Optimaize NIS2SelfCheck
Home Privacy Cookies Terms
Start free scan
Legal

Privacy Statement

How NIS2SelfCheck processes personal data and report-related information.

Last updated: June 2, 2026 Optimaize

Who is responsible

Optimaize is the controller for the personal data processed through the NIS2SelfCheck flow.

Contact: info@optimaize.io. Registered address: Jacob Bontiusplaats 9, 1018LL Amsterdam.

  • KvK: 94040338

What we process

The self-check processes the information you provide and the public technical signals we collect about the submitted domain.

  • Submitted domain name
  • Contact name and email address
  • Questionnaire answers
  • Generated scores, findings, report files, and payment status
  • Service contact request details when you request paid follow-up services
  • Google Analytics 4 data such as page visits, referral source, campaign tags, device and browser category, approximate location, and self-check funnel events

Website analytics

Google Analytics 4 is enabled on this deployment to understand visit volume, traffic sources, campaign performance, and funnel conversion points across the public self-check flow.

The current implementation is intended for analytics measurement and is loaded only after the visitor grants analytics consent through the site's consent banner.

Why we process it

We use this data to operate the self-check product, generate the requested report, send the report by email, handle detailed report purchases, and respond to service requests.

  • Performance of the requested self-check service
  • Communication about the requested report or service
  • Operational security, fraud prevention, and auditability
  • Compliance with legal and tax obligations where applicable

Legal bases

We process personal data where this is necessary to provide the requested self-check service, to communicate about that service, to process a requested paid upgrade, to protect our systems and service integrity, and to comply with legal obligations that apply to our business.

Public scan scope

The self-check only uses publicly accessible technical information about the submitted domain and related public services. It is designed as a passive external review and does not attempt to log in, bypass controls, or exploit vulnerabilities.

Third parties and processors

Depending on the flow you use, third parties may process limited data on our behalf or as independent providers.

  • TransIP or your configured SMTP provider for outgoing report and contact emails
  • Stripe for paid detailed report checkout and payment confirmation
  • Google Analytics / Google Tag infrastructure when analytics consent is granted
  • Google Fonts on the landing page, which can result in browser requests to Google-hosted font infrastructure

Retention

We retain self-check data for as long as needed to deliver the report, handle customer follow-up, support troubleshooting, and maintain a reasonable audit trail for the service.

Self-check run data, questionnaire answers, generated reports, and service contact requests are generally retained for up to 24 months after the last relevant interaction, unless a longer retention period is necessary for an ongoing customer relationship, dispute handling, security investigation, or legal obligation.

Where payment, invoicing, or tax records must be retained for longer under applicable law, the relevant financial records are retained for the legally required period.

Your rights

Under the GDPR/AVG, you may have rights of access, rectification, deletion, restriction, objection, and data portability, depending on the legal basis and context.

Requests can be sent to info@optimaize.io.

Questions or complaints

If you have questions about this statement or our processing, contact info@optimaize.io.

If you are not satisfied with the handling of your request, you may have the right to lodge a complaint with the Dutch Data Protection Authority (Autoriteit Persoonsgegevens).

© 2026 Optimaize | KvK 94040338 | info@optimaize.io | Powered By Polderbase
Privacy Cookies Terms