1.Introduction
Remote Fort is a security and compliance platform operated by Remote Fort B.V., a private limited company established in The Netherlands. We help organisations collect evidence, map controls across frameworks such as SOC 2, ISO/IEC 27001, GDPR, AWS security, and VAPT workflows, manage vendor risk and security questionnaires, and, where contracted, receive hands-on support from our specialists.
We wrote this policy so that security reviewers, privacy counsel, employees of our customers, website visitors, and prospects can see the same record. It is intended to meet the transparency duties in Articles 12–14 of the EU General Data Protection Regulation (EU) 2016/679 (“GDPR”), the UK GDPR, and the Dutch Uitvoeringswet AVG, and to describe our practices for other applicable privacy laws.
Please read it together with our Terms of Service, the public Trust Center (including the live subprocessor list), and, if you are a customer, your Order Form and Data Processing Addendum (“DPA”). If a signed DPA conflicts with this policy on processor activities, the DPA controls for that customer relationship.
2.Who we are
The controller for the processing described in this policy (except where we act as processor for a customer) is:
- Legal entity: Remote Fort B.V.
- Trading name: Remote Fort
- Registered address: Keizersgracht 123, 1015 CJ Amsterdam, The Netherlands
- Website: https://remotefort.com
- Privacy contact: privacy@remotefort.com
- Security / vulnerability reports: security@remotefort.com
- Legal notices: legal@remotefort.com
We have not appointed a statutory Data Protection Officer as a public-facing named individual on this page. Privacy requests, DPIA questions, and regulator correspondence should be sent to privacy@remotefort.com. We will route them to the privacy owner in our ISMS.
Our lead supervisory authority for GDPR is the Autoriteit Persoonsgegevens (The Netherlands). You may also lodge a complaint with the authority in your place of residence or work; see Section 18.
3.Controller and processor roles
GDPR distinguishes the party that determines purposes and means (controller) from the party that processes on documented instructions (processor). Remote Fort occupies both roles, depending on the activity.
3.1 When Remote Fort is the controller
We are the controller when we process personal data for our own business purposes, including:
- Operating and securing the public website, Trust Center, and marketing pages.
- Measuring visits to the marketing site (for example Google Analytics, where enabled).
- Handling demo requests, sales conversations, events, and newsletters.
- Creating and administering billing accounts, invoices, and tax records for our customers as a contracting party.
- Providing company support that is about the commercial relationship rather than tenant content (contract, invoices, access to the workspace).
- Recruiting, running our workforce, and operating our ISMS.
- Complying with law, defending claims, and preventing fraud or abuse of our own systems.
3.2 When Remote Fort is the processor
We are the processor when a customer (or its authorised affiliate) uses the Remote Fort platform, APIs, integrations, AI drafting features, or related hosted services, and personal data is stored or processed inside that customer’s tenant or in logs generated by that tenant. Typical examples:
- Names, emails, and roles of the customer’s authorised users.
- Evidence and artefacts pulled from connected cloud, identity, device, or ticketing systems (which often include workforce identifiers).
- Vendor records, security questionnaire responses, and residual-risk reports.
- Control comments, task assignments, approvals, and audit trails.
- Files, screenshots, and policy documents the customer uploads.
- Support reproductions that contain tenant data the customer chose to share.
For that processing, the customer is the controller (or a processor for its own customer, in which case we are a sub-processor). We process only on documented instructions: the DPA, the Order Form, product configuration the customer’s admins set, and applicable law. We do not use Customer Content to train general-purpose foundation models, and we do not sell it.
If you are an employee, contractor, vendor contact, or other data subject of a Remote Fort customer, please contact that organisation first. We cannot fulfil most access or deletion requests against tenant data without the customer’s instruction, because we are not the controller of that data.
3.3 Professional services
Where we provide onboarding, control mapping, evidence coaching, questionnaire support, or similar professional services, we typically remain a processor of Customer Content accessed to deliver those services. Correspondence about scoping, statements of work, and our own timesheets is controller processing of business contact data. Independent auditors, penetration testers, or other specialists we introduce remain separate controllers or processors under their own terms unless the Order Form says otherwise.
