Privacy Policy
Last updated: 15 September 2026
1. Introduction
Crimson Owl Technologies ("we", "us", "our") is committed to protecting your privacy and personal data. This Privacy Policy explains how we collect, use, store, and protect your personal data when you use our website and services.
We process personal data in accordance with the General Data Protection Regulation (GDPR), the Dutch Implementation Act of the GDPR (Uitvoeringswet AVG), and other applicable data protection laws.
For customers using the Platform Architecture Authority (PAA) platform, we act as a data processor (verwerker) under Article 28 GDPR. Section 7 describes how we act in that role. The binding instrument is our processor agreement: the Data Pro Statement together with the NLdigital Standard Clauses for Processing — see 7.5.
2. Data Controller
The data controller responsible for your personal data is:
Crimson Owl Technologies
KVK (Chamber of Commerce): 99457377
BTW (VAT): NL869000172B01
Email: [email protected]
Our data protection contact is Marc Dekeyser, reachable at [email protected]. For security controls, certifications, and our sub-processor register, visit our Trust Center.
3. What Personal Data We Collect
We may collect and process the following categories of personal data:
3.1 Information You Provide
- Contact information: Name, email address, company name when you contact us or fill out forms
- Communication data: Content of messages you send us via contact forms or email
- Account data: Login credentials and profile information if you use our Platform Architecture Authority (PAA) service
3.2 Information Collected Automatically
- Technical data: IP address, browser type, operating system, device information
- Usage data: Pages visited, time spent on pages, referral source
- Cookie data: Information collected through cookies and similar technologies (see Section 9)
4. Legal Basis for Processing
We process your personal data based on the following legal grounds under Article 6 GDPR:
- Consent (Art. 6(1)(a)): Where you have given explicit consent, such as for marketing communications
- Contract (Art. 6(1)(b)): Where processing is necessary to perform a contract with you or take pre-contractual steps at your request
- Legal obligation (Art. 6(1)(c)): Where we must comply with legal requirements
- Legitimate interests (Art. 6(1)(f)): Where we have a legitimate business interest that does not override your rights, such as improving our services and website security
5. How We Use Your Data
We use your personal data for the following purposes:
- To respond to your inquiries and provide customer support
- To provide and maintain our services, including the PAA platform
- To process transactions and send related information
- To send administrative information, such as service updates
- To improve our website, products, and services
- To detect, prevent, and address technical issues and security threats
- To comply with legal obligations
- To send marketing communications (only with your consent)
6. Data Sharing and Transfers
We do not sell your personal data. We may share your data with:
- Service providers: Third parties who provide services on our behalf (hosting, EU-hosted cookieless website analytics, email delivery), bound by data processing agreements
- Legal requirements: When required by law, regulation, or legal process
- Business transfers: In connection with a merger, acquisition, or sale of assets
International Transfers
Your data is primarily stored and processed within the European Economic Area (EEA). If we transfer data outside the EEA, we ensure appropriate safeguards are in place, such as:
- EU adequacy decisions
- Standard Contractual Clauses (SCCs) approved by the European Commission
- Other valid transfer mechanisms under GDPR
7. Platform Architecture Authority (PAA) — Data Processing Statement
This section applies specifically to customers of the Platform Architecture Authority (PAA) platform. When you use PAA, Crimson Owl Technologies acts as a data processor (verwerker) and you, as the subscribing organisation, act as the data controller (verwerkingsverantwoordelijke). What follows summarises how we act in that role. It is a description, not the agreement itself: the binding instrument is our processor agreement, described in 7.5.
7.1 Data We Process on Your Behalf
When you use PAA, we process the following categories of data on your behalf:
- Azure infrastructure metadata: Resource identifiers, configuration properties, and topology data retrieved via Azure Resource Graph from your connected Azure subscriptions. This data does not include the contents of your workloads, only their configuration and structure.
- Architecture documentation: Documents, assessments, Architecture Decision Records (ADRs), and diagrams generated through the platform. This content is stored in PAA and, where configured, synchronised to your designated GitHub repository or pushed as tickets into your own Jira, ServiceNow or TopDesk instance.
- Conversation data: Input you provide to the AI agents during assessment sessions. This data is processed to generate assessment output and is not used to train AI models.
- Audit logs: Records of actions taken within your workspace, retained according to your subscription plan.
Personal data obtained from you as controller is processed exclusively for the purpose of delivering PAA services to your organisation. It is not shared with other customers, used for our own commercial purposes, or processed for any purpose beyond the scope of the services agreed. All staff with access to customer data are bound by confidentiality obligations.
