← Back to home
Privacy policy
Privacy policy
Version 1.1 · Effective date: 27 August 2026 · Replaces version 1.0 (ContractBridge, 1 May 2025)
This is a translation provided for convenience. In the event of any discrepancy, the Dutch text is the binding version.
Sinecta BV (hereinafter: “we”, “us” or “Sinecta”) attaches great importance to the privacy of its users and the protection of personal data. In this privacy policy we explain which personal data we process, why we do so, how long we retain it and what rights you have. This policy applies to all our products and websites, including CertBridge and ContractBridge.
1. Who are we?
Sinecta BV builds software for IT service providers. We offer two products as Software-as-a-Service:
- ContractBridge — automatically synchronises licence data from supplier portals with Autotask PSA.
- CertBridge — an ISMS portal with which service providers guide, assess and report on their customers' NIS2 and ISO 27001 compliance.
Sinecta BV is the controller for the data we process for our own business operations. For the data we process within our applications on behalf of a customer, we act as processor.
2. Which personal data do we process?
We process only the personal data necessary for providing our service. This concerns the following categories:
- Account data: username, email address, role and (hashed) password of user accounts, including the data required for two-factor authentication.
- Contact details: name, email address and telephone number entered through a contact form on one of our websites.
- Company data: organisation name, Chamber of Commerce number and billing address for the purpose of subscription administration.
- Usage data: log data about synchronisations (time, portal, customer, product quantities) in ContractBridge, and about entries and assessments within an audit round in CertBridge, for the purpose of troubleshooting and the audit trail.
- Technical data: IP address, browser type and session data recorded when logging in to and using the application.
We do not process special categories of personal data (such as health data or national identification numbers).
3. On what legal basis do we process your data?
- Performance of a contract: creating and managing your account, granting access to the application and carrying out synchronisations and assessments.
- Legal obligation: keeping records in accordance with tax and accounting obligations.
- Legitimate interest: securing our systems, keeping logs for troubleshooting and improving our services.
- Consent: sending newsletters or commercial messages, only if you have given explicit consent for this.
4. With whom do we share your data?
We do not share your personal data with third parties unless this is necessary for the performance of our service or is required by law. We use the following categories of processors:
- Hosting partner: our applications run on a European server. A data processing agreement has been concluded with our hosting partner.
- Payment processor: for handling subscription payments.
- Email provider: for sending transactional emails (password resets, invoices).
We never sell your data to third parties.
5. How long do we retain your data?
- Account data: for as long as your subscription is active, and no longer than 12 months after termination.
- Synchronisation logs: a maximum of 90 days, after which they are deleted automatically.
- Audit data in CertBridge: for the duration of the audit cycle and afterwards in the archive, for as long as the Customer wishes to keep that archive — a NIS2 assessment is valid for three years.
- Contact form: a maximum of 2 years after receipt.
- Invoice data: 7 years in accordance with the statutory tax retention obligation.
6. Cookies and tracking
Our websites (sinecta.eu, contractbridge.eu and certbridge.eu) use only functional cookies that are necessary for the operation of the contact form and the language selection. We do not place tracking or advertising cookies. No data is shared with advertising networks.
7. Security
We take appropriate technical and organisational measures to protect your personal data against loss, unlawful access or unauthorised processing. These include:
- Encryption of data in transit (HTTPS/TLS) and at rest.
- Password hashing with a secure algorithm (bcrypt).
- Two-factor authentication (TOTP) for user accounts.
- Authorisation per role and per customer organisation, enforced server-side.
- Regular back-ups at an isolated location.
8. Your rights
Under the General Data Protection Regulation (GDPR) you have the following rights:
- Right of access: you may request which personal data we process about you.
- Right to rectification: you may have incorrect or incomplete data corrected.
- Right to erasure: you may request the deletion of your personal data, unless we are subject to a statutory retention obligation.
- Right to restriction of processing: you may have the processing of your data restricted in certain circumstances.
- Right to data portability: you may request your data in a structured, commonly used and machine-readable format.
- Right to object: you may object to the processing of your data on the basis of legitimate interest.
Send your request to info@sinecta.eu. We respond within 30 days.
9. Lodging a complaint
If you believe that we are not processing your personal data correctly, you can lodge a complaint with the Dutch Data Protection Authority (Autoriteit Persoonsgegevens) via autoriteitpersoonsgegevens.nl.
10. Changes to this policy
We reserve the right to amend this privacy policy. Changes will be published on this page with an updated effective date. We recommend that you consult this policy periodically.
11. Contact
For questions about this privacy policy or the processing of your personal data, you can contact us via: