Privacy Policy
Last updated: 15 July 2026
This Privacy Policy explains how Venation collects, uses, and protects personal data when you visit venation.digital or use the tools and forms on it. We may update this policy from time to time; the latest version is always available at www.venation.digital/privacy.
Who we are
Venation B.V. ("Venation", "we", "us") is the data controller responsible for your personal data.
Company: Venation B.V.
Chamber of Commerce (KvK): 83593357
Address: Roosenburgstraat 5, 5624 JS Eindhoven, The Netherlands
Email: info@venation.digital
Privacy and security enquiries: security@venation.digital
A note on what we collect
You can browse venation.digital without giving us any personal details. We only receive personal data when you choose to give it to us, for example by sending us a message, signing up for our weekly email, or asking us to email or review your assessment results.
Below we explain each case: what we collect, why, our legal basis, and how long we keep it.
Contact form and email enquiries
When you use our contact form or email us, we collect your name, work email address, organisation (optional), and the content of your message.
Purpose: to respond to your enquiry and, where relevant, take steps at your request before entering into an agreement.
Legal basis: our legitimate interest in responding to enquiries, and pre-contractual steps taken at your request (GDPR Art. 6(1)(f) and 6(1)(b)).
Retention: we keep enquiry correspondence for 24 months after our last contact, then delete it, unless it becomes part of a customer relationship.
Risk Tolerance Snapshot and Cyber Readiness Check
You can complete the Risk Tolerance Snapshot and the Cyber Readiness Check without giving us your name or contact details. By default we receive only:
- the answers you select; and
- limited technical and usage information (such as approximate location, browser type, and device information) collected through our website analytics.
Your results are generated and stored privately. We do not ask you to enter, and you should not enter, confidential, incident-specific, or sensitive security information into these tools.
At the end of an assessment we offer two optional choices:
- Email me a copy. If you enter your email address so we can send you your results, we use that address only to deliver your copy.
- Ask Venation to review. If you tick the box asking us to review your results, we look at your answers and reply once with a suggested next step.
Purpose: to deliver your results to you and, only if you ask us to, to review them and contact you once with a recommended next step.
Legal basis: your consent, given by entering your email and/or ticking the review box (GDPR Art. 6(1)(a)); and, where this leads to a conversation about working together, pre-contractual steps at your request (Art. 6(1)(b)). You can withdraw consent at any time by emailing info@venation.digital.
Retention: where you provide an email address, we keep your results and email for 12 months, then delete them, unless they become part of a customer relationship. Anonymous, aggregated assessment data that cannot identify you may be kept longer to improve our tools.
Weekly email: "Decoding Risk"
If you sign up for our weekly Decoding Risk email, we collect your email address. The signup and the sending of these emails are handled by our email marketing provider, Kit (formerly ConvertKit).
Purpose: to send you our weekly email.
Legal basis: your consent (GDPR Art. 6(1)(a)).
Retention: until you unsubscribe. Every email contains an unsubscribe link, and you can opt out at any time.
Chatbot
Our website includes a chatbot ("Get Started" assistant). If you use it, we collect the messages you type, along with a randomly generated conversation ID, your browser/device information (user agent), and a one-way hashed version of your IP address used only to prevent abuse. We use this to answer your questions, help you find information, and, where relevant, suggest a next step or route your enquiry to the right person. Please do not enter confidential, incident-specific, or sensitive personal information into the chatbot.
To generate replies, your messages are sent securely to an AI service (Google's Gemini model, accessed through the Lovable AI Gateway). Your browser does not communicate with Google directly. Conversations are stored in our database within the European Economic Area (see "Where your data is stored" below).
Purpose: to respond to your questions and assist you on the website.
Legal basis: our legitimate interest in helping visitors and responding to enquiries (GDPR Art. 6(1)(f)).
Retention: we keep chatbot conversations for 6 months, then delete them, unless a conversation becomes part of an enquiry or customer relationship.
Booking a call
If you book a call with us, your booking is handled through Google Calendar appointment scheduling, and the details you enter (such as name and email) are used to arrange and hold that meeting.
Legal basis: pre-contractual steps at your request and our legitimate interest in arranging meetings (GDPR Art. 6(1)(b) and 6(1)(f)).
Vigil: accounts, displays and subscriptions
Vigil is our threat-level display tool. You can try the Vigil assessment anonymously; your draft answers are held only in your browser tab (session storage) and are discarded when you close it. We do not receive that draft unless you choose to save it.
If you create a Vigil account to save and publish a display, we collect:
- your email address and password (the password is stored only in hashed form by our authentication provider);
- the company or display name, assessment answers, chosen threat level and any custom text you enter for your display;
- an optional logo image if you upload one, stored in a private storage bucket and served to public viewers of your display only via short-lived signed URLs bound to your display's random, non-guessable slug;
- basic usage metadata such as when the display was last updated (used to show the recency indicator).
Published Vigil displays are reachable by anyone who has the URL (which contains a random slug). The display shows only the information you choose to publish: threat level, company/display name, optional descriptions and your logo if uploaded. It does not expose your email address or account details.
