Privacy & cookie statement

Introduction

We have drawn up this privacy and cookie statement to make it clear to you that we take your privacy seriously. For this reason, the personal data collected by us is carefully processed and secured. We adhere to the European General Data Protection Regulation (GDPR).

Bastion 365 – Data Controller
This statement describes how Bastion 365 and its related entities process your personal data in connection with your use of our platform and related services.
This policy describes the rules that apply when you or a sender uses Bastion 365.

Bastion 365 – Processor
The Bastion 365 platform is mainly used by business service providers. In these cases, Bastion 365 acts as a processor on behalf of these organizations. In the communication, we will always indicate who the organizations are. In this cases, the privacy statement of the organization themself applies.

Bastion 365 has a processing agreement with all these organizations. The organizations themselves are the Data Controller and are therefore also your primary point of contact.

Personal Data

Bastion 365 processes the following personal data.

Organization accounts (subscribers)
The following data is processed for registered customers:

  • Organization name
  • Business address and billing information
  • First and last names
  • Titles and roles
  • Email addresses
  • Language settings
  • Preference settings
  • Phone number(s)
  • Account ID, Microsoft ID
  • Authentication resources
  • Account verification & authentication

 

Message recipents (users)
The following data is processed for message recipients:

  • Email address
  • Language settings
  • Phone numbers used for multifactor authentication
  • Authentication resources used for multifactor authentication
  • Account verification & authentication

 

Transactions (use of the service)
During the use of the service, Bastion 365 processes and logs the following data of transactions that are handled by Bastion 365.

  • Dates and times of transactions
  • Email addresses of senders and recipients
  • Domains and IP addresses of senders and recipients mail servers/mail accounts
  • Security settings of mail servers such as DNSSEC, SPF, DMARC, DKIM and certificates
  • Phone numbers used for multifactor authentication
  • Authentication means and IDs used for multifactor authentication
  • Subject of sent and received messages
  • Classifications and labels of messages and files
  • Delivery, download and read confirmations of communication

 

Cookies
Cookies are necessary for the proper functioning of the service. Only analytical, technical and functional cookies are used for this.

Purposes

Bastion 365 processes the aforementioned personal data for the following purposes:

  • Logging of senders and recipients, with authentication via multiple methods
  • Sending and delivery of notifications, e-mails, forms and files
  • Informing senders about successful or unsuccessful deliveries
  • Notifying senders about the presence of sensitive information, unusual recipients or settings to prevent possible data leaks
  • Providing support for our services
  • To verify unusual activity and/or attempts to gain unauthorized access to our service or data
  • Logging, monitoring and auditing the service
  • Internal reporting on the use of the service for quality and capacity monitoring as well as for improving our service and service provision

Bastion 365 processes these personal data on behalf of its customers to guarantee the correct and safe functioning of the service and for applicable legislation.

Retention period

Data is stored:

  • E-mails, forms and files are not stored longer than necessary for the use of the service. For messages and files that can be delivered directly, this is a maximum of 24 hours, for messages and files that must be retrieved via a portal, this is usually a maximum of 90 days (adjustable by the sender).
    Bastion 365 employees do not have access to the messages and files.
  • Logging is stored as standard in accordance with NEN 7513 (currently 5 years).
  • Administrative data is stored in accordance with the fiscal retention period of 7 years.

 

Storage location & measures

All data is always stored and processed within the European Economic Area (EEA). Bastion 365 and sub processors process data in accordance with ISO 27001. In addition, we have taken appropriate technical and organizational measures to protect your personal data.

Minors

We do not collect, store or use personal data of children under the age of 16.
No part of our services is aimed at children. If you are aware that our services are used by people under the age of 16, please contact us immediately.

Contact details

You can always contact us, also for matters such as the right to access, objection or removal.

If we are the controller, we will handle this ourselves. If we act as a processor, we will refer you to the correct controller of the organization in question.

In principle, we will contact you within two weeks. If necessary, we may ask you to identify yourself.

You can also always file complaints with us directly, with our customers being the controller and of course also with the Dutch Data Protection Authority. https://www.autoriteitpersoonsgegevens.nl

Bastion 365 also has a data protection officer (DPO), who can be reached at: legal@bastion365.nl  / Phone 088-2244000.

Contact

Bastionic B.V. (Bastion 365)
Lange Voorhout 92
2514 EJ  The Hague
Netherlands
EUID: NLNHR.82689342
https://bastion365.com
info@bastion365.nl
Phone +31 88 2244000