Privacy Policy

Last updated: 15 September 2026

1. Introduction

Crimson Owl Technologies ("we", "us", "our") is committed to protecting your privacy and personal data. This Privacy Policy explains how we collect, use, store, and protect your personal data when you use our website and services.

We process personal data in accordance with the General Data Protection Regulation (GDPR), the Dutch Implementation Act of the GDPR (Uitvoeringswet AVG), and other applicable data protection laws.

For customers using the Platform Architecture Authority (PAA) platform, we act as a data processor (verwerker) under Article 28 GDPR. Section 7 describes how we act in that role. The binding instrument is our processor agreement: the Data Pro Statement together with the NLdigital Standard Clauses for Processing — see 7.5.

2. Data Controller

The data controller responsible for your personal data is:

Crimson Owl Technologies

KVK (Chamber of Commerce): 99457377

BTW (VAT): NL869000172B01

Email: [email protected]

Our data protection contact is Marc Dekeyser, reachable at [email protected]. For security controls, certifications, and our sub-processor register, visit our Trust Center.

3. What Personal Data We Collect

We may collect and process the following categories of personal data:

3.1 Information You Provide

  • Contact information: Name, email address, company name when you contact us or fill out forms
  • Communication data: Content of messages you send us via contact forms or email
  • Account data: Login credentials and profile information if you use our Platform Architecture Authority (PAA) service

3.2 Information Collected Automatically

  • Technical data: IP address, browser type, operating system, device information
  • Usage data: Pages visited, time spent on pages, referral source
  • Cookie data: Information collected through cookies and similar technologies (see Section 9)

4. Legal Basis for Processing

We process your personal data based on the following legal grounds under Article 6 GDPR:

  • Consent (Art. 6(1)(a)): Where you have given explicit consent, such as for marketing communications
  • Contract (Art. 6(1)(b)): Where processing is necessary to perform a contract with you or take pre-contractual steps at your request
  • Legal obligation (Art. 6(1)(c)): Where we must comply with legal requirements
  • Legitimate interests (Art. 6(1)(f)): Where we have a legitimate business interest that does not override your rights, such as improving our services and website security

5. How We Use Your Data

We use your personal data for the following purposes:

  • To respond to your inquiries and provide customer support
  • To provide and maintain our services, including the PAA platform
  • To process transactions and send related information
  • To send administrative information, such as service updates
  • To improve our website, products, and services
  • To detect, prevent, and address technical issues and security threats
  • To comply with legal obligations
  • To send marketing communications (only with your consent)

6. Data Sharing and Transfers

We do not sell your personal data. We may share your data with:

  • Service providers: Third parties who provide services on our behalf (hosting, EU-hosted cookieless website analytics, email delivery), bound by data processing agreements
  • Legal requirements: When required by law, regulation, or legal process
  • Business transfers: In connection with a merger, acquisition, or sale of assets

International Transfers

Your data is primarily stored and processed within the European Economic Area (EEA). If we transfer data outside the EEA, we ensure appropriate safeguards are in place, such as:

  • EU adequacy decisions
  • Standard Contractual Clauses (SCCs) approved by the European Commission
  • Other valid transfer mechanisms under GDPR

7. Platform Architecture Authority (PAA) — Data Processing Statement

This section applies specifically to customers of the Platform Architecture Authority (PAA) platform. When you use PAA, Crimson Owl Technologies acts as a data processor (verwerker) and you, as the subscribing organisation, act as the data controller (verwerkingsverantwoordelijke). What follows summarises how we act in that role. It is a description, not the agreement itself: the binding instrument is our processor agreement, described in 7.5.

7.1 Data We Process on Your Behalf

When you use PAA, we process the following categories of data on your behalf:

  • Azure infrastructure metadata: Resource identifiers, configuration properties, and topology data retrieved via Azure Resource Graph from your connected Azure subscriptions. This data does not include the contents of your workloads, only their configuration and structure.
  • Architecture documentation: Documents, assessments, Architecture Decision Records (ADRs), and diagrams generated through the platform. This content is stored in PAA and, where configured, synchronised to your designated GitHub repository or pushed as tickets into your own Jira, ServiceNow or TopDesk instance.
  • Conversation data: Input you provide to the AI agents during assessment sessions. This data is processed to generate assessment output and is not used to train AI models.
  • Audit logs: Records of actions taken within your workspace, retained according to your subscription plan.

Personal data obtained from you as controller is processed exclusively for the purpose of delivering PAA services to your organisation. It is not shared with other customers, used for our own commercial purposes, or processed for any purpose beyond the scope of the services agreed. All staff with access to customer data are bound by confidentiality obligations.

