Direct naar hoofdinhoud
Legal & Privacy

Privacy, Cookie & Legal Policy

Last updated: February 9, 2026

Privacy Policy

How we handle your data

1

Introduction

Welcome to SaitS. We value your privacy and ensure that your personal data is carefully processed and secured. In this privacy policy, we explain what data we collect, how we use it, and what rights you have.

2

What data do we collect?

We collect the following personal data:

  • Account data: name, email address, login credentials
  • Billing data: address, payment details
  • Marketing data: contact information for promotional purposes
  • Technical data: IP address, device and browser information
  • Usage data: profile information and platform activities
3

Use of data

We process personal data for the following purposes:

  • Account management and service delivery
  • Billing and payment processing
  • Marketing and communication (with consent)
  • Security and fraud prevention
  • Legal obligations
4

Sharing data with third parties

We only share data with:

  • Payment providers for processing transactions
  • Cloud providers for secure storage (AWS Cognito)
  • Marketing tools for personalized content

We never sell your data to third parties.

5

Retention period

We do not retain your personal data longer than strictly necessary for the purposes for which it was collected. In practice, this means we retain data:

  • Account data: Up to 90 days after account deletion
  • Invoice data: 7 years (legal retention requirement)
  • Marketing data: Until withdrawal of consent
6

Security

Encryption

All data is encrypted in storage and transit

Access Control

Strict access controls and authentication via AWS Cognito

7

Your rights

You have the right to:

  • Access your data
  • Correct your data
  • Have your data deleted
  • Object to data processing
  • Withdraw your consent

To exercise these rights, please contact us at privacy@saits.online

8

Changes

We reserve the right to modify this privacy policy. Changes will be published on this page. Therefore, please check our privacy policy regularly.

Cookie Policy

How we use cookies on our website

1

What are cookies?

Cookies are small text files that are placed on your device when you visit our website. These files contain information about your preferences and browsing behavior.

3

SAITS-INST Cookie (First-Party Analytics)

We use a proprietary first-party cookie called "SAITS-INST" for website analytics. This cookie is set on the domain .saits.online and is accessible across all our subdomains. The SAITS-INST cookie is classified as an analytical cookie and is ONLY placed after you have explicitly given your consent for analytical cookies through our cookie settings.

Data collected by SAITS-INST:

  • Anonymous visitor ID (randomly generated UUID, not linked to personal identity)
  • Session ID (to distinguish separate browsing sessions)
  • First visit timestamp and session start time
  • Referral source (the website that directed you to us)
  • Landing page and pages visited during session
  • UTM marketing parameters (if present in the URL)
  • Device category (desktop, tablet, or mobile)
  • Browser language and screen resolution
  • Total page views and last activity timestamp

Important safeguards:

  • No personal data (name, email, address) is stored in the cookie
  • No IP addresses are stored in the cookie
  • The visitor ID is a random UUID that cannot be traced back to you personally
  • The cookie is only set AFTER explicit consent — never before
  • If you revoke analytical cookie consent, the SAITS-INST cookie is automatically deleted
  • Data is never shared with or sold to third parties
  • Data is processed exclusively within the European Economic Area (EEA)

Technical details: The SAITS-INST cookie is set with the attributes Secure (HTTPS only), SameSite=Lax, path=/, and domain=.saits.online. Maximum retention: 365 days. The cookie is a first-party cookie and is not accessible by any third-party domains.

Legal & Terms of Use

Your rights and our responsibilities

Service & Product Terms

Specific compliance and legal terms per service and product

1

AI Migration

AI migration services are delivered under strict GDPR/AVG compliance with a Data Processing Agreement (DPA) included. All data processing occurs on European AWS infrastructure. SAITS follows the EU AI Act (2024/1689) guidelines for responsible AI integration.

You retain full ownership of your data and processes. SAITS does not use your business data for AI model training. Migration assessments are confidential and covered by NDA upon request. All deliverables include security audits and compliance documentation.

2

Analytics (SAITS Data)

All analytics services are delivered under strict GDPR/AVG compliance. A Data Processing Agreement (DPA) is included with every engagement. Your business data remains on European AWS infrastructure and is never shared with third parties.

SAITS applies privacy-by-design principles to all data analysis. You retain full ownership of your data and insights. Analyses are confidential and covered by NDA upon request. We comply with all applicable EU and Dutch data protection regulations.

3

Security Services

All security services are delivered under strict GDPR/AVG compliance and covered by NDA. Penetration test reports and vulnerability assessments are confidential. A Data Processing Agreement (DPA) is included with every engagement involving access to systems or data.

SAITS security consultants hold industry certifications and follow responsible disclosure practices. All findings remain strictly between SAITS and the client. We comply with ISO 27001 standards, the NIS2 Directive, and applicable Dutch and EU cybersecurity regulations.

4

Training Services

All training services are delivered under GDPR/AVG compliance. Training materials are confidential and may not be redistributed without written consent. A Data Processing Agreement (DPA) is included when personal data is involved.

