PRIVACY AND COOKIE POLICY
Effective date: October 2025
Controller: Meroi Security, Pastoor van Arslaan 6A, 5622 CK Eindhoven, The Netherlands
Email: [email protected] KvK: 77783077
1. Purpose and Scope
This Policy explains how Meroi Security (“Meroi Security”, “we”, “us”) collects, uses, and protects personal data obtained through our website www.meroisecurity.com and associated tools, including the EU Compliance Checker.
We process your information in accordance with the General Data Protection Regulation (EU) 2016/679 (“GDPR”)and other applicable privacy laws.
2. Legal Bases for Processing (Art. 6 GDPR)
| Purpose | Lawful Basis |
|---|---|
| Responding to enquiries and sending requested information | Art. 6 (1)(b) – performance of a contract or pre-contractual steps |
| Operating the EU Compliance Checker and emailing your assessment | Art. 6 (1)(b) |
| Improving our website and analytics (cookie data) | Art. 6 (1)(f) – legitimate interest in site function and security |
| Optional marketing or follow-up communication | Art. 6 (1)(a) – consent |
| Legal or regulatory compliance obligations | Art. 6 (1)(c) |
You may withdraw consent at any time without affecting prior lawful processing.
3. Categories of Data We Process
Name and surname
Company name
Email address and (optional) phone
Country and business location
Information entered into the EU Compliance Checker (questionnaire answers about industry, products, security practices)
Technical data (IP address, browser type, device, usage logs)
Cookie and tracking data (see Section 8)
We do not intentionally collect special-category data (Art. 9 GDPR) or data from children under 16.
4. Processing in the EU Compliance Checker
When you submit the form:
Your data is transmitted via SSL/TLS to our hosting on Microsoft Azure (EU datacentres).
The text you enter is processed through the OpenAI API for automated generation of your 2-page report.
Results are returned to Meroi Security for email delivery to the address you provided.
Automated processing is limited to content generation and does not constitute automated decision-making with legal or similarly significant effects (Art. 22 GDPR).
5. Data Retention (Art. 5 (1)(e))
EU Compliance Checker submissions are stored for 30 days, then automatically deleted or irreversibly anonymised.
Contact form messages are retained only as long as needed to respond to your request.
Statutory or contractual retention periods override these limits where required by law.
6. Recipients and International Transfers (Arts. 28–46)
| Processor / Service | Role | Location & Safeguard |
|---|---|---|
| WPMU DEV (Forminator) | Website form engine | EU servers |
| Microsoft Azure | Cloud hosting | EU datacentres – standard contractual clauses (SCCs) |
| OpenAI LLC | AI text processing API | United States – SCCs (2021/914 EU Model Clauses) |
| Microsoft 365 | Email infrastructure | EU datacentres |
All processors act under written Data-Processing Agreements and provide adequate safeguards for international transfers (Art. 46).
We never sell or trade your personal data.
7. Data Security (Art. 32)
We apply technical and organisational measures to protect personal data, including encryption (HTTPS/TLS 1.2+), firewall protection, role-based access control, and regular security audits.
8. Cookies and Similar Technologies
8.1 What Are Cookies
Cookies are small text files stored on your device when you visit our website.
They enable basic functions, usage analysis, and personalisation.
8.2 Types of Cookies We Use
Essential cookies – required for form submissions and security.
Analytics cookies – help us understand visitor behavior (e.g. Google Analytics with IP anonymization).
Preference cookies – remember your settings (e.g. language choice).
Marketing / tracking cookies – set only with your explicit consent.
8.3 Cookie Consent and Control
On your first visit you choose which cookie categories to allow.
You may change or withdraw consent at any time via your browser settings or cookie banner.
Disabling cookies may limit website functionality.
8.4 Retention of Cookie Data
Session cookies expire when you close your browser; persistent cookies remain for no longer than 13 months (Art. 5 (1)(e)).
9. Your Rights (Arts. 12–23 GDPR)
You have the right to:
Access your personal data (Art. 15)
Rectify inaccuracies (Art. 16)
Request erasure (Art. 17)
Restrict processing (Art. 18)
Object to processing (Art. 21)
Port your data to another controller (Art. 20)
Withdraw consent at any time (Art. 7 (3))
To exercise your rights, email [email protected].
We respond within one month.
You may also lodge a complaint with your national supervisory authority or the Dutch Data Protection Authority (Autoriteit Persoonsgegevens).
10. Children Under 16
Our services are not intended for minors under 16. If you believe we have collected data from a child without consent, please contact us immediately.
11. Changes to This Policy
We may update this Policy to reflect legal or technical developments.
The latest version is always available at www.meroisecurity.com.
Significant changes will be announced on the website.
12. Contact for Privacy Matters
Meroi Security
Pastoor van Arslaan 6A, 5622 CK Eindhoven, The Netherlands
Phone: +886 979-192-891
Email: [email protected]