4.Scope and whose data this covers
This policy applies to personal data relating to:
- Visitors of remotefort.com and the Trust Center.
- People who request a demo, download materials, attend a webinar, or otherwise inquire about Remote Fort.
- Customer personnel who create accounts or are invited into a tenant.
- People whose data appears in Customer Content only to the extent we must describe processor practices; the customer’s own privacy notice governs that relationship.
- People who email sales, support, privacy, legal, or security.
- Job applicants who contact us about roles at Remote Fort.
It does not apply to third-party websites, auditor portals, or tools a customer connects that are not operated by us. Those services have their own policies.
The Service is designed for organisations. It is not directed at children, and we do not knowingly collect personal data from anyone under 18. See Section 20.
5.Key definitions
Unless a signed contract defines a term differently, the following meanings apply in this policy. GDPR Article 4 meanings apply to “personal data”, “processing”, “controller”, “processor”, “recipient”, “consent”, and “personal data breach”.
- Customer: the organisation that enters into an Order Form or otherwise contracts for the Service.
- Customer Content: data, files, evidence, configurations, and other material submitted to or collected into a tenant, including personal data therein.
- Service: the Remote Fort website, platform, APIs, documentation, Trust Center, and professional services we provide.
- Authorised User: an individual the Customer permits to access a tenant.
- Subprocessor: a third party we engage to process personal data on our behalf (as controller vendors) or on a customer’s behalf (as processor subprocessors).
- Special category data: data revealing racial or ethnic origin, political opinions, religious or philosophical beliefs, trade-union membership, genetic data, biometric data for unique identification, health data, or data concerning a person’s sex life or sexual orientation (GDPR Article 9).
6.Personal data we collect as controller
The categories below describe controller processing. We only collect what is relevant to the purpose. Fields marked as collected “if you provide them” are optional unless a form requires them to complete the request.
6.1 Sales, demo, and contact data
When you submit the demo or contact form, or email sales or support, we collect:
- Identity: name.
- Contact: business email address, phone number.
- Organisation: company name (if provided in correspondence), approximate employee numbers, and a description of what you need (for example SOC 2, ISO 27001, GDPR, VAPT).
- Communication content: messages, attachments, meeting notes, and follow-up emails.
- Source: the page or campaign from which you reached us, if that is technically available.
6.2 Account and billing data
If you become a customer or are invited as an Authorised User, we process:
- Account identifiers: name, work email, role or seat type, authentication identifiers (including SSO/SCIM attributes the Customer configures), and security events such as sign-in time and MFA status.
- Workspace metadata needed to operate tenancy: company name, tenant ID, plan, feature flags, and admin settings.
- Billing: billing contact, company name, billing address, VAT/tax numbers you supply, invoice history, and payment status. Card numbers, if you pay by card, are collected by Stripe; we store truncated payment metadata, not full card PAN or CVC.
6.3 Website, device, and security logs
When you visit the public site or authenticate to the Service, our systems and edge providers automatically process:
- Technical: IP address, approximate location derived from IP (city/region level, not precise geolocation), browser and OS type, device characteristics, language preference, referring URL, pages viewed, timestamps, and request headers.
- Diagnostics: error logs, performance timings, and abuse/WAF signals.
- Cookies and similar identifiers described in Section 10.
We use this data to deliver the site, keep sessions working, remember your language, detect attacks, debug incidents, and (on the marketing site, where analytics is enabled) understand aggregate traffic. We do not use marketing-site analytics inside customer tenants.
6.4 Support and security reports
Emails to support@remotefort.com, security@remotefort.com, privacy@remotefort.com, or legal@remotefort.com, and any ticket or vulnerability report, are stored as correspondence. Please do not send passwords, full production dumps, or special category data unless we specifically request a secure channel for an incident.
6.5 Recruitment
If you apply for a role or send a CV, we process identity and contact data, professional history, and any information you choose to include. We use it to evaluate candidacy and, where required, to meet employment-law obligations. Unsolicited applications are handled under legitimate interests. We do not require special category data for applications; if you include it, we will process it only as needed to consider the application or as required by law.
