Skip to content
Remote Fort logo

Privacy

Privacy Policy

This Privacy Policy explains how Remote Fort B.V. collects, uses, discloses, retains, and protects personal data when you visit https://remotefort.com, request a demo, communicate with us, or use the Remote Fort platform and related professional services.

Effective
19 August 2026
Last updated
19 August 2026
Teilnehmer der Allianz fur Cyber-Sicherheit
TISAX
PROKS

1.Introduction

Remote Fort is a security and compliance platform operated by Remote Fort B.V., a private limited company established in The Netherlands. We help organisations collect evidence, map controls across frameworks such as SOC 2, ISO/IEC 27001, GDPR, AWS security, and VAPT workflows, manage vendor risk and security questionnaires, and, where contracted, receive hands-on support from our specialists.

We wrote this policy so that security reviewers, privacy counsel, employees of our customers, website visitors, and prospects can see the same record. It is intended to meet the transparency duties in Articles 12–14 of the EU General Data Protection Regulation (EU) 2016/679 (“GDPR”), the UK GDPR, and the Dutch Uitvoeringswet AVG, and to describe our practices for other applicable privacy laws.

Please read it together with our Terms of Service, the public Trust Center (including the live subprocessor list), and, if you are a customer, your Order Form and Data Processing Addendum (“DPA”). If a signed DPA conflicts with this policy on processor activities, the DPA controls for that customer relationship.

2.Who we are

The controller for the processing described in this policy (except where we act as processor for a customer) is:

  • Legal entity: Remote Fort B.V.
  • Trading name: Remote Fort
  • Registered address: Keizersgracht 123, 1015 CJ Amsterdam, The Netherlands
  • Website: https://remotefort.com
  • Privacy contact: privacy@remotefort.com
  • Security / vulnerability reports: security@remotefort.com
  • Legal notices: legal@remotefort.com

We have not appointed a statutory Data Protection Officer as a public-facing named individual on this page. Privacy requests, DPIA questions, and regulator correspondence should be sent to privacy@remotefort.com. We will route them to the privacy owner in our ISMS.

Our lead supervisory authority for GDPR is the Autoriteit Persoonsgegevens (The Netherlands). You may also lodge a complaint with the authority in your place of residence or work; see Section 18.

3.Controller and processor roles

GDPR distinguishes the party that determines purposes and means (controller) from the party that processes on documented instructions (processor). Remote Fort occupies both roles, depending on the activity.

3.1 When Remote Fort is the controller

We are the controller when we process personal data for our own business purposes, including:

  • Operating and securing the public website, Trust Center, and marketing pages.
  • Measuring visits to the marketing site (for example Google Analytics, where enabled).
  • Handling demo requests, sales conversations, events, and newsletters.
  • Creating and administering billing accounts, invoices, and tax records for our customers as a contracting party.
  • Providing company support that is about the commercial relationship rather than tenant content (contract, invoices, access to the workspace).
  • Recruiting, running our workforce, and operating our ISMS.
  • Complying with law, defending claims, and preventing fraud or abuse of our own systems.

3.2 When Remote Fort is the processor

We are the processor when a customer (or its authorised affiliate) uses the Remote Fort platform, APIs, integrations, AI drafting features, or related hosted services, and personal data is stored or processed inside that customer’s tenant or in logs generated by that tenant. Typical examples:

  • Names, emails, and roles of the customer’s authorised users.
  • Evidence and artefacts pulled from connected cloud, identity, device, or ticketing systems (which often include workforce identifiers).
  • Vendor records, security questionnaire responses, and residual-risk reports.
  • Control comments, task assignments, approvals, and audit trails.
  • Files, screenshots, and policy documents the customer uploads.
  • Support reproductions that contain tenant data the customer chose to share.

For that processing, the customer is the controller (or a processor for its own customer, in which case we are a sub-processor). We process only on documented instructions: the DPA, the Order Form, product configuration the customer’s admins set, and applicable law. We do not use Customer Content to train general-purpose foundation models, and we do not sell it.

If you are an employee, contractor, vendor contact, or other data subject of a Remote Fort customer, please contact that organisation first. We cannot fulfil most access or deletion requests against tenant data without the customer’s instruction, because we are not the controller of that data.

