Privacy Policy
Last updated: 2026-08-05
This Privacy Policy explains how Cermus ("we", "us", "our") collects, uses, stores, and protects personal data of visitors to our website www.cermus.com and prospective or existing clients. We process personal data in accordance with the EU General Data Protection Regulation (GDPR) and the Dutch implementation act (UAVG).
This is our only privacy policy. It applies to every part of our website,
including the "Get started" funnel and our checkout pages at
secure-checkout.cermus.com.
1. Data controller
Cermus IT B.V.
Heerderweg 59c, 6224 LG Maastricht, The Netherlands
KVK 89607988 · VAT NL865038697B01
For any data protection question, exercise of rights, or complaint, please contact us through our legal inquiry form. The form reaches our privacy contact directly and is the fastest route to a reply; we acknowledge every submission within two working days and answer substantively within one month, in line with Art. 12(3) GDPR. If a request is complex we may extend that period by two further months and will tell you so, with reasons, within the first month.
We are not required to appoint a Data Protection Officer under Art. 37 GDPR and have not appointed one. Privacy matters are handled by the contact route above.
2. What data we collect and why
2.1 Strictly necessary (no consent required)
A minimum set of technical data is processed on the basis of our legitimate
interest to operate and secure the website (Art. 6(1)(f) GDPR): server
access logs (IP address, user-agent, request path, timestamp) retained for
up to 14 days for security monitoring, and your cookie-consent preference
stored under the key cermus-consent in your browser's
localStorage and in a first-party cookie on
.cermus.com, so your choice carries across our www and
checkout subdomains and does not have to be asked twice.
2.2 Anonymous analytics — PostHog (no consent required)
On the basis of our legitimate interest in understanding how visitors use our website (Art. 6(1)(f) GDPR), and on the conditions of art. 11.7a(3) Telecommunicatiewet for measurement with no or limited impact on privacy, we use PostHog (hosted on EU Cloud, Frankfurt, by PostHog Inc.) in cookieless mode: no cookies are set, no persistent identifiers are stored in your browser, no cross-site tracking occurs, and your IP address is not stored as an event property.
We record page views and page leaves, and interaction events such as clicks on links and buttons. An interaction event records which element you clicked, its visible label, and the page you were on — for example that someone clicked a button labelled "Get started" on the home page. We do not record the contents of form fields, and we do not capture screen recordings. Because the events carry no cookie, no device identifier and no directly identifying data, they cannot be traced back to you as an individual.
Data is kept for up to 12 months, never sold, and never enriched with personal data you submit. You can object to this processing at any time through our legal inquiry form. See PostHog privacy policy.
When an order is completed, our systems additionally record a server-side purchase event in the same PostHog project for aggregate revenue measurement (order number, amount, currency and product). This event is keyed on the internal order number only — it contains no name or e-mail address and is not linked to your browsing activity. Legal basis: our legitimate interest in measuring sales of our own services (Art. 6(1)(f) GDPR).
2.3 Marketing — Meta Pixel (consent required)
With your consent (Art. 6(1)(a) GDPR) we use the Meta Pixel
(Meta Platforms Ireland Ltd.) to measure the effectiveness of our
advertising on Meta platforms (Facebook, Instagram) and to build
audiences for retargeting. The Meta Pixel sends pseudonymised identifiers
(_fbp, _fbc) to Meta along with the URL of the
page you visited. Retention and further processing are governed by Meta.
See Meta privacy policy.
If you have given this consent, we also send Meta a matching event directly from our servers (the Meta "Conversions API"), so that a single action is measured reliably even when the browser request does not arrive. The two events describe the same action and are de-duplicated by a shared event identifier — they do not double-count you. This server-side event is sent only where you have given marketing consent; without it, no event leaves our systems.
The server-side event carries: your e-mail address, phone number, first
and last name and country, each irreversibly hashed
(SHA-256) before it is sent, so Meta receives a fingerprint
rather than the value itself; together with your IP address,
browser user agent and the _fbp / _fbc
identifiers, which Meta's specification requires to be sent unhashed. We
store those same items on your enquiry or order record so the event can
be sent and retried; they follow the retention periods in section 6.
Transfers to Meta may involve a transfer to the United States. Meta participates in the EU-US Data Privacy Framework; where additional safeguards are required we rely on the European Commission's Standard Contractual Clauses.
