Privacy Policy
Introduction
Pro CISO® B.V. is committed to safeguarding the personal information of our leads, customers, and website visitors. This policy explains what data we collect, why we collect it, how we use it, and your rights under the General Data Protection Regulation (GDPR).
This policy governs data collected via our website (prociso.com) and professional platforms such as LinkedIn, in connection with requests for quotes, product trials, and service delivery.
Information We Collect
We collect personal data directly from you when you interact with us. This includes:
- Contact details: name, postal address, email address, phone number
- Company name and job title
- Any additional information you voluntarily provide when submitting a request or enquiry
We do not collect sensitive personal data (special categories under GDPR Article 9) through our website.
Purpose of Processing
We use your personal data solely for the following purposes:
- To respond to your enquiries and provide information about our products and services
- To activate trials, demos, and service engagements you have requested
- To fulfil our contractual obligations where a service agreement is in place
- To comply with our legal and regulatory obligations
Legal Basis for Processing
The processing of your personal data is based on your consent, given when you submit a request through our website or LinkedIn. Where we have entered into a contract with you, processing may also be based on contractual necessity (GDPR Article 6(1)(b)). Where required by law, processing is based on a legal obligation (GDPR Article 6(1)(c)).
You may withdraw your consent at any time by contacting us at privacy@prociso.com. Withdrawal does not affect the lawfulness of processing carried out before withdrawal.
Data Sharing and Disclosure
Pro CISO® B.V. does not sell your personal data. We may share data with carefully selected technology partners and sub-processors solely to deliver our services. All partners are required to comply with GDPR and maintain appropriate data protection standards.
We may disclose data where required by law, court order, or competent regulatory authority.
Data Retention
We retain your personal data only for as long as necessary to fulfil the purposes for which it was collected, including satisfying any legal, accounting, or reporting obligations. For prospective customers who did not proceed to engagement, data is retained for a maximum of 24 months from last contact. Data relating to active engagements is retained for 7 years in accordance with Dutch financial record-keeping requirements.
Your Rights Under GDPR
As a data subject under the GDPR, you have the following rights:
- Right of Access - to obtain a copy of the personal data we hold about you
- Right to Rectification - to have inaccurate data corrected without undue delay
- Right to Erasure - to have your data deleted in certain circumstances ("right to be forgotten")
- Right to Restrict Processing - to limit how we use your data in certain circumstances
- Right to Data Portability - to receive your data in a structured, machine-readable format
- Right to Object - to object to processing based on legitimate interests or direct marketing
- Right to Withdraw Consent - at any time, without affecting prior lawful processing
To exercise any of these rights, contact our privacy team at privacy@prociso.com. We will respond within 30 days. You also have the right to lodge a complaint with the Dutch Data Protection Authority (Autoriteit Persoonsgegevens).
Security of Your Personal Data
Pro CISO® B.V. is ISO/IEC 27001:2022 certified. We implement appropriate technical and organisational measures to protect your personal data against unauthorised access, alteration, disclosure, or destruction. These measures are reviewed and updated regularly as part of our Information Security Management System (ISMS).
If you believe you have discovered a security vulnerability in our systems or website, please see our Responsible Disclosure Policy.
Cookies and Analytics
Our website uses only technically necessary session cookies required for the site to function. We also use Google Analytics 4 in cookieless mode (client_storage: none) with IP anonymisation enabled. In this configuration, no _ga cookies are set and no personally identifiable information is sent to Google. Aggregate, anonymous usage data (page views, session counts) is collected solely to improve the website.
Because no cookies are placed and no personal data is transmitted, no consent banner is required under GDPR Recital 30.
Changes to This Policy
Pro CISO® B.V. reserves the right to update this privacy policy at any time. Material changes will be notified via a notice on our website. The effective date at the top of this page reflects the date of the most recent revision.
Contact Us
For any questions regarding this policy or the handling of your personal data, please contact:
Pro CISO® B.V.Van Heuven Goedhartlaan 121
1181KK Amstelveen
The Netherlands
privacy@prociso.com