Legal
Privacy Policy
How AssistSec handles personal data when you visit assistsec.nl, use the free exposure scanner or get in touch. Written to match what this website actually does, in plain language.
Last updated September 2, 2026 · Version 1.0
Open items before publication · 14 items
The details below are not recorded anywhere in our systems and must be supplied and checked by AssistSec before this document is relied on. Each one is marked where it belongs in the text.
- full legal name and legal form of the company (e.g. B.V.)
- Chamber of Commerce (KvK) number
- registered office / business address
- whether a data protection officer has been appointed, and their contact details
- link to the privacy notice of the ARGUS customer portal (scanner.assistsec.nl)
- retention period of server and access logs
- name and location of the hosting and infrastructure provider(s)
- retention period for enquiries received by e-mail
- name and location of the e-mail provider
- confirmation of the report retention period configured in production
- schedule on which expired scan records are actually deleted (no automated purge is configured yet)
- retention period for the business details left to unlock a report
- decision on the newsletter field on blog articles: connect it to a mailing service and describe that processing here, or remove the field
- the AI/LLM providers used in pentest engagements and the terms under which they process customer data (relevant to customer agreements, referenced here for completeness)
1. Who we are and how to reach us
AssistSec is a Dutch cybersecurity company. We carry out penetration tests on web applications and APIs, combining the judgement of experienced pentesters with an AI-assisted testing engine. This policy is issued by full legal name and legal form of the company (e.g. B.V.), registered with the Dutch Chamber of Commerce under number Chamber of Commerce (KvK) number, with its registered office at registered office / business address. For the processing described in this policy, we are the controller within the meaning of the General Data Protection Regulation (GDPR).
- Website
- assistsec.nl (English) and assistsec.nl/nl (Dutch). Each language is a separate build of the same site.
- contact@assistsec.nl
- Data protection officer
- whether a data protection officer has been appointed, and their contact details
2. What this policy covers
This policy applies to the public website, to the free digital exposure scanner at assistsec.nl/security-scan, and to the communication you have with us through the site or by e-mail.
It does not apply to:
- the ARGUS customer portal at scanner.assistsec.nl, which the login, demo and registration links on this site lead to. The portal is a separate service with its own privacy notice: link to the privacy notice of the ARGUS customer portal (scanner.assistsec.nl).
- personal data we process while performing a penetration test or other engagement for a customer. That processing is governed by the engagement agreement and, where we act as a processor, by a data processing agreement.
This website uses Google Analytics to count visits, and only after you have agreed to it. It carries no advertising, builds no profiles across other websites, and we do not sell or rent personal data. If you refuse, or have not answered yet, no analytics script is loaded and nothing is stored in your browser.
3. What we process, why, and for how long
The website does a small number of things. Each is described below with the data involved, the purpose, the legal basis under Article 6 GDPR and how long the data is kept.
3.1 Visiting the website
The site is delivered as pre-rendered pages. Like every website, it is served by infrastructure that keeps technical logs of the requests it receives.
- Data
- IP address, browser and device characteristics, the pages requested, the referring page and the time of the request, as recorded in the server logs of the infrastructure that serves the site.
- Purpose
- Delivering the pages you ask for, keeping the site available and secure, detecting abuse and diagnosing faults.
- Legal basis
- Our legitimate interest in operating a secure, reliable website (Article 6(1)(f) GDPR).
- Retention
- retention period of server and access logs
- Recipients
- Our hosting provider: name and location of the hosting and infrastructure provider(s).
3.2 Web fonts
The site's typefaces (Inter and Geist Mono) are loaded from Google Fonts. When your browser fetches them it connects to servers of Google LLC, which receives your IP address and the technical details of the request. Google states that Fonts requests are not used to set cookies or to build advertising profiles.
- Legal basis
- Our legitimate interest in consistent, fast-loading typography (Article 6(1)(f) GDPR).
- Transfer
- Google LLC is established in the United States and is certified under the EU-U.S. Data Privacy Framework. See also Transfers outside the EEA.
3.3 Contacting us
The contact form on assistsec.nl/contact does not send anything to our servers. When you submit it, it opens a message in your own e-mail program, addressed to us and containing the name, e-mail address, company, chosen service and message you typed. Nothing is stored by the website itself; the message only reaches us when you send it.
- Data
- Your name, e-mail address, company (if given), the service you asked about and the content of your message, plus the technical e-mail headers.
- Purpose
- Answering your question and, where relevant, preparing a proposal.
- Legal basis
- Taking steps at your request prior to entering into a contract (Article 6(1)(b) GDPR), or otherwise our legitimate interest in responding to enquiries (Article 6(1)(f)).
