Privacy Policy Neo Security B.V.
Last updated: 1 September 2026
1. Introduction
Neo Security B.V. respects the privacy of website visitors, prospects, and customers. In this privacy policy, we explain which personal data we process, why we do so, with whom we share data, and how we protect data. We act in accordance with the General Data Protection Regulation (GDPR).
2. Who is responsible?
Neo Security B.V. (CoC 99240890)
Willem de Zwijgerlaan 137H, 1056 JK Amsterdam, The Netherlands
Email: [email protected]
3. What data do we process?
Depending on your use of our website, we process (some of) the following data:
- Website usage: IP address, browser and device information (user agent), timestamp, and pages viewed (for security, statistics, and performance).
- Contact: name, email address, and message (required) and optionally: company name, phone number, chosen service.
- Technical metadata upon contact: IP address and derived information (e.g. country/region/city based on IP), browser/OS/device (for abuse prevention, context, and internal follow-up).
4. Purposes and legal bases
We process personal data for the following purposes:
- Contact and follow-up: to answer your enquiry and (where relevant) prepare a quote/assignment. Legal basis: performance of contract / legitimate interest.
- Security and fraud prevention: protection of our website and systems, rate limiting, detection of abuse. Legal basis: legitimate interest.
- Website analytics (Google Analytics 4) and uX/heatmaps (Microsoft clarity): insight into website usage, improving content and UX. Legal basis: consent (analytics cookies).
5. Cookies, analytics, and your choices
We use functional techniques to make the website work and (optionally) analytics cookies for Google Analytics 4 and Microsoft Clarity.
Analytics scripts are only loaded after you have given consent via the cookie banner. You can always change or withdraw your choice (see our cookie policy).
6. Processors and recipients
For some parts of our services, we engage (sub)processors. These include:
- Google Analytics 4 (Google LLC): website statistics.
- Microsoft clarity (Microsoft): session analysis/UX insights.
- Mailgun (Sinch Mailgun, EU region): sending email when the contact form is used.
- Salesforce (Salesforce, Inc.): CRM registration and internal follow-up of contact requests. We do not send IP addresses, device data, or derived location data to Salesforce.
7. Transfers outside the EEA (Schrems II)
For Google Analytics, Microsoft Clarity, and Salesforce, it is possible that personal data is processed in the United States or by parties engaging (sub)processors outside the European Economic Area (EEA).
Where there is a transfer outside the EEA, we base such transfer on appropriate safeguards, such as: (i) the vendor's participation in the EU–US Data Privacy Framework (where applicable), and/or (ii) Standard Contractual Clauses (SCC's) with supplementary measures.
Supplementary measures we apply include: data minimisation (only loading after consent), transport encryption (TLS), access security on a need-to-know basis, logging/monitoring, and retention periods kept as short as possible for the purpose.
8. Retention periods
We do not retain personal data longer than necessary for the purposes for which they were collected, unless a statutory retention obligation applies.
- Contact requests: as long as necessary for answering and follow-up; in principle a maximum of 24 months, unless a customer relationship arises.
- Analytics: according to the configured retention in Google Analytics/Clarity (see cookie policy) and as short as possible for analysis purposes.
9. Security and organisation
Neo Security B.V. is a subsidiary of Korper ICT B.V. Within this group, we take appropriate technical and organisational measures to protect personal data against loss or any form of unlawful processing.
Korper ICT B.V. (of which Neo Security B.V. is a subsidiary) is ISO 27001 and ISO 9001 certified. Neo Security B.V. operates within the (certified) management system of Korper ICT B.V.
10. Your rights
You have (subject to conditions) the right to access, rectification, erasure, restriction, data portability, and objection. For processing based on consent, you can always withdraw your consent.
You can submit a request via [email protected].
11. Complaints
If you have a complaint about how we handle personal data, please contact us first. You also have the right to file a complaint with the Dutch Data Protection Authority (Autoriteit Persoonsgegevens).
12. Changes
We reserve the right to amend this privacy policy. Changes will be published on this website.