Privacy Statement

Version 3.0 | Effective date: 23 August 2026

Who we are

Cordaata provides a cyber risk management platform that translates technical cyber risk into financial terms. This Privacy Statement explains how we collect, use, share, and protect personal data when you visit our websites, contact us, or do business with us.

The controller of your personal data is the Cordaata entity you interact with:

  • Cordaata BV, enterprise number BE1031907675, Gaaienlaan 19, 2360 Oud-Turnhout, Belgium.
  • Cordaata Inc., a Delaware corporation, 251 Little Falls Drive, Wilmington, Delaware 19808, USA.

For visitors to cordaata.com and for prospects, marketing contacts, and business contacts in the European Economic Area and the United Kingdom, the controller is Cordaata BV. For prospects, marketing contacts, and business contacts in the United States, the controller is Cordaata Inc. For customers, partners, and suppliers, the controller is the Cordaata entity that is party to the applicable Order or contract, which may be either Cordaata BV or Cordaata Inc. regardless of the location of the customer, partner, or supplier. References to "Cordaata", "we", "us", or "our" mean the relevant entity.

For all privacy matters, contact legal@cordaata.com .

What this statement covers

This statement covers personal data we process for our own purposes as a controller. That includes our websites, marketing, sales, events, supplier relationships, and business administration.

It does not cover personal data we process on behalf of our customers within the Cordaata platform. When a customer uses the platform, Cordaata acts as a processor and that processing is governed by our Data Processing Addendum, available at cordaata.com/legal/dpa.html , and the customer's agreement with us. If your personal data is in a customer's Cordaata environment, contact that customer with any privacy request. We will refer requests to the relevant customer where required.

Our services are designed for businesses and business professionals. They are not directed at children, and we do not knowingly collect personal data from anyone under 18.

Personal data we collect

We collect personal data that you provide to us, including when you:

  • Complete a contact, demo, or download form on our website.
  • Subscribe to our newsletter or other communications.
  • Register for or attend a webinar or event.
  • Communicate with us by email, phone, LinkedIn, or other channels.
  • Enter into or perform a contract with us as a customer, partner, or supplier.

This data typically includes your name, job title, company, email address, phone number, and the content of your communications with us. For customers, partners, and suppliers, it also includes billing and payment details and contract records.

We also collect certain data automatically when you visit our websites, including IP address, device and browser information, pages viewed, and interactions with our pages and emails. This is collected through cookies and similar technologies as described below and subject to your consent choices.

We may supplement contact records with business information from publicly available professional sources, such as your company website or LinkedIn profile, to keep our records accurate and our communications relevant.

How we use personal data and why we may lawfully do so

We use personal data to:

  • Respond to your enquiries and provide information you request.
  • Provide, administer, and improve our websites and services.
  • Manage customer, partner, and supplier relationships, including billing and account administration.
  • Send business-to-business marketing about our products and services, subject to your right to opt out at any time.
  • Organise and run webinars and events.
  • Analyse how our websites and communications perform.
  • Maintain the security of our websites and systems and prevent fraud or misuse.
  • Comply with legal obligations and establish, exercise, or defend legal claims.

Where the GDPR or UK GDPR applies, we rely on the following legal bases:

  • Performance of a contract, where we process data to deliver services you or your organisation have requested.
  • Legitimate interests, including operating and promoting our business, communicating with business contacts, securing our systems, and improving our services, in each case balanced against your rights.
  • Consent, for non-essential cookies and where local law requires consent for marketing, which you may withdraw at any time.
  • Legal obligation, where processing is required by law.

When you submit a contact or demo form, we will use your details to respond to your enquiry and to follow up about our products and services. Every marketing email we send includes an unsubscribe option.

Cookies and similar technologies

Our websites use cookies and similar technologies. Essential cookies are required for the site to function and do not need consent. Analytics and marketing cookies are used only with your consent, which you can give, refuse, or change at any time through the cookie banner and preference centre.