- Retention
- retention period for enquiries received by e-mail
- Recipients
- Our e-mail provider: name and location of the e-mail provider.
3.4 The free exposure scanner
On assistsec.nl/security-scan you can enter a website domain and receive an overview of its publicly visible security exposure. The scan is passive: it looks only at what anyone on the internet can observe about the domain. We do not send attack traffic, we do not log in, and we do not test business logic.
What the scan looks at:
- DNS records, including DNSSEC and certificate authority authorisation (CAA).
- The TLS certificate and handshake of the domain.
- HTTP response headers and the flags on cookies the site sets (security headers, HTTPS redirects, HSTS).
- E-mail authentication records: SPF, DMARC and MTA-STS.
- Hostnames published for the domain in public Certificate Transparency logs.
- Registered domains that resemble the domain (lookalikes), and whether they can receive mail.
- Well-known files the site publishes (robots.txt, security.txt and similar), directory listings, the images on the homepage and the technologies the site announces about itself.
- Data we store
- The domain you entered, encrypted at rest (AES-256-GCM) together with a keyed fingerprint that is used only to recognise a repeat request for the same domain within five minutes; the status of the scan; the results, being observations about the domain as listed above with sensitive evidence such as paths and version banners removed; the language of the page you used; and timestamps.
- Data we do not store
- Your IP address is not written to the scan record. It is used only in memory to limit the number of scans per connection (eight per ten minutes) and is not retained. The scan is not linked to an account or to you; nobody signs in to run one.
- Purpose
- Producing the report you asked for and showing it to whoever holds its link.
- Legal basis
- Performance of the service you request (Article 6(1)(b) GDPR). A domain name is normally information about an organisation rather than a person; where it identifies a natural person, we rely on our legitimate interest in providing the check you asked for (Article 6(1)(f)).
- Retention
- A report is readable for 72 hours after it is created (confirmation of the report retention period configured in production). After that the link answers that the report has expired. Expired records are deleted: schedule on which expired scan records are actually deleted (no automated purge is configured yet).
- Who can read the report
- Anyone who has the link. The report identifier is random and appears nowhere else, but the link is the only protection, so treat it as you would the report itself.
To perform the scan, our servers send the domain name to a number of third parties: public DNS resolvers, the web servers of the domain itself, the Certificate Transparency search services crt.sh and Cert Spotter (SSLMate, Inc., United States) and the HackerTarget host search (HackerTarget, Australia). These parties receive the domain name and the address of our server, not yours.
Only scan domains you own or are authorised to assess; see our Terms of Service. The hostnames a report lists are taken from public certificate logs and are already public. Evidence that would shorten an attack, such as readable paths and version banners, is removed before anything is stored.
The scanner has also been built to produce personal e-mail exposure reports, delivered through a single-use link sent to the address concerned. That service is not available at present. Should we offer it, we will describe the processing in this policy first.
3.5 Unlocking a full report
A website report shows its headline findings to everyone. To see every finding, we ask for your work details. This is a commercial choice on our part, not a security measure: the report concerns the public exposure of a domain, and the details you leave tell us who is interested in our services.
- Data
- Your name, company, job title and work e-mail address, together with the identifier of the scan and the time you submitted the form. Personal webmail addresses are refused; a company address is required.
- Purpose
- Giving you access to the complete report, and contacting you about our services following your scan.
- Legal basis
- Your consent, given by choosing to provide the details (Article 6(1)(a) GDPR), which you can withdraw at any time; and our legitimate interest in following up business enquiries (Article 6(1)(f)). You can object to follow-up at any time by writing to contact@assistsec.nl.
- Storage
- Stored in readable form in our database and visible to authorised AssistSec staff in our content management system. The details outlive the scan they belong to.
- Retention
- retention period for the business details left to unlock a report
- Recipients
- Nobody outside AssistSec, other than the hosting provider that runs our database.
So that the report stays unlocked while you keep it open, your browser records a flag in session storage under the name scanner:unlocked followed by the scan identifier. It contains no personal data and is discarded when you close the tab.
3.6 Blog, feed and sharing
Articles are loaded from our own content management system. Reading them involves no data beyond the technical logs described under Visiting the website. The same applies to the RSS feed.
The share button on an article opens LinkedIn with the article's address; from that point LinkedIn's own privacy policy applies. Copying a link uses your browser's clipboard and sends nothing to us.
Articles carry a field to subscribe to a newsletter. At present that field does not transmit or store your address and no newsletter is sent. decision on the newsletter field on blog articles: connect it to a mailing service and describe that processing here, or remove the field.
