Rechtliches

Privacy Policy

Last updated: July 2026

1. Responsible Entity (Verantwortlicher)

Louis Sieg
ReadySecGo
Herwarthstraße 31
50672 Köln, Germany
Email: info@readysecgo.com
Phone: +49 221 29887384

2. Scope of This Policy

This policy covers three distinct contexts in which we process personal data. Where a section applies to only one context, this is stated explicitly.

  • (A) Website — our public site at readysecgo.com, including the Knowledge Hub, the contact form, the self-assessment quiz, and the booking link.
  • (B) Consulting Services — the information-security and compliance advisory work we perform for clients (internal audit, gap analysis, audit readiness, virtual CISO), and the business communication around it.
  • (C) Compliance App — our compliance-automation application at app.readysecgo.com. The app is currently in a limited pre-launch / beta phase.

3. What Data We Collect and Why

3.1 Website (A)

Contact form. When you submit a contact request, we collect your name, email address, company name, and your message. We use this solely to respond to your inquiry. Submissions are processed in our CRM (HubSpot). If you have consented to statistics cookies, we additionally attach basic campaign attribution (the utm_source, utm_medium and utm_campaign parameters of the link that brought you here) and your Google Analytics identifier (ga_client_id) to the resulting CRM record, so we can understand which channels generate enquiries. Without statistics consent these fields are neither collected nor transmitted. If you have also consented to marketing cookies, HubSpot’s tracking code links your visit history to the resulting CRM record so we can see which channel originally brought you to us; the cookies involved are listed in the cookie table below.

Self-assessment quiz. If you choose to receive your quiz results by email, we collect your email address and your answers and forward them to HubSpot to generate and send your results. This happens only with your explicit consent, which you may withdraw at any time at info@readysecgo.com.

Knowledge Hub. Public articles are served from our headless CMS (Sanity). If you sign in to the Knowledge Hub, authentication is handled by Supabase, which sets a strictly necessary session cookie (see section 7).

Server logs. Our hosting provider (Vercel) automatically records technical access data including IP address, browser type, pages visited, and timestamps. We use this for security and performance and do not use it to identify you.

Booking. The contact page links out to HubSpot’s scheduling tool (HubSpot Meetings) to book a consultation. We do not embed the scheduler on our pages; data is only transmitted to HubSpot after you actively click the booking link and open HubSpot in a new tab.

Session recordings and heatmaps. We use PostHog (EU Cloud, Frankfurt) to record session replays and generate heatmaps of on-site interactions, so we can understand usability issues and improve the site. PostHog cookies are set only after you give consent for the “statistics” category in our consent banner (Cookiebot) and are blocked until then, in the same way as our Google Analytics cookies (see section 7). All form inputs and all on-page text are masked in recordings; non-text elements such as page layout and images are captured. We do not capture network request headers or bodies. Client IP addresses are discarded after being used momentarily to derive an approximate location — raw IP addresses are not retained. Recordings are kept for 30 days.

Error monitoring. We use Sentry to automatically capture technical error reports from the website — including stack traces, the affected page URL, and browser/OS/runtime information. Client IP addresses are not stored. We use this solely to detect, diagnose, and fix bugs, under our legitimate interest in operating a secure and functional website (Art. 6(1)(f) GDPR — see section 4). Sentry data is stored in the EU. We do not use Sentry’s session-replay feature.

3.2 Consulting Services (B)

To deliver and administer our advisory services we process the business-contact and engagement data of clients and their staff — for example names, business email addresses, roles, and the content of our correspondence and project documentation. We use Google Workspace for business email, calendar, and document handling, and HubSpot to manage the client relationship.

Where, in the course of an engagement, we process personal data contained in a client’s own systems or documents strictly on that client’s behalf and under their instructions, the client is the controller and we act as a processor under a separate data-processing agreement (Art. 28 GDPR). This policy then governs only the data for which ReadySecGo is itself the controller.

3.3 Compliance App — app.readysecgo.com (C)

When you use the app we process the account and usage data needed to operate it — for example your name, email address, authentication identifiers, and the records you create in the application. Authentication and the application database are provided by Supabase; the application is hosted on Vercel. Both are configured for EU data residency (see sections 5 and 6).