3.3 Professional services

Where we provide onboarding, control mapping, evidence coaching, questionnaire support, or similar professional services, we typically remain a processor of Customer Content accessed to deliver those services. Correspondence about scoping, statements of work, and our own timesheets is controller processing of business contact data. Independent auditors, penetration testers, or other specialists we introduce remain separate controllers or processors under their own terms unless the Order Form says otherwise.

4.Scope and whose data this covers

This policy applies to personal data relating to:

  • Visitors of remotefort.com and the Trust Center.
  • People who request a demo, download materials, attend a webinar, or otherwise inquire about Remote Fort.
  • Customer personnel who create accounts or are invited into a tenant.
  • People whose data appears in Customer Content only to the extent we must describe processor practices; the customer’s own privacy notice governs that relationship.
  • People who email sales, support, privacy, legal, or security.
  • Job applicants who contact us about roles at Remote Fort.

It does not apply to third-party websites, auditor portals, or tools a customer connects that are not operated by us. Those services have their own policies.

The Service is designed for organisations. It is not directed at children, and we do not knowingly collect personal data from anyone under 18. See Section 20.

5.Key definitions

Unless a signed contract defines a term differently, the following meanings apply in this policy. GDPR Article 4 meanings apply to “personal data”, “processing”, “controller”, “processor”, “recipient”, “consent”, and “personal data breach”.

  • Customer: the organisation that enters into an Order Form or otherwise contracts for the Service.
  • Customer Content: data, files, evidence, configurations, and other material submitted to or collected into a tenant, including personal data therein.
  • Service: the Remote Fort website, platform, APIs, documentation, Trust Center, and professional services we provide.
  • Authorised User: an individual the Customer permits to access a tenant.
  • Subprocessor: a third party we engage to process personal data on our behalf (as controller vendors) or on a customer’s behalf (as processor subprocessors).
  • Special category data: data revealing racial or ethnic origin, political opinions, religious or philosophical beliefs, trade-union membership, genetic data, biometric data for unique identification, health data, or data concerning a person’s sex life or sexual orientation (GDPR Article 9).

6.Personal data we collect as controller

The categories below describe controller processing. We only collect what is relevant to the purpose. Fields marked as collected “if you provide them” are optional unless a form requires them to complete the request.

6.1 Sales, demo, and contact data

When you submit the demo or contact form, or email sales or support, we collect:

  • Identity: name.
  • Contact: business email address, phone number.
  • Organisation: company name (if provided in correspondence), approximate employee numbers, and a description of what you need (for example SOC 2, ISO 27001, GDPR, VAPT).
  • Communication content: messages, attachments, meeting notes, and follow-up emails.
  • Source: the page or campaign from which you reached us, if that is technically available.

6.2 Account and billing data

If you become a customer or are invited as an Authorised User, we process:

  • Account identifiers: name, work email, role or seat type, authentication identifiers (including SSO/SCIM attributes the Customer configures), and security events such as sign-in time and MFA status.
  • Workspace metadata needed to operate tenancy: company name, tenant ID, plan, feature flags, and admin settings.
  • Billing: billing contact, company name, billing address, VAT/tax numbers you supply, invoice history, and payment status. Card numbers, if you pay by card, are collected by Stripe; we store truncated payment metadata, not full card PAN or CVC.

6.3 Website, device, and security logs

When you visit the public site or authenticate to the Service, our systems and edge providers automatically process:

  • Technical: IP address, approximate location derived from IP (city/region level, not precise geolocation), browser and OS type, device characteristics, language preference, referring URL, pages viewed, timestamps, and request headers.
  • Diagnostics: error logs, performance timings, and abuse/WAF signals.
  • Cookies and similar identifiers described in Section 10.

We use this data to deliver the site, keep sessions working, remember your language, detect attacks, debug incidents, and (on the marketing site, where analytics is enabled) understand aggregate traffic. We do not use marketing-site analytics inside customer tenants.

6.4 Support and security reports

Emails to support@remotefort.com, security@remotefort.com, privacy@remotefort.com, or legal@remotefort.com, and any ticket or vulnerability report, are stored as correspondence. Please do not send passwords, full production dumps, or special category data unless we specifically request a secure channel for an incident.

6.5 Recruitment

If you apply for a role or send a CV, we process identity and contact data, professional history, and any information you choose to include. We use it to evaluate candidacy and, where required, to meet employment-law obligations. Unsolicited applications are handled under legitimate interests. We do not require special category data for applications; if you include it, we will process it only as needed to consider the application or as required by law.

