1. Who is responsible for your data?
Dennis Radermacher, trading as EyeOnCyber, a Portuguese trabalhador independente (NIF 284204633), established in Portugal, is responsible for personal data processed in connection with this website and EyeOnCyber services.
Geographic establishment address
Lugar S. Gregório, Casais, M1357 4960-130 Melgaço Portugal
Email: contact@eyeoncyber.com
2. Scope of this Privacy Policy
This policy explains how information is handled when you visit the EyeOnCyber website, prepare an enquiry, or engage EyeOnCyber for cybersecurity consulting. It covers the current static marketing website and information received through consulting work.
3. Visiting the website
This is a static website. It does not create user accounts, does not use a database, and does not run analytics, advertising tracking or session recording.
The EyeOnCyber website is hosted on Vercel. Vercel may process technical request information necessary to deliver and protect the website, such as IP addresses, request metadata and server logs. EyeOnCyber does not operate a separate visitor analytics product on this website.
4. Enquiries and contact
The enquiry form on this website prepares a message in your browser. Nothing is submitted to an EyeOnCyber server, database or API when you use the form. You may open the prepared message in your email app or copy the text. You review and send it yourself.
If you later send an enquiry, EyeOnCyber will use the information you provide to understand your request, reply, and, if relevant, scope work. Please do not include passwords, secrets or sensitive findings in an initial message.
5. Consulting engagements
If you engage EyeOnCyber, additional information may be processed as needed to perform the agreed work. That can include contact details, project information, system descriptions, and materials you supply. Processing is limited to the agreed security purpose and the contractual documents for the engagement.
6. OSINT and information about third parties
Where a service involves public-source exposure research, EyeOnCyber limits research to the agreed security purpose, minimises unnecessary personal data, and applies the contractual OSINT boundaries agreed for the engagement.
7. Recipients and service providers
EyeOnCyber does not sell personal data. Information may be processed by infrastructure providers used to operate the website, or by professional tools needed to deliver an engagement.
The website is hosted on Vercel. Email service provider details will be updated once the mailbox configuration is finalised.
8. International data transfers
Information processed by Vercel to host the website, or by the email service used to receive enquiries, may be processed in or accessed from countries outside Portugal or the European Economic Area. Where that occurs, EyeOnCyber will take appropriate steps required by applicable law.
9. How long information is kept
Retention depends on the type of information and the reason it is held:
- Temporary credentials and access details are deleted or revoked when they are no longer necessary.
- Temporary source-code working copies are deleted after the engagement or an agreed short retest window.
- Raw security evidence is normally kept no longer than 90 days after final delivery.
- Final security reports are normally kept no longer than 12 months.
- Contracts, invoices and statutory records are retained according to applicable Portuguese legal requirements.
10. Security
EyeOnCyber applies practical security measures appropriate to the nature of the information and the service. No method of transmission or storage is completely secure.
11. Your rights
Depending on applicable law, you may have rights to request access, rectification, erasure, restriction or objection, and to lodge a complaint with a supervisory authority. In Portugal, the Comissão Nacional de Proteção de Dados (CNPD) is the data protection authority.
Rights requests can be sent to contact@eyeoncyber.com, or through the communication channel you already use with EyeOnCyber.
12. Automated decision-making
EyeOnCyber does not use automated decision-making, including profiling, that produces legal or similarly significant effects about website visitors.
13. Cookies and similar technologies
The current EyeOnCyber website does not use analytics, advertising pixels, session recording or known non-essential tracking technologies.
This will be reassessed if such technology is added later. If that happens, this policy will be updated before those technologies are used.
14. Changes to this policy
This policy may be updated as the website, services or legal requirements change. The version published on this page is the current one.