Purpose: to provide the Vigil service, to let you create, save, publish and manage a threat-level display, and to authenticate you.
Legal basis: performance of a contract with you (GDPR Art. 6(1)(b)) and our legitimate interest in operating and securing the service (Art. 6(1)(f)).
Retention: for as long as your Vigil account is active. If you delete your account or ask us to close it, we delete your displays, uploaded logos and account within 30 days, except where we are required to retain limited billing records (see below).
Paid subscriptions (Vigil). Paid Vigil features are billed through Stripe. When you subscribe, payment card details are collected and processed directly by Stripe. We never see or store your full card number. Stripe sends us a customer ID, subscription status, plan, billing country and the last four digits and brand of the card, which we store to run your subscription and show it in your account. Invoices and payment receipts are issued by Stripe.
Legal basis: performance of a contract with you (GDPR Art. 6(1)(b)) and compliance with our legal obligations, in particular tax and accounting law (Art. 6(1)(c)).
Retention: billing and invoice records are retained for 7 years to meet Dutch tax law requirements. Subscription metadata is retained for the life of the account and deleted with it, subject to those legal retention periods.
Cookies and similar technologies
We do not use advertising trackers, and we do not use third-party analytics services such as Google Analytics, Hotjar, Plausible, or PostHog.
The only information stored in your browser is strictly necessary or functional. It makes the site work and is not used to track you:
- venation-cookie-consent (local storage): remembers your choice on our cookie notice. Stays until you clear your site data.
- venation_assistant_cid (session storage): a random ID for your chatbot conversation. Cleared when you close the tab.
- venation_assistant_nudged (session storage): remembers that the chat prompt has already been shown, so it is not repeated. Cleared when you close the tab.
- Cloudflare Turnstile: a privacy-friendly bot check that protects our forms and chatbot from abuse. Any related storage is set by Cloudflare on its own challenge domain, not on venation.digital.
Because these are necessary or functional only, we do not require your consent to use them.
Our website platform's built-in analytics (Lovable Project Analytics) is cookieless: it measures aggregate usage without setting cookies or storing identifiers in your browser, and it does not store your IP address in raw form. We use it only to understand, in aggregate, how our website is used so we can improve it, not to identify individual visitors. Because we set no non-essential cookies or trackers, we provide this information for transparency rather than asking you for cookie consent.
Embedded Notion Systems Pack and Google Analytics
The Venation website includes access to a Systems Pack hosted by Notion. The resource may be shown within an embedded frame or opened directly on Notion.
The hosted Systems Pack includes Google Analytics 4. When the resource is loaded, Notion, Google or their authorised service providers may use cookies, local storage, analytics identifiers or similar technologies to deliver the resource, maintain security and measure its use.
These technologies may be used to process information about:
- whether the resource was opened;
- pages and sections viewed;
- interactions with the resource;
- browser and device type;
- referral information;
- approximate location;
- technical identifiers; and
- repeat visits, where supported by the relevant analytics configuration.
The purpose of this processing is to measure the use of the Systems Pack and improve its content, structure and usefulness.
Where consent is required, the Notion content and associated analytics should be treated as non-essential analytics or external content. Visitors can manage or withdraw their consent through the website's cookie settings.
| Service | Venation Systems Pack hosted by Notion |
| Providers | Notion Labs, Inc. and Google Ireland Limited |
| Category | Analytics and embedded external content |
| Purpose | To provide the embedded Venation Systems Pack and understand how visitors access and use it. |
| Legal basis | Consent, where required. |
| Data potentially processed | Technical information, page views, interactions, browser and device information, referral information, approximate location, IP-derived information and analytics identifiers. |
| Activation | When the hosted or embedded Systems Pack is opened, subject to the website's applicable consent configuration. |
| Duration | Varies according to the cookies, browser storage and analytics configuration used by Notion and Google. Exact durations must be confirmed through a technical cookie scan. |
| Third-country processing | Possible, depending on the infrastructure and service providers used by Notion and Google. |
| Withdrawal | Visitors may change or withdraw their choice through the website's cookie settings. Visitors opening the Systems Pack directly on Notion may also need to use controls made available by Notion or their browser. |
Embedded Notion resources and analytics
We make selected Venation resources available through Notion, including the Venation Systems Pack. The Systems Pack may be accessed directly through a Notion-hosted page or displayed as embedded content on the Venation website.
When the Systems Pack is opened or the embedded content is loaded, the visitor's browser may establish a connection with services operated by Notion Labs, Inc. Notion may process technical and usage information required to deliver the page, maintain security and operate its service.
We have also configured Google Analytics 4 on the Notion-hosted Systems Pack. We use this service to understand how the resource is accessed and used and to improve its content and structure.
Depending on the visitor's interaction and the configuration of the services, the information processed may include:
- pages viewed;
- interactions with the Systems Pack;
- date and time of access;
- referring page or source;
- browser and device information;
- operating system;
- approximate location derived from technical information;
- IP address or information derived from it;
- analytics identifiers; and
- information about how visitors navigate the resource.