6.6 Special category and criminal data

We do not seek special category data or criminal-offence data for the marketing site or ordinary SaaS operation. Customer Content might theoretically contain such data if a customer uploads it (for example a health-sector policy). Customers must not submit special category data unless a written instruction and lawful basis exist. We ask that website forms not be used to send health, biometric, or similarly sensitive information.

7.How we collect personal data

  • Directly from you: forms, email, calls, events, account settings, and support tickets.
  • Automatically: cookies, server logs, edge/WAF logs, and product telemetry needed to run and secure the Service.
  • From the Customer: when an admin invites you, provisions SSO/SCIM, or configures integrations.
  • From connected systems the Customer authorises (processor context): identity providers, cloud accounts, device management, ticketing, and similar sources.
  • From payment providers: confirmation that a charge succeeded, truncated card brand/last four, and billing identity Stripe or our invoicing flow returns to us.
  • From publicly available business sources or referrals, only where this is a fair and lawful way to follow up on a B2B inquiry.

8.Purposes and legal bases

Where GDPR or UK GDPR applies, we do not process personal data without a legal basis under Article 6. The table maps our main controller purposes. Legitimate interests are balanced against your rights; you may object as described in Section 17. We do not rely on consent for the core B2B Service contract, but we do rely on consent where ePrivacy rules require it for non-essential cookies or where you opt into optional marketing.

Controller purposes and GDPR Article 6 bases

PurposeTypical dataLegal basis
Provide the website and remember languageIP address, locale cookie, security logsArt. 6(1)(f) legitimate interests (operating a secure site); Art. 6(1)(b) where you create an account
Respond to demo and sales requestsName, phone, work email, company size, stated needArt. 6(1)(b) steps prior to contract; Art. 6(1)(f) B2B development
Negotiate, perform, and administer the customer contract, including access and billingAccount, contract, and invoice dataArt. 6(1)(b) contract; Art. 6(1)(c) tax and accounting duties
Process card or invoice payments via Stripe or bank transferBilling contact, payment metadataArt. 6(1)(b) contract; Art. 6(1)(c) legal obligation
Secure the Service, prevent abuse, investigate incidentsLogs, IP addresses, account security eventsArt. 6(1)(f) security and fraud prevention; Art. 6(1)(c) where law requires retention
Improve the marketing site using analytics (where enabled)Online identifiers, page views, device/browser dataArt. 6(1)(a) consent where required; otherwise Art. 6(1)(f) with opt-out
Send product, security, or service messagesWork email, name, tenant roleArt. 6(1)(b) contract (service notices); Art. 6(1)(f) or consent for optional marketing
RecruitmentCV and application dataArt. 6(1)(b) or (f); Art. 6(1)(c) where employment law applies
Establish, exercise, or defend legal claimsRelevant correspondence and recordsArt. 6(1)(f); Art. 6(1)(c) where a legal hold applies
Process Customer Content in a tenantCustomer ContentWe act as processor. The Customer supplies the Article 6 (and 9, if any) basis. Our processing is Art. 28 GDPR.

Our legitimate interests include running a B2B security-and-compliance business, keeping systems available and trustworthy, understanding which public pages help buyers, and communicating with business contacts who asked about the Service. We do not use legitimate interests for processing that GDPR requires consent for, and we will not override a compelling objection that outweighs those interests.

9.Customer Content (processor terms in brief)

This section summarises how we handle personal data in Customer Content. The signed DPA is the binding processor contract; customers and qualified prospects may request it from the Trust Center documents pack.

  • Instructions: we process Customer Content only to provide, secure, and support the Service, to follow the Customer’s documented configurations, and to comply with law.
  • Confidentiality: personnel with access are bound to confidentiality. Production access is least-privilege, SSO plus MFA, time-bound, and logged.
  • Subprocessors: listed in Section 12 and at /trust/subprocessors. Material additions are notified at least 30 days in advance where the DPA requires it, except where a shorter window is needed to contain a security incident.
  • International transfers: primary tenant data is stored in AWS eu-central-1 (Frankfurt). Backups stay in-region. Listed subprocessors may process limited personal data elsewhere only with a DPA and a transfer mechanism (usually Standard Contractual Clauses).
  • Assistance: we help the Customer respond to data-subject requests, DPIAs, and consultations that relate to the Service, as described in the DPA.
  • Breach: if a personal-data breach affects a tenant, we notify the Customer in line with GDPR Articles 33 and 34 duties as processor and the timelines in the DPA, without waiting on a marketing review.
  • Deletion and export: export is available during the contract. After termination we delete tenant data from production on the DPA schedule; backups then age out on their rolling window. Confirm dates with support.
  • AI: Customer Content is not used to train general-purpose foundation models. AI features that draft control answers or questionnaire text run against the Customer’s workspace under the DPA.

