Dutch Cybersecurity Act: is your organisation secure online? →

// PRIVACY / PUBLIC REQUEST FLOW

Know what happens to your request data.

This notice covers data submitted through the public website and pentest request. A later engagement receives its own written scope, data terms and, where needed, a signed data processing agreement.

Controller: Loki Intelligence B.V. · Dutch Chamber of Commerce 42116362 · VAT NL869803438B01 · The Netherlands · [email protected]

Data, purposes, and legal basis

We receive business contact and company data, request type, an optional URL and scope context, correspondence, and limited security logs. We use it to assess and answer the request, prepare a possible contract, protect the form, and keep applicable records. A submission neither starts nor authorizes testing; acceptance remains a human decision.

Retention by data category

  • Request data remains while the request is open and then only as needed for the response, outcome, security, and a relevant claim or legal duty.
  • Contract and authorization records follow the engagement and applicable accounting, dispute, and legal record duties.
  • Assessment evidence, reports, and temporary access follow the signed engagement through delivery, agreed retest, and closure, after which return, revocation, or deletion is recorded.

No model training or unrelated reuse

Loki does not use request or assessment data for model training, advertising, or unrelated analysis unless the customer first gives a separate explicit written instruction and the parties record the terms.

Providers, locations, and transfers

Before an engagement in which Loki is a processor, the signed DPA or its referenced register names the providers actually relevant to customer data, their function, processing location, change notice, and any transfer safeguard. We do not publish an unverified provider list as fact.

Your questions and rights

Where the law provides, you can request access, correction, deletion, restriction, transfer, or objection and complain to the competent privacy authority. Email [email protected]. Never submit secrets or test accounts through the public form.