Privacy Policy
Last updated 12 September 2026 · covers reqlio.eu
This policy covers this website. The Reqlio application (<customer>.reqlio.eu) processes customer data under a separate data processing agreement, where we act as processor and the customer as controller.
Short version: this site sets no cookies and sends nothing to any third party. We do count visits, with analytics we run on our own server — it stores no cookie, no device identifier and no IP address. The only personal data we keep is the email address you choose to send us, and the address it was sent from.
1. Controller
Holtstiege ConsultingKon. Wilhelminaplein 1142
1062 KS Amsterdam
Netherlands
info@reqlio.eu
No data protection officer has been appointed. One is not required here: our core activity is not large-scale monitoring or large-scale processing of special categories of data (art. 37 GDPR).
2. Hosting and server logs
This website runs on servers operated by creoline GmbH, Bergstraße 9a, 48341 Altenberge, Germany — certified to ISO/IEC 27001:2022 by TÜV SÜD for the operation of virtual servers and infrastructure, valid to March 2028. The machines stand in the FRA4 data centre of firstcolo GmbH, Kruppstraße 105, Frankfurt am Main, which holds ISO/IEC 27001:2022 with data-centre operation in scope (TÜV Rheinland, valid to February 2028) and a TÜV-certified data centre level 3 rating against DIN EN 50600.
creoline acts as our processor and handles this data only to host the service, on our instructions. firstcolo provides the building, power and physical security of the data centre; it has no access to the servers or the data on them and is therefore not a processor. No content delivery network sits in front of the service, and no request leaves the EU.
The web server records each request as:
- date and time of the request
- the URL requested and the HTTP status returned
- bytes transferred, referrer, and browser user-agent string
Your IP address is not among them. The site sits behind a reverse proxy, so the only address the web server ever sees is an internal one belonging to our own infrastructure — and we shorten even that before writing it. Your address reaches the proxy and is discarded there unread.
| Purpose | Delivering the site, and spotting faults and attacks |
|---|---|
| Legal basis | Art. 6(1)(f) GDPR — our legitimate interest in a working, secure website |
| Retention | Logs rotate automatically and hold roughly the last 30 MB of entries; older lines are discarded. Nothing is archived elsewhere. |
The reverse proxy that terminates TLS keeps no access log at all, so no record of who visited this site exists anywhere.
3. Analytics, and what we do not use
We measure how the site is used with Plausible Analytics, which we run on our own server in Germany (analytics.holtstiege.eu, same provider as the site itself). It is not the hosted Plausible service and not a third party: the data never leaves infrastructure we control, and nobody else receives it.
It sets no cookie and stores nothing on your device, so there is nothing to consent to under article 11.7a of the Dutch Telecommunications Act — that provision governs storing or reading data on your equipment, and this does neither.
Each page view records:
- the page you opened, and the referring site if you came from a link
- browser, operating system, device type and screen size category
- country, derived from your IP address and then discarded
- whether you submitted the access-request form (recorded as the event Access request, without the address you typed)
Your IP address is not stored. It is used for two things in the moment the request arrives — deriving the country, and computing a visitor identifier — and then dropped. That identifier is a hash of your IP address, your browser's user-agent string and a secret that changes every 24 hours, which means the same person cannot be recognised across two days and the hash cannot be turned back into an address.
| Purpose | Knowing which pages are read and whether the site leads anywhere — no profiling, no advertising |
|---|---|
| Legal basis | Art. 6(1)(f) GDPR — our legitimate interest in understanding whether our own website works. The processing is limited to the aggregate numbers above and cannot identify you |
| Recipients | None. The instance is ours |
We use no tag manager, advertising pixel, remarketing tag, chat widget, A/B testing service, session recorder or heat map. Fonts are served from our own servers rather than from Google Fonts, so opening this page sends nothing to Google.
Local storage
If you use the light/dark switch, your choice is stored in your browser's local storage under the key reqlio-site-theme. It stays on your device, is never sent to us, and you can clear it in your browser settings. Storing it is strictly necessary to deliver the display setting you asked for, so no consent is required under article 11.7a of the Dutch Telecommunications Act.
4. Requesting access (the form on this site)
If you submit your email address through the form, we store it in order to reply, to tell you when access is available, and to set up a workspace if you ask for one.
| Data | Email address, the date and time of submission, and the IP address it was sent from |
|---|---|
| Purpose | Answering your enquiry and preparing access. The IP address is used only to rate-limit the form against automated abuse |
| Legal basis | Art. 6(1)(b) GDPR (steps prior to a contract, at your request) and art. 6(1)(f) GDPR (our interest in responding to enquiries) |
| Retention | The email address until you ask us to delete it, or until it is clear that no contract will follow — whichever comes first. The IP address only as long as the application log holds it, which rotates; it is never written to a database |
We do not use these addresses for newsletters or any other marketing without asking you separately first, and we never pass them to anyone else.
5. Email
Mail to and from info@reqlio.eu is handled by our own mail server, on the same German infrastructure as the rest of the service — not by a third-party mailbox provider such as Google or Microsoft. Your message and address are processed to deal with your enquiry, on the basis of art. 6(1)(b) or (f) GDPR.
6. Recipients
Only creoline GmbH, named in section 2, which hosts the site as our processor. The analytics in section 3 runs on our own server and is not a recipient. We pass personal data to no one else, and nothing connected with this website is transferred outside the EU/EEA.
7. Your rights
Under the GDPR you have the right to:
- access the personal data we hold about you (art. 15)
- have inaccurate data corrected (art. 16)
- have your data erased (art. 17)
- have processing restricted (art. 18)
- receive your data in a portable format (art. 20)
- object to processing based on legitimate interest (art. 21)
- withdraw consent at any time, with effect for the future (art. 7(3))
To exercise any of these, write to info@reqlio.eu.
You also have the right to lodge a complaint with a supervisory authority (art. 77 GDPR). Ours is the Dutch one:
Autoriteit PersoonsgegevensPostbus 93374, 2509 AJ Den Haag, Netherlands
autoriteitpersoonsgegevens.nl
You may also complain to the authority where you live or work.
8. Changes
We update this policy when the site changes. The date at the top always reflects the current version.
