Privacy Statement
What we collect through this site, why we collect it, and the rights you have over it.
Last updated: 20 July 2026.
Atomic Security (“we”, “us”) is a sole proprietorship (eenmanszaak) registered in the Netherlands, and the data controller for personal data collected through atomicsecurity.nl. This statement explains what we collect, why, and how to exercise your rights under the General Data Protection Regulation (GDPR / AVG).
Who we are
- Atomic Security — Keizersgracht 520H, 1017 EK Amsterdam, Netherlands
- KVK: 96494190
- BTW-id: NL005213092B78
- Contact: hello@atomicsecurity.nl
What we collect
Information you send us. When you use the contact form, we receive the name, email address, and message you provide. We use those details only to read and answer your enquiry.
Technical data. This site is hosted on Cloudflare Pages. To deliver and protect the site, Cloudflare processes standard request data on our behalf — including your IP address, browser user-agent, and the time of each request.
Analytics. We use Cloudflare Web Analytics to understand aggregate traffic — page views, referrers, and performance. It is privacy-first: it sets no cookies, does not fingerprint your device, and does not track you across sites or build a profile of you.
We do not use advertising or behavioural profiling. Because the site sets no tracking cookies — only strictly necessary ones, if any — there is no cookie-consent banner.
Why we’re allowed to (legal basis)
- Answering your enquiry — to take steps at your request before entering a possible agreement, and our legitimate interest in responding to you (Art. 6(1)(b) and 6(1)(f) GDPR).
- Delivering and securing the website — our legitimate interest in a functioning, protected site (Art. 6(1)(f) GDPR).
Who we share it with
We do not sell your data or share it for marketing. We rely on these processors:
- Cloudflare, Inc. — website hosting and delivery, bot protection on the contact form (Turnstile), and privacy-first traffic analytics, under a data-processing agreement.
- Resend (Plus Five Five, Inc.) — sends your contact-form submission to us by email, under a data-processing agreement.
These providers are based in the United States, so this may involve transfer of data outside the EEA, covered by appropriate safeguards such as the EU Standard Contractual Clauses.
We may also disclose data where we are legally required to.
How long we keep it
We keep contact-form correspondence for as long as needed to handle your request and any reasonable follow-up, after which it is deleted. Resend retains a copy of the delivered email and its sending logs for up to 30 days, after which they are removed. Technical logs held by Cloudflare are retained only for short operational and security periods.
Your rights
Under the GDPR you can ask us to give you access to, correct, delete, restrict, or hand over your personal data, and you can object to processing based on legitimate interest. To do any of these, email hello@atomicsecurity.nl.
You also have the right to lodge a complaint with the Dutch supervisory authority, the Autoriteit Persoonsgegevens (autoriteitpersoonsgegevens.nl).
Changes to this statement
We may update this statement as our practices or the law change. The date at the top shows when it was last revised.