7.2 How PAA Accesses Your Azure Environment
PAA connects to your Azure environment using a service principal that you create and configure. The service principal is granted Reader role on the target subscription — it can read resource configuration and topology but cannot create, modify, or delete resources. Your service principal credentials are encrypted at rest, under a key derived separately for each customer workspace so that one workspace's credentials cannot be decrypted with another's key.
To be precise about what that does and does not mean: these keys are derived and held by Crimson Owl, not by you. PAA does not offer bring-your-own-key or customer-managed keys, and we are able to decrypt the credentials you supply in order to run assessments. Your control over that access is the service principal itself — you can revoke it at any time by removing the service principal or deleting your workspace, which ends our ability to read your environment regardless of what we hold.
7.3 AI Processing
Assessment content is processed using AI model APIs. Anthropic (Claude) is the provider used for all assessments on the PAA platform. The platform also implements support for OpenAI (GPT), Google (Gemini) and Mistral, but these are not enabled as platform providers and are reachable only where a customer supplies its own API key for that provider.
Two protections apply to this processing. No supported provider uses customer data submitted via API to train its models. In addition, since 17 August 2026 our Anthropic workspace operates under Zero Data Retention: inputs and outputs are not stored after the response is returned, so assessment content is processed and leaves nothing behind at the provider. All data is transmitted over encrypted connections (TLS 1.2 minimum).
7.4 Data Residency
PAA platform infrastructure is hosted across two Azure regions in the EEA: Azure West Europe (Amsterdam, Netherlands) as the primary region and Azure North Europe (Dublin, Ireland) as the secondary region used for geo-redundancy and disaster recovery. Platform operational data — workspace configuration, user accounts, audit logs — remains within these EEA regions. AI inference requests are routed to Anthropic, which processes them in the United States; appropriate safeguards (Standard Contractual Clauses) are in place for that transfer, and under Zero Data Retention the content is not stored after processing. A transfer impact assessment covering this transfer is available on request.
7.5 Data Processing Agreement
All customers using PAA to process personal data are entitled to a processor agreement (verwerkersovereenkomst) under Article 28(3) GDPR. Ours is the NLdigital standard processor agreement in full, in two parts: a Data Pro Statement (Part 1) setting out the specifics of our processing, and the NLdigital Standard Clauses for Processing, March 2025 edition (Part 2). Both parts are attached to our quotations, and the agreement is not complete without either of them. The NLdigital Terms and Conditions 2025 apply to the contract as our general terms and are published on this site; where the processor agreement and Chapter 4 of those Terms overlap, the processor agreement prevails as the parties' express written arrangement under Article 1.2 of the Terms. Standard Contractual Clauses cover the one transfer outside the EEA, described in 7.4. Request the current Data Pro Statement and Standard Clauses from [email protected].
7.6 Sub-processors
A sub-processor is a party we engage to carry out part of our service to you, acting on our instructions. We use the following:
| Sub-processor | Purpose | Location |
|---|---|---|
| Microsoft Azure | Platform hosting, storage, authentication, key management | EU (West Europe + North Europe) |
| Cloudflare | CDN, DDoS protection, and network security | EU (SCCs in place for non-EEA nodes) |
| Anthropic | AI model inference for assessment generation (Claude) — the provider used for all assessments | USA (SCCs in place; Zero Data Retention active) |
| OpenAI | AI model inference (GPT) — not enabled as a platform provider; reachable only with a customer-supplied API key | USA (SCCs in place) |
| AI model inference (Gemini) — not enabled as a platform provider; reachable only with a customer-supplied API key | USA/EU (SCCs in place) | |
| Mistral AI | AI model inference (Mistral) — not enabled as a platform provider; reachable only with a customer-supplied API key | EU (France) |
| Mollie | Payment processing for subscription billing. Mollie acts as our processor for the processing described in its data processing agreement, and as an independent data controller for payment transaction data, fraud prevention and the obligations it carries as a financial institution, including anti-money-laundering and know-your-customer checks | EU (Netherlands) |
| Vanta | Compliance monitoring and security control management | EU |
The three alternative AI providers are disabled at platform level. They process nothing unless you explicitly select one and supply your own API key — an instruction from you, which adds a sub-processor for your workspace only.
We will notify customers of any material changes to this sub-processor list with at least 14 days' advance notice, providing an opportunity to object before the change takes effect. An up-to-date sub-processor register is maintained in our Trust Center.
