Privacy policy
Last updated: 1 July 2026 · Version 1.0
Korpalis ("we", "us") is an AI security intelligence platform operated from the Netherlands. We take the protection of your personal data seriously, and this policy explains what we collect, why, and what your rights are. It is written to comply with the EU General Data Protection Regulation (GDPR) and the Dutch GDPR Implementation Act (UAVG).
1. Who is responsible for your data
The data controller is Korpalis.
Korte Schoonderloostraat 39, 3024 TN Rotterdam, Netherlands
Chamber of Commerce (KvK): 42088615
VAT number (BTW): NL005489194B09
Email for all privacy matters: privacy@korpalis.com
2. What we collect and why
| Data | When | Purpose | Legal basis | Retention |
|---|---|---|---|---|
| Email address | You join the waitlist | To inform you about early access and the subscription launch | Consent (art. 6(1)(a) GDPR) | Until launch communication is complete or you withdraw, max 24 months |
| Email address | You subscribe to the newsletter | To send you the weekly newsletter | Consent (art. 6(1)(a) GDPR) | Until you unsubscribe |
| Name, email, message content | You use the contact form or email us | To answer your question or prepare a consulting engagement | Legitimate interest / pre-contractual steps (art. 6(1)(b) and (f) GDPR) | Max 12 months after the conversation ends, longer if a contract follows |
| IP address, browser data, requested pages | You visit the site (server logs, rate limiting) | Security, abuse prevention, keeping the site running | Legitimate interest (art. 6(1)(f) GDPR) | Max 30 days |
| Cookie consent choice | You use the cookie banner | To remember and prove your consent decision | Legal obligation (art. 7(1) GDPR) | 6 months |
We do not collect special categories of personal data, and we do not use your data for automated decision-making or profiling.
3. Who we share data with (processors)
We only share personal data with service providers who help us run Korpalis, under data processing agreements:
- Railway Corp. (USA): website hosting and database storage, in their European region. Transfers are covered by standard contractual clauses.
- TransIP B.V. (Netherlands): domain registration and DNS.
- Resend (Plus Five Five, Inc., USA): delivery of our email, being contact form notifications to us, account emails such as password resets, and the newsletter. Transfers are covered by standard contractual clauses.
- Bunny Fonts (BunnyWay d.o.o., EU): font delivery. Bunny Fonts does not log or store personal data.
We never sell your data, and we never share it for advertising.
4. Your rights
Under the GDPR you can, at any time:
- request access to the data we hold about you;
- have incorrect data corrected;
- have your data deleted ("right to be forgotten");
- restrict or object to processing;
- receive your data in a portable format;
- withdraw consent, without affecting processing that happened before withdrawal.
Send any request to privacy@korpalis.com. We respond within one month. You also have the right to lodge a complaint with the Dutch supervisory authority, the Autoriteit Persoonsgegevens (autoriteitpersoonsgegevens.nl).
5. Security
Security is our trade, and we apply it to your data too: HTTPS everywhere, security headers, rate limiting on all forms, credentials stored outside the public web root, and access limited to the people who need it.
6. Cookies
We use only strictly necessary cookies by default. Details, including the full cookie table, are in our cookie policy.
7. Changes to this policy
When we change this policy we update the date and version number at the top. For significant changes we notify newsletter subscribers and waitlist members by email.