For personal data that customers upload into the app about their own staff or third parties, the customer is the controller and ReadySecGo acts as a processor under a data-processing agreement (Art. 28 GDPR). As the app is in a limited beta, this section will be expanded before general availability.

4. Legal Bases for Processing

We process your data on the following legal bases under the GDPR:

  • Art. 6(1)(b) GDPR — performance of a (pre-)contractual obligation: responding to inquiries, delivering consulting services, and operating the app for account holders.
  • Art. 6(1)(a) GDPR — consent: sending quiz results by email, and non-essential cookies (such as the Google Analytics statistics cookies) set via our consent banner.
  • Art. 6(1)(f) GDPR — legitimate interest: operating a secure and functional website and app (server logs, error monitoring, abuse prevention).
  • Art. 6(1)(c) GDPR — legal obligation: statutory commercial and tax retention duties.

5. Recipients and Processors

We do not sell your personal data. We share data only with service providers acting as processors under Art. 28 GDPR. The core processing of website, services, and app data takes place inside the European Union; residual non-EU flows are described in section 6.

  • Vercel Inc.

    Purpose
    Hosting, edge delivery, server logs
    Context
    Website, App
    Data region
    EU (Frankfurt) origin; global edge CDN
  • Supabase Inc.

    Purpose
    Authentication and application database
    Context
    Website, App
    Data region
    EU
  • Sanity AS

    Purpose
    Headless CMS and image delivery (no account PII stored)
    Context
    Website
    Data region
    EU (Belgium); global image CDN
  • HubSpot Ireland Ltd.

    Purpose
    CRM, contact form, quiz results, consultation booking scheduler, campaign attribution (UTM / GA client ID)
    Context
    Website, Services
    Data region
    EU (Frankfurt); some sub-processors in the US
  • Google (Google Ireland Ltd.)

    Purpose
    Business email, calendar, documents; website analytics (Google Analytics 4 via Google Tag Manager, consent-gated)
    Context
    Services, Website
    Data region
    EU with residual US transfers
  • Functional Software, Inc. (Sentry)

    Purpose
    Error tracking and monitoring
    Context
    Website, App
    Data region
    EU
  • PostHog Inc.

    Purpose
    Session recording and heatmap analytics (consent-gated)
    Context
    Website
    Data region
    EU (Frankfurt)
  • Cybot A/S (Usercentrics)

    Purpose
    Consent management (cookie banner)
    Context
    Website
    Data region
    EU (Denmark)

We have data-processing agreements in place with our processors in accordance with Art. 28 GDPR; copies are available on request. A complete, current list of sub-processors for the app will be maintained for app customers as part of their data-processing agreement.

6. International Data Transfers

The core processing of your data takes place in the European Union: website and app hosting with Vercel (Frankfurt region), authentication and database with Supabase (EU region), CRM with HubSpot (Frankfurt data residency), the headless CMS with Sanity (Belgium), error monitoring with Sentry (EU data storage region), and session-replay/heatmap analytics with PostHog (EU Cloud, Frankfurt region). We select EU hosting regions wherever a provider offers them.

Certain residual flows may nonetheless reach the United States: (i) the global edge and image CDNs of Vercel and Sanity may serve cached responses from non-EU points of presence; (ii) HubSpot and Google rely on US-based sub-processors for parts of their service. Where recipients in the US process data, transfers are made primarily on the basis of the EU-U.S. Data Privacy Framework (adequacy decision of 10 July 2023, Art. 45 GDPR) and, in addition, on Standard Contractual Clauses pursuant to Art. 46(2)(c) GDPR.

7. Cookies and Similar Technologies

This website sets technically necessary cookies for authentication when you sign in to the Knowledge Hub (Supabase). Pages that embed or link to third-party services may cause those services to set their own cookies and receive your IP address only after you interact with them. We use Google Analytics 4 (loaded via Google Tag Manager) for statistical reach analysis; its cookies are set only after you give consent for the “statistics” category in our consent banner (Cookiebot) and are blocked until then. You can change or withdraw your choice at any time via the consent banner. The consent banner itself stores a strictly necessary cookie to remember your decision.

