// LEGAL
Privacy Policy
Last updated: 21 June 2026.
Who we are
Acta Security ("we", "us") is the data controller for personal data processed through this website and our client services. Contact: hello@actasecurity.eu or via our contact form.
What we collect
- Contact form: your email, any name/organisation/subject you provide, your message, an anti-spam timestamp and a proof-of-work bot-check token (ALTCHA, processed entirely in your browser — no data leaves your device for this step), and your IP address (for rate-limiting).
- Booking: if you book an assessment or discovery call, the appointment is handled by meetergo; the details you enter there (name, email, chosen time) are processed by them on our behalf.
- Client portal: your email (for passwordless sign-in), your name, organisation, phone number, country, timezone, and VAT number; the engagement details and intake answers you submit; payment reference data (we receive only the Mollie payment reference and your email from Mollie — full card data is processed by Mollie directly); files you upload; and any reports we deliver to you. Sign-in uses signed, HttpOnly cookies — no passwords are stored.
- SMS notifications: if you provide a phone number in your portal profile, we may send you transactional SMS messages (engagement updates, OTP delivery confirmations). These are sent via Bird B.V. and your phone number is passed to them for that purpose only.
- Live support chat: if you use the live chat widget on the client portal, the conversation (including your name, email, and message content) is processed through our self-hosted Chatwoot instance, which runs on our EU infrastructure.
- File uploads: files you attach to engagements or support tickets are scanned for malware. File content is submitted to VirusTotal (a Google LLC service) for this purpose. Do not upload documents containing highly sensitive personal data unless necessary for your engagement.
- Accounting: when your onboarding is approved, your name, email address, company name, and purchase details are passed to Sage for the creation of your client record and invoice.
- Incident response: only what you choose to send us via our secure contact channels.
- Traffic & security logs: IP address, User-Agent string, request path and response status are processed by our CDN/WAAP provider (Gcore) and retained in our security monitoring system for up to 90 days. This data is used to operate and protect the site and portal, and to detect and block attacks.
We do not use advertising, profiling or third-party analytics/tracking.
Why we process it (legal bases)
- Consent — when you contact us, request a booking, or opt to provide a phone number for SMS alerts.
- Contract — to scope, deliver, and invoice engagements you order through the portal.
- Legitimate interests — to secure the website and portal against abuse, detect and block attacks, prevent spam, and respond to enquiries.
- Legal obligation — where we are required to retain or disclose data by law.
Who processes data for us
We work with EU/EEA-resident providers wherever possible:
- Infomaniak Network SA (Switzerland, EU-adequate) — cloud hosting, email relay (SMTP/IMAP), and object storage for backups and file attachments.
- Gcore Luxembourg S.A. (Luxembourg, EU) — content delivery network (CDN), web application firewall (WAAP), and DDoS protection. All traffic to actasecurity.eu, portal.actasecurity.eu, and chat.actasecurity.eu passes through Gcore edge nodes, which process IP addresses, request headers, and User-Agent strings.
- ALTCHA (self-hosted, EU infrastructure) — proof-of-work bot-check on the contact form and portal sign-in. The challenge is generated and verified entirely on our own servers; no data is sent to any third party for this purpose.
- Mollie B.V. (Netherlands, EU) — payment processing for portal purchases. Mollie acts as an independent controller for PCI purposes; we receive only the payment reference and your email.
- Bird B.V. (Netherlands, EU) — transactional SMS notifications. Your phone number and message content are passed to Bird only when an SMS is sent to you.
- meetergo GmbH (Germany, EU) — appointment booking for discovery and engagement calls.
- Sage Group plc (United Kingdom, adequacy decision) — accounting and invoicing. Client contact details and purchase information are passed to Sage when an engagement is created.
- Google LLC / VirusTotal (USA, SCC) — malware scanning of file uploads. File content is submitted to VirusTotal at upload time; no copy is retained by Google beyond the scan.
We never sell personal data. Where a provider may process data outside the EEA, it is done under appropriate safeguards (Standard Contractual Clauses or an adequacy decision).
How long we keep it
- Contact form enquiries: retained only as long as needed to respond, then deleted.
- Security and traffic logs: automatically purged after 90 days.
- Engagement records and reports: retained for as long as necessary for the purposes described above and any applicable legal or contractual obligations, then securely deleted.
- Portal accounts: kept until you request closure. On closure, personal data is deleted within 30 days.
Your rights
Under the GDPR you may request access, rectification, erasure, restriction, portability, or object to processing, and you may withdraw consent at any time. To exercise these rights, contact privacy@actasecurity.eu. You also have the right to lodge a complaint with your local EU supervisory authority.
How we protect it
Our infrastructure is operated within the EU. Key measures include: TLS 1.2+ encryption in transit; access-controlled, encrypted-at-rest report and attachment storage; passwordless OTP authentication (no stored passwords); all credentials stored in a dedicated secrets management service (OpenStack Barbican), not in configuration files; network-level firewalling (UFW) with Gcore CDN CIDR allowlists; web application firewall and DDoS protection (Gcore WAAP); host-based intrusion detection and automated blocking (CrowdSec); 24/7 security event monitoring via a dedicated SIEM (Wazuh); daily container vulnerability scanning (Trivy); automated encrypted database backups (AES-256) to EU object storage; and a 90-day log retention and purge policy. See our Cookie Policy for cookie details.
Changes & contact
We may update this policy; the "last updated" date will change. Questions: privacy@actasecurity.eu or the contact form.