Customers are responsible for providing notices and obtaining any consents required for their workforce, vendors, and other data subjects whose data they place in the Service, and for configuring integrations so that only necessary data is synced.

10.Cookies and similar technologies

We use cookies, local storage, pixels, and similar technologies on the public website and, where needed to keep you signed in, on the application. A cookie is a small file stored on your device. Similar technologies include scripts that read a device identifier or store a preference.

Dutch and EU ePrivacy rules distinguish strictly necessary cookies (which we may set to deliver a service you requested) from other cookies (which generally require consent). You can also delete or block cookies in your browser; blocking strictly necessary cookies may break language selection or sign-in.

Cookies and similar technologies we use or may set

Name / typeProviderPurposeDuration (typical)Category
NEXT_LOCALERemote FortStores the interface language you select (English or Dutch).1 yearStrictly necessary
Session / authentication cookies (application)Remote FortKeep Authorised Users signed in and enforce session security.Session or as configured with SSOStrictly necessary
Cloudflare security cookies (for example bot-management cookies)CloudflareDNS, TLS, CDN, and WAF in front of public surfaces; abuse protection.As set by Cloudflare (often up to 30 minutes for bot cookies)Strictly necessary / security
_ga, _ga_*, and related Google Analytics cookiesGoogle Ireland LimitedMeasure visits to the marketing site so we can improve content. Not used inside customer tenants. Loaded on the public site in production when analytics is enabled.Up to 24 months (Google default; we may configure shorter)Analytics (non-essential)

Where analytics is enabled, Google may process online identifiers and device/browser data. Google Ireland Limited is the contracting entity; support personnel in other countries may have access under Google’s terms. See Google’s advertising and analytics documentation for its own processing.

You can limit analytics by using browser controls, tracking-protection features, or Google’s opt-out tools. If we present a consent banner or preference centre, your choice there is the primary control for non-essential cookies on that browser.

We do not currently use advertising cookies or sell personal data in exchange for cross-context behavioural advertising.

11.Artificial intelligence features

The Service may include AI-assisted features, such as mapping controls across frameworks, drafting questionnaire answers with citations, or suggesting evidence tasks. Those features are optional product functions of a customer tenant.

  • Customer Content used to generate an output remains Customer Content and is processed as a processor activity under the DPA.
  • We do not use Customer Content to train general-purpose foundation models operated by us or, to our knowledge under our vendor contracts, by subprocessors for their own generic model improvement, unless a Customer enables a feature that clearly discloses a different treatment.
  • Outputs can be incomplete or incorrect. They are not legal, audit, or certification advice. Customers must review AI drafts before sending them to auditors or buyers.
  • Prompts and outputs may be logged inside the tenant for lineage, security, and support, consistent with product telemetry described in the Terms.

12.Who we share personal data with

We do not sell personal data. We do not share personal data for cross-context behavioural advertising. We disclose personal data only as follows.

  • Service providers / subprocessors that host, secure, bill, analyse (marketing site), or help us operate the Service, under contract and only for those tasks. The current inventory is in the table below and at /trust/subprocessors.
  • Professional advisers (legal, accounting, insurance, security assessors) under confidentiality, where needed to run the company or an audit of Remote Fort.
  • Independent auditors, penetration testers, or specialists a Customer asks us to involve; they receive only what is needed for that engagement.
  • Corporate transactions: if we negotiate or complete a merger, acquisition, financing, or sale of assets, personal data may be disclosed to counterparties and advisers under appropriate safeguards, and transferred to the successor operator of the Service.
  • Authorities and legal process: where required by law, regulation, or a binding order, or to protect the rights, safety, and integrity of Remote Fort, our users, or the public. We will challenge overbroad requests where we reasonably can, and we will notify the Customer of compulsory legal process targeting Customer Content unless legally prohibited.
  • With your direction: for example if you ask us to send a package to your auditor or to introduce a partner.