7.2 How PAA Accesses Your Azure Environment

PAA connects to your Azure environment using a service principal that you create and configure. The service principal is granted Reader role on the target subscription — it can read resource configuration and topology but cannot create, modify, or delete resources. Your service principal credentials are encrypted at rest, under a key derived separately for each customer workspace so that one workspace's credentials cannot be decrypted with another's key.

To be precise about what that does and does not mean: these keys are derived and held by Crimson Owl, not by you. PAA does not offer bring-your-own-key or customer-managed keys, and we are able to decrypt the credentials you supply in order to run assessments. Your control over that access is the service principal itself — you can revoke it at any time by removing the service principal or deleting your workspace, which ends our ability to read your environment regardless of what we hold.

7.3 AI Processing

Assessment content is processed using AI model APIs. Anthropic (Claude) is the provider used for all assessments on the PAA platform. The platform also implements support for OpenAI (GPT), Google (Gemini) and Mistral, but these are not enabled as platform providers and are reachable only where a customer supplies its own API key for that provider.

Two protections apply to this processing. No supported provider uses customer data submitted via API to train its models. In addition, since 17 August 2026 our Anthropic workspace operates under Zero Data Retention: inputs and outputs are not stored after the response is returned, so assessment content is processed and leaves nothing behind at the provider. All data is transmitted over encrypted connections (TLS 1.2 minimum).

7.4 Data Residency

PAA platform infrastructure is hosted across two Azure regions in the EEA: Azure West Europe (Amsterdam, Netherlands) as the primary region and Azure North Europe (Dublin, Ireland) as the secondary region used for geo-redundancy and disaster recovery. Platform operational data — workspace configuration, user accounts, audit logs — remains within these EEA regions. AI inference requests are routed to Anthropic, which processes them in the United States; appropriate safeguards (Standard Contractual Clauses) are in place for that transfer, and under Zero Data Retention the content is not stored after processing. A transfer impact assessment covering this transfer is available on request.

7.5 Data Processing Agreement

All customers using PAA to process personal data are entitled to a processor agreement (verwerkersovereenkomst) under Article 28(3) GDPR. Ours is the NLdigital standard processor agreement in full, in two parts: a Data Pro Statement (Part 1) setting out the specifics of our processing, and the NLdigital Standard Clauses for Processing, March 2025 edition (Part 2). Both parts are attached to our quotations, and the agreement is not complete without either of them. The NLdigital Terms and Conditions 2025 apply to the contract as our general terms and are published on this site; where the processor agreement and Chapter 4 of those Terms overlap, the processor agreement prevails as the parties' express written arrangement under Article 1.2 of the Terms. Standard Contractual Clauses cover the one transfer outside the EEA, described in 7.4. Request the current Data Pro Statement and Standard Clauses from [email protected].

7.6 Sub-processors

A sub-processor is a party we engage to carry out part of our service to you, acting on our instructions. We use the following:

Sub-processor Purpose Location
Microsoft Azure Platform hosting, storage, authentication, key management EU (West Europe + North Europe)
Cloudflare CDN, DDoS protection, and network security EU (SCCs in place for non-EEA nodes)
Anthropic AI model inference for assessment generation (Claude) — the provider used for all assessments USA (SCCs in place; Zero Data Retention active)
OpenAI AI model inference (GPT) — not enabled as a platform provider; reachable only with a customer-supplied API key USA (SCCs in place)
Google AI model inference (Gemini) — not enabled as a platform provider; reachable only with a customer-supplied API key USA/EU (SCCs in place)
Mistral AI AI model inference (Mistral) — not enabled as a platform provider; reachable only with a customer-supplied API key EU (France)
Mollie Payment processing for subscription billing. Mollie acts as our processor for the processing described in its data processing agreement, and as an independent data controller for payment transaction data, fraud prevention and the obligations it carries as a financial institution, including anti-money-laundering and know-your-customer checks EU (Netherlands)
Vanta Compliance monitoring and security control management EU

The three alternative AI providers are disabled at platform level. They process nothing unless you explicitly select one and supply your own API key — an instruction from you, which adds a sub-processor for your workspace only.

We will notify customers of any material changes to this sub-processor list with at least 14 days' advance notice, providing an opportunity to object before the change takes effect. An up-to-date sub-processor register is maintained in our Trust Center.

7.6a Integrations you enable yourself

PAA can deliver its output into systems you operate. These are not sub-processors: they do not act on our instructions, you supply the instance and the credentials, and the delivery happens because you instructed it. We list them so you know where your data can go before you switch anything on.

