Privacy Policy
Last updated: 2026-07-30
Who we are
SecurityGab Inc operates dengisan.nl and its forum at website.dengisan.nl. Contact for any privacy question: [email protected].
What we collect
- Account data — username, email address, password (stored as a salted hash, never in plain text), forum posts/threads you create.
- Security data — IP address, timestamps of logins/registrations/posts. Used only for rate-limiting, abuse prevention, and lockout protection. Not sold, not shared with advertisers.
- Error-page abuse monitoring — when a request results in a 404, 413, or 429 response, we log the IP address, request path, and browser user-agent string, plus a city-level location for that IP obtained from a third-party geolocation lookup (see "Third parties" below). This is city/region accuracy only — we do not have and do not claim GPS-level or "exact" location. Shown on the error page itself so it's never a surprise.
- Cookies — a session cookie and a cross-domain access cookie, both strictly necessary for the site to function (keeping you logged in, and letting the forum recognize you arrived from the main site). Neither is used for tracking or advertising, so no cookie-consent banner is required for them under GDPR/ePrivacy.
Why we collect it
Solely to operate accounts, secure the platform against abuse, and deliver the forum's core features (posting, moderation, email verification, password reset).
How long we keep it
- Unverified accounts are automatically deleted after 10 minutes if the verification email isn't confirmed.
- Verified account data is kept until you request deletion (see below) or your account is removed by moderation action.
- Security/rate-limit logs are short-lived and rotate automatically.
- Error-page abuse-monitoring records (see above) are kept for 90 days, then automatically purged.
Your rights
Under GDPR you can request access to, export of, or deletion of your data at any time. Logged-in members can delete their own account and all associated posts instantly from their account settings page. You can also email [email protected] for any request we haven't automated yet.
Data breach notification
In the event of a data breach affecting your personal data, we will notify affected users and, where required, the relevant supervisory authority within 72 hours of becoming aware, per GDPR Article 33/34.
Third parties
Transactional email (verification, password reset, alerts) is sent through Brevo (Sendinblue SAS), acting as our data processor for message delivery only. IP-to-city geolocation for error-page abuse monitoring is performed by ipapi.co, which receives only the IP address being looked up — no account or profile data. No data is sold or shared for marketing purposes.