Current inventory (also published at /trust/subprocessors)

VendorPurposeDataLocationTransfer tool

Amazon Web Services

Amazon Web Services EMEA SARL

Primary hosting for the Remote Fort platform: compute, datastores, object storage, backups, and KMS in eu-central-1.Customer tenant content, account data, logs, backupsEU — Frankfurt (eu-central-1)EU processing · AWS DPA

Cloudflare

Cloudflare, Inc.

DNS, CDN, TLS, and WAF in front of public web surfaces. Caching of static marketing assets only.IP addresses, request metadata, static site assetsGlobal edge · EU routing preferredSCCs + Cloudflare DPA

Google Analytics

Google Ireland Limited

Measurement of visits to remotefort.com so we can improve the marketing site. Not used inside customer tenants.Online identifiers, device/browser data, page viewsEEA (Google Ireland) with possible US support accessSCCs · Google Ads Data Processing Terms

Google Workspace

Google Ireland Limited

Corporate email, calendar, and documents for Remote Fort staff, including support correspondence.Business contact data, email content, support attachmentsEU data regions for Workspace (as configured)Google Cloud DPA · SCCs as needed

GitHub

GitHub, Inc. (Microsoft)

Source control, code review, and CI for the Remote Fort product. Customer tenant data is not stored in git.Source code, issue metadata, workforce identitiesUnited States / Microsoft cloudSCCs + GitHub DPA

Slack

Slack Technologies Limited (Salesforce)

Internal operations chat. Customer names or ticket snippets may appear when staff discuss support issues.Workforce messages; incidental customer identifiersSalesforce / Slack cloud (region per workspace)SCCs + Slack DPA

Linear

Linear Orbit, Inc.

Engineering issue tracking. May contain sanitized reproductions or customer-reported defects without bulk tenant exports.Ticket text, workforce identities, occasional customer namesUnited StatesSCCs + Linear DPA

Notion

Notion Labs, Inc.

Internal ISMS documentation, runbooks, and company wiki. Not a store of customer evidence files.Internal docs; limited personal data of staff and contactsUnited States / AWSSCCs + Notion DPA

Stripe

Stripe Payments Europe, Limited

Subscription billing when a customer pays Remote Fort by card. Card numbers are captured by Stripe, not stored by us.Billing contact, company name, truncated payment metadataEEA (Stripe Payments Europe) with US support entitiesSCCs + Stripe DPA

A signed DPA may list a narrower set for a given Customer; that list then controls for processor activities. We require subprocessors to protect personal data and to use it only to provide services to us or to the Customer, as applicable.

13.International transfers

Remote Fort B.V. is established in the European Union. Primary customer tenant data is stored in AWS eu-central-1 (Frankfurt, Germany). Backups remain in that region.

Some subprocessors are located outside the EEA or the United Kingdom, or may allow support access from outside those regions (for example United States entities of Cloudflare, GitHub, Linear, Notion, Slack, Stripe, or Google). When we transfer personal data from the EEA to a country that is not the subject of an adequacy decision under GDPR Article 45, we use appropriate safeguards under Article 46 — typically the European Commission’s Standard Contractual Clauses, plus a vendor DPA, and supplementary measures where our transfer assessment requires them. UK transfers use the UK International Data Transfer Addendum or UK adequacy where available.

You may request information about the relevant safeguards by emailing our privacy contact, subject to confidentiality and the need to protect security details.

Enterprise plans may include additional contractual residency commitments; those Order Form terms prevail for that Customer.

14.Retention

We keep personal data only as long as needed for the purposes in this policy, including to provide the Service, meet tax and accounting rules, resolve disputes, and maintain security. When a period ends, we delete or irreversibly anonymise the data, except where a legal hold applies. Backups expire on a rolling window after production deletion.