SAITS trainers operate under NDA for any proprietary business information shared during sessions. Certificates of completion are issued per participant. Custom training content remains the intellectual property of SAITS unless otherwise agreed in writing.

5

SAITS AI Bots

SAITS AI Bots comply with the EU AI Act (2024/1689) and operate under full GDPR/AVG data processing agreements. All models run self-hosted on European AWS infrastructure — your data never leaves the EU and is never shared with third-party AI providers.

A Data Processing Agreement (DPA) is included with every plan. Human handoff and oversight are guaranteed per Article 14 EU AI Act. SAITS does not use client conversations or knowledge base data for model training. You retain full ownership and can request deletion at any time.

6

SAITS Brain (AI Company)

SAITS Brain is designed to comply with the EU AI Act (2024/1689) and operates under full GDPR/AVG data processing agreements. All AI models run on European AWS infrastructure — no data leaves the EU.

A Data Processing Agreement (DPA) is included with every engagement. Human oversight is guaranteed per Article 14 EU AI Act. SAITS does not use client data for model training without explicit consent.

7

Radio & Audio Streaming

Applies to: SAITS Radio, G-Force Radio

Audio broadcasting requires valid music licensing. As the station operator, you are responsible for Buma/Stemra (composition rights) and Sena (neighboring rights) payments in the Netherlands, or equivalent licensing bodies in your jurisdiction. SAITS provides the streaming infrastructure only — not broadcasting licenses.

You must comply with Agentschap Telecom regulations and applicable media legislation (Mediawet). All listener data is processed under GDPR/AVG on European AWS infrastructure with a Data Processing Agreement (DPA) included.

8

SAITS Music

Music creation and distribution requires compliance with copyright law. You retain 100% ownership of original compositions created with SAITS Music. However, you are responsible for Buma/Stemra (composition rights) and Sena (neighboring rights) registrations and payments when distributing or publicly performing your music.

AI-generated content may have specific licensing implications — consult a music lawyer for commercial releases. SAITS does not claim rights to your creations. All data is processed under GDPR/AVG on European AWS infrastructure with a Data Processing Agreement (DPA) included.

9

NFT Ticket Services

SAITS NFT Ticket Services operates under EU consumer protection regulations (Directive 2011/83/EU) and the Markets in Crypto-Assets Regulation (MiCA). NFT tickets are utility tokens — not financial instruments or investment products.

Event organizers remain responsible for event delivery and refund policies. SAITS provides the technical infrastructure only. All personal data is processed in accordance with GDPR/AVG. Smart contracts are audited and open for verification.

10

SAITS Insides

SAITS Insides processes website analytics data under strict GDPR/AVG compliance. All data is stored on European AWS infrastructure. A Data Processing Agreement (DPA) is included with every subscription.

Analytics data is collected with privacy-by-design principles. No personal data is sold or shared with third parties. You retain full ownership of your data and can request deletion at any time per Article 17 GDPR.

11

SAITS GIT

SAITS GIT is self-hosted on European AWS infrastructure under GDPR/AVG compliance. Source code and repositories remain your intellectual property. A Data Processing Agreement (DPA) covers all stored data.

You are responsible for ensuring your code complies with applicable open-source licenses and export control regulations (EAR/ITAR). SAITS does not access, review, or use your source code. All data is encrypted at rest (AES-256) and in transit (TLS 1.3).

12

SAITS RPC

SAITS RPC infrastructure runs on European AWS regions under GDPR/AVG compliance. Service Level Agreements (SLA) with guaranteed uptime are included. A Data Processing Agreement (DPA) covers all transmitted data.

SAITS does not log, inspect, or store the content of RPC calls. All traffic is encrypted with TLS 1.3. Infrastructure is monitored 24/7 with automated incident response. Fair use policies apply to prevent abuse.

13

Solana RPC

SAITS Solana RPC provides blockchain infrastructure only — not financial advice, investment recommendations, or custodial services. SAITS is not a financial institution and does not hold, transfer, or manage digital assets on your behalf.

This service operates in compliance with GDPR/AVG and the EU Markets in Crypto-Assets Regulation (MiCA) where applicable. All infrastructure runs on European AWS regions. You are responsible for ensuring your use of blockchain technology complies with applicable laws in your jurisdiction.

14

SAITS Communications

SAITS Communications aggregates data from your connected SAITS products under strict GDPR/AVG compliance. All data remains on European AWS infrastructure. Access controls follow the principle of least privilege.

A Data Processing Agreement (DPA) covers all aggregated data. SAITS does not sell, share, or use your operational data for any purpose beyond service delivery. You retain full data ownership and portability rights per GDPR Articles 17 and 20.

15

WP-Automated

WP-Automated handles your website data migration under strict GDPR/AVG compliance. A Data Processing Agreement (DPA) is included with every migration. All data is processed and stored on European AWS infrastructure only.

You are responsible for ensuring you have the right to migrate all content, including images, plugins, and themes with valid licenses. SAITS does not retain copies of your data after migration is complete. Automated rollback is available for 30 days post-migration.

Do you have any questions?

Contact our privacy officer or legal department for questions about your data or these terms.