7.6a Integrations you enable yourself
PAA can deliver its output into systems you operate. These are not sub-processors: they do not act on our instructions, you supply the instance and the credentials, and the delivery happens because you instructed it. We list them so you know where your data can go before you switch anything on.
| Integration | What is sent | Location |
|---|---|---|
| GitHub | Generated documentation, synchronised to a repository you nominate | Determined by your repository |
| Atlassian Jira | Findings, created as issues in your own Jira instance | Determined by your instance |
| ServiceNow | Findings, created as records in your own ServiceNow instance | Determined by your instance |
| TopDesk | Findings, created as calls in your own TopDesk instance | Determined by your instance |
| Webhook endpoint | Event notifications, to a URL you nominate | Determined by you |
Every one of these is off by default and sends nothing until you turn it on. Once you do, the receiving system processes that data under your own responsibility, not ours — including how long it is kept there, who can see it, and where it goes next. Our obligations under Section 7 stop at the point of delivery.
Because these are not sub-processors, making a new integration of this kind available is a change to the product rather than a change to the list in 7.6, and the 14-day notice above does not apply to it. Any such integration is documented before it can be enabled.
7.7 Data Breach Notification
If we discover a personal data breach involving your data, we will notify you without undue delay and no later than 48 hours after becoming aware, so that you — as controller — can assess whether to notify the Autoriteit Persoonsgegevens within the statutory 72-hour window. The decision to notify the supervisory authority or affected data subjects remains your responsibility as controller.
Our breach notification will include, at minimum:
- A description of the incident: nature of the breach, categories and approximate number of affected data subjects and records
- Contact details of our data protection contact for follow-up questions
- The likely consequences and potential impact of the breach
- Measures taken or proposed to address the breach and mitigate its effects
- Recommended steps for you or affected data subjects (e.g., password changes)
We will keep you informed of further developments and, where requested, support you in the notification process to the supervisory authority or data subjects.
7.8 Supporting Data Subject Rights
We provide you with the technical means to fulfil your obligations under GDPR toward data subjects whose data is processed in PAA. This includes:
- Access and portability: Workspace data can be exported in machine-readable format (JSON/CSV) via the PAA platform or on request
- Erasure: Individual records or entire workspaces can be deleted via the platform; upon request we will confirm deletion in writing
- Rectification: You retain full control over data stored in your workspace and can modify it at any time
- Restriction: You can stop further collection yourself, without involving us — disable an Azure connection or an individual subscription, disable the Microsoft 365 connection or an individual data area within it (including Entra ID directory data), or remove a connection entirely. Data already collected is retained; stopping collection and erasing data are separate actions
- Objection: The platform performs no profiling and no automated decision-making about individuals, so an objection concerns the processing you carry out as controller. We act on your instruction as to what follows from it
Requests to exercise data subject rights can be submitted to [email protected]. Where we act as processor, the decision on such a request rests with the customer who is the controller: we forward the request to them without delay and confirm to you that we have done so, within one month. We do not decide such requests ourselves. Where we are the controller — see sections 1 to 6 — we answer the request ourselves, within one month.
7.9 Data Deletion After Contract End
Upon termination of your PAA subscription or workspace, we will delete or render inaccessible all personal data processed on your behalf within 3 months of the end of the agreement, unless a longer retention period is required by law. Prior to deletion, workspace data is available for export in machine-readable format. If a different retention period has been agreed in writing, that period prevails.
Two categories are retained beyond that point. They stay subject to the same security measures and are not processed for any other purpose. We keep them apart here, because one rests on a statutory obligation and the other on a period we set ourselves:
a. Required by law
- AI quality feedback and AI incident records — 3 years from creation, EU AI Act Art. 25
b. A period we set ourselves, and why
- Workspace audit logs — 365 days from creation. No law prescribes this. Audit logging is one of the security measures we owe you under Article 32 GDPR, and a log that is erased on request stops being evidence of who did what. Twelve months is the period our ISMS applies under ISO/IEC 27001:2022 A.8.15, it covers a full audit cycle, and it is the shortest span in which a security question raised after the fact can still be answered. We do not describe this as a legal obligation, because it is not one.
Billing and payment records are handled separately and are not covered by this section. We process those for our own purposes as a controller, not on your behalf as a processor; the seven-year fiscal retention period that applies to them is set out in Section 8.
In practice deletion begins immediately: access is revoked the moment the request is made, and erasure of the underlying data runs directly afterwards. The three months above is an outer limit, not a waiting period.
