Privacy Policy
Last updated: April 9, 2026
Open Security is run by me, Alex Chamberlain. I provide hands-on cybersecurity monitoring and management for small and medium businesses. You can reach me at [email protected].
| Controller | Open Security — Alex Chamberlain |
| [email protected] | |
| Website | open-security.ai |
| KvK | 98112821 |
Website visitors
| Data | Purpose | Legal basis |
|---|---|---|
| IP address, browser type, pages visited | Website functionality and security | Legitimate interest (Art. 6(1)(f)) |
| Cloudflare analytics (anonymized) | Understanding website usage | Legitimate interest |
I do not use cookies for tracking or advertising. Cloudflare may set strictly necessary cookies for security (DDoS protection, bot detection).
Free Security Scan users
| Data | Purpose | Legal basis |
|---|---|---|
| Domain name scanned | Performing the scan | Legitimate interest |
| Email address (if provided for report) | Sending the scan report | Consent (Art. 6(1)(a)) |
| Scan results | Displaying results, generating report | Legitimate interest |
Scan results are not stored permanently. Email addresses provided for reports may be used as a potential business lead. You may request deletion at any time.
Contact form and email
| Data | Purpose | Legal basis |
|---|---|---|
| Name, email, message content | Responding to your inquiry | Legitimate interest / pre-contractual measures |
| Phone number (if provided) | Following up on your inquiry | Legitimate interest |
Clients (managed security services)
For clients using my managed security services, I process additional data as described in the Data Processing Agreement (DPA) that is part of the service contract. In that context, you are the Controller and I am the Processor.
| Data | Purpose | Legal basis |
|---|---|---|
| Contact person name, email, phone | Service delivery and communication | Performance of contract (Art. 6(1)(b)) |
| Company name, address, KvK number | Contract and invoicing | Performance of contract / legal obligation |
| Payment information | Processing payments via Stripe | Performance of contract |
| Endpoint telemetry (logs, alerts, events) | Security monitoring and threat detection | Performance of contract (governed by DPA) |
Payment processing
Payments are processed by Stripe, Inc. When you make a payment, your payment data (credit card, bank details) is handled directly by Stripe. I never see or store your full payment details. I receive a transaction confirmation and basic billing information. See Stripe's privacy policy.
- Delivering services — security scans, managed monitoring, reports
- Communication — responding to inquiries, sending security alerts
- Billing and administration — invoicing, contract management
- Legal compliance — tax, bookkeeping, data breach notification
- Security — protecting my website and platform from abuse
- Service improvement — understanding how my services are used
I do not:
- Sell personal data to third parties
- Use personal data for advertising or profiling
- Send unsolicited marketing emails
- Make automated decisions with legal effects concerning you
I share personal data only with the following parties, and only to the extent necessary:
| Recipient | Purpose | Location |
|---|---|---|
| Contabo GmbH | Infrastructure hosting | Germany (EU) |
| Cloudflare, Inc. | DDoS protection, CDN | EU edge / US (DPF certified) |
| Stripe, Inc. | Payment processing | EU / US (DPF certified) |
| Bitdefender S.R.L. | Endpoint protection (when active) | Romania (EU) |
| Accountant | Tax and financial administration | Netherlands |
I do not share data with any other third parties unless required by law or with your explicit consent.
All primary data processing takes place within the European Economic Area (EEA), specifically in Germany (Contabo). Where data is transferred to the United States (Cloudflare, Stripe), appropriate safeguards are in place:
- EU-U.S. Data Privacy Framework certification
- Standard Contractual Clauses (SCCs) approved by the European Commission
I regularly verify that these safeguards remain in effect.
| Data category | Retention period |
|---|---|
| Website access logs | 90 days |
| Free scan results | Not stored (real-time only) |
| Email addresses from scan reports | 12 months (or upon request) |
| Contact form submissions | 12 months after last contact |
| Client contract data | Duration of contract + 7 years (Dutch tax obligation) |
| Invoices and financial records | 7 years (fiscale bewaarplicht) |
| Client security data (as Processor) | As specified in the DPA (typically 90 days) |
After the retention period expires, I delete the data or anonymize it so it can no longer be linked to you.
You have the following rights regarding your personal data:
Request a copy of the personal data I hold about you.
Request correction of inaccurate or incomplete data.
Request deletion of your data, unless I have a legal obligation to retain it.
Request that I restrict the processing of your data in certain circumstances.
Receive your data in a structured, commonly used, machine-readable format.
Object to processing based on legitimate interest. I will stop unless I have compelling grounds that override your interests.
Where processing is based on consent, withdraw it at any time without affecting prior lawfulness.
How to exercise your rights: Send an email to [email protected]. I will respond within 30 days. I may ask you to verify your identity before processing the request.
If you believe your data protection rights have been violated, you have the right to lodge a complaint with the Dutch Data Protection Authority:
| Authority | Autoriteit Persoonsgegevens |
| Address | Postbus 93374, 2509 AJ Den Haag |
| Website | autoriteitpersoonsgegevens.nl |
I take the security of your data seriously. Measures include:
- Encryption of data in transit (TLS 1.2+); data at rest protected by strict access controls
- Access control with multi-factor authentication where available
- Cloudflare Zero Trust for application access
- Fail2ban for brute-force protection
- Regular security updates and patching
- Infrastructure hosted exclusively in the EU (Contabo, Germany)
- Logical data isolation between clients
No method of transmission over the internet is 100% secure. While I use commercially acceptable means to protect your data, I cannot guarantee absolute security.
This website only uses essential cookies — specifically Cloudflare security cookies required for the site to function. I do not use any analytics, tracking, or marketing cookies.
My services are not directed at children under the age of 16. I do not knowingly collect personal data from children. If you believe I have inadvertently collected data from a child, please contact me and I will delete it promptly.
I may update this Privacy Policy from time to time. When I make material changes, I will update the "Last updated" date at the top. For clients, I will notify you via email if changes affect the processing of your data.
Questions about this policy?
Email [email protected] — I'm happy to help.