Neolyth Privacy Policy
Introduction
Neolyth is the controller for the personal data described in this policy. Neolyth is a sole proprietorship (eenmanszaak) of Marwand Ayubi, registered with the Dutch Chamber of Commerce under number 95055592. This policy explains what we collect when you visit neolyth.io or contact us, why we collect it, on what legal basis, and how long we keep it.
This policy does not cover patient data processed in VocaDoc. When a healthcare provider uses VocaDoc, that provider is the controller of its patients' data and Neolyth is only its processor. What may and may not be done with that data is set out in the VocaDoc processor agreement, not here. If you are a patient, ask your healthcare provider: they decide, and they must inform you.
Data We Collect
Some of this you give us yourself. Some is recorded automatically the moment your browser makes a request to our server:
- Contact form: your name, your email address and your message, together with your IP address and the time you submitted it. Legal basis: Article 6(1)(b) GDPR where your enquiry concerns our services and you are asking us to take steps before entering into a contract, and otherwise Article 6(1)(f) GDPR, our legitimate interest in answering correspondence addressed to us. The IP address and the timestamp rest on Article 6(1)(f) GDPR, our legitimate interest in preventing abuse of a form that stands open to anyone.
- Server and gateway logs: your IP address, the date and time of the request, the page or file requested and the response code, the referring page where your browser sends one, and your browser and operating system. These are recorded automatically on every request, whether or not you accept cookies, so that we can keep the site available, diagnose faults, and detect and block attacks, scraping and abuse. Legal basis: Article 6(1)(f) GDPR, our legitimate interest in the security and availability of our own website. We do not use them for analytics and we do not use them to build a profile of you.
Your browser sends an Accept-Language header with every request. On the English pages we read it at the moment of the request to decide whether to send you to the German or Dutch version instead. We do not use it for anything else and we do not keep it, except that our security gateway records the whole request, headers included, when one trips a firewall rule.
The box you tick on the form is your confirmation that you have read this policy. It is not the legal basis for the processing, and ticking it does not give up any right.
Use of Personal Data
We use your personal data to:
- Respond to your inquiries and provide customer support.
- Protect the website and services from fraudulent or malicious activity.
Data Sharing and Processing
We do not share your personal data with third parties, except:
- With Worldstream B.V. and Hetzner Online GmbH, which operate the rented servers on which we run the security gateway in front of this website and the encrypted tunnel behind it.
- With Amazon Web Services, which transmits the notification email we receive when you use the contact form, through Simple Email Service in the eu-central-1 (Frankfurt) region. That email contains the name, email address, message and IP address you submitted.
- With Google, if and only if you accept analytics cookies. What that involves is set out under Cookies and Analytics below.
International Data Transfers
The machine that stores and serves this website, together with its database, is hardware Neolyth owns and operates itself in Nijmegen, the Netherlands. It is not a public cloud instance and it is not managed by anyone else. We use no content delivery network: no third party caches, inspects or monetises this site's traffic.
Your HTTPS connection is not terminated on that machine. It is terminated by a security gateway that we configure and operate on a server we rent from Worldstream B.V. in the Netherlands. That gateway inspects requests with a web application firewall in order to filter attacks, which means it reads your request in unencrypted form. It also keeps a list of IP addresses temporarily blocked for abusive traffic.
Traffic between that gateway and the web server travels through an encrypted tunnel that is relayed by a server we rent from Hetzner Online GmbH in Nuremberg, Germany. That relay carries encrypted traffic only and cannot read its contents.
The authoritative DNS for neolyth.io is operated by Amazon Web Services (Route 53). DNS only translates the name neolyth.io into an address; no page content and no form data passes through it.
Everything described above is inside the EU and the EEA. Two things leave it. Google Analytics, which we load only if you accept analytics cookies, may send data to Google LLC in the United States; that transfer takes place under the European Commission's Standard Contractual Clauses and, in so far as Google relies on it, the EU-US Data Privacy Framework. Amazon Web Services we use only in EU regions, but AWS is part of a United States group, so an incidental transfer can occur, for example where support staff outside the EEA access a system; AWS commits to Standard Contractual Clauses in its Data Processing Addendum for those cases. If you would like to see the relevant safeguard, ask us at data@neolyth.io and we will provide it.
Cookies and Analytics
This site sets two cookies of its own, neither of them before you act. cc_cookie stores your cookie choice for six months. It is strictly necessary: without it we could not remember that you refused, and Article 7(1) GDPR requires us to be able to demonstrate your choice. We process it on the basis of Article 6(1)(c) GDPR and it does not require your consent.
The second is lang, which stores the language you choose with the EN / DE / NL switch in the header and lasts a year. It contains nothing but that choice, it is only ever set when you click one of those three links, and it is not used to recognise you or to follow you between visits. Remembering a setting you asked for is part of delivering the page you asked for, so it is exempt from consent under Article 11.7a(3) of the Dutch Telecommunications Act; under the GDPR we process it on the basis of Article 6(1)(f), our legitimate interest in showing you the site in the language you picked. Click another language and the value is overwritten; delete it in your browser and the choice is gone. If you never use the switch, no such cookie is set.
If, and only if, you accept the analytics category, we load Google Analytics 4 (property G-E2787R8WQ5) to count visits and to see which pages are read. It sets the cookies _ga and _ga_<id>, which last two years, and _gid, which lasts 24 hours. It records the pages you view, an approximate location derived from your IP address, your device and browser type, the source that referred you, and a randomly generated identifier. The legal basis is your consent, under Article 6(1)(a) GDPR and Article 11.7a of the Dutch Telecommunications Act.