2.4 Enquiries, quotes and the "Get started" funnel
When you complete a form we process the data you provide — typically name, business e-mail address, company name, phone number and your project description and budget range — on the basis of steps taken at your request prior to entering into a contract (Art. 6(1)(b) GDPR).
Providing this data is not a statutory or contractual obligation, and you are free not to provide it. It is, however, necessary for us to answer your enquiry or prepare a quote: if you do not provide it, we cannot respond to you. We keep enquiry data for 24 months after our last contact with you, unless a contract is concluded, in which case the retention periods in section 6 apply.
We use these details to contact you about your enquiry. If you begin the "Get started" funnel and do not finish it, we may send you an automated reminder e-mail, on the basis of the same pre-contractual interest.
2.5 Marketing communications (consent required)
If you separately tick the newsletter or WhatsApp box, we send you commercial updates about our services on the basis of your consent (Art. 6(1)(a) GDPR and art. 11.7 Telecommunicatiewet). These boxes are never pre-ticked, and ticking them is never a condition of anything else. You can withdraw your consent at any time — via the unsubscribe link in every e-mail, by replying STOP to a WhatsApp message, or through our legal inquiry form — without affecting the lawfulness of processing carried out before withdrawal. WhatsApp messages are delivered through WhatsApp Ireland Ltd. (Meta).
We record which consent wording you agreed to and when, so that we can demonstrate the consent was validly obtained (Art. 7(1) GDPR).
2.6 Orders and payments
If you place an order we process your name, business contact details, company and business registration details, order contents and payment status in order to perform the contract (Art. 6(1)(b) GDPR) and to meet our tax and accounting obligations (Art. 6(1)(c) GDPR). Card details are entered directly into Stripe's checkout component and are never received or stored by us.
2.7 Data we receive from other sources
If you submit an advertising lead form on Facebook or Instagram, Meta passes us the contact details you entered there — typically your name, e-mail address and phone number — and we import them into our CRM. We use them for the same purposes and on the same legal basis as section 2.4. Where we obtain your data this way rather than directly from you, we inform you of it at the latest when we first contact you, in line with Art. 14 GDPR.
2.8 Meetings, recordings and notes
We meet clients and prospects over Microsoft Teams. Where a meeting is recorded or transcribed, Teams shows every participant a notification at the time — nothing is recorded covertly, and you can ask us not to record before or during the call.
From those meetings we keep a written summary only: who attended, the date and subject, the decisions taken and the dated action points. We do not keep the raw transcript or the recording in our own systems — only the summary is retained. We do this on the basis of our legitimate interest in an accurate record of what was discussed and agreed (Art. 6(1)(f) GDPR), which protects both sides when a question comes up later about scope or commitments.
We keep meeting summaries for the duration of the engagement and 24 months thereafter; for meetings that do not lead to an engagement, 24 months from the meeting. You can object to this processing, or ask for a summary of a meeting you attended to be corrected or deleted, through our legal inquiry form.
3. Cookies and similar technologies
PostHog anonymous analytics (section 2.2) set no cookies and store nothing in your browser. The only non-essential technology that places cookies is the Meta Pixel, and it is blocked by our consent manager until you explicitly allow it. You can give, refuse, or change your consent at any time via the "Cookie settings" link in the footer.
Two further third-party components load only on the specific pages that need them: the Cal.com booking widget on our booking page, and Cloudflare Turnstile on our legal inquiry form. Both are necessary to deliver the function you asked for on that page — you cannot book a call without the booking widget, and the form cannot be protected from automated abuse without Turnstile — so they are not gated by the consent banner. Both providers may set storage on their own domains; if you prefer not to use them, do not visit the booking page, and contact us by post instead of through the form.
| Service | Purpose | Category | Provider |
|---|---|---|---|
| PostHog (cookieless) | Website measurement — no cookies, no device identifiers | Exempt measurement | PostHog Inc. (EU Cloud, Frankfurt) |
| Meta Pixel | Ad attribution, retargeting | Marketing (consent required) | Meta Platforms Ireland Ltd. |
| Cal.com booking widget | Scheduling an intro call — loads only on /get-started/book-a-call | Functional | Cal.com, Inc. |
| Cloudflare Turnstile | Bot protection — loads only on /legal-contact | Strictly necessary | Cloudflare, Inc. |
Stripe (__stripe_mid, __stripe_sid) | Fraud detection and completing your payment — set on our checkout pages at secure-checkout.cermus.com | Strictly necessary | Stripe Payments Europe Ltd. / Stripe, Inc. |
4. Who we share data with
We do not sell personal data and we do not share it for other organisations' own marketing. We share it only with the service providers below, each of which processes it on our documented instructions under a data processing agreement, except where stated otherwise.