Integration What is sent Location
GitHub Generated documentation, synchronised to a repository you nominate Determined by your repository
Atlassian Jira Findings, created as issues in your own Jira instance Determined by your instance
ServiceNow Findings, created as records in your own ServiceNow instance Determined by your instance
TopDesk Findings, created as calls in your own TopDesk instance Determined by your instance
Webhook endpoint Event notifications, to a URL you nominate Determined by you

Every one of these is off by default and sends nothing until you turn it on. Once you do, the receiving system processes that data under your own responsibility, not ours — including how long it is kept there, who can see it, and where it goes next. Our obligations under Section 7 stop at the point of delivery.

Because these are not sub-processors, making a new integration of this kind available is a change to the product rather than a change to the list in 7.6, and the 14-day notice above does not apply to it. Any such integration is documented before it can be enabled.

7.7 Data Breach Notification

If we discover a personal data breach involving your data, we will notify you without undue delay and no later than 48 hours after becoming aware, so that you — as controller — can assess whether to notify the Autoriteit Persoonsgegevens within the statutory 72-hour window. The decision to notify the supervisory authority or affected data subjects remains your responsibility as controller.

Our breach notification will include, at minimum:

  • A description of the incident: nature of the breach, categories and approximate number of affected data subjects and records
  • Contact details of our data protection contact for follow-up questions
  • The likely consequences and potential impact of the breach
  • Measures taken or proposed to address the breach and mitigate its effects
  • Recommended steps for you or affected data subjects (e.g., password changes)

We will keep you informed of further developments and, where requested, support you in the notification process to the supervisory authority or data subjects.

7.8 Supporting Data Subject Rights

We provide you with the technical means to fulfil your obligations under GDPR toward data subjects whose data is processed in PAA. This includes:

  • Access and portability: Workspace data can be exported in machine-readable format (JSON/CSV) via the PAA platform or on request
  • Erasure: Individual records or entire workspaces can be deleted via the platform; upon request we will confirm deletion in writing
  • Rectification: You retain full control over data stored in your workspace and can modify it at any time
  • Restriction: You can stop further collection yourself, without involving us — disable an Azure connection or an individual subscription, disable the Microsoft 365 connection or an individual data area within it (including Entra ID directory data), or remove a connection entirely. Data already collected is retained; stopping collection and erasing data are separate actions
  • Objection: The platform performs no profiling and no automated decision-making about individuals, so an objection concerns the processing you carry out as controller. We act on your instruction as to what follows from it

Requests to exercise data subject rights can be submitted to [email protected]. Where we act as processor, the decision on such a request rests with the customer who is the controller: we forward the request to them without delay and confirm to you that we have done so, within one month. We do not decide such requests ourselves. Where we are the controller — see sections 1 to 6 — we answer the request ourselves, within one month.

7.9 Data Deletion After Contract End

Upon termination of your PAA subscription or workspace, we will delete or render inaccessible all personal data processed on your behalf within 3 months of the end of the agreement, unless a longer retention period is required by law. Prior to deletion, workspace data is available for export in machine-readable format. If a different retention period has been agreed in writing, that period prevails.

Two categories are retained beyond that point. They stay subject to the same security measures and are not processed for any other purpose. We keep them apart here, because one rests on a statutory obligation and the other on a period we set ourselves:

a. Required by law

  • AI quality feedback and AI incident records — 3 years from creation, EU AI Act Art. 25

b. A period we set ourselves, and why

  • Workspace audit logs — 365 days from creation. No law prescribes this. Audit logging is one of the security measures we owe you under Article 32 GDPR, and a log that is erased on request stops being evidence of who did what. Twelve months is the period our ISMS applies under ISO/IEC 27001:2022 A.8.15, it covers a full audit cycle, and it is the shortest span in which a security question raised after the fact can still be answered. We do not describe this as a legal obligation, because it is not one.

Billing and payment records are handled separately and are not covered by this section. We process those for our own purposes as a controller, not on your behalf as a processor; the seven-year fiscal retention period that applies to them is set out in Section 8.

In practice deletion begins immediately: access is revoked the moment the request is made, and erasure of the underlying data runs directly afterwards. The three months above is an outer limit, not a waiting period.

