Politique de confidentialité
Ce document est disponible en anglais. Seule la version anglaise fait foi.
Version: 1.1
Effective Date: 20 Aug, 2025
This privacy statement is updated frequently. Make sure always to check the latest version on our website for the current legal situation. This privacy statement relates to the personal data collected by Passguard B.V. (hereinafter referred to as: Passguard or we) as controller in accordance with the regulations of the GDPR, during your interactions with Passguard. This is, among other things, the case when you visit our website, purchase services and/or products from Passguard, use products offered by Passguard, subscribe to newsletters or when you contact Passguard. Using this website includes placement of cookies by Passguard. Cookies are small text files placed on your computer, tablet or mobile phone when you consult our website. Cookies facilitate and speed up the use of the Passguard website. Read more about cookies in our cookie statement.
1. Contact
For questions about this privacy statement or questions about the processing of your personal data, please do not hesitate to contact Passguard. Passguard B.V. is registered in the trade register of the Chamber of Commerce as number 81993587 and has its registered office in Leusden. You can reach out to Passguard at the address Grasdrogerijweg 47, 3833 BZ, Leusden. Please contact us by e-mail at info@passguard.com or by telephone at +31 85 250 2750.
2. Processing Personal Data
Passguard processes the following categories of personal data, depending on the way you interact with us:
a. Data you provide directly to us (e.g. via website, forms, contact)
- Name, job title, organisation name and address
- Contact details such as email address, phone number, postal address
- Information you provide via forms (e.g. applications, feedback, correspondence)
- Information about services or products you purchase from us
- Communication with Passguard (questions, comments, complaints)
- Technical data when you use our website (IP address, browser information, device identifier, pages visited, social media activity if interacting with our channels)
b. Data processed as part of the Passguard service:
- Personal data leaked through so-called “infostealers” and found on criminal marketplaces. These may include login credentials (username, email address, password), browser session tokens and other identifiers that are relevant to protecting our customers’ security.
- These data are always processed in the context of our service to organisations and are limited to what is necessary for mitigating cyber risks.
3. Purposes for processing personal data
a. Core purposes (legitimate interest / contractual)
- To mitigate cyber risks by identifying and analysing data leaked through infostealers.
- To inform our customer organisations about exposed credentials or risks relevant to their employees.
- To help prevent damage to organisations and individuals resulting from the misuse of stolen data
- To deliver and manage our services and products, including customer support.
- To comply with legal and regulatory obligations.
b. Website and communication purposes (consent / legitimate interest):
- To operate and improve our website and online services.
- To respond to questions, feedback or complaints.
- To send newsletters and product/service updates (only with your consent).
- To carry out satisfaction surveys and improve our communication.
c. Marketing purposes (consent):
- To personalise content, messages and special offers.
- To provide personalised advertisements, based on cookies and similar techniques. (See our cookie statement for details.)
4. Legal bases for processing personal data
Passguard relies on different legal bases under the GDPR, depending on the specific processing activity:
- Legitimate interest (Article 6(1)(f) GDPR): For the core processing of leaked data from infostealers, to protect organisations and their employees against cyber risks. Passguard has conducted a Legitimate Interest Assessment (LIA) to ensure this processing is necessary, proportionate and balanced.
- Performance of a contract (Article 6(1)(b) GDPR): For the delivery of services and products purchased by customer organisations, including related support.
- Consent (Article 6(1)(a) GDPR): For sending newsletters and mailings, for the use of marketing cookies and personalised advertisements, and for any other processing where explicit opt-in is required.
- Legal obligation (Article 6(1)(c) GDPR): Where processing is necessary to comply with legal requirements (e.g. tax, regulatory reporting).
5. Our website and third parties
This privacy statement does not apply to websites of any party that is connected to our websites through links, like social media (Youtube, LinkedIn, Facebook and X). Before using third party websites, please read the privacy statement of these websites in order to understand how they handle your personal data.