  • sb-<id>-auth-token

    Purpose
    Knowledge Hub authentication
    Lifetime
    Session
    Category / Basis
    Strictly necessary · §25(2) no. 2 TDDDG
  • sb-<id>-refresh-token

    Purpose
    Authentication token renewal
    Lifetime
    Until logout
    Category / Basis
    Strictly necessary · §25(2) no. 2 TDDDG
  • CookieConsent

    Purpose
    Stores your cookie-consent choices (Cookiebot)
    Lifetime
    1 year
    Category / Basis
    Strictly necessary · §25(2) no. 2 TDDDG
  • rsg_internal

    Purpose
    Marks a ReadySecGo staff browser so our own visits are excluded from analytics; set only when a team member opens /?rsg=team, and removed again via /?rsg=off
    Lifetime
    1 year
    Category / Basis
    Strictly necessary · §25(2) no. 2 TDDDG
  • _ga

    Purpose
    Google Analytics — distinguishes visitors
    Lifetime
    2 years
    Category / Basis
    Statistics · consent, Art. 6(1)(a) GDPR · §25(1) TDDDG
  • _ga_<id>

    Purpose
    Google Analytics 4 — persists session state
    Lifetime
    2 years
    Category / Basis
    Statistics · consent, Art. 6(1)(a) GDPR · §25(1) TDDDG
  • ph_<public_api_key>_posthog

    Purpose
    PostHog — distinguishes visitors for session recording
    Lifetime
    1 year (default)
    Category / Basis
    Statistics · consent, Art. 6(1)(a) GDPR · §25(1) TDDDG
  • hubspotutk

    Purpose
    HubSpot — identifies returning visitors; links form submissions to a CRM contact
    Lifetime
    6 months
    Category / Basis
    Marketing · consent, Art. 6(1)(a) GDPR · §25(1) TDDDG
  • __hstc

    Purpose
    HubSpot — visit analytics (first visit, last visit, visit count)
    Lifetime
    6 months
    Category / Basis
    Marketing · consent, Art. 6(1)(a) GDPR · §25(1) TDDDG
  • __hssc

    Purpose
    HubSpot — current session tracking
    Lifetime
    30 minutes
    Category / Basis
    Marketing · consent, Art. 6(1)(a) GDPR · §25(1) TDDDG
  • __hssrc

    Purpose
    HubSpot — session-start marker
    Lifetime
    Session
    Category / Basis
    Marketing · consent, Art. 6(1)(a) GDPR · §25(1) TDDDG

8. Data Retention

  • Contact inquiries — up to 6 months, unless an ongoing business relationship is established.
  • CRM / client records — for the duration of the business relationship and any applicable statutory retention periods (up to 10 years for commercial and tax records under German HGB and AO).
  • Quiz data — retained until you withdraw consent or object.
  • App account data — for the duration of the account, then deleted or anonymised subject to statutory retention duties.
  • Server logs — short-term, for security and performance purposes only.
  • Error events (Sentry) — retained for 30 days, then automatically deleted.
  • Session recordings (PostHog) — retained for 30 days, then automatically deleted.

9. Your Rights

Under the GDPR, you have the following rights:

  • Right of access (Art. 15 GDPR) — request a copy of the data we hold about you
  • Right to rectification (Art. 16 GDPR) — request correction of inaccurate data
  • Right to erasure (Art. 17 GDPR) — request deletion of your data
  • Right to restriction (Art. 18 GDPR) — request limited processing of your data
  • Right to data portability (Art. 20 GDPR) — receive your data in a structured, machine-readable format
  • Right to object (Art. 21 GDPR) — object to processing based on legitimate interest
  • Right to withdraw consent (Art. 7(3) GDPR) — withdraw any consent you have given, with effect for the future

To exercise any of these rights, contact us at info@readysecgo.com.

10. Right to Lodge a Complaint

You have the right to lodge a complaint with a supervisory authority. The competent authority for North Rhine-Westphalia is:

Landesbeauftragte für Datenschutz und Informationsfreiheit NRW (LDI NRW)
Kavalleriestraße 2–4, 40213 Düsseldorf
www.ldi.nrw.de

11. Changes to This Policy

We may update this privacy policy from time to time. The current version is always available at this URL. Last updated: July 2026.