This privacy policy explains which personal data is processed when you visit this website and when you contact us. It is as short as the website allows: this website sets no cookies, uses no analytics or marketing services and contains no forms.
1. Controller
SECURITY INSIGHTS S.R.L. Str. General Grigore Balan Nr. 34, 420094 Bistrița, Romania Phone: +40 363 630 006 Email: rooffice@securityinsights.net
German office (sales and engineering): Kolonnenstr. 8, 10827 Berlin, Germany Phone: +49 30 75437148 Email: deoffice@securityinsights.net
Represented by: Michael Witzsche
2. What happens when you visit the website
This website consists of static pages. When you open a page, only the data that is technically required to deliver it is processed (see section 3). No cookies are set, nothing is stored in your browser, and no third-party content is loaded. Fonts, images and scripts are served by our hosting provider.
3. Hosting
The website is served through Firebase Hosting, a service provided by Google. For users in the European Economic Area the contracting entity is Google Ireland Limited, Gordon House, Barrow Street, Dublin 4, Ireland; Google Ireland Limited is part of Google LLC, based in the USA.
When a page is requested, Google, acting as our processor, processes the data your browser transmits: IP address, date and time of the request, requested URL, amount of data transferred, browser type and operating system, and the previously visited page (referrer). This data is needed to deliver the website, keep the service secure and detect abuse. Google keeps access logs for a limited period. We do not evaluate these logs ourselves and do not combine them with other data.
Content is delivered through Google’s global network, so processing outside the European Economic Area, in particular in the USA, is possible. Google LLC is certified under the EU-US Data Privacy Framework; in addition, the standard contractual clauses adopted by the European Commission apply as part of Google’s data processing terms.
The legal basis is Art. 6(1)(f) GDPR. Our legitimate interest lies in providing the website securely, reliably and quickly. Further information is available in Google’s privacy information for Firebase at firebase.google.com/support/privacy.
4. No cookies, no analytics
This website does not set cookies and does not use comparable technologies such as local storage. No analytics, tracking or marketing services are used, so no consent banner is required. Should we introduce audience measurement in the future, we will update this policy beforehand and, where required, ask for your consent.
5. Contacting us by email or phone
If you contact us by email or phone, we process the data you provide (such as your name, email address, phone number, company and the content of your message) in order to handle your enquiry and communicate with you.
The legal basis is Art. 6(1)(b) GDPR where your enquiry is aimed at concluding or performing a contract; otherwise it is Art. 6(1)(f) GDPR, based on our legitimate interest in responding to enquiries.
We keep the data for as long as it is needed to handle your enquiry and any business relationship that follows. Beyond that, we retain correspondence where statutory retention obligations require it. Please note that unencrypted email can be read by third parties in transit; for confidential information we are happy to agree on an encrypted channel.
6. Disclosure of data
We disclose personal data only where this is necessary to handle your enquiry, where we are legally obliged to do so, or where you have given your consent. Processors, such as our hosting provider, are contractually bound to comply with the GDPR.
7. Links to other websites
This website links to external sites, including our NIS2-Guardian quick check at nis2.securityinsights.net as well as websites of Microsoft and other providers. The privacy notices published there apply to those sites. When you click on such a link, you leave this website.
8. Your rights
You have the right to obtain information about the data we hold about you (Art. 15 GDPR), and to rectification (Art. 16), erasure (Art. 17), restriction of processing (Art. 18) and data portability (Art. 20). Where processing is based on Art. 6(1)(f) GDPR, you may object at any time on grounds relating to your particular situation (Art. 21). Consent you have given can be withdrawn at any time with effect for the future.
To exercise your rights, an email to one of the addresses above is sufficient.
9. Right to lodge a complaint
You have the right to lodge a complaint with a data protection supervisory authority. For our headquarters this is the Romanian authority: Autoritatea Națională de Supraveghere a Prelucrării Datelor cu Caracter Personal (ANSPDCP), B-dul G-ral. Gheorghe Magheru 28-30, Sector 1, Bucharest, Romania, www.dataprotection.ro. For our Berlin office, the Berlin Commissioner for Data Protection and Freedom of Information is competent, Alt-Moabit 59-61, 10555 Berlin, Germany, www.datenschutz-berlin.de. You may also contact the supervisory authority of your place of residence.
10. Data security
This website is available exclusively over an encrypted connection (HTTPS with HSTS). Our hosting provider applies technical and organisational measures to protect data against unauthorised access, loss and manipulation.
11. Changes
We update this privacy policy when the website, the services used or the legal situation change. The version published here applies.