6. Sharing personal data
Passguard shares your personal data with business partners and third parties if this is necessary for the performance of a service or for the delivery of the products you have purchased. These partners include, but are not limited to, suppliers, carriers, website managers and financial administration. If third parties process your data on behalf of Passguard, we contract a processing agreement with the party to ensure the same level of security and confidentiality of all your personal data. Passguard remains solely responsible for these data processing operations. Passguard only shares your personal data with associated companies or external service providers outside the European Economic Area (EEA) if legal transfer mechanisms have been respected. Passguard only shares your data with law enforcement authorities and other parties if it is required to do so by law or if it is legally permitted to do so. “For the processing of leaked data (see §2b), Passguard only shares results that are strictly relevant for the customer organisation, in order to mitigate security risks. Raw data is not shared beyond what is necessary for this purpose.”
7. Security
Passguard guarantees a level of security for all data that we store that is appropriate to the risks that are involved. To achieve this, we have implemented appropriate technical and organisational security measures to guarantee the integrity, availability and confidentiality of your personal data. We regularly test and check our systems, make periodic backups, apply encryption, work through encrypted connections and maintain a strict confidentiality policy for our screened employees at all times. If data is transferred to a party outside the EEA, an appropriate equivalent level of security also applies here. Passguard also has a thorough procedure in place in the case of a (possible) data breach.
8. Retention period
Passguard retains your data depending on the purpose for which we received or collect the data and for as long as they are necessary to achieve the purposes described above, unless a legal obligation imposes or permits a longer retention period. Passguard will remove your personal data in a responsible manner when the retention of your personal data is no longer necessary.
9. Your rights on your personal data
You have the right to information about your personal data that we process. These rights are explained in more detail below. Right of access: You have the right to access to the personal data that we process about you. Right to rectification and completion: If you determine that your personal data is no longer correct, you can provide us with the correct data. This also applies if you determine that the data we process about you is incomplete. Right to erasure (right to be forgotten): You have the right to have your personal data erased by Passguard. We will delete your personal data if:
- you have withdrawn your consent to the processing or object to the processing on legitimate grounds (and there is no other legal basis for the processing);
- the personal data have been unlawfully processed;
- the personal data must be erased based on European or national legislation.
Right to restriction: You have the right to restrict the processing of your personal data by Passguard. Restriction means that we are (temporarily) not allowed to process the data. Right to data portability: You have the right to receive your personal data in a structured, commonly used and machine-readable format and to transmit it to another controller without hindrance. Right to object: You can object to the processing of your personal data if it is processed based on legitimate interest. If you believe that a different balance of interests is necessary in your situation, you can report this digitally or in writing (by post) to Passguard. Upon receipt of your objection, we will assess whether this objection is justified. We will cease processing in the event of an objection, unless Passguard has compelling legitimate grounds for the processing that outweigh your interests, rights and freedoms, or if we have to do with a legal claim. Right to human assessment in decisions: You have the right not to be subject to a decision based solely on automated processing, including profiling.
10. Submit request
You can address a specified request regarding your rights to Passguard by using the contact details above under 1, stating your name and address. Passguard will then check your identity before your request can be executed. No costs are involved in exercising your rights, unless requests are considered manifestly unfounded or excessive.
11. Response
Passguard will reply on your request within one month. In the event of a complex request, Passguard can extend this period with two further months. Passguard will always indicate the reason for this extension within one month. In the event of a request for removal, Passguard will remove the personal data as soon as possible, unless and to the extent that the law requires the personal data to be retained or if there are (other) urgent reasons that oppose removal.
12. Complaints
Should you have a complaint about our processing of your personal data or the handling of one of your data subject rights, you can submit this complaint to the Data Protection Officer of Passguard: privacy@passguard.com. You also have the right to submit a complaint to the Autoriteit Persoonsgegevens (Dutch Data Protection Authority). More information can be found here.