Third-party technologies we use include Google Tag Manager, Google Analytics 4, HubSpot, and the LinkedIn Insight Tag. These help us measure site performance, manage enquiries, and reach relevant professional audiences with our advertising. Where required, these technologies operate under consent mode so that no analytics or marketing data is collected before you consent.

How we share personal data

We do not sell personal data. We share personal data only as described here:

  • Service providers who process data on our behalf, such as HubSpot for CRM, forms, and email, Google for analytics and tag management, and our hosting and IT providers. These providers act under contracts that restrict their use of your data.
  • Professional advisers, such as lawyers, accountants, and auditors, where needed for our business.
  • Public authorities, where disclosure is required by law or necessary to protect our rights, our users, or others.
  • A buyer or successor, in connection with a merger, acquisition, financing, or sale of assets, under appropriate confidentiality protections.
  • Within the Cordaata group, between Cordaata BV and Cordaata Inc., for the purposes described in this statement.

Marketing cookies may involve sharing identifiers with advertising platforms such as LinkedIn. Under some US state laws this may be considered "sharing" for targeted advertising. You can opt out at any time through the cookie banner, which applies your choice to these technologies.

International transfers

Cordaata operates from Belgium and the United States. Where personal data is transferred outside the European Economic Area or the United Kingdom, we rely on European Commission adequacy decisions, including the EU-US Data Privacy Framework where the recipient is certified, or the European Commission's Standard Contractual Clauses and the UK addendum, together with appropriate supplementary measures.

How long we keep personal data

We keep personal data only as long as needed for the purposes described in this statement, and then delete or anonymise it. As a guide, customer and supplier records are kept for the duration of the relationship plus up to seven years for legal, tax, and accounting purposes. Marketing contact data is kept until you opt out or after a sustained period of inactivity. Website analytics data is kept in accordance with the retention settings of the relevant tool, typically no longer than 26 months. We may keep data for longer where necessary to comply with law or to establish, exercise, or defend legal claims.

Your rights

Depending on where you live, you may have the right to:

  • Access the personal data we hold about you and receive a copy.
  • Correct inaccurate or incomplete data.
  • Request deletion of your data.
  • Restrict or object to certain processing, including direct marketing.
  • Receive your data in a portable format.
  • Withdraw consent at any time, without affecting processing before withdrawal.
  • Opt out of targeted advertising, as described in the cookies section.
  • Not be discriminated against for exercising your rights.

To exercise any right, contact legal@cordaata.com . We may need to verify your identity before acting on a request. We respond within the timeframes required by applicable law and will tell you if we need longer for a complex request. Where an exemption applies, we may decline a request and will explain why.

If you are in the EEA, you may lodge a complaint with the Belgian supervisory authority, the Gegevensbeschermingsautoriteit, at gegevensbeschermingsautoriteit.be , or with your local supervisory authority. If you are in the UK, you may contact the Information Commissioner's Office. If you are in the US, you may contact your state attorney general.

How we protect personal data

We maintain technical and organisational measures designed to protect personal data against unauthorised access, loss, alteration, and disclosure, appropriate to the risk. These include encryption of data in transit and at rest, role-based access controls with multi-factor authentication for production systems, segregation of production and development environments, security awareness for our team, and contractual security requirements for our service providers. No system is completely secure, and we cannot guarantee absolute security, but we review and improve our measures on an ongoing basis.

Changes to this statement

We may update this statement from time to time. The current version, with its effective date, is always available on this page. If we make material changes, we will take reasonable steps to bring them to your attention, such as a notice on our website. Your continued use of our websites after an update takes effect indicates acceptance of the updated statement to the extent permitted by law.

Contact

  • Cordaata BV, Gaaienlaan 19, 2360 Oud-Turnhout, Belgium
  • Cordaata Inc., 251 Little Falls Drive, Wilmington, Delaware 19808, USA