What we do
Case studies
See If You Qualify
/ What we do
New ProductsInternal ToolsPractical AI
/ Case studies
VattenfallEasyEnergy
All case studies
See If You Qualify
Privacy PolicyTerms & ConditionsSecurity
/ New Products / Internal Tools / Practical AI
/ Vattenfall / EasyEnergy / View all case studies
Privacy PolicyTerms & ConditionsSecurity
Vattenfall case
EasyEnergy case

Privacy Policy

Last updated: 2026-08-05

This Privacy Policy explains how Cermus ("we", "us", "our") collects, uses, stores, and protects personal data of visitors to our website www.cermus.com and prospective or existing clients. We process personal data in accordance with the EU General Data Protection Regulation (GDPR) and the Dutch implementation act (UAVG).

This is our only privacy policy. It applies to every part of our website, including the "Get started" funnel and our checkout pages at secure-checkout.cermus.com.

1. Data controller

Cermus IT B.V.
Heerderweg 59c, 6224 LG Maastricht, The Netherlands
KVK 89607988 · VAT NL865038697B01

For any data protection question, exercise of rights, or complaint, please contact us through our legal inquiry form. The form reaches our privacy contact directly and is the fastest route to a reply; we acknowledge every submission within two working days and answer substantively within one month, in line with Art. 12(3) GDPR. If a request is complex we may extend that period by two further months and will tell you so, with reasons, within the first month.

We are not required to appoint a Data Protection Officer under Art. 37 GDPR and have not appointed one. Privacy matters are handled by the contact route above.

2. What data we collect and why

2.1 Strictly necessary (no consent required)

A minimum set of technical data is processed on the basis of our legitimate interest to operate and secure the website (Art. 6(1)(f) GDPR): server access logs (IP address, user-agent, request path, timestamp) retained for up to 14 days for security monitoring, and your cookie-consent preference stored under the key cermus-consent in your browser's localStorage and in a first-party cookie on .cermus.com, so your choice carries across our www and checkout subdomains and does not have to be asked twice.

2.2 Anonymous analytics — PostHog (no consent required)

On the basis of our legitimate interest in understanding how visitors use our website (Art. 6(1)(f) GDPR), and on the conditions of art. 11.7a(3) Telecommunicatiewet for measurement with no or limited impact on privacy, we use PostHog (hosted on EU Cloud, Frankfurt, by PostHog Inc.) in cookieless mode: no cookies are set, no persistent identifiers are stored in your browser, no cross-site tracking occurs, and your IP address is not stored as an event property.

We record page views and page leaves, and interaction events such as clicks on links and buttons. An interaction event records which element you clicked, its visible label, and the page you were on — for example that someone clicked a button labelled "Get started" on the home page. We do not record the contents of form fields, and we do not capture screen recordings. Because the events carry no cookie, no device identifier and no directly identifying data, they cannot be traced back to you as an individual.

Data is kept for up to 12 months, never sold, and never enriched with personal data you submit. You can object to this processing at any time through our legal inquiry form. See PostHog privacy policy.

When an order is completed, our systems additionally record a server-side purchase event in the same PostHog project for aggregate revenue measurement (order number, amount, currency and product). This event is keyed on the internal order number only — it contains no name or e-mail address and is not linked to your browsing activity. Legal basis: our legitimate interest in measuring sales of our own services (Art. 6(1)(f) GDPR).

2.3 Marketing — Meta Pixel (consent required)

With your consent (Art. 6(1)(a) GDPR) we use the Meta Pixel (Meta Platforms Ireland Ltd.) to measure the effectiveness of our advertising on Meta platforms (Facebook, Instagram) and to build audiences for retargeting. The Meta Pixel sends pseudonymised identifiers (_fbp, _fbc) to Meta along with the URL of the page you visited. Retention and further processing are governed by Meta. See Meta privacy policy.

If you have given this consent, we also send Meta a matching event directly from our servers (the Meta "Conversions API"), so that a single action is measured reliably even when the browser request does not arrive. The two events describe the same action and are de-duplicated by a shared event identifier — they do not double-count you. This server-side event is sent only where you have given marketing consent; without it, no event leaves our systems.

The server-side event carries: your e-mail address, phone number, first and last name and country, each irreversibly hashed (SHA-256) before it is sent, so Meta receives a fingerprint rather than the value itself; together with your IP address, browser user agent and the _fbp / _fbc identifiers, which Meta's specification requires to be sent unhashed. We store those same items on your enquiry or order record so the event can be sent and retried; they follow the retention periods in section 6.

