Privacy without the small print.
This page sets out which personal data AvdB processes, why that happens, which parties may be involved, and what rights you have.
Last updated: 8 September 2026
A note on this translation
This is an English translation of the Dutch privacy statement, provided for convenience. The Dutch version is the authoritative text; if the two differ, the Dutch version prevails.
1. Who is responsible?
AvdB Security & Protection is the controller for the personal data processed for its own purposes through this website.
AvdB Security & Protection
Chamber of Commerce (KvK): 99972654
Based in Utrecht, Netherlands
Email: contact@avdbsecurity.com
Phone: +31 6 43 11 56 10
2. Website visits and technical security
On every website visit, the web server and hosting provider may process technically necessary data such as IP address, date and time, the URL requested, browser information, error messages and security logs. This data is needed to deliver the website, investigate faults and prevent misuse.
The legal basis is AvdB's legitimate interest in keeping the website available and secure. Technical logs are not kept longer than necessary for security, fault investigation and the normal backup cycle of the hosting environment.
3. Privacy-friendly statistics with Umami
AvdB uses Umami Cloud to understand general visitor statistics, such as pages visited, referring pages, device category, browser, operating system and country at a high level. The standard Umami tracker does not use cookies, and AvdB does not use these analytics to follow visitors across other websites.
On this website AvdB does not use any personal identifier in Umami, no email address or name as an analytics ID, and no marketing profiles. The sole purpose is to see which parts of the website are being used and where technical or editorial improvement is needed.
The legal basis is the legitimate interest in measuring and improving its own website in a privacy-friendly way. See also the cookie statement.
4. Contact form and direct contact
When you use the contact form, AvdB processes your name, email address, chosen service and message. Company name, phone number and budget are optional. Please do not enter special-category personal data, passwords, medical information, identity documents or other confidential data in the free-text field if it is not needed for your question.
The data is used to assess and answer your enquiry and — where you ask for a project or a quote — to take steps prior to a possible agreement. For an ordinary question, processing is based on the legitimate interest in handling business correspondence.
Web3Forms
The form is technically handled through Web3Forms. As a result, the form data is sent to Web3Forms and then delivered to AvdB. Web3Forms publicly states that its servers are located in the United States (US-East). AvdB only uses Web3Forms for as long as appropriate GDPR arrangements and a valid basis for any transfer outside the EEA are available for this processing.
As a rule, enquiries received are kept by AvdB for a maximum of 12 months after the last substantive contact, unless a project arises or a statutory retention obligation requires a longer period. Records that become part of the financial administration may be kept longer in line with statutory retention obligations.
5. hCaptcha against spam and misuse
The contact form is protected with hCaptcha from Intuition Machines, Inc. On this website the security check is only loaded once you actually start using the form. To carry out the check, hCaptcha may process technical and behavioural data such as IP address, browser and device characteristics, timing and interactions needed to distinguish human use from automated misuse.
The purpose is to protect the form, the website and the inbox against spam, bots and misuse. The processing is based on AvdB's legitimate interest in securing the service and, where the check is necessary in order to send an enquiry you have asked to send safely, on the necessity for that service. hCaptcha may process data inside and outside the EEA and publishes information about this, including on the EU-US Data Privacy Framework and Standard Contractual Clauses.
6. The AI assistant Cipher
Cipher is clearly identified on the website as an AI assistant. So you are talking to an AI system and not to a person. AI can make mistakes. Do not use Cipher for emergencies and do not share special-category or confidential personal data if it is not necessary.
Once you send a message to Cipher yourself, the text of that message is forwarded to OpenAI, the developer of the GPT models that power Cipher. OpenAI processes the message to generate a reply, which is sent back to the website and shown to you. Nothing is forwarded unless you actually use the chat window yourself.
OpenAI is based in the United States. For this transfer of data outside the EEA, AvdB relies on the standard safeguards OpenAI offers to users of its API, including a data processing agreement (Data Processing Addendum) based on the EU Standard Contractual Clauses.
Under OpenAI's current standard API terms, messages sent through the API are not used to train OpenAI's models, and are generally retained by OpenAI for no longer than a limited period (OpenAI states a term of up to 30 days), solely for security and abuse-prevention purposes, unless a longer period is legally required or needed for an ongoing abuse investigation. AvdB itself does not store the content of your conversation with Cipher: messages exist only in your browser's memory during your visit and disappear once you refresh or close the page.
AvdB does not intend to use Cipher for automated decisions with legal or similarly significant effects, profiling for advertising, credit assessment, candidate selection or other high-risk decisions.
7. Who can data be shared with?
AvdB does not sell personal data. Data can only be shared with parties needed to provide the service, such as the hosting and email provider, Web3Forms for handling the form, hCaptcha for security and, when you use Cipher, OpenAI as the AI provider behind Cipher.
Where a supplier processes personal data on behalf of AvdB, arrangements meeting Article 28 GDPR are made where required. For transfers outside the EEA, AvdB only relies on an applicable transfer mechanism, such as an adequacy decision or appropriate contractual safeguards.
8. How long is data kept?
- General contact enquiries: as a rule, a maximum of 12 months after the last substantive contact.
- Data that becomes part of a project or the administration: for as long as the agreement runs and afterwards for as long as statutory evidentiary or tax retention obligations require.
- Technical security logs: only for as long as needed for security, fault investigation and the normal backup cycle.
- AI conversations: Cipher itself does not store the content of your conversation for longer than your visit to the website lasts. Messages you send are processed by OpenAI and, under its standard terms, generally retained for a maximum of 30 days for security and abuse-prevention purposes; they are not used to train models.
9. Your privacy rights
You can ask AvdB for access to, correction of, or erasure of personal data. Depending on the situation you can also ask for restriction of processing, object to processing based on legitimate interest, or ask for data portability. If processing were to be based on consent, you can withdraw that consent at any time without affecting the lawfulness of processing before withdrawal.
Send your request to contact@avdbsecurity.com. AvdB may ask for additional information where that is needed to reasonably verify your identity. You also have the right to lodge a complaint with the Dutch Data Protection Authority (Autoriteit Persoonsgegevens).
10. Security and data minimisation
AvdB tries to process only the data needed for the purpose in question and takes appropriate technical and organisational measures against loss, unauthorised access and misuse. No internet service, however, can guarantee absolute security.
11. Changes
This privacy statement is updated whenever the website, suppliers or processing activities change. The date at the top shows when the last substantive change was made. If the AI provider used for Cipher changes in the future, this statement will be updated before that change takes effect.