Privacy & security
This page explains which personal data Mechanis processes, why, and how we protect it. It also explains how to report a security problem.
Last updated: 24 August 2026
1. Who we are
Mechanis is a Dutch company that builds automation and AI systems for B2B businesses. We are the data controller for the processing described here.
| Trading name | Mechanis, a trading name of yowal |
|---|---|
| VAT identification number | NL004961248B75 |
| Chamber of Commerce (KVK) | 92559433 |
| Registered address | to be completed — see note below |
| General contact | yoran@mechanis.tech |
| Privacy enquiries | privacy@mechanis.tech |
| Security reports | security@mechanis.tech |
We provide our full postal address on request via yoran@mechanis.tech.
2. This website does not track you
mechanis.tech carries no analytics or tracking software whatsoever. No Google Analytics, no Tag Manager, no advertising pixels from LinkedIn, Meta or anyone else. The site sets no cookies of its own.
Web fonts are served from our own server rather than from Google, so your IP address is not shared with any third party when you view this site.
One exception: if you click Book a call, the Calendly scheduling widget opens. Only at that moment does Calendly software load, and it may set cookies. If you do not click, nothing loads.
3. What we process
When you get in touch or book a call
Your name, email address, company name and whatever you write in your message. Legal basis: performance of a contract or steps taken prior to entering into one (Article 6(1)(b) GDPR). We use this only to answer your question and hold the conversation.
When you are a client
Contact details, billing details, and the data needed to build and maintain the agreed systems. Legal basis: performance of the contract, and for invoicing a legal obligation (Article 6(1)(c) GDPR).
Server logs
Our web server records IP address, timestamp, requested page and browser type as standard. This is needed to diagnose faults and detect abuse. Legal basis: legitimate interest (Article 6(1)(f) GDPR). These logs are never used to profile visitors.
4. Parties that process data for us
| TransIP (Netherlands) | Web hosting and email. Data stays within the EU. |
|---|---|
| Calendly (United States) | Only if you book a call yourself. Transfer to the US takes place under the EU-US Data Privacy Framework and the European Commission's standard contractual clauses. |
We have a data processing agreement with every party that processes personal data on our behalf. We do not sell your data and do not use it for advertising.
5. How long we keep data
| Enquiries with no follow-up | 12 months |
|---|---|
| Server logs | 6 months maximum |
| Client files | up to 2 years after the engagement ends |
| Invoices and accounts | 7 years (statutory retention period) |
6. Your rights
You have the right to access, rectify or erase your data. You may also restrict processing, object to it, and request your data in a portable format.
Send your request to privacy@mechanis.tech. We respond within 30 days. If you are unhappy with how we handle it, you may lodge a complaint with the Dutch data protection authority, the Autoriteit Persoonsgegevens.
7. Security and reporting vulnerabilities
We take the following measures:
- All traffic runs over HTTPS, enforced with HSTS.
- A Content Security Policy restricts which sources the site may load, blocking script injection.
- Access to systems is protected with two-factor authentication.
- Software and servers are updated regularly.
- Only people who need the data have access to it.
Reporting a vulnerability
Think you have found a security problem in mechanis.tech? Report it to security@mechanis.tech. We acknowledge every report within three working days.
We ask that you:
- do not disclose the issue publicly before it is fixed;
- do not access more data than needed to demonstrate the problem;
- do not modify or delete anyone else's data;
- do not run automated attacks or denial-of-service tests.
If you follow these terms, we will not pursue legal action. Our contact details are also published in /.well-known/security.txt in line with RFC 9116.
We are a small company and do not run a bug bounty programme, so we cannot pay a reward. We are happy to credit you if you would like that.
8. Changes
We update this statement when our services or the applicable rules change. The date at the top shows the most recent revision.
Nederlands