Open Security Open Security Back to site

Privacy Policy

Last updated: April 9, 2026

Open Security is run by me, Alex Chamberlain. I provide hands-on cybersecurity monitoring and management for small and medium businesses. You can reach me at [email protected].

ControllerOpen Security — Alex Chamberlain
Email[email protected]
Websiteopen-security.ai
KvK98112821

Website visitors

DataPurposeLegal basis
IP address, browser type, pages visitedWebsite functionality and securityLegitimate interest (Art. 6(1)(f))
Cloudflare analytics (anonymized)Understanding website usageLegitimate interest

I do not use cookies for tracking or advertising. Cloudflare may set strictly necessary cookies for security (DDoS protection, bot detection).

Free Security Scan users

DataPurposeLegal basis
Domain name scannedPerforming the scanLegitimate interest
Email address (if provided for report)Sending the scan reportConsent (Art. 6(1)(a))
Scan resultsDisplaying results, generating reportLegitimate interest

Scan results are not stored permanently. Email addresses provided for reports may be used as a potential business lead. You may request deletion at any time.

Contact form and email

DataPurposeLegal basis
Name, email, message contentResponding to your inquiryLegitimate interest / pre-contractual measures
Phone number (if provided)Following up on your inquiryLegitimate interest

Clients (managed security services)

For clients using my managed security services, I process additional data as described in the Data Processing Agreement (DPA) that is part of the service contract. In that context, you are the Controller and I am the Processor.

DataPurposeLegal basis
Contact person name, email, phoneService delivery and communicationPerformance of contract (Art. 6(1)(b))
Company name, address, KvK numberContract and invoicingPerformance of contract / legal obligation
Payment informationProcessing payments via StripePerformance of contract
Endpoint telemetry (logs, alerts, events)Security monitoring and threat detectionPerformance of contract (governed by DPA)

Payment processing

Payments are processed by Stripe, Inc. When you make a payment, your payment data (credit card, bank details) is handled directly by Stripe. I never see or store your full payment details. I receive a transaction confirmation and basic billing information. See Stripe's privacy policy.

  • Delivering services — security scans, managed monitoring, reports
  • Communication — responding to inquiries, sending security alerts
  • Billing and administration — invoicing, contract management
  • Legal compliance — tax, bookkeeping, data breach notification
  • Security — protecting my website and platform from abuse
  • Service improvement — understanding how my services are used

I do not:

  • Sell personal data to third parties
  • Use personal data for advertising or profiling
  • Send unsolicited marketing emails
  • Make automated decisions with legal effects concerning you

I share personal data only with the following parties, and only to the extent necessary:

RecipientPurposeLocation
Contabo GmbHInfrastructure hostingGermany (EU)
Cloudflare, Inc.DDoS protection, CDNEU edge / US (DPF certified)
Stripe, Inc.Payment processingEU / US (DPF certified)
Bitdefender S.R.L.Endpoint protection (when active)Romania (EU)
AccountantTax and financial administrationNetherlands

I do not share data with any other third parties unless required by law or with your explicit consent.

All primary data processing takes place within the European Economic Area (EEA), specifically in Germany (Contabo). Where data is transferred to the United States (Cloudflare, Stripe), appropriate safeguards are in place:

  • EU-U.S. Data Privacy Framework certification
  • Standard Contractual Clauses (SCCs) approved by the European Commission

I regularly verify that these safeguards remain in effect.

Data categoryRetention period
Website access logs90 days
Free scan resultsNot stored (real-time only)
Email addresses from scan reports12 months (or upon request)
Contact form submissions12 months after last contact
Client contract dataDuration of contract + 7 years (Dutch tax obligation)
Invoices and financial records7 years (fiscale bewaarplicht)
Client security data (as Processor)As specified in the DPA (typically 90 days)

After the retention period expires, I delete the data or anonymize it so it can no longer be linked to you.

You have the following rights regarding your personal data:

Right of access (Article 15)

Request a copy of the personal data I hold about you.

Right to rectification (Article 16)

Request correction of inaccurate or incomplete data.

Right to erasure (Article 17)

Request deletion of your data, unless I have a legal obligation to retain it.

Right to restriction (Article 18)

Request that I restrict the processing of your data in certain circumstances.

Right to data portability (Article 20)

Receive your data in a structured, commonly used, machine-readable format.

Right to object (Article 21)

Object to processing based on legitimate interest. I will stop unless I have compelling grounds that override your interests.

Right to withdraw consent (Article 7(3))

Where processing is based on consent, withdraw it at any time without affecting prior lawfulness.

How to exercise your rights: Send an email to [email protected]. I will respond within 30 days. I may ask you to verify your identity before processing the request.

If you believe your data protection rights have been violated, you have the right to lodge a complaint with the Dutch Data Protection Authority:

AuthorityAutoriteit Persoonsgegevens
AddressPostbus 93374, 2509 AJ Den Haag
Websiteautoriteitpersoonsgegevens.nl

I take the security of your data seriously. Measures include:

  • Encryption of data in transit (TLS 1.2+); data at rest protected by strict access controls
  • Access control with multi-factor authentication where available
  • Cloudflare Zero Trust for application access
  • Fail2ban for brute-force protection
  • Regular security updates and patching
  • Infrastructure hosted exclusively in the EU (Contabo, Germany)
  • Logical data isolation between clients

No method of transmission over the internet is 100% secure. While I use commercially acceptable means to protect your data, I cannot guarantee absolute security.

This website only uses essential cookies — specifically Cloudflare security cookies required for the site to function. I do not use any analytics, tracking, or marketing cookies.

My services are not directed at children under the age of 16. I do not knowingly collect personal data from children. If you believe I have inadvertently collected data from a child, please contact me and I will delete it promptly.

I may update this Privacy Policy from time to time. When I make material changes, I will update the "Last updated" date at the top. For clients, I will notify you via email if changes affect the processing of your data.

Questions about this policy?
Email [email protected] — I'm happy to help.