Privacy Policy.
What personal data Calyraen holds about you, why we are allowed to hold it, and what you can tell us to do with it.
We collect as little as possible, sell nothing, and tell you plainly what we keep and why. You can see, export or delete your data whenever you like. The full document below is the binding version.
The full text.
Calyraen designs and builds its own hardware, writes its own operating system, and runs the services that go with them. That means we hold personal data about the people who buy from us, use our machines, ask us questions, and apply to work with us. This policy explains what we hold, why we are allowed to hold it, how long we keep it, and what you can tell us to do about it.
We are established in the Netherlands and we sell into the European Union. This policy is written to meet the General Data Protection Regulation (Regulation (EU) 2016/679, known in Dutch as the AVG) and the Dutch implementing act, the Uitvoeringswet AVG (UAVG). The site is in English, so this policy is in English. If you would rather write to us in Dutch, please do. We will answer in Dutch.
One thing to be clear about up front: our catalogue is not open for orders yet. The parts of this policy that deal with orders, payment, delivery, and guarantee claims describe what will happen once you can buy from us. They apply from the moment the shop opens.
Last updated: 25 July 2026
Who is responsible for your data
The controller of the personal data described in this policy is:
- [registered legal name], trading as Calyraen
- Registered address: [registered address]
- Chamber of Commerce (KvK) number: [KvK number]
- VAT number: [BTW-nummer]
- Privacy contact: [privacy contact address]
You can also reach us through our contact page. If you write about privacy, please say so in the subject line so it goes to the right people.
Where we operate through more than one legal entity, the entity named above is the controller for this website, the accounts held on it, and the products and services sold through it. Some services have their own controller and their own privacy notice. Where that is the case we say so in the notice for that service, and that notice takes priority over this one for that service.
Data protection officer
If we appoint a data protection officer under article 37 of the GDPR, we will publish their contact details here and register them with the Autoriteit Persoonsgegevens. The contact for that role, once it is filled, is [data protection officer contact]. Until then, privacy questions and requests go to [privacy contact address] and are handled by the people responsible for data protection inside the company. You do not need to know who they are to get an answer.
What this policy covers
- This website, calyraen.com, and the account area on it.
- Calyraen hardware: Forge servers, the Atlas, Vantage and Stratus computers, and our embedded and edge machines.
- CalyOS, in the editions CalyOS Desktop, CalyOS Server and CalyOS Edge. CalyOS ships on Calyraen hardware and is not sold on its own, so any data it sends us comes from a machine you already own or manage.
- CalyCloud, the browser based service for managing those machines.
- Our consumer facing platforms, where a platform does not publish a privacy notice of its own.
When we act for you rather than for ourselves
Not everything we do makes us the controller.
If you are a business and you use CalyCloud to manage machines belonging to your organisation, you decide what happens to the data about your staff and your devices. In that situation you are the controller and we are your processor under article 28 of the GDPR. We act on your documented instructions, and a data processing agreement covers the work. Ask us and we will send you ours.
The same applies where we host or operate systems on behalf of a customer. If you are an employee of such a customer and you want to exercise your rights, ask your own organisation first. We will help them answer you.
Do you have to give us your data?
Mostly, no. You can read this site without an account, and without accepting anything beyond the cookies that are strictly necessary.
Some data is unavoidable if you want something from us. Once the shop opens, placing an order will mean giving us your name, your address, and your payment details, because we cannot deliver or invoice without them. That is a contractual requirement. If you do not give it, we cannot complete the sale. Tax law then requires us to keep the invoice, whether you want us to or not.
Everything else is optional. If you decline optional data, you lose only the thing it was for. Refusing analytics and marketing cookies does not restrict your access to any part of this site.
The personal data we collect
Data you give us
- Account details. Name, email address, password (stored as a hash, never in readable form), and the settings and preferences you choose. Optionally a phone number and a company name.
- Order details. Billing address, delivery address, the items you ordered, order history, and any purchase order or reference you supply. We hold none of this yet, because the catalogue is not open for orders.
- Payment details. Handled by our payment provider. We receive a confirmation, the payment method type, and a truncated card number or masked account reference. Full card numbers do not reach our systems.
- Business and partner details. For business customers, resellers, and suppliers: contact names, job titles, business addresses, VAT numbers, and the content of quotes and contracts.
