Privacy policy
What personal data RagnarOps Security Labs collects through this website, why, where it goes, how long it is kept, and how to exercise your rights over it.
Last updated
Who we are
RagnarOps Security Labs is a trading name of Pablo Ruiz Encinas, who is the controller of the personal data described in this policy. There is no separate company: the practice is not incorporated, so the controller is an individual.
- Based in: Amsterdam, Netherlands
- Contact: contact@ragnaropsec.com
We have one contact address. Every question, request, or complaint under this policy goes to contact@ragnaropsec.com — there is no separate privacy or legal mailbox.
What this policy covers
This website is a static marketing site. The contact form is the only place it collects personal data, and this policy covers what happens to what you submit there. The field notes also carry view and like counters; those hold no personal data, and they are described below so that nothing the site does is left unstated. This policy does not cover data we may process inside a client environment during a contracted engagement — see "When we act as a processor" below.
What we collect
When you submit the contact form, we collect:
- Your name
- Your work email address
- Your company
- An optional free-text note describing the scope of what you want to discuss
- The service-interest tags you select
- The language the site was set to when you submitted the form
- The website you arrived from, as a bare hostname — for example
www.linkedin.com— and nothing more of it - Any campaign labels in the link you followed (
utm_source,utm_medium,utm_campaign), which are labels we write into our own published links
That is the complete list.
The last two are how we understand which of our own channels reach people, and they are deliberately narrow. We keep the host of the referring site, never the full address: an address on someone else's site can carry their query strings, and those can contain data about you or about other people. Your browser discards everything but the host before the form is sent, and our server rejects anything that does not look like a bare hostname rather than trying to trim it. If you came to us directly, typed the address, or used a bookmark, there is nothing to record and we record nothing.
We do not do this by watching you around the site. There is no script measuring where you go; these two values are read once, from the page you landed on, and are only ever sent if you choose to submit the form.
Field-note counters
Each field note carries a view count and a like count. What we store for this is two whole numbers per article and nothing else. There is no visitor identifier, no IP address, no per-read record, and no timestamp beyond when a total last changed — so we cannot tell who read an article, whether two views were the same person, or which articles any individual has read. These totals are not personal data and are not linked to anything that is.
Opening a note makes your browser call the counter endpoint, which runs on the same Frankfurt infrastructure as the contact form. As with any request over the internet, that endpoint receives your IP address in order to send a reply. It is not written to the counters and we do not store it.
Whether this browser has already been counted for a note, and which notes you have liked, is kept in your own browser's local storage. It is never transmitted to us. Clearing your site data resets it; the only consequence is that a later visit may be counted again.
What we do not collect
- We do not log or store your IP address, user agent, or any device fingerprint. Automated abuse controls run inside the server-side function that processes submissions and are not persisted anywhere.
- We do not run analytics. There is no page-view tracking, no session recording, no third-party analytics service, and no advertising or tracking network. Nothing on this site measures your visit. The field-note counters described above are aggregate totals with no identifier attached, and cannot report who read what. The one thing we do record about where visitors come from is the referring host on a submitted enquiry, described in "What we collect" — that is attached to an enquiry you chose to send us, not to a visit.
- We do not set cookies.
- We do not use third-party tracking or advertising networks.
- We do not operate an account system, a login, or user profiles.
- We do not use your data for automated decision-making or profiling that has a legal or similarly significant effect on you (Article 22 GDPR).
Why we process it, and on what basis
We process the data in the contact form to respond to your enquiry and, where relevant, to prepare a scope and quote for an engagement.
- Where we are responding to a general enquiry, our lawful basis is our legitimate interest in operating this business and answering messages addressed to us (Article 6(1)(f) GDPR).
- The referring host and campaign labels are processed on the same legitimate-interest basis (Article 6(1)(f)): a practice this size has to know which of its own channels actually reach people. We weighed that against your interests and kept the processing to the minimum that answers the question — no identifier, no browsing history, no profile, nothing that changes how we treat you or what you are shown. You can object to it under Article 21; see "Your rights" below.
- Where your enquiry is the first step toward a contract — for example, scoping a specific engagement — our lawful basis is the steps necessary to enter into that contract, and its subsequent performance (Article 6(1)(b) GDPR).
We do not use the data for any other purpose, and we do not send you marketing you have not asked for.
Where it goes
We use three subprocessors to run this site. This is the complete list.
- Supabase — receives your contact-form submission and stores it, and holds the field-note counters. The functions that handle both, and the database they write to, run in the
eu-central-1(Frankfurt, Germany) region. The database denies all direct access from your browser; only those server-side functions can write to it. - Resend — a transactional email provider, EU region. Submitting the form triggers a notification email to us via Resend.
- Netlify — serves the pages of this website. Your form submission does not pass through Netlify: the form posts directly to the Frankfurt endpoint above. As the host, Netlify does process the technical request data involved in delivering a web page to you, including your IP address; we do not receive or store that data.
Where your data is processed
The contact form submits directly to infrastructure in Frankfurt, and the data stays there. What you send through the form is not transferred outside the European Economic Area, so no adequacy decision or standard contractual clauses are engaged for it. The field-note counters run on the same Frankfurt infrastructure and hold no personal data to transfer.
We do not sell your data, and we do not share it with anyone outside this list except where the law compels us to.
How long we keep it
Enquiries are deleted 24 months after submission. We keep them that long because enterprise and public-sector security procurement cycles routinely run past a year from first contact to a signed engagement. A scheduled job runs against the database daily and deletes anything past that age.
The referring host and campaign labels sit on the same record as the rest of the enquiry, so they are deleted with it and on the same schedule. There is no separate copy anywhere.
The field-note counters have no retention period, because there is nothing in them to retain about you — they are running totals per article with no record of any individual read.
Your rights
Under the GDPR, you can ask us to:
- Give you a copy of the personal data we hold about you (Article 15)
- Correct inaccurate data (Article 16)
- Delete your data (Article 17)
- Restrict processing while a dispute is resolved (Article 18)
- Give you your data in a portable format, where the processing is based on consent or contract and carried out by automated means (Article 20)
- Stop processing based on our legitimate interest, unless we can show compelling legitimate grounds that override your interests (Article 21)
Send a request to contact@ragnaropsec.com. We will respond within one month of receiving it, as required by Article 12(3) GDPR. Where a request is complex or we have received a number of them, that period can be extended by a further two months — if that applies, we will tell you within the first month and explain why.
Complaints
If you are unhappy with how we have handled your data, contact us first at contact@ragnaropsec.com. You also have the right to lodge a complaint with the Dutch supervisory authority, the Autoriteit Persoonsgegevens (autoriteitpersoonsgegevens.nl), or with the data protection authority in the EU member state where you live or work.
When we act as a processor
If your enquiry leads to a signed engagement, we may process personal data inside your environment while carrying out that work — for example, data we encounter while testing a system you have authorised us to assess. In that context you are the controller of that data and we act as processor, working on your instructions.
That processing is governed by the data processing terms in the engagement contract, not by this policy. We do not describe those practices here because they are set out, engagement by engagement, in that agreement.
Changes to this policy
If we change this policy, we update the date at the top of this page.