Transfers to Meta may involve a transfer to the United States. Meta participates in the EU-US Data Privacy Framework; where additional safeguards are required we rely on the European Commission's Standard Contractual Clauses.

2.4 Enquiries, quotes and the "Get started" funnel

When you complete a form we process the data you provide — typically name, business e-mail address, company name, phone number and your project description and budget range — on the basis of steps taken at your request prior to entering into a contract (Art. 6(1)(b) GDPR).

Providing this data is not a statutory or contractual obligation, and you are free not to provide it. It is, however, necessary for us to answer your enquiry or prepare a quote: if you do not provide it, we cannot respond to you. We keep enquiry data for 24 months after our last contact with you, unless a contract is concluded, in which case the retention periods in section 6 apply.

We use these details to contact you about your enquiry. If you begin the "Get started" funnel and do not finish it, we may send you an automated reminder e-mail, on the basis of the same pre-contractual interest.

2.5 Marketing communications (consent required)

If you separately tick the newsletter or WhatsApp box, we send you commercial updates about our services on the basis of your consent (Art. 6(1)(a) GDPR and art. 11.7 Telecommunicatiewet). These boxes are never pre-ticked, and ticking them is never a condition of anything else. You can withdraw your consent at any time — via the unsubscribe link in every e-mail, by replying STOP to a WhatsApp message, or through our legal inquiry form — without affecting the lawfulness of processing carried out before withdrawal. WhatsApp messages are delivered through WhatsApp Ireland Ltd. (Meta).

We record which consent wording you agreed to and when, so that we can demonstrate the consent was validly obtained (Art. 7(1) GDPR).

2.6 Orders and payments

If you place an order we process your name, business contact details, company and business registration details, order contents and payment status in order to perform the contract (Art. 6(1)(b) GDPR) and to meet our tax and accounting obligations (Art. 6(1)(c) GDPR). Card details are entered directly into Stripe's checkout component and are never received or stored by us.

2.7 Data we receive from other sources

If you submit an advertising lead form on Facebook or Instagram, Meta passes us the contact details you entered there — typically your name, e-mail address and phone number — and we import them into our CRM. We use them for the same purposes and on the same legal basis as section 2.4. Where we obtain your data this way rather than directly from you, we inform you of it at the latest when we first contact you, in line with Art. 14 GDPR.

2.8 Meetings, recordings and notes

We meet clients and prospects over Microsoft Teams. Where a meeting is recorded or transcribed, Teams shows every participant a notification at the time — nothing is recorded covertly, and you can ask us not to record before or during the call.

From those meetings we keep a written summary only: who attended, the date and subject, the decisions taken and the dated action points. We do not keep the raw transcript or the recording in our own systems — only the summary is retained. We do this on the basis of our legitimate interest in an accurate record of what was discussed and agreed (Art. 6(1)(f) GDPR), which protects both sides when a question comes up later about scope or commitments.

We keep meeting summaries for the duration of the engagement and 24 months thereafter; for meetings that do not lead to an engagement, 24 months from the meeting. You can object to this processing, or ask for a summary of a meeting you attended to be corrected or deleted, through our legal inquiry form.

3. Cookies and similar technologies

PostHog anonymous analytics (section 2.2) set no cookies and store nothing in your browser. The only non-essential technology that places cookies is the Meta Pixel, and it is blocked by our consent manager until you explicitly allow it. You can give, refuse, or change your consent at any time via the "Cookie settings" link in the footer.

Two further third-party components load only on the specific pages that need them: the Cal.com booking widget on our booking page, and Cloudflare Turnstile on our legal inquiry form. Both are necessary to deliver the function you asked for on that page — you cannot book a call without the booking widget, and the form cannot be protected from automated abuse without Turnstile — so they are not gated by the consent banner. Both providers may set storage on their own domains; if you prefer not to use them, do not visit the booking page, and contact us by post instead of through the form.

ServicePurposeCategoryProvider
PostHog (cookieless) Website measurement — no cookies, no device identifiers Exempt measurement PostHog Inc. (EU Cloud, Frankfurt)
Meta Pixel Ad attribution, retargeting Marketing (consent required) Meta Platforms Ireland Ltd.
Cal.com booking widget Scheduling an intro call — loads only on /get-started/book-a-call Functional Cal.com, Inc.
Cloudflare Turnstile Bot protection — loads only on /legal-contact Strictly necessary Cloudflare, Inc.
Stripe (__stripe_mid, __stripe_sid) Fraud detection and completing your payment — set on our checkout pages at secure-checkout.cermus.com Strictly necessary Stripe Payments Europe Ltd. / Stripe, Inc.