3.7 Links to other services
The site links to services we do not operate as part of it: the ARGUS customer portal at scanner.assistsec.nl for logging in, booking a demo and creating an account (link to the privacy notice of the ARGUS customer portal (scanner.assistsec.nl)), our company pages on LinkedIn and YouTube, and Google Fonts as described above. Once you follow such a link, the privacy notice of that service applies.
3.8 Our own editors
Articles and scanner leads are managed in an administrative area that only authorised AssistSec staff can sign in to. For those staff we keep a login session, which records the IP address and browser used, and an audit log of the actions they take. This is a security measure for the site; it concerns our own people, not visitors.
5. Who receives your data
Your data is shared only with the parties needed to run what is described above:
- our hosting and infrastructure provider, which runs the website, the database and the scanner: name and location of the hosting and infrastructure provider(s);
- our e-mail provider, for messages you send us: name and location of the e-mail provider;
- Google LLC, for the web fonts, as described under Web fonts;
- the DNS resolvers, target web servers and Certificate Transparency services the scanner consults, which receive a domain name only;
- public authorities, where we are legally obliged to provide data or to protect our rights.
Where a provider processes personal data on our behalf, we have a data processing agreement with them. We do not sell personal data, and we do not share it for other parties' marketing.
This website does not use artificial intelligence to process data about visitors. Our pentest services do use AI models under human supervision; how customer data is handled in that context is set out in the engagement agreement and data processing agreement with the customer (the AI/LLM providers used in pentest engagements and the terms under which they process customer data (relevant to customer agreements, referenced here for completeness)).
6. Transfers outside the EEA
We aim to keep personal data within the European Economic Area. Two exceptions follow from how the site is built:
- Google LLC (United States) receives your IP address when your browser loads the web fonts. Google is certified under the EU-U.S. Data Privacy Framework, which the European Commission has recognised as providing adequate protection.
- If you allow measurement, Google LLC also receives the pages you view on this site, together with your IP address and browser details, through Google Analytics. This happens under the same Data Privacy Framework certification, and only for as long as your consent stands.
- When you run a scan, the domain name you entered is sent to SSLMate, Inc. (United States) and HackerTarget (Australia) as part of the lookups. These parties receive no data about you.
The location of our hosting provider is stated above: name and location of the hosting and infrastructure provider(s).
7. How we protect data
The site and its services are built with the following measures, among others:
- All traffic to the site and its API is encrypted in transit (HTTPS).
- Scan subjects and scan results are encrypted at rest with AES-256-GCM; the key is kept outside the database.
- Scan reports carry a random identifier, are never cached and are excluded from search engines.
- Requests to the scanner are rate-limited per connection, and domains that resolve to private or internal addresses are refused.
- Access to the administrative area requires a password stored with argon2id, uses server-side sessions that can be revoked, and is protected against cross-site request forgery. Editors' actions are logged.
- The results the scanner stores never contain passwords, in any form, and evidence that would help an attacker is removed before storage.
8. Your rights
Under the GDPR you have the right to:
- access the personal data we hold about you and receive a copy;
- have inaccurate data corrected and incomplete data completed;
- have your data erased, where there is no longer a reason for us to keep it;
- restrict processing, in the situations the law provides for;
- receive the data you provided to us in a structured, commonly used format (portability);
- object to processing based on our legitimate interest, and to object at any time to direct marketing;
- withdraw consent you have given, without affecting the lawfulness of processing before the withdrawal.
To exercise any of these rights, write to contact@assistsec.nl. We respond within one month; if a request is complex we may extend that by two months and will tell you so. We may ask you to confirm your identity before acting on a request, so that we do not hand your data to someone else.
If you believe we have handled your personal data unlawfully, you can lodge a complaint with the Dutch supervisory authority, the Autoriteit Persoonsgegevens (autoriteitpersoonsgegevens.nl). We would appreciate the chance to resolve your concern first.
9. Children
This website and its services are aimed at organisations and professionals, not at children. We do not knowingly collect personal data from anyone under 16. If you believe a child has provided us with personal data, contact us and we will delete it.
10. Automated decision-making
We make no decisions about you based solely on automated processing that have legal or similarly significant effects. The scanner's score describes a domain's technical exposure at one moment; it is informational and says nothing about a person.
11. Changes to this policy
We update this policy when the site changes in a way that affects your data, or when the law requires it. The date and version at the top show the current text. Where a change is material, we will draw attention to it on the site.
12. Contact
Questions about this policy or about your data can be sent to contact@assistsec.nl or to our postal address: registered office / business address.