Privacy policy
Draft, to be reviewed by a lawyer before launch.
to verify is the controller for the personal data described here. This policy explains what we hold, why, for how long, and who else sees it. Last updated 2026-08-31.
What we hold
- Account data: name, email address, password hash, two factor secret and recovery codes, sessions.
- Organisation data: company name, country, authorised representative, notifier and backup assignments.
- Product data: the SBOMs you upload and the components in them, findings, incidents and dossier content.
- Audit data: who did what and when inside an incident, as an append only trail with a hash chain.
- Billing data: customer and subscription identifiers from Stripe. Card data never reaches us.
- Marketing data: the address and answers of a free scope check, and the content of a contact request.
Why we hold it, and on what basis
- To deliver the service you subscribed to: performance of the contract.
- To alert your notifier and to keep the audit trail intact: performance of the contract and our legitimate interest in a defensible record.
- To send the result of a free scope check and to keep you informed after it: your consent, which you can withdraw in every message.
- To answer a contact or demo request: our legitimate interest in answering the person who wrote to us.
- To bill you and to keep our books: performance of the contract and a legal obligation.
How long we keep it
- Incident and audit data: 10 years, because it is evidence of what you knew and when. "to verify" against the CRA documentation duties.
- SBOMs, components and vault documents: while your account exists, and 30 days after termination.
- Backups: 30 daily and 12 monthly copies, encrypted, in the EU.
- Marketing leads: until you ask us to remove them, and at most two years after the last contact.
- Invoices: as long as tax law requires.
Who else sees it
Only the subprocessors named in the data processing agreement, and only for the purpose named there. We do not sell data and we do not use it to train models.
Stripe processes billing data outside the EU. That transfer is named in the data processing agreement, and the transfer mechanism is "to verify" before launch.
Where it lives
The application, the database and the backups run on EU infrastructure. The site loads no external fonts, scripts or trackers, so opening a page sends no request outside our own servers.
Your rights
You can ask for access, correction, deletion, restriction, objection and a copy of your data in a portable form. Write to albert@beltar.nl and we handle it manually within one month. You can complain to the Autoriteit Persoonsgegevens if you think we got it wrong.
Security
- TLS on every connection, passwords hashed with the framework standard hasher.
- Two factor authentication required for administrators and notifiers.
- Rate limiting on authentication and public endpoints, revocable per product API tokens.
- Append only audit tables and a hash chain per incident, so tampering is detectable.
- No customer data in application logs.
Contact
to verify, to verify, the Netherlands. albert@beltar.nl.
to verify, to verify, the Netherlands. albert@beltar.nl.