Privacy Policy – Refracted Security
At Refracted Security (42 Secure BV), we understand the importance of protecting your personal data. As a Belgian cybersecurity consultancy and product company, we are committed to processing personal data in a transparent, secure, and lawful manner in accordance with the General Data Protection Regulation (GDPR) and applicable Belgian legislation.
This Privacy Policy explains which personal data we collect, why we process it, how long we retain it, how we protect it, and which rights you have as a data subject.
Your personal data is processed exclusively for legitimate business purposes related to our cybersecurity services, software products, customer relationships, and business operations.
We do not sell your personal data, and we do not share it with third parties for commercial purposes. When we rely on external service providers who process personal data on our behalf, we ensure that appropriate contractual and security measures are in place in accordance with the GDPR.
Data Controller:
Refracted Security (42 Secure BV)
Guido Gezellelaan 11,2500Lier
Belgium
BTW BE 0775.918.638
For any questions regarding this Privacy Policy or the processing of your personal data, you can contact us at: info@refracted.eu.
Why does Refracted Security process your personal data?
Refracted Security processes personal data to provide and manage its cybersecurity services and products, including consultancy, security assessments, testing, incident response, implementation, support, and customer management.
We may also process personal data to:
- communicate with customers, prospects, and partners;
- respond to requests and provide support;
- manage contracts, invoicing, and legal obligations;
- improve our services, products, security, and customer experience;
- send marketing communications were permitted by law, legitimate interest or based on consent.
Which personal data do we process?
We only process personal data necessary for the purposes described above. Depending on your relationship with Refracted Security, this may include:
- Identification and contact data
- name, professional role, company details, email address, telephone number, and business correspondence.
- Professional and contractual data
- organization details, contracts, communications, and service-related information.
- Technical and security data
- user accounts, system information, logs, configurations, and security assessment data where required for our services.
We do not intentionally process special categories of personal data under Article 9 GDPR unless necessary and permitted by law.
What are the legal grounds for processing?
Refracted Security processes personal data based on:
- Contractual necessity: to provide agreed services and products;
- Legal obligations: such as accounting, tax, and regulatory requirements;
- Legitimate interests: such as managing business relationships, improving services, securing systems, and preventing misuse;
- Consent: where required, for example for certain marketing activities or cookies.
How long do we retain personal data?
We retain personal data only for as long as necessary for the purposes for which it was collected or to comply with legal obligations.
Retention periods depend on the type of data, including:
- customer and contractual data: during the relationship and any legally required period thereafter,
- financial records: according to applicable Belgian retention requirements,
- prospect data: only while relevant or until consent is withdrawn,
- technical and security data: only as long as necessary for service delivery and security purposes.
When no longer required, data is securely deleted or anonymized.
Who receives personal data?
We only share personal data where necessary for our activities and service delivery, including with:
- IT, cloud, hosting, and software providers;
- professional advisors and accounting partners;
- subcontractors acting on our behalf.
Such parties may only process personal data according to our instructions and appropriate GDPR safeguards, including data processing agreements where required.
We do not sell personal data and no transfers outside the European Economic Area take place.
How do we protect personal data?
As a cybersecurity company, Refracted Security applies appropriate technical and organizational measures to protect personal data against unauthorized access, loss, alteration, disclosure, or destruction.
Measures include access controls, secure authentication, encryption, monitoring, backups, security reviews, confidentiality obligations, and supplier security requirements.
Your GDPR rights
You have the right to:
- access your personal data,
- correct inaccurate data,
- request deletion where applicable,
- restrict processing in certain circumstances,
- object to certain processing activities, including direct marketing,
- receive your data in a portable format where applicable,
- withdraw consent where processing is based on consent.
To exercise your rights, contact: info@refracted.eu.
We may request information to verify your identity before processing your request.
Cookies
Our website may use cookies or similar technologies for functionality, security, and user experience.
Strictly necessary cookies may be used without consent. Other cookies, such as analytics or marketing cookies, will only be used with your consent where required by law.
Complaints
If you have concerns about our processing of personal data, please contact us first so we can address your concern.
You may also lodge a complaint with the Belgian Data Protection Authority:
Belgian Data Protection Authority (DPA)
Rue de la Presse 35
1000 Brussels, Belgium
Website: https://www.dataprotectionauthority.be
Changes to this Privacy Policy
Refracted Security may update this Privacy Policy to reflect changes in services, processing activities, or legal requirements.
The latest version will always be available on our website.
Last updated: August 2026
