⚠️ Legal notice: This is a suggestion for a privacy policy.
This document is not legal advice and does not replace consultation with a
lawyer or privacy professional. Have this policy reviewed by your legal department
before putting it into use.
Privacy Policy
Iveras OSINT Case Management System — Last updated: July 2026
1. Data Controller
[Organization name] is the data controller for the processing of
personal data within the Iveras CMS. For questions about this privacy policy, please
contact us at [email address].
2. What data do we process?
Depending on the context, the following categories of personal data may be processed:
- User data: name, email address, role, phone number
- Subjects: name, date of birth, address, phone number, email address, identification numbers (BSN/passport), bank account number, license plate, vehicle identification
- Client data: contact information, financial information
- Search queries: phone numbers, email addresses, names and other search parameters in the context of OSINT investigations
- Log data: IP addresses, user agents, audit trail of actions
3. Purposes of processing
Your personal data is processed for the following purposes:
- Conducting OSINT investigations in the context of criminal investigations and fraud investigations
- User account management and access control
- Audit trail and legal accountability
- Compliance with legal retention obligations
4. Legal bases for processing
The processing is based on:
- Legal obligation (GDPR Art. 6(1)(c)): for compliance with retention obligations and legal investigation tasks
- Legitimate interest (GDPR Art. 6(1)(f)): for the exercise of investigative powers and fraud prevention
- Consent (GDPR Art. 6(1)(a)): for specific processing where consent is required
5. Retention periods
- Audit logs: 365 days (configurable via settings)
- Search queries (phone lookup): 90 days (configurable)
- User accounts: up to 30 days after termination of employment
- Case data: in accordance with legal retention obligations for investigations
6. Your rights (GDPR)
Data subjects have the following rights under the GDPR:
- Right of access (Art. 15): request your personal data
- Right to rectification (Art. 16): have incorrect data corrected
- Right to erasure (Art. 17): deletion of data (subject to legal exceptions)
- Right to data portability (Art. 20): transfer data
- Right to restriction (Art. 18): temporarily stop processing
- Right to object (Art. 21): object to processing
Use the DSAR form
to submit a request.
7. Security
We apply appropriate technical and organizational measures to secure personal data,
including:
- Encryption of personal data (Fernet encryption)
- Role-based access control (RBAC)
- Audit logging of all access and changes
- Tenant isolation between organizations
- Strict rate limiting on API endpoints
8. Cookies
This system only uses functional cookies that are necessary
for the operation of the application (session management). No tracking cookies,
advertising cookies, or third-party analytics tools are used.
9. Sharing with third parties
Personal data is not shared with third parties, unless:
- This is necessary for the investigation (e.g. querying public sources)
- We are legally obliged to do so (e.g. court order)
- You have given explicit consent
10. Contact and Complaints
For questions or complaints about the processing of personal data, please
contact the Data Protection Officer at [email address].
You also have the right to file a complaint with the
Dutch Data Protection Authority (Autoriteit Persoonsgegevens).
← Back to Privacy Policy
📝 Submit DSAR