Privacy policy
Short version: we collect as little as we can, we never sell it, and the free tools on this site do not send your answers anywhere.
1. Controller
Cryptaguard SRL, Fazantenlaan 9, 1600 Sint-Pieters-Leeuw, Belgium, VAT BE 1007.610.660. Privacy contact: subscription@cryptaguard.com.
We have not appointed a Data Protection Officer. Our processing does not involve large-scale monitoring or special categories of data under article 9 GDPR, so article 37 does not require one. The address above reaches the person responsible for privacy questions.
2. What we process, why, and on what basis
| Purpose | Data | Legal basis | Retention |
|---|---|---|---|
| Fulfilling an order | Name, email, organisation, country, VAT number, order and payment references | Contract, art. 6(1)(b) | 7 years (Belgian accounting law) |
| Giving you access to your files | Email, access-link token (hashed), entitlement records | Contract, art. 6(1)(b) | Tokens 1 year; entitlements for the life of the licence |
| Answering your message | Name, email, organisation, message content | Legitimate interest, art. 6(1)(f) | 3 years after last contact |
| Sending you the launch or product email you asked for | Email, consent record (timestamp, hashed IP) | Consent, art. 6(1)(a) | Until you unsubscribe, then 3 years for proof of consent |
| Security and abuse prevention | Hashed IP address, rate-limit counters, server logs | Legitimate interest, art. 6(1)(f) | Logs 12 months; counters hours |
| Statutory invoicing | Invoice data including VAT number | Legal obligation, art. 6(1)(c) | 7 years |
3. What we deliberately do not do
- We do not store your IP address in readable form. Where we need to distinguish visitors — rate limiting, proof of consent — we store a keyed hash, not the address.
- The free tools send nothing. The scope check and the penalty calculator run entirely in your browser. Your answers never reach our server, so there is nothing for us to keep.
- We do not sell or rent personal data, and we do not share it for anyone else's marketing.
- We never see your card details. Payment is handled on Stripe's own pages.
4. Cookies and local storage
We use no advertising or tracking cookies. What we do use:
- Cart and theme (local storage). Strictly necessary to provide a shopping cart you asked to use, and to remember your light or dark preference. No consent is required for these under the ePrivacy rules, and they never leave your browser.
- Session cookie (
DN2SESS). Set only after you open an access link, so we can show you your downloads. Expires when you close your browser. - Consent record (local storage). Remembers your answer to the cookie banner so we stop asking.
- Measurement. Not currently enabled. If we enable it, it will load only after you accept, and declining will keep every function of the site working.
5. Processors and transfers
We use a small number of processors, each under a data processing agreement:
- Stripe Payments Europe Ltd (Ireland) — payment processing and invoicing. Stripe is a controller in its own right for fraud prevention and regulatory purposes.
- OVH SAS (France) — hosting. Data is stored within the European Union.
Where a processor transfers data outside the EEA, that transfer relies on an adequacy decision or on the European Commission's standard contractual clauses.
6. Your rights
You have the right to access your data, to rectify it, to erase it, to restrict or object to processing, to data portability, and to withdraw consent at any time where consent is the basis. Write to subscription@cryptaguard.com and we will respond within one month.
Note one limit: we cannot erase invoice data before the 7-year statutory retention period expires, because keeping it is a legal obligation.
You may lodge a complaint with the Belgian Data Protection Authority (Autorité de protection des données / Gegevensbeschermingsautoriteit), Rue de la Presse 35, 1000 Brussels, autoriteprotectiondonnees.be, or with the authority of your own member state.
7. Security
The site is served over HTTPS with HSTS. Secrets live outside the web root. Access tokens are stored hashed, never in clear. We apply a strict Content Security Policy with per-request nonces. We would rather practise what the documents we sell describe.
8. Changes
If we change this policy materially we will say so on this page and, where the change affects a purpose you consented to, ask you again.
Last updated .