Effective date: July 2026
Controller: Meroi Security, Pastoor van Arslaan 6A, 5622 CK Eindhoven, The Netherlands
Email: contact@meroisecurity.com KvK: 77783077
1. Purpose and Scope
This Policy explains how Meroi Security (“Meroi Security”, “we”, “us”) collects, uses, and protects personal data obtained through our website www.meroisecurity.com, including our contact form.
We process your information in accordance with the General Data Protection Regulation (EU) 2016/679 (“GDPR”) and other applicable privacy laws.
2. Legal Bases for Processing (Art. 6 GDPR)
| Purpose | Lawful Basis |
|---|---|
| Responding to enquiries and sending requested information | Art. 6 (1)(b) – performance of a contract or pre-contractual steps |
| Improving our website and analytics (cookie data) | Art. 6 (1)(f) – legitimate interest in site function and security |
| Optional marketing or follow-up communication | Art. 6 (1)(a) – consent |
| Legal or regulatory compliance obligations | Art. 6 (1)(c) |
You may withdraw consent at any time without affecting prior lawful processing.
3. Categories of Data We Process
Name and surname
Company name
Email address and (optional) phone
Country and business location
The content of any message you send us through the contact form or by email
Technical data (IP address, browser type, device, usage logs)
Cookie and tracking data (see Section 7)
We do not intentionally collect special-category data (Art. 9 GDPR) or data from children under 16.
4. Data Retention (Art. 5 (1)(e))
Contact form messages and related correspondence are retained only as long as needed to respond to your request and for a reasonable follow-up period.
A copy of each contact form submission is also stored on our own web server for 90 days, after which it is deleted automatically. This copy exists so that an enquiry cannot be lost if email delivery fails, and it is accessible only to us over an authenticated connection.
Analytics data is retained for no longer than 14 months, in line with our Google Analytics configuration.
Statutory or contractual retention periods override these limits where required by law.
5. Recipients and International Transfers (Arts. 28–46)
| Processor / Service | Role | Location & Safeguard |
|---|---|---|
| Microsoft 365 | Email correspondence (contact form and enquiries) | EU datacentres |
| Bluehost | Website hosting | United States – standard contractual clauses (SCCs) |
| Google Analytics 4 | Website analytics | United States – SCCs; loaded only after your consent |
| Cloudflare Turnstile | Spam protection on the contact form | EU/global – SCCs; sets no tracking cookies and does not profile visitors |
All processors act under written Data-Processing Agreements and provide adequate safeguards for international transfers (Art. 46).
We never sell or trade your personal data.
6. Data Security (Art. 32)
We apply technical and organisational measures to protect personal data, including encryption (HTTPS/TLS 1.2+), firewall protection, role-based access control, and regular security audits.
7. Cookies and Similar Technologies
7.1 What Are Cookies
Cookies are small text files stored on your device when you visit our website.
They enable basic functions, usage analysis, and personalisation.
7.2 Cookies We Actually Set
We use two categories only. We do not use marketing, advertising, profiling or cross-site tracking cookies of any kind.
| Cookie | Category | Purpose | Duration |
|---|---|---|---|
meroi_consent | Strictly necessary | Remembers your cookie choice so we do not ask again. Set only once you have made a choice. | 6 months |
_ga, _ga_<id> | Analytics (optional) | Google Analytics 4 — distinguishes visitors so we can count visits and see which pages are useful. Set only after you accept. | 13 months |
Until you make a choice, no cookie is stored on your device at all. If you decline, Google Analytics receives only anonymous, cookieless signals that let us count page views in aggregate — no identifier is stored on your device and you are not recognised across visits.
The spam protection on our contact form (Cloudflare Turnstile) sets no cookie on this website and does not profile visitors.
7.3 Cookie Consent and Control
On your first visit you choose whether to allow analytics cookies. Declining is one click, exactly like accepting.
You may change or withdraw your choice at any time from the cookie preferences link in the site footer, or through your browser settings.
Withdrawing consent deletes the analytics cookies immediately. Declining does not limit any part of this website.
7.4 Retention of Cookie Data
Analytics cookies expire after 13 months; your consent record expires after 6 months (Art. 5 (1)(e)).
8. Your Rights (Arts. 12–23 GDPR)
You have the right to:
Access your personal data (Art. 15)
Rectify inaccuracies (Art. 16)
Request erasure (Art. 17)
Restrict processing (Art. 18)
Object to processing (Art. 21)
Port your data to another controller (Art. 20)
Withdraw consent at any time (Art. 7 (3))
To exercise your rights, email contact@meroisecurity.com.
We respond within one month.
You may also lodge a complaint with your national supervisory authority or the Dutch Data Protection Authority (Autoriteit Persoonsgegevens).
9. Children Under 16
Our services are not intended for minors under 16. If you believe we have collected data from a child without consent, please contact us immediately.
10. Changes to This Policy
We may update this Policy to reflect legal or technical developments.
The latest version is always available at www.meroisecurity.com.
Significant changes will be announced on the website.
11. Contact for Privacy Matters
Meroi Security
Pastoor van Arslaan 6A, 5622 CK Eindhoven, The Netherlands
Phone: +886 979-192-891
Email: contact@meroisecurity.com