Reliability Engineering Lab

Legal

Privacy Policy

Last updated: March 2026

Who we are

Reliability Engineering Lab is a cloud infrastructure assessment firm based in Amsterdam. We deliver fixed-fee assessments across cost, security, availability, architecture, and operations.

For the purposes of data protection law, Reliability Engineering Lab is the data controller for personal data collected through this website and our engagement processes. Contact: hello@reliabilityengineeringlab.com

What data we collect

We collect personal data in the following situations:

  • Contact form submissions — name, email address, company name, and any message you provide when requesting a discovery call or scoping conversation.
  • Client portal access — name and email address associated with your authentication provider account (Auth0). We do not store passwords.
  • Engagement correspondence — emails, meeting notes, and documents exchanged during an active or prospective assessment engagement.
  • Usage data — anonymised page view data collected via privacy-respecting analytics (no cross-site tracking, no fingerprinting).

How we use your data

  • To respond to enquiries and scope assessments
  • To deliver and manage active client engagements
  • To provide access to the client portal
  • To issue invoices and maintain financial records
  • To improve our website and understand how visitors engage with our content

We process your data on the basis of:

  • Contractual necessity — data required to deliver a scoped assessment
  • Legitimate interests — responding to inbound enquiries and operating our website
  • Legal obligation — financial records required under Dutch and EU law

Data sharing

We do not sell or rent your personal data. We share data only where strictly necessary:

  • Auth0 — authentication provider for the client portal
  • Cloud infrastructure providers — hosting and database services (data stored in the EU)
  • Accounting software — for invoice and payment processing

All sub-processors are bound by GDPR-compliant data processing agreements.

Data retention

Contact form submissions are retained for up to 12 months or until an engagement begins, whichever comes first. Client engagement data is retained for 7 years to comply with Dutch financial record-keeping requirements. Portal account data is deleted within 30 days of account closure upon request.

Your rights

Under the GDPR you have the right to:

  • Access the personal data we hold about you
  • Request correction of inaccurate data
  • Request deletion of your data (subject to legal obligations)
  • Object to processing based on legitimate interests
  • Request data portability
  • Lodge a complaint with the Dutch DPA (Autoriteit Persoonsgegevens)

To exercise any of these rights, email hello@reliabilityengineeringlab.com. We will respond within 30 days.

Security

Access to client data is restricted to personnel directly involved in your engagement. All data in transit is encrypted via TLS. Portal authentication uses industry-standard OAuth 2.0 flows via Auth0. We do not store cloud credentials — read-only access granted for assessments is revocable at any time.

Changes to this policy

We may update this policy from time to time. The date at the top of this page reflects when it was last revised. Material changes will be communicated to active clients by email.