Privacy Policy

How we collect, use, and protect your personal data.

Effective date: July 2026
Controller: Meroi Security, Pastoor van Arslaan 6A, 5622 CK Eindhoven, The Netherlands
Email: contact@meroisecurity.com KvK: 77783077

1. Purpose and Scope

This Policy explains how Meroi Security (“Meroi Security”, “we”, “us”) collects, uses, and protects personal data obtained through our website www.meroisecurity.com, including our contact form.
We process your information in accordance with the General Data Protection Regulation (EU) 2016/679 (“GDPR”) and other applicable privacy laws.


2. Legal Bases for Processing (Art. 6 GDPR)

Purpose Lawful Basis
Responding to enquiries and sending requested information Art. 6 (1)(b) – performance of a contract or pre-contractual steps
Improving our website and analytics (cookie data) Art. 6 (1)(f) – legitimate interest in site function and security
Optional marketing or follow-up communication Art. 6 (1)(a) – consent
Legal or regulatory compliance obligations Art. 6 (1)(c)

You may withdraw consent at any time without affecting prior lawful processing.


3. Categories of Data We Process

  • Name and surname

  • Company name

  • Email address and (optional) phone

  • Country and business location

  • The content of any message you send us through the contact form or by email

  • Technical data (IP address, browser type, device, usage logs)

  • Cookie and tracking data (see Section 7)

We do not intentionally collect special-category data (Art. 9 GDPR) or data from children under 16.


4. Data Retention (Art. 5 (1)(e))

  • Contact form messages and related correspondence are retained only as long as needed to respond to your request and for a reasonable follow-up period.

  • A copy of each contact form submission is also stored on our own web server for 90 days, after which it is deleted automatically. This copy exists so that an enquiry cannot be lost if email delivery fails, and it is accessible only to us over an authenticated connection.

  • Analytics data is retained for no longer than 14 months, in line with our Google Analytics configuration.

  • Statutory or contractual retention periods override these limits where required by law.


5. Recipients and International Transfers (Arts. 28–46)

Processor / Service Role Location & Safeguard
Microsoft 365 Email correspondence (contact form and enquiries) EU datacentres
Bluehost Website hosting United States – standard contractual clauses (SCCs)
Google Analytics 4 Website analytics United States – SCCs; loaded only after your consent
Cloudflare Turnstile Spam protection on the contact form EU/global – SCCs; sets no tracking cookies and does not profile visitors

All processors act under written Data-Processing Agreements and provide adequate safeguards for international transfers (Art. 46).

We never sell or trade your personal data.


6. Data Security (Art. 32)

We apply technical and organisational measures to protect personal data, including encryption (HTTPS/TLS 1.2+), firewall protection, role-based access control, and regular security audits.


7. Cookies and Similar Technologies

7.1 What Are Cookies

Cookies are small text files stored on your device when you visit our website.
They enable basic functions, usage analysis, and personalisation.

7.2 Cookies We Actually Set

We use two categories only. We do not use marketing, advertising, profiling or cross-site tracking cookies of any kind.

CookieCategoryPurposeDuration
meroi_consentStrictly necessaryRemembers your cookie choice so we do not ask again. Set only once you have made a choice.6 months
_ga, _ga_<id>Analytics (optional)Google Analytics 4 — distinguishes visitors so we can count visits and see which pages are useful. Set only after you accept.13 months

Until you make a choice, no cookie is stored on your device at all. If you decline, Google Analytics receives only anonymous, cookieless signals that let us count page views in aggregate — no identifier is stored on your device and you are not recognised across visits.

The spam protection on our contact form (Cloudflare Turnstile) sets no cookie on this website and does not profile visitors.

7.3 Cookie Consent and Control

On your first visit you choose whether to allow analytics cookies. Declining is one click, exactly like accepting.
You may change or withdraw your choice at any time from the cookie preferences link in the site footer, or through your browser settings.
Withdrawing consent deletes the analytics cookies immediately. Declining does not limit any part of this website.

7.4 Retention of Cookie Data

Analytics cookies expire after 13 months; your consent record expires after 6 months (Art. 5 (1)(e)).


8. Your Rights (Arts. 12–23 GDPR)

You have the right to:

  • Access your personal data (Art. 15)

  • Rectify inaccuracies (Art. 16)

  • Request erasure (Art. 17)

  • Restrict processing (Art. 18)

  • Object to processing (Art. 21)

  • Port your data to another controller (Art. 20)

  • Withdraw consent at any time (Art. 7 (3))

To exercise your rights, email contact@meroisecurity.com.
We respond within one month.
You may also lodge a complaint with your national supervisory authority or the Dutch Data Protection Authority (Autoriteit Persoonsgegevens).


9. Children Under 16

Our services are not intended for minors under 16. If you believe we have collected data from a child without consent, please contact us immediately.


10. Changes to This Policy

We may update this Policy to reflect legal or technical developments.
The latest version is always available at www.meroisecurity.com.
Significant changes will be announced on the website.


11. Contact for Privacy Matters

Meroi Security
Pastoor van Arslaan 6A, 5622 CK Eindhoven, The Netherlands
Phone: +886 979-192-891
Email: contact@meroisecurity.com