4. Who we share data with

We do not sell personal data and we do not share it for other organisations' own marketing. We share it only with the service providers below, each of which processes it on our documented instructions under a data processing agreement, except where stated otherwise.

RecipientPurposeData location
Microsoft Ireland Operations Ltd. (Azure) Hosting of our website, APIs and database EU (West Europe)
Microsoft Ireland Operations Ltd. (Microsoft 365) Business e-mail and calendar correspondence with you EU
HubSpot, Inc. CRM — storing your enquiry and managing our follow-up EU / United States
Stripe Payments Europe Ltd. / Stripe, Inc. Payment processing and fraud prevention. Stripe also acts as an independent controller for its own fraud, anti-money-laundering and regulatory obligations. EU / United States
Moneybird B.V. Invoicing and accounting records EU (Netherlands)
Cal.com, Inc. Scheduling intro calls EU / United States
Cloudflare, Inc. Bot protection on our forms EU / United States
PostHog, Inc. Cookieless website measurement EU Cloud (Frankfurt)
Meta Platforms Ireland Ltd. Advertising measurement and retargeting; WhatsApp delivery EU / United States

We also disclose personal data to our accountant, and to the Belastingdienst or other competent authorities where we are legally required to do so.

5. International data transfers

Our own systems run in the European Union. Where a recipient listed above processes personal data outside the European Economic Area, that transfer is covered by the European Commission's adequacy decision for the EU-US Data Privacy Framework where the recipient participates in it, and otherwise by the European Commission's Standard Contractual Clauses together with the recipient's supplementary technical and organisational measures. Where a recipient participates in the Data Privacy Framework we also maintain Standard Contractual Clauses as a fallback mechanism. You can request details of the safeguards applied to a specific transfer through our legal inquiry form.

6. Data retention

DataRetention period
Server access logs14 days
Cookieless analytics events12 months
Enquiry and funnel submissions where no contract follows24 months after last contact
CRM records for clientsDuration of the engagement, then 24 months
Invoices, orders and payment records7 years (art. 52 Algemene wet inzake rijksbelastingen)
Business correspondence7 years where it forms part of our accounting records, otherwise 24 months
Meeting summaries (section 2.8)Duration of the engagement, then 24 months; 24 months from the meeting where no engagement follows
Marketing consent recordsUntil withdrawal, then 3 years as evidence of consent

After these periods the data is deleted or irreversibly anonymised.

7. Automated decision-making and profiling

We group enquiries into follow-up categories based on the answers you give us in the funnel, so that the e-mails we send you are relevant to what you asked about. This is profiling within the meaning of Art. 4(4) GDPR, and it affects only which messages you receive.

We do not carry out automated decision-making that produces legal effects concerning you or similarly significantly affects you within the meaning of Art. 22 GDPR. Every decision about whether to work with you, on what terms and at what price is taken by a person.

8. Your rights under GDPR

Under Articles 15–22 GDPR you have the right to:

  • Access the personal data we hold about you.
  • Rectification of inaccurate or incomplete data.
  • Erasure ("right to be forgotten") where applicable.
  • Restriction of processing.
  • Data portability in a structured, machine-readable format.
  • Object to processing based on legitimate interest.
  • Withdraw consent at any time without affecting the lawfulness of prior processing.

To exercise any of these rights, submit a request through our legal inquiry form. You also have the right to lodge a complaint with the Dutch Data Protection Authority (Autoriteit Persoonsgegevens, autoriteitpersoonsgegevens.nl) or your local supervisory authority.

9. Security

We apply technical and organisational measures appropriate to the risk, including TLS encryption in transit, encryption at rest on our cloud provider, least-privilege access controls, and regular security monitoring. No method of transmission or storage is 100% secure, but we strive to protect your data to industry standards.

10. Changes to this policy

We may update this Privacy Policy to reflect changes in our services or applicable law. Material changes will be communicated via the website. The date at the top of this page indicates the most recent revision.

11. Manage your cookie preferences

You can update your cookie consent at any time:

This document is provided for transparency and GDPR compliance. For tailored legal advice consult qualified counsel.

For privacy or GDPR-related requests, please use our legal inquiry form.

Pages
HomeWhat we doCase studies
Legal
Privacy PolicyTerms & ConditionsSecurity Legal inquiry
Company
Cermus IT B.V. KVK 89607988 VAT NL865038697B01

© 2026 Cermus® and the Cermus logo are registered trademarks.