| Recipient | Purpose | Data location |
|---|---|---|
| Microsoft Ireland Operations Ltd. (Azure) | Hosting of our website, APIs and database | EU (West Europe) |
| Microsoft Ireland Operations Ltd. (Microsoft 365) | Business e-mail and calendar correspondence with you | EU |
| HubSpot, Inc. | CRM — storing your enquiry and managing our follow-up | EU / United States |
| Stripe Payments Europe Ltd. / Stripe, Inc. | Payment processing and fraud prevention. Stripe also acts as an independent controller for its own fraud, anti-money-laundering and regulatory obligations. | EU / United States |
| Moneybird B.V. | Invoicing and accounting records | EU (Netherlands) |
| Cal.com, Inc. | Scheduling intro calls | EU / United States |
| Cloudflare, Inc. | Bot protection on our forms | EU / United States |
| PostHog, Inc. | Cookieless website measurement | EU Cloud (Frankfurt) |
| Meta Platforms Ireland Ltd. | Advertising measurement and retargeting; WhatsApp delivery | EU / United States |
We also disclose personal data to our accountant, and to the Belastingdienst or other competent authorities where we are legally required to do so.
5. International data transfers
Our own systems run in the European Union. Where a recipient listed above processes personal data outside the European Economic Area, that transfer is covered by the European Commission's adequacy decision for the EU-US Data Privacy Framework where the recipient participates in it, and otherwise by the European Commission's Standard Contractual Clauses together with the recipient's supplementary technical and organisational measures. Where a recipient participates in the Data Privacy Framework we also maintain Standard Contractual Clauses as a fallback mechanism. You can request details of the safeguards applied to a specific transfer through our legal inquiry form.
6. Data retention
| Data | Retention period |
|---|---|
| Server access logs | 14 days |
| Cookieless analytics events | 12 months |
| Enquiry and funnel submissions where no contract follows | 24 months after last contact |
| CRM records for clients | Duration of the engagement, then 24 months |
| Invoices, orders and payment records | 7 years (art. 52 Algemene wet inzake rijksbelastingen) |
| Business correspondence | 7 years where it forms part of our accounting records, otherwise 24 months |
| Meeting summaries (section 2.8) | Duration of the engagement, then 24 months; 24 months from the meeting where no engagement follows |
| Marketing consent records | Until withdrawal, then 3 years as evidence of consent |
After these periods the data is deleted or irreversibly anonymised.
7. Automated decision-making and profiling
We group enquiries into follow-up categories based on the answers you give us in the funnel, so that the e-mails we send you are relevant to what you asked about. This is profiling within the meaning of Art. 4(4) GDPR, and it affects only which messages you receive.
We do not carry out automated decision-making that produces legal effects concerning you or similarly significantly affects you within the meaning of Art. 22 GDPR. Every decision about whether to work with you, on what terms and at what price is taken by a person.
8. Your rights under GDPR
Under Articles 15–22 GDPR you have the right to:
- Access the personal data we hold about you.
- Rectification of inaccurate or incomplete data.
- Erasure ("right to be forgotten") where applicable.
- Restriction of processing.
- Data portability in a structured, machine-readable format.
- Object to processing based on legitimate interest.
- Withdraw consent at any time without affecting the lawfulness of prior processing.
To exercise any of these rights, submit a request through our legal inquiry form. You also have the right to lodge a complaint with the Dutch Data Protection Authority (Autoriteit Persoonsgegevens, autoriteitpersoonsgegevens.nl) or your local supervisory authority.
9. Security
We apply technical and organisational measures appropriate to the risk, including TLS encryption in transit, encryption at rest on our cloud provider, least-privilege access controls, and regular security monitoring. No method of transmission or storage is 100% secure, but we strive to protect your data to industry standards.
10. Changes to this policy
We may update this Privacy Policy to reflect changes in our services or applicable law. Material changes will be communicated via the website. The date at the top of this page indicates the most recent revision.
11. Manage your cookie preferences
You can update your cookie consent at any time:
This document is provided for transparency and GDPR compliance. For tailored legal advice consult qualified counsel.
For privacy or GDPR-related requests, please use our legal inquiry form.