- Support and enquiry content. What you write in a support ticket, a contact form, or a quote request, along with any attachments, screenshots, logs, or photographs you send.
- Guarantee and repair details. Serial numbers, order numbers, fault descriptions, diagnostic output, and repair notes.
- Job applications. Your CV, covering letter, contact details, and the notes we make during a hiring process.
Data we collect automatically
- Technical data. IP address, browser and device type, operating system, referring page, the pages you view, the actions you take, and the date and time. This is written to server logs whenever you load a page.
- Security data. Sign in attempts, failed logins, session identifiers, and records of anything our fraud and abuse checks flag.
- Cookies and similar technologies. Cookies, local storage, session storage, and tags. What each category does is set out in our Cookie Policy.
- Device and product data. Where you run CalyOS Desktop, CalyOS Server or CalyOS Edge, or connect a machine to CalyCloud, we may receive the device identifier, the edition and version in use, the hardware configuration, health and error reports, and crash diagnostics. Optional diagnostics are off unless you switch them on, and you can switch them off again in the settings on the device.
Data we get from other people
- Confirmation and fraud signals from our payment provider.
- Delivery status from carriers.
- Publicly registered business information, for example a company's KvK entry, when we check a business customer.
- Your name and email address from a sign in provider, if you choose to sign in with one.
- A referral from a partner or reseller who introduced you to us.
We combine this with what we already hold about you so that our records stay accurate.
Why we use your data, and the legal basis for each purpose
Under article 6 of the GDPR we need a legal basis for every use. Here is ours, purpose by purpose.
To create and run your account
We use your account details to register you, sign you in, keep the account secure, and let you see your own records.
Legal basis: performance of a contract with you, article 6(1)(b).
To take, fulfil, and deliver an order
Once the shop opens, we will use your order, address, and payment data to accept the order, take payment, arrange delivery, and keep you informed about it.
Legal basis: performance of a contract with you, article 6(1)(b). This also covers steps taken at your request before a contract is agreed, such as a quote.
To invoice you and keep our books
We use order and payment records to issue invoices, handle refunds, and keep the accounts.
Legal basis: a legal obligation, article 6(1)(c), under Dutch tax and accounting rules including article 52 of the Algemene wet inzake rijksbelastingen and article 2:10 of the Burgerlijk Wetboek.
To handle returns, guarantee claims, and repairs
We use serial numbers, order records, fault reports, and repair notes to assess a claim, repair or replace a product, or refund you.
Legal basis: performance of a contract, article 6(1)(b), together with a legal obligation, article 6(1)(c), because the legal conformity guarantee under Dutch law and Directive (EU) 2019/771 requires us to deal with these claims.
To answer your questions and give support
We read and store what you send us so we can help, and so the next person you speak to does not make you repeat yourself.
Legal basis: performance of a contract, article 6(1)(b), where your question concerns a product or an order. Our legitimate interest in answering enquiries, article 6(1)(f), where you are not a customer.
To keep the site, the accounts, and our products secure
We use technical and security data to detect intrusion, block abuse, prevent fraud, investigate incidents, and keep services running.
Legal basis: our legitimate interest in protecting our systems, our customers, and our business, article 6(1)(f). Where the law requires a specific security measure, article 6(1)(c).
To fix faults and improve what we build
We use error reports, crash diagnostics, and aggregated usage data to find bugs, plan updates, and improve hardware and software design.
Legal basis: our legitimate interest in making our products work properly, article 6(1)(f), for the basic diagnostics needed to keep a machine healthy. Your consent, article 6(1)(a), for optional or extended telemetry, which you can withdraw in the settings on the device.
To measure how the site is used
Analytics tell us which pages people read and where the site fails them.
Legal basis: your consent, article 6(1)(a), given through the cookie banner. Reading or writing anything on your device that is not strictly necessary also needs consent under article 11.7a of the Dutch Telecommunicatiewet.
To send you service messages
Order confirmations, delivery updates, security alerts, guarantee notices, and important changes to a service you use.
Legal basis: performance of a contract, article 6(1)(b), or a legal obligation, article 6(1)(c). These are not marketing, so you cannot unsubscribe from them while you hold an account or an open order with us.