8. Data Retention

We retain your personal data only for as long as necessary for the purposes described in this policy, or as required by law. Specific retention periods:

  • Contact form submissions: 2 years after last contact, unless a business relationship is established
  • Customer account data: Duration of the business relationship plus 7 years (Dutch fiscal retention requirement)
  • PAA workspace data: Retained for the duration of the active subscription; deleted within 3 months after contract end, except for the two categories listed in Section 7.9
  • Workspace audit logs: 365 days from creation — a period we set ourselves as a security measure, explained in Section 7.9(b)
  • AI quality feedback and AI incident records: 3 years from creation (EU AI Act Art. 25)
  • Marketing consent records: Until consent is withdrawn, plus 3 years for documentation purposes

9. Cookies and Tracking Technologies

This website does not use advertising cookies or tracking cookies. We do not profile visitors and we do not share visitor data with advertising networks. Our website analytics are cookieless and collect no personal data, as described below.

What We Store on Your Device

  • Strictly necessary storage: Required for the website to function and to keep it secure. This does not require consent.
  • Functional storage: Local browser storage that remembers small things between visits, such as whether you have dismissed this site's cookie notice. This stays in your browser and is not transmitted to us.

You can clear or block this storage through your browser settings. Doing so may reset your preferences but will not otherwise affect the site.

Website Analytics

We measure website traffic using Plausible Analytics, a privacy-preserving analytics service built and hosted in the European Union. Plausible sets no cookies, stores no persistent identifiers, and does not track visitors across sites or devices. It records aggregate statistics only, such as page URLs, referring sites, campaign parameters, approximate country, and browser and device type. No personal data is collected, no visitor profiles are built, and nothing is shared with advertising networks.

Because no information is stored on or read from your device for this purpose, this measurement does not require cookie consent. We rely on our legitimate interest (Art. 6(1)(f) GDPR) in understanding which content is useful. You can object to processing at any time using the contact details in this policy.

10. Your Rights

Under the GDPR, you have the following rights regarding your personal data:

  • Right of access (Art. 15): Request a copy of your personal data
  • Right to rectification (Art. 16): Request correction of inaccurate data
  • Right to erasure (Art. 17): Request deletion of your data ("right to be forgotten")
  • Right to restriction (Art. 18): Request limitation of processing
  • Right to data portability (Art. 20): Receive your data in a structured, machine-readable format
  • Right to object (Art. 21): Object to processing based on legitimate interests or for direct marketing
  • Right to withdraw consent (Art. 7): Withdraw consent at any time, without affecting the lawfulness of prior processing

To exercise these rights, please contact our data protection contact Marc Dekeyser at [email protected]. We will respond to your request within one month.

11. Complaints

If you believe we have not handled your personal data properly, you have the right to lodge a complaint with the Dutch Data Protection Authority:

Autoriteit Persoonsgegevens

Postbus 93374

2509 AJ Den Haag

Website: autoriteitpersoonsgegevens.nl

We encourage you to contact us first so we can try to resolve your concerns directly.

12. Data Security

We implement appropriate technical and organisational measures to protect personal data against unauthorised access, alteration, disclosure, or destruction, in accordance with Article 32 GDPR. Our information security management system is aligned with the ISO 27001:2022 standard; certification is in progress. Current security status, controls, and evidence are published in our Trust Center.

Our security measures include, but are not limited to:

  • Pseudonymisation and encryption of personal data at rest and in transit (TLS 1.2 minimum)
  • Data at rest encrypted with platform-managed keys, with Azure infrastructure encryption (a second, independent layer) enabled on blob storage
  • Service principal credentials encrypted under a key derived separately per workspace and held in our Azure Key Vault — see Section 7.2 for what that does and does not mean
  • Access controls, role-based authorisation, and multi-factor authentication
  • Geo-redundant infrastructure (Azure West Europe + North Europe) to guarantee ongoing availability, integrity, and resilience of processing systems
  • Automated backups and tested restore procedures to recover access to personal data in the event of an incident
  • Regular security assessments, penetration testing, and vulnerability management
  • Confidentiality obligations for all personnel with access to personal data
  • Employee training on data protection and information security

We evaluate and update our security measures at least annually and after any significant change to our services or threat landscape, in line with our ISO 27001 management cycle (plan–do–check–act). Results of audits and relevant assurance information are made available to customers on request and through the Trust Center.

13. Children's Privacy

Our services are not directed to individuals under 16 years of age. We do not knowingly collect personal data from children. If you become aware that a child has provided us with personal data, please contact us.

14. Changes to This Policy

We may update this Privacy Policy from time to time. We will notify you of significant changes by posting the new policy on this page and updating the "Last updated" date. We encourage you to review this policy periodically.

15. Contact Us

If you have questions about this Privacy Policy, our data practices, or wish to request a Data Processing Agreement, please contact us:

Crimson Owl Technologies

General: [email protected]

Data protection (Marc Dekeyser): [email protected]

Trust Center: trust.crimsonowl.eu