Google Ireland Limited acts as our processor for that data and may pass it on to Google LLC in the United States. We want to be accurate about IP addresses rather than reassuring: Google Analytics 4 uses your IP address to derive an approximate location and does not retain it afterwards, but Google still receives it in the request. We cannot prevent that, which is exactly why we ask you first.
You can change or withdraw your choice at any time through Cookie settings in the footer of any page. Refusing is one click, in the same place and the same size as accepting, and the site works identically either way. If you refuse, no Google script is loaded and any Google cookies already set are cleared. We do not use cookie walls.
So that you do not have to take our word for the absence of things: this site has no heatmaps, no chat widget, no embedded videos or maps, no advertising or remarketing tags, and no externally hosted fonts or scripts other than the Google Analytics script described above. Our fonts are served from our own server.
Data Retention
Contact Form Submissions: Personal data is retained as long as necessary to respond to your inquiry and deleted when no longer needed.
Your Rights
You have the right to:
- Access: Request a copy of the personal data we hold about you.
- Rectification: Request corrections to any inaccurate information.
- Erasure: Request deletion of your personal data, subject to legal requirements.
- Restriction: Request that we limit the processing of your data under certain conditions.
- Portability: Request that we transfer your data to another organization, where technically feasible.
- Objection: Object to any processing we base on legitimate interest, which is the server and gateway logs and the IP address recorded with a contact form submission. Tell us how it affects you and we will stop, unless we have compelling grounds that override your interests.
- Withdrawal of consent: Withdraw your consent for anything based on it, above all analytics, at any time and as easily as you gave it. Withdrawal does not make the processing before it unlawful.
To exercise these rights, contact us at data@neolyth.io. We will respond without undue delay and in any event within one month of receiving your request. If a request is complex, or you have made several, we may extend that by up to two further months, and if we do we will tell you within the first month and explain why. This is the standard in Article 12(3) GDPR. There is normally no charge.
If you are unhappy with how we have handled your data, please tell us first at data@neolyth.io. You are also entitled at any time to lodge a complaint with the Dutch supervisory authority, the Autoriteit Persoonsgegevens, Postbus 93374, 2509 AJ Den Haag, autoriteitpersoonsgegevens.nl. If you live or work in another EU country, you may complain to your own national supervisory authority instead.
Legal Compliance
We comply with the General Data Protection Regulation (GDPR) and other applicable laws regarding data privacy and protection.
Data Security
We protect your data with the following measures:
- HTTPS encryption for secure data transmission.
- Regular updates and security patches for our systems.
- Strict access controls to our servers and data.
- A web application firewall on our gateway filters attacks, and IP addresses sending abusive traffic are temporarily blocked.
- Backups are encrypted before they leave the machine, and the storage provider holds no decryption key.
We hold no ISO and no NEN certification. We operate controls aligned with NEN 7510 and NEN 7512, which is a statement about how we work and not a certificate. As a sole proprietorship we have no separation of duties, and we say so rather than implying a larger organisation. Our processor agreement says the same thing, and we are not going to say something different on a website.
Contact Information
If you have any questions or concerns about this Privacy Policy or your personal data, please contact us at:
Email: data@neolyth.io
Address: Graafsweg 274, 6532 ZV Nijmegen, Netherlands
Changes to This Privacy Policy
We may update this Privacy Policy from time to time. Any changes will be posted on this page with an updated 'Effective Date.'
Session Recording
If, and only if, you accept the session recording category, we record how you use this site with OpenReplay, session replay software that we host ourselves. It is not a third-party service: the software runs on infrastructure Neolyth owns and operates in Nijmegen, the Netherlands, and no recording is sent to any other company.
The recording is sent to analytics.vocadoc.com. That is the address of our own instance, on a vocadoc.com domain because the same instance also serves VocaDoc, and it is named here so that you can check what this page connects to instead of taking our word for it.
A recording reconstructs your visit: the pages you moved through, where you clicked and scrolled, how you moved the pointer, which form fields you entered and left, your browser and device, and how long you stayed. We want to be plain about what that means, because it reaches further than counting visits. Session replay is a reconstructable recording of one identifiable person's behaviour, not an aggregate statistic, and the technique is capable of capturing text typed into form fields. We mask form input, and the message field of the contact form is never captured. Masking is a setting rather than a law of nature, so we check it by watching real recordings back instead of trusting the configuration.
Recordings are held in object storage running on our own hardware in Nijmegen. They are not shared with any third party, they are not used for advertising or for any purpose other than finding and fixing problems with this website, and they do not leave the EU.
We keep a recording for 90 days and then delete it.
The legal basis is your consent, under Article 6(1)(a) GDPR and Article 11.7a of the Dutch Telecommunications Act. Session recording has its own choice in the cookie banner, separate from analytics: accepting analytics does not switch it on, because consent has to be given separately for each purpose. If you do not accept it, no recording software is loaded and nothing about your visit is recorded.
You can withdraw your consent at any time through Cookie settings in the footer of any page. Recording stops immediately, and if you ask us at data@neolyth.io we will delete the recordings already made of your visits. We do not fall back on a legitimate interest here: if you say no, or change your mind, there is no other ground we rely on to go on recording you.