Privacy Policy
vCyberBoard Advisor is an independent advisory firm operating within the European Union. This policy explains how we handle personal data in accordance with the GDPR (Regulation 2016/679), the EU AI Act, NIS2, and DORA.
1. Controller
vCyberBoard Advisor B.V. is the data controller for personal data collected through this website and the client portal. For any privacy enquiry, contact us through the briefing request form or the support request function in your portal.
2. Data we process
- Identifiers: name, organisation, role and contact email submitted via the inquiry or briefing form.
- Context: sector, the board-level challenge, and the regulatory frameworks relevant to your enquiry.
- Account data: authentication email and role assigned when you are onboarded as a client.
- Engagement records: briefings, milestones, documents you upload, and support correspondence.
- Technical: IP address and standard interaction logs needed for security and availability.
3. Purpose and lawful basis
We process personal data to triage and deliver advisory engagements, to operate the secure client portal, to meet our obligations under EU cybersecurity and AI regulation, and to respond to legitimate requests from boards and executives. The lawful bases are performance of a contract, compliance with a legal obligation, and our legitimate interest in delivering independent board-level counsel.
4. Retention
Inquiry data is retained only as long as needed to progress the engagement. Client records are retained for the duration of the mandate and the regulatory retention period that applies to it, after which they are deleted or anonymised.
5. Sharing and sub-processors
We do not sell personal data. We share data only with sub-processors that host the platform and deliver advisory services, under contract and limited to what is necessary. Where data leaves the EU, we rely on recognised safeguards such as Standard Contractual Clauses.
6. Your rights
- Access, rectification and erasure of your personal data.
- Restriction and objection to processing.
- Data portability.
- Withdrawal of consent, where consent is the basis.
- Lodge a complaint with your supervisory authority or the Dutch Autoriteit Persoonsgegevens.
7. Security
The portal enforces authenticated access, role-based permissions and row-level isolation of client data. Uploaded documents are held in private storage with signed, time-limited access links.
8. Automated processing
The website concierge uses a language model to triage questions and route visitors to the appropriate counsel. It does not make automated decisions with legal effect. Sensitive matters are escalated to a live advisor.
vCyberBoard Advisor · Amsterdam, The Netherlands · Last reviewed August 2026