Legal notice and privacy statement
Version 1.0 · 6 September 2026
Two things belong on this page and they are usually split across two: who is behind this site, and what happens to your personal data if you end up in my inbox or I end up in yours. Both are short, because there is not much of either.
Registration in progress. The KVK and VAT numbers below are not yet issued. The Kamer van Koophandel registration is under way and this page is updated the day it completes. They are marked pending rather than left blank or quietly omitted, which is the standard this site asks of everyone else.
Who publishes this site
| Responsible publisher | Lars Oosterloo |
|---|---|
| Trading as | Sole trader (eenmanszaak) in formation, to be established in the Netherlands |
| Postal address | Stalpaert van der Wielestraat 32 5921 VW Venlo Nederland |
| Contact | cra@oosterloo.eu for anything about the practice; security@oosterloo.eu for vulnerability reports only, under the disclosure policy |
| KVK number | Not yet issued — registration in progress |
| VAT identification number | Not yet issued — follows KVK registration |
The two addresses are deliberately separate. Sales traffic and vulnerability reports have different urgencies and different readers, and mixing them is how a real report ends up behind forty pieces of correspondence. That split is finding C1 of my own audit applied to myself.
Who hosts this site
bHosted.nl B.V., Netherlands — bhosted.nl. Server logs are held by the host as part of normal operation; see below for what I do with them.
The site itself collects nothing
No cookies, no analytics, no tracking pixels, no embedded third-party scripts, no contact form. Nothing on these pages profiles you, and there is no consent banner because there is nothing to consent to. The dark-mode toggle stores your preference in your own browser's local storage; that value never leaves your device and I never see it.
The web server keeps ordinary access logs — IP address, timestamp, requested URL, referrer, user agent — which exist for security and troubleshooting and are the only reason an IP address of yours touches my infrastructure at all. I read them in aggregate to see which page a link sent people to. I do not attempt to identify individuals from them. Legal basis: legitimate interests (Art. 6(1)(f) GDPR) in operating and securing the site. Retention: 90 days, then deletion by the host's rotation.
If you email me
Mail to either address is handled by Proton AG (Switzerland) as my mail provider, under an adequacy decision for Switzerland. I keep correspondence for as long as it is useful and in any case no longer than two years after our last exchange, except where I need it longer to defend a legal claim or where it is part of a client engagement record.
Anything you tell me about your own product stays confidential, NDA or no NDA. That is a commitment about how I work, not a privacy technicality.
If I emailed you first
This is the part that actually needs saying, and most sites bury it. If you received an unsolicited email from me about the Cyber Resilience Act, here is the whole of it.
| What I hold | Your name, your role, your business email address, your employer, and public information about the products your company sells — typically a firmware download page or a documentation link. |
|---|---|
| Where I got it | Publicly available professional sources: your company's own website, its published contact or security pages, trade-fair exhibitor directories, industry-alliance membership lists, and public code repositories. Never a purchased list, never a scraper, never a data broker. The specific source is named in the email itself. |
| Why | To ask whether your company has a vulnerability-reporting path in place before Article 14 of the Cyber Resilience Act starts to apply, and to offer help with it. That is direct marketing, and I am not going to call it anything else. |
| Legal basis | Legitimate interests (Art. 6(1)(f) GDPR) — business-to-business contact with a named professional about a regulation that applies to their employer's products. I have weighed that against your interests; the safeguards are that I write to professional addresses only, about your professional role, in small numbers, with the source disclosed and a working opt-out in every message. |
| Who else sees it | Proton AG as mail provider. Nobody else. Your details are not sold, shared, syndicated or used to train anything. |
| How long | Deleted within 30 days of the last message in the sequence if you do not reply, or immediately on request. If you ask me to stop, I keep the minimum needed to honour that — your email address on a suppression list — because the only way to reliably not write to you again is to remember not to. |
| Automated decisions | None. No profiling, no scoring, no automated decision-making of any kind. |
| Transfers | None outside the EEA and Switzerland. |
To make it stop: reply with the word “no”. That is the whole procedure. You do not have to explain, you do not have to fill anything in, and you will not get a follow-up asking you to reconsider. You have an unconditional right to object to direct marketing under Art. 21(2) GDPR and it takes effect immediately, not after a processing period.
Your rights
You can ask me for a copy of what I hold about you, to correct it, to delete it, to restrict what I do with it, to have it handed over in a portable form, or to object to it — Articles 15 to 22 GDPR. Write to cra@oosterloo.eu and I will answer within a month, free of charge. In practice, for the outreach data described above, the honest answer to most access requests is a single line naming your employer and the page I found you on.
If you are not satisfied with how I handle that, you can complain to the Dutch data protection authority, the Autoriteit Persoonsgegevens (autoriteitpersoonsgegevens.nl), or to the supervisory authority where you live or work.
Liability and scope
- Nothing on this site is legal advice. It is an engineer's reading of a regulation, and the regulation is linked in every official EU language so you can check it against the source rather than against me.
- No document I produce makes a product compliant by itself. The declaration of conformity is the manufacturer's to make and to sign.
- The audit published on this site concerns my own hardware, sold to nobody, and describes its state on a stated date. It is not an assessment of anyone else's product.
- External links are provided because the source is worth reading. I am not responsible for what is on the other end of them.
Changes
If this page changes materially, the version number and date at the top change with it and the previous version stays available on request. It will not be edited quietly — for the same reason the teardown is not.