Privacy Policy
Last updated: June 12, 2026
Verse, operating the VirtualSpace product/trade brand ("VirtualSpace", "we", "us", "our"), respects your privacy and is committed to protecting your personal data. This Privacy Policy explains what personal data we collect, why we collect it, how we use it, who we share it with, and the rights you have under the EU General Data Protection Regulation (Regulation (EU) 2016/679, "GDPR") and the Dutch Implementation Act (UAVG).
This Policy covers the VirtualSpace website/storefront at virtualspacesec.com, license activation, support, and the VirtualSpace AppSec software. It does not cover third-party websites or services we do not operate.
1. Data controller
The data controller for the processing described in this Policy is the business identified in section 13. You can contact us by email at support@virtualspacesec.com for any privacy-related question or to exercise your rights.
2. Our privacy-by-design principle
The AI and machine-learning models bundled with the Software execute locally within a fixed, predefined framework. The analysis engine cannot be directly prompted by the user and does not connect to our servers to evaluate your code. This local-only design is core to the product and to our compliance posture under the GDPR data-minimization principle.
3. What personal data we collect, and why
We process only the personal data we need to operate the storefront, fulfil orders, deliver and protect the Software, and meet our legal obligations. Specifically:
| Category | What it includes | Why we process it |
|---|---|---|
| Account & order data | Name, email, billing address, country, VAT/BTW number where applicable, order history. | Fulfil your order, issue invoices, provide support, comply with bookkeeping law. |
| Payment data | Last four digits and card brand, payment method type, transaction reference. Full card numbers are never stored by us. | Take payment and handle refunds through Shopify checkout and PCI-DSS compliant payment providers, including Worldline and Tazapay where available. |
| License activation | License key, activation timestamp, a salted hash of a non-reversible machine fingerprint, country-level location derived from IP. | Enforce license terms, prevent abuse, allow license transfer between machines. |
| Support correspondence | Emails and ticket content you send to us, plus the metadata around them. | Respond to your inquiries and improve support quality. |
| Website technical data | IP address, browser and device type, pages visited, referring URL, session identifiers. | Operate the website securely, prevent fraud and abuse, debug errors. |
| Analytics (optional) | Aggregated and anonymized usage statistics. No content of your code or scans, ever. | Improve the website. Only set with your consent via the cookie banner. |
| Marketing (optional) | Email address and basic preferences. | Send product updates and offers, only with your explicit opt-in. |
We do not collect special categories of personal data (such as data revealing health, ethnicity, religion, or sexual orientation), and we do not knowingly process the data of minors. The website and Software are intended for professional and educational software-security use.
4. Legal bases for processing
We process personal data under one or more of the following legal bases set out in Article 6 GDPR:
- Performance of a contract (Art. 6(1)(b)): processing account, order, payment, license activation, and support data to deliver the Software license you purchased.
- Compliance with a legal obligation (Art. 6(1)(c)): retaining invoices and tax records as required by Dutch law.
- Legitimate interests (Art. 6(1)(f)): operating the website securely, preventing fraud and license abuse, and improving the Software and support workflow. We balance these interests against your rights and freedoms and do not rely on this basis where your rights override it.
- Consent (Art. 6(1)(a)): analytics cookies and marketing emails. You can withdraw your consent at any time without affecting the lawfulness of processing before withdrawal.
5. How long we keep your data
- Invoices and tax records: 7 years, in line with the Dutch General Tax Act (Algemene wet inzake rijksbelastingen).
- Account and license data: for the active life of your account and license, plus a reasonable archival period for dispute resolution and abuse prevention, normally up to 24 months after termination.
- Support correspondence: up to 24 months after the case is closed.
- Website logs: up to 12 months, then aggregated or deleted.
- Marketing data: deleted promptly on opt-out.
Where law requires a longer period, or where data is genuinely needed to defend or pursue legal claims, we retain it only for as long and to the extent strictly necessary, and we periodically review our retention practices.
6. Who we share data with
We share personal data only with processors that are necessary to run the storefront, checkout, license activation, support, and accounting workflow, each bound by a written data-processing agreement that meets Article 28 GDPR. Categories of recipient include:
- Storefront and checkout: Shopify, which hosts the storefront and processes orders.
- Payment processing: Shopify checkout and PCI-DSS compliant payment providers, including Worldline and Tazapay where available.
- Transactional and support email: our email provider for order confirmations, license delivery, and support correspondence.
- Accounting and tax: our accounting software and external accountant, for legally required record-keeping.
- Anti-fraud and infrastructure: CDN and security providers used to protect the website.
We do not sell personal data. We do not disclose personal data to third parties for their own marketing purposes. Where the law strictly requires us to disclose data, such as a valid court order or a lawful request from a competent authority, we disclose only the minimum necessary to comply.
7. International transfers
We aim to keep personal data within the European Economic Area (EEA). Where a processor transfers data outside the EEA, we rely on appropriate safeguards under Chapter V GDPR, in particular the European Commission's Standard Contractual Clauses (Decision (EU) 2021/914) together with any supplementary measures needed in light of the destination country. You can request a copy of the safeguards in place by emailing support@virtualspacesec.com.
8. Security
We apply appropriate technical and organizational measures under Article 32 GDPR to protect personal data, including encryption in transit (TLS), encryption at rest where supported by our providers, strict access controls on a need-to-know basis, multi-factor authentication for administrative accounts, logging and monitoring, and regular review of our security practices. No system is ever perfectly secure, but we work to keep the risk to your data low.
9. Your rights
Under the GDPR you have the right to:
- access the personal data we hold about you (Art. 15);
- rectify inaccurate or incomplete data (Art. 16);
- erase your data ("right to be forgotten") where the conditions are met (Art. 17);
- restrict processing (Art. 18);
- data portability for data you provided to us (Art. 20);
- object to processing based on legitimate interests, including profiling, where applicable (Art. 21);
- withdraw consent at any time, without affecting prior processing (Art. 7); and
- not be subject to a decision based solely on automated processing that produces legal effects (Art. 22). We do not make such automated decisions about you.
To exercise any of these rights, email support@virtualspacesec.com. We will respond within one month, and may ask for proof of identity to keep your data safe. We will not charge a fee for reasonable requests.
You also have the right to lodge a complaint with a supervisory authority. In the Netherlands this is the Autoriteit Persoonsgegevens (autoriteitpersoonsgegevens.nl). You may also contact the supervisory authority in your country of residence or place of work.
10. Cookies and similar technologies
We use a minimal set of cookies and similar technologies:
- Strictly necessary cookies: required for the cart, checkout, login, and basic security. No consent is required for these under the ePrivacy Directive.
- Analytics cookies: only set with your consent, used to understand aggregated, non-identifying usage patterns so we can improve the website.
- Functional cookies: for example, remembering your language preference.
You can change or withdraw your consent at any time via the cookie banner. You can also manage cookies through your browser settings. The Software itself does not set any cookies on third-party systems.
11. Children
The website and Software are not directed at children under 16. We do not knowingly collect personal data from children. If you believe a child has provided us with personal data, please contact us so we can delete it.
12. Changes to this Policy
We may update this Policy from time to time. The "Last updated" date at the top of this page reflects the most recent change. Where changes materially affect how we process your personal data, we will notify active customers by email or by a prominent notice on the website before the changes take effect, where required by law.