Privacy Policy
Last updated: 18 March 2026
1. Who we are
Cermus IT B.V. ("Cermus", "we", "us") is the data controller for the personal data processed through this website.
- Chamber of Commerce (CoC): 89607988
- VAT: NL 865038697B01
- Contact: legal inquiry form
- Website: cermus.com
2. Scope
This privacy policy applies to the personal data we collect when you use our get-started pages at cermus.com/get-started, including the qualification form, payment checkout, and booking pages. Cermus provides B2B software development services, including a 14-day validation sprint, full project builds, and retainer engagements.
3. What data we collect
3.1 Data you provide directly
| Data | Purpose |
|---|---|
| Name, email address, company name | Qualifying your enquiry and contacting you about our services |
| Project description and budget range | Assessing project fit |
3.2 Data collected by Stripe during checkout
When you proceed to payment, Stripe, Inc. collects payment information through its Embedded Checkout component. This may include:
- Email address
- Payment card details (card number, expiry, CVC)
- Billing address
- Browser and device metadata for fraud prevention
Stripe processes this data as our data processor and also as an independent controller for its own fraud-prevention and compliance obligations. See Stripe's Privacy Policy.
4. Legal basis for processing
We process your personal data on the following legal grounds under the GDPR:
| Processing activity | Legal basis |
|---|---|
| Payment processing via Stripe | Art. 6(1)(b) — performance of a contract (completing your purchase) |
| Qualification form submissions | Art. 6(1)(b) — pre-contractual steps taken at your request |
| Sending service-related communications | Art. 6(1)(b) — contract performance |
| Compliance with tax and accounting obligations | Art. 6(1)(c) — legal obligation |
5. Cookies and tracking
We do not use analytics cookies, advertising trackers, or third-party tracking scripts on this website.
Stripe may set strictly necessary cookies (e.g., __stripe_mid, __stripe_sid) that are required for fraud detection and to complete the checkout process. These cookies are exempt from consent requirements under ePrivacy rules because they are essential for the service you requested.
6. Who we share data with
| Recipient | Role | Purpose |
|---|---|---|
| Stripe, Inc. | Processor / independent controller | Payment processing, fraud prevention |
| Cal.com | Processor | Scheduling calls via embedded booking widget |
We do not sell your personal data to third parties.
7. International data transfers
Stripe, Inc. is headquartered in the United States. Data transferred to Stripe outside the European Economic Area (EEA) is protected by Standard Contractual Clauses (SCCs) as approved by the European Commission, supplemented by Stripe's additional technical and organisational safeguards. See Stripe's Data Transfers page for details.
8. Data retention
| Data | Retention period |
|---|---|
| Qualification form submissions | 12 months after last contact, unless a contract is entered |
| Customer and payment records | 7 years after the end of the financial year (Dutch fiscal retention obligation) |
| Stripe payment data | Per Stripe's retention policy |
9. Your rights
Under the GDPR you have the right to:
- Access — request a copy of the personal data we hold about you
- Rectification — ask us to correct inaccurate data
- Erasure — ask us to delete your data (subject to legal retention obligations)
- Restriction — ask us to restrict processing in certain circumstances
- Data portability — receive your data in a structured, machine-readable format
- Objection — object to processing based on legitimate interests
To exercise any of these rights, submit a request through our legal inquiry form. We will respond within 30 days.
10. Supervisory authority
If you believe we have not handled your data correctly, you have the right to lodge a complaint with the Dutch Data Protection Authority:
Autoriteit Persoonsgegevens
autoriteitpersoonsgegevens.nl
Telephone: +31 (0)70 888 8500
11. Changes to this policy
We may update this privacy policy from time to time. Material changes will be posted on this page with an updated "Last updated" date. We encourage you to review this page periodically.