Typical retention periods (controller data unless noted)

RecordRetention
Demo and sales inquiries with no contract24 months after last meaningful contact, unless you ask us to delete sooner and no overriding obligation applies
Marketing suppression / unsubscribe listsAs long as needed to honour your opt-out
Customer contract, invoice, and tax recordsSeven years after the end of the financial year (Dutch administrative retention), or longer if a dispute is pending
Authorised User account dataDuration of the account, then deleted or anonymised within 30 days after the Customer’s offboarding instruction, subject to backup TTL
Customer Content (processor)For the subscription and any contractual wind-down; then deleted from production per the DPA; backups age out on the rolling window
Website and edge security logsGenerally up to 90 days, longer if needed to investigate abuse or an incident
Marketing analytics identifiersPer Google Analytics configuration, typically no more than 14–24 months
Support and security correspondenceUp to 3 years after closure, or longer if tied to an incident, claim, or vulnerability
Recruitment records (unsuccessful)Generally up to 12 months after the process ends, unless you consent to a longer talent pool or law requires otherwise
Locale cookie1 year or until you clear cookies

15.Security

We implement administrative, technical, and organisational measures designed to protect personal data against accidental or unlawful destruction, loss, alteration, unauthorised disclosure, or access. Measures currently described in our Trust Center include:

  • TLS 1.2 or higher in transit; AES-256 at rest via AWS-managed encryption and KMS for application keys.
  • Production in AWS eu-central-1 with encrypted disks, IAM-scoped roles, private networking for data stores, and in-region backups.
  • Tenant isolation in application and storage layers.
  • HTTPS-only public surfaces, modern cipher suites, DNS and WAF at the edge.
  • Workforce access to production through SSO, MFA, and time-bound roles; secrets in a managed vault; MDM-enrolled laptops with disk encryption.
  • Logging of privileged access; an ISMS mapped to ISO/IEC 27001:2022 and SOC 2 Trust Services Criteria, with independent marks we hold described on the Trust Center (including TISAX where applicable).
  • At least annual independent vulnerability assessment / penetration testing.

No method of transmission or storage is completely secure. You must keep credentials confidential, use MFA where offered, and tell us promptly of suspected unauthorised access. Detailed architecture, SOC 2, ISO, TISAX, and pentest packs are available to customers and qualified prospects under NDA via the Trust Center.

16.Your rights (EEA, UK, and similar laws)

If GDPR, UK GDPR, or the Swiss Federal Act on Data Protection applies to you, you have the rights summarised below, subject to the conditions and exceptions in those laws (for example, we may refuse a request that is manifestly unfounded or excessive, or that would adversely affect others).

  • Access (Art. 15): obtain confirmation of processing and a copy of personal data we hold as controller.
  • Rectification (Art. 16): correct inaccurate personal data and complete incomplete data.
  • Erasure (Art. 17): request deletion in the cases the law provides (for example the data is no longer needed, or you withdraw consent and there is no other basis).
  • Restriction (Art. 18): request that we only store data while a challenge is resolved.
  • Portability (Art. 20): receive data you provided to us on the basis of consent or contract, in a structured, commonly used, machine-readable format, and transmit it where technically feasible.
  • Objection (Art. 21): object to processing based on legitimate interests, including profiling based on those interests. You may object at any time to processing for direct marketing, and we will stop that marketing.
  • Withdraw consent (Art. 7(3)): where we rely on consent, you may withdraw it without affecting the lawfulness of processing before withdrawal.
  • Not to be subject to a solely automated decision with legal or similarly significant effects (Art. 22). See Section 21.
  • Lodge a complaint with a supervisory authority (Art. 77). See Section 18.

Authorised Users can correct much account data inside the product. Tenant Customer Content is controlled by the Customer; we will redirect data-subject requests about Customer Content to the Customer unless we are required to handle them ourselves.

17.How to exercise your rights

Email privacy@remotefort.com from a work address we can reasonably associate with the request, and tell us which right you wish to exercise and which email, phone, or company identity the request concerns. You may also write to us at the Amsterdam address in Section 2.

We will respond within one month of receipt, or we will tell you if we need up to two further months because of complexity or number of requests (GDPR Art. 12(3)). We may ask for information reasonably necessary to verify identity and to locate the data. We will not charge a fee unless a request is manifestly unfounded or excessive.

If you are an employee or vendor of a Customer, contact that organisation. If you contact us instead, we will forward the request to the Customer where we can identify the tenant, unless doing so would be unlawful.

You may authorise an agent to act for you, subject to proof of authority and identity. We will not discriminate against you for exercising privacy rights.