To send you marketing
Newsletters and product announcements, and the measurement of how they perform.
Legal basis: your consent, article 6(1)(a). If you have already bought from us, we may email you about our own similar products under article 11.7(3) of the Telecommunicatiewet, relying on our legitimate interest, article 6(1)(f). Every marketing message carries a one click unsubscribe, and you can object at any time.
To handle a job application
We use application material to assess candidates and run a hiring process.
Legal basis: steps taken at your request before entering a contract, article 6(1)(b). Your consent, article 6(1)(a), if we keep your details on file after the process ends.
To meet legal duties and defend legal claims
Responding to lawful requests from authorities, meeting regulatory duties, and establishing, exercising, or defending legal claims.
Legal basis: a legal obligation, article 6(1)(c), and our legitimate interest in defending our position, article 6(1)(f).
To transfer or restructure the business
If Calyraen is ever sold, merged, or reorganised, customer and supplier records may pass to the buyer.
Legal basis: our legitimate interest in being able to sell or restructure the business, article 6(1)(f). We would keep the protections in this policy in place through the transfer, and tell you if the controller changes.
Where we rely on legitimate interests, we weigh our interest against your rights first. You can ask us for the reasoning behind any of those decisions, and you can object to the processing. See Your rights below.
Special categories of data, and children
We do not ask for special category data as defined in article 9 of the GDPR, such as health, religion, political opinions, or biometric data, and our services are not designed to collect it.
Two exceptions are worth naming.
If you tell us about a disability or a health condition when you ask for an accessible alternative or an adjustment, that is health data. We use it only to help you, we keep it out of your general customer record where we can, and we delete it when the request is closed. The basis is your explicit consent, article 9(2)(a). You do not have to tell us your diagnosis to get help. Telling us what you need is enough.
If you send us a copy of an identity document, please black out your photograph and your citizen service number (BSN). We do not need either, we do not want them, and article 46 of the UAVG allows a number of that kind to be used only where a law says it may be. We will destroy any copy we did not ask for.
Our services are not aimed at children. Under article 5 of the UAVG, a child in the Netherlands must be 16 before they can consent to an online service on their own account. Below that age a parent or guardian has to consent. If you believe a child has given us personal data without that consent, tell us and we will delete it.
Cookies and similar technologies
We ask for your consent before we place any cookie that is not strictly necessary, as required by article 11.7a of the Telecommunicatiewet and the ePrivacy Directive 2002/58/EC. Strictly necessary cookies, such as the session cookie and the cross site request forgery token, are exempt and are always on.
You can accept or refuse each optional category, and you can change your mind at any time through the cookie settings on this site. Withdrawing consent is as easy as giving it. Refusing optional cookies does not block you from any part of the site, and it does not change the price of anything.
The full list of categories, what each one does, and roughly how long each cookie lasts is in our Cookie Policy.
Who we share your data with
We share personal data only where it is needed to run the business, or where the law requires it. We do not sell personal data. We do not hand it to anyone for their own marketing.
- Hosting and infrastructure. Our website, account area, and shop run on software we operate ourselves, hosted with [hosting provider], with servers in [hosting location].
- Payment processing. [payment provider] processes card and bank payments and runs fraud checks. They act as an independent controller for parts of that work, under their own privacy notice.
- Delivery. [delivery carriers] receive the name, delivery address, and contact details needed to deliver a parcel and to let you track it.
- Email delivery, support tooling, and analytics. Providers who send our transactional and marketing email, run our ticketing, and measure site usage. Our analytics provider is named in the Cookie Policy.
- Professional advisers. Accountants, auditors, and lawyers, all bound by confidentiality.
- Authorities. Tax authorities, regulators, police, and courts, where we are legally required to hand data over. We check that a request is lawful before we answer it, and we tell you unless we are forbidden from doing so.
- A buyer of the business, in the circumstances described above.
Everyone who processes data on our behalf is bound by a processor agreement under article 28 of the GDPR. They may use your data only to do the job we gave them, they must keep it secure, and they must delete or return it when the work ends. We keep a current list of our processors and will send it to you if you ask.
Sending data outside the EEA
Our preference is to keep personal data inside the European Economic Area, and that is where our hosting sits.
