does not cover the practices of any third party. We are not responsible for the content, security, or privacy practices of external sites, and we encourage you to review the privacy notices of any third-party service you access. Where we integrate reputable third-party tools into our services, we assess their handling of personal data as part of our vendor due diligence before use.
14. Marketing Communications and Opt-Out
We send marketing communications only where we have a lawful basis to do so, and only in relation to our own consultancy and advisory services. Where consent is required, we will obtain it before contacting you, and we will never share your details with third parties for their own marketing purposes.
You may withdraw your consent or opt out of marketing communications at any time by using the unsubscribe link included in each message or by contacting us directly. Opting out of marketing does not affect service-related communications that are necessary to administer an active engagement, such as scheduling, deliverables, or important notices.
15. Automated Decision-Making and Profiling
We do not subject you to decisions based solely on automated processing, including profiling, that produce legal effects concerning you or similarly significantly affect you. Any analysis we perform in the course of security assessments is conducted under human oversight by qualified personnel and is limited to the agreed engagement scope. Where analytics are used to understand aggregated Site usage, they do not involve individual profiling and are not used to make decisions about identifiable individuals.
16. Data Breach Notification Procedures
As a cybersecurity practice, incident response and breach management are core competencies embedded in our own operations. We maintain documented procedures for detecting, assessing, containing, and remediating personal data breaches, and we regularly test these procedures as part of our internal security program.
In the event of a personal data breach that is likely to result in a risk to the rights and freedoms of individuals, we will notify the Dutch Data Protection Authority (Autoriteit Persoonsgegevens) without undue delay and, where feasible, within 72 hours of becoming aware of it. Where the breach is likely to result in a high risk to affected individuals, we will also notify them directly without undue delay, in accordance with the GDPR.
17. Confidentiality of Engagement Data
Data generated or accessed during security assessments, penetration tests, and advisory engagements is treated as strictly confidential. Such data — including technical findings, vulnerability details, and system information — is processed only for the agreed assessment scope, restricted to authorized personnel bound by confidentiality obligations, and never disclosed to third parties except as required to deliver the engagement or as compelled by law. Engagement data is segregated, access-controlled, and securely destroyed or returned once the engagement's defined purpose has been fulfilled, in line with the terms of the relevant contract and our data minimization principles.
18. Anonymization and Aggregated Data
We may anonymize or aggregate personal data so that it no longer identifies you, either directly or indirectly. Anonymized and aggregated data — such as statistical trends, threat intelligence patterns, and service performance metrics — may be used to improve our methodologies, research emerging risks, and enhance the quality of our services. Because such data cannot be attributed to an identifiable individual, it falls outside the scope of the GDPR and this Policy. We apply recognized techniques to ensure that anonymization is irreversible and that re-identification is not reasonably possible.
19. Employee and Personnel Access Controls
Access to personal data within our organization is granted strictly on a need-to-know basis and governed by least-privilege principles. All personnel are subject to binding confidentiality agreements, undergo appropriate vetting, and receive regular data protection and security awareness training. Access rights are role-based, logged, and periodically reviewed, and are promptly revoked when no longer required or when an individual's role changes. These controls ensure that personal data is handled only by authorized individuals for legitimate, documented purposes.
20. Subprocessors and Vendor Due Diligence
Where we engage subprocessors or service providers to support our operations — for example secure hosting, communications, or analytics providers — we conduct due diligence to assess their security posture and data protection practices before onboarding them. Each subprocessor is bound by a written data processing agreement that restricts their use of personal data to our documented instructions and imposes confidentiality and security obligations consistent with the GDPR. We maintain oversight of our subprocessors and periodically reassess them to ensure they continue to meet our standards.
21. Data Protection Officer
We have appointed a data protection function responsible for overseeing compliance with this Policy and applicable data protection law, advising on our processing activities, and serving as a point of contact for data subjects and supervisory authorities. If you have questions about how we handle your personal data or wish to raise a concern, you may contact our data protection team using the details set out in the Contact section below.
22. Data Subject Request Verification Process
To protect your personal data and prevent unauthorized disclosure, we verify the identity of any individual making a data subject request before acting on it. We may ask you to provide sufficient information to confirm your identity and to help us locate the relevant data. We will only request information that is proportionate and necessary for verification, and any details provided for this purpose are used solely to process your request. Where we are unable to verify your identity, we may decline to act on the request as permitted by applicable law, and we respond to verified requests within the timeframes required by the GDPR.
23. Cross-Border Engagement Data Handling
Certain engagements may involve clients, systems, or infrastructure located outside the European Economic Area. Where the delivery of an engagement requires personal or technical data to be processed across borders, we implement appropriate safeguards — including Standard Contractual Clauses, encryption, and access restrictions — to ensure that the data continues to receive an equivalent level of protection. Cross-border handling is limited to what is strictly necessary for the agreed scope, documented within the engagement contract, and subject to the same confidentiality and security controls that apply to all engagement data.
24. Severability and Governing Law
This Privacy Policy is governed by and construed in accordance with the laws of the Netherlands, without regard to conflict-of-law principles. If any provision of this Policy is found to be invalid, unlawful, or unenforceable by a competent authority, that provision will be severed to the minimum extent necessary, and the remaining provisions will continue in full force and effect. Any disputes arising in connection with this Policy or our processing of personal data are subject to the jurisdiction of the competent Dutch courts, without prejudice to your right to lodge a complaint with the Dutch Data Protection Authority (Autoriteit Persoonsgegevens).
25. Contact Us
If you have any questions about this Privacy Policy, wish to exercise your data protection rights, or have concerns about how we handle your personal data, please contact our data protection team using the details below.
DATA PROTECTION INQUIRIES
privacy@forgedcybersentinel.com
ForgedCyberSentinel, Amsterdam, The Netherlands