6.6 Special category and criminal data
We do not seek special category data or criminal-offence data for the marketing site or ordinary SaaS operation. Customer Content might theoretically contain such data if a customer uploads it (for example a health-sector policy). Customers must not submit special category data unless a written instruction and lawful basis exist. We ask that website forms not be used to send health, biometric, or similarly sensitive information.
7.How we collect personal data
- Directly from you: forms, email, calls, events, account settings, and support tickets.
- Automatically: cookies, server logs, edge/WAF logs, and product telemetry needed to run and secure the Service.
- From the Customer: when an admin invites you, provisions SSO/SCIM, or configures integrations.
- From connected systems the Customer authorises (processor context): identity providers, cloud accounts, device management, ticketing, and similar sources.
- From payment providers: confirmation that a charge succeeded, truncated card brand/last four, and billing identity Stripe or our invoicing flow returns to us.
- From publicly available business sources or referrals, only where this is a fair and lawful way to follow up on a B2B inquiry.
8.Purposes and legal bases
Where GDPR or UK GDPR applies, we do not process personal data without a legal basis under Article 6. The table maps our main controller purposes. Legitimate interests are balanced against your rights; you may object as described in Section 17. We do not rely on consent for the core B2B Service contract, but we do rely on consent where ePrivacy rules require it for non-essential cookies or where you opt into optional marketing.
Controller purposes and GDPR Article 6 bases
| Purpose | Typical data | Legal basis |
|---|---|---|
| Provide the website and remember language | IP address, locale cookie, security logs | Art. 6(1)(f) legitimate interests (operating a secure site); Art. 6(1)(b) where you create an account |
| Respond to demo and sales requests | Name, phone, work email, company size, stated need | Art. 6(1)(b) steps prior to contract; Art. 6(1)(f) B2B development |
| Negotiate, perform, and administer the customer contract, including access and billing | Account, contract, and invoice data | Art. 6(1)(b) contract; Art. 6(1)(c) tax and accounting duties |
| Process card or invoice payments via Stripe or bank transfer | Billing contact, payment metadata | Art. 6(1)(b) contract; Art. 6(1)(c) legal obligation |
| Secure the Service, prevent abuse, investigate incidents | Logs, IP addresses, account security events | Art. 6(1)(f) security and fraud prevention; Art. 6(1)(c) where law requires retention |
| Improve the marketing site using analytics (where enabled) | Online identifiers, page views, device/browser data | Art. 6(1)(a) consent where required; otherwise Art. 6(1)(f) with opt-out |
| Send product, security, or service messages | Work email, name, tenant role | Art. 6(1)(b) contract (service notices); Art. 6(1)(f) or consent for optional marketing |
| Recruitment | CV and application data | Art. 6(1)(b) or (f); Art. 6(1)(c) where employment law applies |
| Establish, exercise, or defend legal claims | Relevant correspondence and records | Art. 6(1)(f); Art. 6(1)(c) where a legal hold applies |
| Process Customer Content in a tenant | Customer Content | We act as processor. The Customer supplies the Article 6 (and 9, if any) basis. Our processing is Art. 28 GDPR. |
Our legitimate interests include running a B2B security-and-compliance business, keeping systems available and trustworthy, understanding which public pages help buyers, and communicating with business contacts who asked about the Service. We do not use legitimate interests for processing that GDPR requires consent for, and we will not override a compelling objection that outweighs those interests.
9.Customer Content (processor terms in brief)
This section summarises how we handle personal data in Customer Content. The signed DPA is the binding processor contract; customers and qualified prospects may request it from the Trust Center documents pack.
- Instructions: we process Customer Content only to provide, secure, and support the Service, to follow the Customer’s documented configurations, and to comply with law.
- Confidentiality: personnel with access are bound to confidentiality. Production access is least-privilege, SSO plus MFA, time-bound, and logged.
