1. Data Controller
ISMS Calculator is a SaaS product operated by ISMS Calculator (hereinafter referred to as "we", "us", or "the Company").
For any privacy-related inquiries, you may contact us at support@ismscalculator.com.
2. What Data We Collect
When you use ISMS Calculator, we may collect the following information:
- Account data: Your name, email address, and profile picture (when authenticating via Google OAuth).
- Estimation data: The calculator inputs you provide (company size, industry, maturity ratings, etc.) and the resulting estimates, when you choose to save them.
- Technical data: IP address, browser type, device information, and usage analytics collected automatically to maintain and improve the service.
3. How We Use Your Data
- To provide and maintain the ISMS Calculator service.
- To authenticate your identity and manage your account.
- To store and retrieve your saved estimates.
- To improve the service, fix issues, and develop new features.
- To comply with legal obligations applicable under Belgian and EU law.
4. Legal Basis for Processing (GDPR)
We process your personal data based on:
- Contractual necessity: Processing required to provide the service you signed up for.
- Legitimate interest: Analytics and service improvement.
- Consent: Where explicitly given, such as optional marketing communications.
5. Data Storage and Security
Your data is stored on secure, encrypted servers. We implement industry-standard technical and organizational measures to protect your personal data against unauthorized access, alteration, disclosure, or destruction. Each user's saved estimates are fully isolated and not accessible to other users.
6. Data Retention
We retain your account data and saved estimates for as long as your account is active. You may delete individual estimates at any time. If you wish to delete your account entirely, contact us at the address above.
7. Your Rights (GDPR)
Under the General Data Protection Regulation (GDPR), you have the right to:
- Access the personal data we hold about you.
- Rectify inaccurate or incomplete data.
- Request erasure of your personal data.
- Restrict or object to certain processing activities.
- Data portability in a machine-readable format.
- Lodge a complaint with the Belgian Data Protection Authority (Gegevensbeschermingsautoriteit).
8. Third-Party Services
We may use the following third-party services:
- Google OAuth: For social login authentication. Google's privacy policy applies to their handling of your authentication data.
- Analytics providers: To understand usage patterns and improve the service.
9. Cookies
We use essential cookies for authentication (session tokens). We may also use analytics cookies to understand how the service is used. You can control cookie settings through your browser preferences.
10. Changes to This Policy
We may update this Privacy Policy from time to time. We will notify you of significant changes by posting a notice on the service. Continued use of the service after changes constitutes acceptance of the revised policy.