8. Data Retention
We retain your personal data only for as long as necessary for the purposes described in this policy, or as required by law. Specific retention periods:
- Contact form submissions: 2 years after last contact, unless a business relationship is established
- Customer account data: Duration of the business relationship plus 7 years (Dutch fiscal retention requirement)
- PAA workspace data: Retained for the duration of the active subscription; deleted within 3 months after contract end, except for the two categories listed in Section 7.9
- Workspace audit logs: 365 days from creation — a period we set ourselves as a security measure, explained in Section 7.9(b)
- AI quality feedback and AI incident records: 3 years from creation (EU AI Act Art. 25)
- Marketing consent records: Until consent is withdrawn, plus 3 years for documentation purposes
9. Cookies and Tracking Technologies
This website does not use advertising cookies or tracking cookies. We do not profile visitors and we do not share visitor data with advertising networks. Our website analytics are cookieless and collect no personal data, as described below.
What We Store on Your Device
- Strictly necessary storage: Required for the website to function and to keep it secure. This does not require consent.
- Functional storage: Local browser storage that remembers small things between visits, such as whether you have dismissed this site's cookie notice. This stays in your browser and is not transmitted to us.
You can clear or block this storage through your browser settings. Doing so may reset your preferences but will not otherwise affect the site.
Website Analytics
We measure website traffic using Plausible Analytics, a privacy-preserving analytics service built and hosted in the European Union. Plausible sets no cookies, stores no persistent identifiers, and does not track visitors across sites or devices. It records aggregate statistics only, such as page URLs, referring sites, campaign parameters, approximate country, and browser and device type. No personal data is collected, no visitor profiles are built, and nothing is shared with advertising networks.
Because no information is stored on or read from your device for this purpose, this measurement does not require cookie consent. We rely on our legitimate interest (Art. 6(1)(f) GDPR) in understanding which content is useful. You can object to processing at any time using the contact details in this policy.
10. Your Rights
Under the GDPR, you have the following rights regarding your personal data:
- Right of access (Art. 15): Request a copy of your personal data
- Right to rectification (Art. 16): Request correction of inaccurate data
- Right to erasure (Art. 17): Request deletion of your data ("right to be forgotten")
- Right to restriction (Art. 18): Request limitation of processing
- Right to data portability (Art. 20): Receive your data in a structured, machine-readable format
- Right to object (Art. 21): Object to processing based on legitimate interests or for direct marketing
- Right to withdraw consent (Art. 7): Withdraw consent at any time, without affecting the lawfulness of prior processing
To exercise these rights, please contact our data protection contact Marc Dekeyser at [email protected]. We will respond to your request within one month.
11. Complaints
If you believe we have not handled your personal data properly, you have the right to lodge a complaint with the Dutch Data Protection Authority:
We encourage you to contact us first so we can try to resolve your concerns directly.
12. Data Security
We implement appropriate technical and organisational measures to protect personal data against unauthorised access, alteration, disclosure, or destruction, in accordance with Article 32 GDPR. Our information security management system is aligned with the ISO 27001:2022 standard; certification is in progress. Current security status, controls, and evidence are published in our Trust Center.
Our security measures include, but are not limited to:
- Pseudonymisation and encryption of personal data at rest and in transit (TLS 1.2 minimum)
- Data at rest encrypted with platform-managed keys, with Azure infrastructure encryption (a second, independent layer) enabled on blob storage
- Service principal credentials encrypted under a key derived separately per workspace and held in our Azure Key Vault — see Section 7.2 for what that does and does not mean
- Access controls, role-based authorisation, and multi-factor authentication
- Geo-redundant infrastructure (Azure West Europe + North Europe) to guarantee ongoing availability, integrity, and resilience of processing systems
- Automated backups and tested restore procedures to recover access to personal data in the event of an incident
- Regular security assessments, penetration testing, and vulnerability management
- Confidentiality obligations for all personnel with access to personal data
- Employee training on data protection and information security
We evaluate and update our security measures at least annually and after any significant change to our services or threat landscape, in line with our ISO 27001 management cycle (plan–do–check–act). Results of audits and relevant assurance information are made available to customers on request and through the Trust Center.
13. Children's Privacy
Our services are not directed to individuals under 16 years of age. We do not knowingly collect personal data from children. If you become aware that a child has provided us with personal data, please contact us.
14. Changes to This Policy
We may update this Privacy Policy from time to time. We will notify you of significant changes by posting the new policy on this page and updating the "Last updated" date. We encourage you to review this policy periodically.
15. Contact Us
If you have questions about this Privacy Policy, our data practices, or wish to request a Data Processing Agreement, please contact us:
Crimson Owl Technologies
General: [email protected]
Data protection (Marc Dekeyser): [email protected]
Trust Center: trust.crimsonowl.eu