- Subprocessors: listed in Section 12 and at /trust/subprocessors. Material additions are notified at least 30 days in advance where the DPA requires it, except where a shorter window is needed to contain a security incident.
- International transfers: primary tenant data is stored in AWS eu-central-1 (Frankfurt). Backups stay in-region. Listed subprocessors may process limited personal data elsewhere only with a DPA and a transfer mechanism (usually Standard Contractual Clauses).
- Assistance: we help the Customer respond to data-subject requests, DPIAs, and consultations that relate to the Service, as described in the DPA.
- Breach: if a personal-data breach affects a tenant, we notify the Customer in line with GDPR Articles 33 and 34 duties as processor and the timelines in the DPA, without waiting on a marketing review.
- Deletion and export: export is available during the contract. After termination we delete tenant data from production on the DPA schedule; backups then age out on their rolling window. Confirm dates with support.
- AI: Customer Content is not used to train general-purpose foundation models. AI features that draft control answers or questionnaire text run against the Customer’s workspace under the DPA.
Customers are responsible for providing notices and obtaining any consents required for their workforce, vendors, and other data subjects whose data they place in the Service, and for configuring integrations so that only necessary data is synced.
11.Artificial intelligence features
The Service may include AI-assisted features, such as mapping controls across frameworks, drafting questionnaire answers with citations, or suggesting evidence tasks. Those features are optional product functions of a customer tenant.
- Customer Content used to generate an output remains Customer Content and is processed as a processor activity under the DPA.
- We do not use Customer Content to train general-purpose foundation models operated by us or, to our knowledge under our vendor contracts, by subprocessors for their own generic model improvement, unless a Customer enables a feature that clearly discloses a different treatment.
- Outputs can be incomplete or incorrect. They are not legal, audit, or certification advice. Customers must review AI drafts before sending them to auditors or buyers.
- Prompts and outputs may be logged inside the tenant for lineage, security, and support, consistent with product telemetry described in the Terms.
13.International transfers
Remote Fort B.V. is established in the European Union. Primary customer tenant data is stored in AWS eu-central-1 (Frankfurt, Germany). Backups remain in that region.
Some subprocessors are located outside the EEA or the United Kingdom, or may allow support access from outside those regions (for example United States entities of Cloudflare, GitHub, Linear, Notion, Slack, Stripe, or Google). When we transfer personal data from the EEA to a country that is not the subject of an adequacy decision under GDPR Article 45, we use appropriate safeguards under Article 46 — typically the European Commission’s Standard Contractual Clauses, plus a vendor DPA, and supplementary measures where our transfer assessment requires them. UK transfers use the UK International Data Transfer Addendum or UK adequacy where available.
You may request information about the relevant safeguards by emailing our privacy contact, subject to confidentiality and the need to protect security details.
Enterprise plans may include additional contractual residency commitments; those Order Form terms prevail for that Customer.
14.Retention
We keep personal data only as long as needed for the purposes in this policy, including to provide the Service, meet tax and accounting rules, resolve disputes, and maintain security. When a period ends, we delete or irreversibly anonymise the data, except where a legal hold applies. Backups expire on a rolling window after production deletion.
Typical retention periods (controller data unless noted)
| Record | Retention |
|---|---|
| Demo and sales inquiries with no contract | 24 months after last meaningful contact, unless you ask us to delete sooner and no overriding obligation applies |
| Marketing suppression / unsubscribe lists | As long as needed to honour your opt-out |
| Customer contract, invoice, and tax records | Seven years after the end of the financial year (Dutch administrative retention), or longer if a dispute is pending |
| Authorised User account data | Duration of the account, then deleted or anonymised within 30 days after the Customer’s offboarding instruction, subject to backup TTL |
| Customer Content (processor) | For the subscription and any contractual wind-down; then deleted from production per the DPA; backups age out on the rolling window |
| Website and edge security logs | Generally up to 90 days, longer if needed to investigate abuse or an incident |
| Marketing analytics identifiers | Per Google Analytics configuration, typically no more than 14–24 months |
| Support and security correspondence | Up to 3 years after closure, or longer if tied to an incident, claim, or vulnerability |
| Recruitment records (unsuccessful) | Generally up to 12 months after the process ends, unless you consent to a longer talent pool or law requires otherwise |
| Locale cookie | 1 year or until you clear cookies |
15.Security
We implement administrative, technical, and organisational measures designed to protect personal data against accidental or unlawful destruction, loss, alteration, unauthorised disclosure, or access. Measures currently described in our Trust Center include:
- TLS 1.2 or higher in transit; AES-256 at rest via AWS-managed encryption and KMS for application keys.