We use this information for aggregated usage analysis, content improvement and evaluation of the usefulness of the Systems Pack. We do not use the Systems Pack analytics to make decisions about individual visitors.
Where consent is legally required, the legal basis for the use of analytics is the visitor's consent under Article 6(1)(a) of the General Data Protection Regulation. Consent may be withdrawn at any time through the cookie or privacy settings available on the Venation website. Withdrawal does not affect processing that occurred before consent was withdrawn.
The service providers involved may include:
- Notion Labs, Inc.;
- Google Ireland Limited; and
- affiliated companies and authorised service providers used by Notion or Google.
Because these providers operate internationally, personal data may be processed outside the European Economic Area. Where this occurs, the relevant provider is responsible for applying an appropriate transfer mechanism and safeguards in accordance with applicable data-protection law. Further details are available in the privacy information published by Notion and Google.
Visitors who open the Systems Pack directly on Notion interact with a service hosted outside the Venation website. Notion's own privacy information and service terms also apply to that interaction.
We retain analytics information according to the retention settings configured within the relevant analytics service. The exact retention period should be confirmed against the current Google Analytics property settings.
Who we share data with
We do not sell your personal data. We share it only with service providers (processors) who help us run our website and services, and only as needed:
| Provider | What it does | Where it processes data |
|---|---|---|
| Lovable (on Cloudflare) | Website hosting, content delivery, built-in analytics, AI gateway for the chatbot, transactional email (acknowledgements, notifications, result copies), and our admin tool | Global edge network |
| Supabase (on AWS) | Stores form submissions, assessment results, leads, admin data, and chatbot conversations | Frankfurt, Germany (EEA) |
| Google (Gemini, via Lovable AI Gateway) | Generates the chatbot's replies | Google infrastructure (global) |
| Kit (formerly ConvertKit) | Manages signup and sending of the weekly email | United States |
| Cloudflare Turnstile | Protects forms and the chatbot from bots | Global |
| Google Calendar | Appointment scheduling when you book a call | United States / global |
| Notion | Where we manually record and manage leads and enquiries | United States |
| Stripe | Payment processing and subscription management for Vigil paid plans; issues invoices and receipts | Ireland (EEA) / United States |
Lovable publishes its Data Processing Agreement and full subprocessor list at trust.lovable.dev. We may also disclose data where required by law.
Where your data is stored
The personal data you submit through our website (contact messages, assessment results, chatbot conversations, and leads) is stored in our database hosted in the European Economic Area (Frankfurt, Germany). Some of the providers above process data outside the EEA, as described in the next section.
International transfers
Some of our providers process personal data outside the European Economic Area, mainly in the United States, specifically Kit (newsletter), Google (chatbot replies via Gemini, and Calendar booking), Notion (leads), and Stripe (Vigil subscription payments; Stripe's EU entity is in Ireland but some processing may take place in the United States). Where data is transferred outside the EEA, we rely on an appropriate safeguard, such as a European Commission adequacy decision or the Standard Contractual Clauses, to protect it. You can ask us for details using the contact details below.
How we keep your data secure
We have put in place appropriate technical and organisational measures to protect your personal data against loss, misuse, and unauthorised access. The website is served over an encrypted (HTTPS) connection, and data you submit is stored in an access-controlled database within the EEA. We practise data minimisation. For example, where we need your IP address to prevent abuse of our forms and chatbot, we use it only temporarily or store it in a one-way hashed form rather than keeping your raw IP address. For more detail, contact security@venation.digital.
Automated processing
The Risk Tolerance Snapshot and Cyber Readiness Check generate indicative, decision-support outputs based on the answers you provide. These are not decisions that produce legal or similarly significant effects about you, and a person at Venation reviews your results before any follow-up.
Your rights
Under the General Data Protection Regulation (GDPR / AVG) you have the right to:
- access the personal data we hold about you;
- have inaccurate data corrected (rectification);
- have your data deleted (erasure);
- restrict or object to our processing;
- data portability; and
- withdraw consent at any time, where our processing is based on consent.
To exercise any of these rights, email info@venation.digital. We may ask you to verify your identity first. We do not charge for handling your request. We may charge a reasonable fee or decline to act only where a request is manifestly unfounded or excessive, and we will tell you before doing so.
You also have the right to lodge a complaint with a data protection authority. In the Netherlands this is the Autoriteit Persoonsgegevens: https://autoriteitpersoonsgegevens.nl/en/contact-dutch-dpa/contact-us
Links to other websites
Our website may contain links to other sites. Once you leave venation.digital we have no control over those sites and are not responsible for how they handle your information. We encourage you to read their privacy policies.
Changes to this policy
We may update this Privacy Policy from time to time. When we do, we will revise the "Last updated" date at the top of this page.
Contact
For any questions about this Privacy Policy or your personal data, contact us at info@venation.digital, or write to Venation B.V., Roosenburgstraat 5, 5624 JS Eindhoven, The Netherlands.