18.Complaints and supervisory authorities

Please contact privacy@remotefort.com first so we can try to resolve the issue. You have the right to lodge a complaint with a supervisory authority, in particular in the EU Member State of your habitual residence, place of work, or place of the alleged infringement.

Our lead authority is the Autoriteit Persoonsgegevens: https://www.autoriteitpersoonsgegevens.nl/

UK data subjects may also contact the Information Commissioner’s Office (https://ico.org.uk/). Swiss data subjects may contact the Federal Data Protection and Information Commissioner.

19.Additional information for US state privacy laws

If you are a resident of California or another US state with a consumer privacy statute (including, as applicable, the CCPA/CPRA, CPA, CTDPA, UCPA, VCDPA, and similar laws), this section supplements the rest of the policy. Remote Fort is a B2B service. Much of the data we handle in a tenant is processed as a “service provider” or “processor” to the Customer. Requests about that data should go to the Customer.

For personal information we collect as a business (for example, website and sales data), in the preceding 12 months we may have collected the categories listed in Section 6: identifiers, commercial information, internet or electronic network activity, professional information, and inferences drawn from those categories only to the extent needed to run B2B sales and the site. We collect them from the sources in Section 7, for the purposes in Section 8, and we disclose them to the parties in Section 12.

We do not sell personal information as “sale” is defined in the CCPA, and we do not share it for cross-context behavioural advertising. We do not use or disclose sensitive personal information for purposes that require a right to limit under CPRA beyond what is necessary to provide the Service.

Subject to verification and exceptions, you may request to know/access, correct, or delete personal information we hold as a business, and to opt out of sale/sharing (which we do not engage in). Submit requests to the privacy email in Section 2. We will not deny goods or services, charge a different price, or provide a different level of quality because you exercised these rights, except as the law allows.

This policy is not an acknowledgement that every US statute applies to Remote Fort B.V.; applicability depends on thresholds and the nature of the processing.

20.Children

The Service is built for organisations and adults acting in a professional capacity. You must be at least 18 to use the Service. We do not knowingly collect personal data from children. If you believe a child has provided personal data, contact our privacy email and we will delete it where required and appropriate.

21.Automated decision-making and profiling

We do not make solely automated decisions that produce legal or similarly significant effects about website visitors or Authorised Users as contemplated by GDPR Article 22 (for example, we do not use an algorithm alone to refuse a job or to set a legally binding credit decision).

We do use limited profiling in the ordinary sense of logs and analytics (security scoring at the WAF, aggregate traffic analysis, and optional AI drafts inside a tenant). Security automation may block abusive traffic. Product AI suggestions are tools for the Customer’s reviewers, not automated legal determinations about individuals.

22.Third-party services and integrations

The website and product may link to third-party sites (auditors, partners, documentation, payment pages). We are not responsible for their privacy practices.

If a Customer connects identity, cloud, device, or other systems, those providers process data under the Customer’s contract with them. We receive what the integration is configured to send. The Customer must ensure the connection is authorised and proportionate.

23.Records of processing and personal-data breaches

We maintain records of processing activities for controller and processor operations as required by GDPR Article 30.

If we suffer a personal-data breach as controller, we will assess risk to data subjects and notify the Autoriteit Persoonsgegevens within 72 hours where required by Article 33, and notify affected individuals where Article 34 requires it.

If we suffer a personal-data breach as processor, we will notify the affected Customer without undue delay as required by Article 33(2) and the DPA so the Customer can meet its own duties.

24.Changes to this policy

We may update this Privacy Policy to reflect changes in the Service, subprocessors, or the law. We will post the updated policy on this page and change the “Last updated” date. If a change is material, we will provide a more prominent notice (for example an email to the billing or privacy contact on file, or an in-product notice) where we can reasonably do so.

The “Effective” date is the date the current version took effect. Prior versions may be requested from our privacy or legal email. Continued use of the public website after an update constitutes notice of the new policy for controller activities on the site. Customer contracts and DPAs are changed only in accordance with those documents.

25.Contact

Questions, requests, or complaints about this policy or our privacy practices:

  • Remote Fort B.V.
  • Keizersgracht 123
  • 1015 CJ Amsterdam
  • The Netherlands
  • Privacy: privacy@remotefort.com
  • Legal: legal@remotefort.com
  • Security: security@remotefort.com
  • Support: support@remotefort.com