- Production in AWS eu-central-1 with encrypted disks, IAM-scoped roles, private networking for data stores, and in-region backups.
- Tenant isolation in application and storage layers.
- HTTPS-only public surfaces, modern cipher suites, DNS and WAF at the edge.
- Workforce access to production through SSO, MFA, and time-bound roles; secrets in a managed vault; MDM-enrolled laptops with disk encryption.
- Logging of privileged access; an ISMS mapped to ISO/IEC 27001:2022 and SOC 2 Trust Services Criteria, with independent marks we hold described on the Trust Center (including TISAX where applicable).
- At least annual independent vulnerability assessment / penetration testing.
No method of transmission or storage is completely secure. You must keep credentials confidential, use MFA where offered, and tell us promptly of suspected unauthorised access. Detailed architecture, SOC 2, ISO, TISAX, and pentest packs are available to customers and qualified prospects under NDA via the Trust Center.
16.Your rights (EEA, UK, and similar laws)
If GDPR, UK GDPR, or the Swiss Federal Act on Data Protection applies to you, you have the rights summarised below, subject to the conditions and exceptions in those laws (for example, we may refuse a request that is manifestly unfounded or excessive, or that would adversely affect others).
- Access (Art. 15): obtain confirmation of processing and a copy of personal data we hold as controller.
- Rectification (Art. 16): correct inaccurate personal data and complete incomplete data.
- Erasure (Art. 17): request deletion in the cases the law provides (for example the data is no longer needed, or you withdraw consent and there is no other basis).
- Restriction (Art. 18): request that we only store data while a challenge is resolved.
- Portability (Art. 20): receive data you provided to us on the basis of consent or contract, in a structured, commonly used, machine-readable format, and transmit it where technically feasible.
- Objection (Art. 21): object to processing based on legitimate interests, including profiling based on those interests. You may object at any time to processing for direct marketing, and we will stop that marketing.
- Withdraw consent (Art. 7(3)): where we rely on consent, you may withdraw it without affecting the lawfulness of processing before withdrawal.
- Not to be subject to a solely automated decision with legal or similarly significant effects (Art. 22). See Section 21.
- Lodge a complaint with a supervisory authority (Art. 77). See Section 18.
Authorised Users can correct much account data inside the product. Tenant Customer Content is controlled by the Customer; we will redirect data-subject requests about Customer Content to the Customer unless we are required to handle them ourselves.
17.How to exercise your rights
Email privacy@remotefort.com from a work address we can reasonably associate with the request, and tell us which right you wish to exercise and which email, phone, or company identity the request concerns. You may also write to us at the Amsterdam address in Section 2.
We will respond within one month of receipt, or we will tell you if we need up to two further months because of complexity or number of requests (GDPR Art. 12(3)). We may ask for information reasonably necessary to verify identity and to locate the data. We will not charge a fee unless a request is manifestly unfounded or excessive.
If you are an employee or vendor of a Customer, contact that organisation. If you contact us instead, we will forward the request to the Customer where we can identify the tenant, unless doing so would be unlawful.
You may authorise an agent to act for you, subject to proof of authority and identity. We will not discriminate against you for exercising privacy rights.
18.Complaints and supervisory authorities
Please contact privacy@remotefort.com first so we can try to resolve the issue. You have the right to lodge a complaint with a supervisory authority, in particular in the EU Member State of your habitual residence, place of work, or place of the alleged infringement.
