THIRTEEN DELTA BOUTIQUE CYBERSECURITY START THE CONVERSATION
PRIVACY

Privacy statement.

Last updated 27 September 2026. This website uses no tracking cookies, runs no analytics and loads nothing from other websites. This page explains the little we do process, and why.

Who is responsible

Thirteen Delta, Oder 20 - Box C0131, 2491 DC Den Haag, the Netherlands (KvK 42105300), is the controller for the personal data described here. Questions: info@thirteen-delta.com.

Visiting this website

We set no cookies and use no analytics, tracking pixels, embedded media or third-party fonts. Nothing on this site is loaded from other websites. Our hosting provider, Vercel, may set a single strictly necessary, short-lived security cookie if it has to verify that a visitor is a real browser while it mitigates an attack; it is not used for tracking.

To deliver the site and keep it secure, Vercel processes standard server logs for us: IP address, time of the request, page requested and browser type. We don't use them to identify or profile visitors. The logs we can see are deleted automatically within a day. Vercel deletes or anonymises the personal data in its own service logs once it no longer needs it to run and secure its service.

When you contact us

If you email us, we process your name, email address, organisation and the content of your message in order to answer you and, if you ask for one, to prepare a proposal. The legal basis is our legitimate interest in responding to your request. We keep this correspondence for as long as it takes to handle your request, and for up to two years after our last contact unless a legal retention duty applies.

When you become a client

For an engagement we process the contact and business details needed for the agreement, delivery, invoicing and our legal obligations. The legal basis is the performance of the contract and, for administrative records, Dutch tax law, which requires us to keep those records for seven years. What we learn about your organisation during an engagement is treated as confidential.

Sharing

We do not sell or trade personal data. We share it only with the service providers we need to run the business, such as Vercel for hosting and our email provider, under processing agreements, and with authorities when the law requires it. Vercel is based in the United States; our agreement with Vercel includes the EU standard contractual clauses for that transfer, and Vercel also takes part in the EU-U.S. Data Privacy Framework. Where another provider processes data outside the European Economic Area, we rely on the safeguards the GDPR requires.

Security

We take appropriate technical and organisational measures to protect personal data. If you find a vulnerability in this website, please report it to info@thirteen-delta.com (see also /.well-known/security.txt).

Your rights

Under the GDPR you may ask for access to your personal data, and for correction, erasure, restriction or transfer of it, and you may object to processing based on our legitimate interest. Email us and we will respond within one month. You also have the right to lodge a complaint with the Dutch data protection authority, the Autoriteit Persoonsgegevens.

Changes

We update this statement when our processing changes. The date at the top shows the current version.

CONTACT

Start the conversation.

A keynote, the First Responder Workshop or its board version, the Board & Executive Workshop, or just a hard question you'd like a straight answer to. Tell us what you're facing and we'll find the right format together, in the Netherlands, abroad or remote. You speak with the expert directly, and in confidence.

info@thirteen-delta.com

Active incident? HOW WE CAN HELP