Our lead authority is the Autoriteit Persoonsgegevens: https://www.autoriteitpersoonsgegevens.nl/
UK data subjects may also contact the Information Commissioner’s Office (https://ico.org.uk/). Swiss data subjects may contact the Federal Data Protection and Information Commissioner.
19.Additional information for US state privacy laws
If you are a resident of California or another US state with a consumer privacy statute (including, as applicable, the CCPA/CPRA, CPA, CTDPA, UCPA, VCDPA, and similar laws), this section supplements the rest of the policy. Remote Fort is a B2B service. Much of the data we handle in a tenant is processed as a “service provider” or “processor” to the Customer. Requests about that data should go to the Customer.
For personal information we collect as a business (for example, website and sales data), in the preceding 12 months we may have collected the categories listed in Section 6: identifiers, commercial information, internet or electronic network activity, professional information, and inferences drawn from those categories only to the extent needed to run B2B sales and the site. We collect them from the sources in Section 7, for the purposes in Section 8, and we disclose them to the parties in Section 12.
We do not sell personal information as “sale” is defined in the CCPA, and we do not share it for cross-context behavioural advertising. We do not use or disclose sensitive personal information for purposes that require a right to limit under CPRA beyond what is necessary to provide the Service.
Subject to verification and exceptions, you may request to know/access, correct, or delete personal information we hold as a business, and to opt out of sale/sharing (which we do not engage in). Submit requests to the privacy email in Section 2. We will not deny goods or services, charge a different price, or provide a different level of quality because you exercised these rights, except as the law allows.
This policy is not an acknowledgement that every US statute applies to Remote Fort B.V.; applicability depends on thresholds and the nature of the processing.
20.Children
The Service is built for organisations and adults acting in a professional capacity. You must be at least 18 to use the Service. We do not knowingly collect personal data from children. If you believe a child has provided personal data, contact our privacy email and we will delete it where required and appropriate.
21.Automated decision-making and profiling
We do not make solely automated decisions that produce legal or similarly significant effects about website visitors or Authorised Users as contemplated by GDPR Article 22 (for example, we do not use an algorithm alone to refuse a job or to set a legally binding credit decision).
We do use limited profiling in the ordinary sense of logs and analytics (security scoring at the WAF, aggregate traffic analysis, and optional AI drafts inside a tenant). Security automation may block abusive traffic. Product AI suggestions are tools for the Customer’s reviewers, not automated legal determinations about individuals.
22.Third-party services and integrations
The website and product may link to third-party sites (auditors, partners, documentation, payment pages). We are not responsible for their privacy practices.
If a Customer connects identity, cloud, device, or other systems, those providers process data under the Customer’s contract with them. We receive what the integration is configured to send. The Customer must ensure the connection is authorised and proportionate.
23.Records of processing and personal-data breaches
We maintain records of processing activities for controller and processor operations as required by GDPR Article 30.
If we suffer a personal-data breach as controller, we will assess risk to data subjects and notify the Autoriteit Persoonsgegevens within 72 hours where required by Article 33, and notify affected individuals where Article 34 requires it.
If we suffer a personal-data breach as processor, we will notify the affected Customer without undue delay as required by Article 33(2) and the DPA so the Customer can meet its own duties.
24.Changes to this policy
We may update this Privacy Policy to reflect changes in the Service, subprocessors, or the law. We will post the updated policy on this page and change the “Last updated” date. If a change is material, we will provide a more prominent notice (for example an email to the billing or privacy contact on file, or an in-product notice) where we can reasonably do so.
The “Effective” date is the date the current version took effect. Prior versions may be requested from our privacy or legal email. Continued use of the public website after an update constitutes notice of the new policy for controller activities on the site. Customer contracts and DPAs are changed only in accordance with those documents.
25.Contact
Questions, requests, or complaints about this policy or our privacy practices:
- Remote Fort B.V.
- Keizersgracht 123
- 1015 CJ Amsterdam
- The Netherlands
- Privacy: privacy@remotefort.com
- Legal: legal@remotefort.com
- Security: security@remotefort.com
- Support: support@remotefort.com