Some suppliers, or their support teams, sit outside the EEA. When personal data goes to a country outside the EEA, we rely on one of these safeguards:
- an adequacy decision of the European Commission under article 45 of the GDPR, which recognises that the country protects personal data properly, or
- the Standard Contractual Clauses adopted by the European Commission in Implementing Decision (EU) 2021/914, under article 46 of the GDPR, together with a transfer impact assessment and, where that assessment calls for it, extra technical measures such as encryption where we hold the keys.
If neither is available, the transfer does not happen. Write to [privacy contact address] and we will tell you which safeguard applies to a specific transfer, and send you a copy of the relevant clauses.
How long we keep your data
We keep data only as long as we need it. When the period ends, we delete it or strip out everything that identifies you. Deleted records also disappear from our backups when the backup cycle they sit in rolls over. We do not restore deleted data from a backup except to recover from an incident.
| What | How long |
|---|---|
| Account data | While your account is open, then deleted or anonymised within 6 months of closure |
| Invoices, orders, and payment records | 7 years from the end of the financial year, as Dutch tax law requires |
| Guarantee, repair, and return records | The length of the guarantee period, plus 5 years, which is the general limitation period for claims under the Burgerlijk Wetboek |
| Support tickets | 24 months after the ticket is closed, unless it belongs to a guarantee claim, in which case it follows the line above |
| Contact forms and quote requests that lead nowhere | 12 months |
| Marketing consent and subscriber data | Until you unsubscribe or withdraw consent. We keep a record of the withdrawal itself for as long as we need it to be sure we do not contact you again |
| Cookie consent record | Up to 6 months, then we ask you again |
| Server and security logs | Up to 12 months, longer only for a specific incident under investigation |
| Device diagnostics and crash reports | Up to 12 months in identifiable form, then aggregated or deleted |
| Job applications | 4 weeks after the process ends, or up to 1 year if you give us permission to keep them |
Where a longer period is forced on us by law, or where data is needed for a legal claim that is live, we keep it until that ends and no longer.
Automated decision making and profiling
We do not make decisions about you that produce legal effects, or similarly significant effects, by automated means alone, in the sense of article 22 of the GDPR.
Two things come close, so we will name them.
Our payment provider runs automated fraud and risk checks, and those checks can cause a payment to be refused. If an automated check of that kind blocks a purchase, you can ask us to look at it again by hand, put your side of it, and challenge the outcome. Write to [privacy contact address].
We sort marketing lists in simple ways, for example by which product family you asked about. That is profiling in the broad sense, but it does not decide anything about you, and you can object to it at any time.
We do not score you, rank you, or assess your creditworthiness, and we do not sell profiles to anyone.
How we protect your data
Article 32 of the GDPR asks for security that matches the risk, and this is what we do. We use encryption in transit across this site. Passwords are stored as hashes, never in readable form. Access to customer data is limited to staff who need it for their work, and it is logged. We patch our systems, review our code, back up our data, and test the restores. Our own hardware and CalyOS are built with the same approach.
No system is completely secure, and we will not claim otherwise. If you hold an account, use a strong and unique password, turn on any extra security we offer, and tell us straight away if you think someone else has been in it.
If you believe you have found a security flaw in our site, our software, or our devices, please report it to us rather than publish it. We will respond, we will not take legal action against a researcher who acts in good faith and gives us reasonable time to fix the problem, and we will credit you if you want the credit.
If something goes wrong
If a personal data breach happens and it is likely to create a risk to people's rights and freedoms, we report it to the Autoriteit Persoonsgegevens within 72 hours of becoming aware of it, as article 33 of the GDPR requires. If the risk to you is high, we contact you directly and tell you plainly what happened, what data was involved, what we are doing about it, and what you should do, as article 34 requires.
Your rights
You have the following rights over your personal data. They apply whether or not you hold an account with us.
- Access. Ask what we hold about you and get a copy of it, along with the information in this policy applied to your own case. Article 15.
- Rectification. Have inaccurate data corrected and incomplete data completed. Article 16.
- Erasure. Ask us to delete your data where we no longer need it, where you withdraw the consent it rested on, or where you successfully object. Article 17. We cannot delete records that tax law obliges us to keep, and we will tell you when that is the reason.
- Restriction. Ask us to freeze the use of your data while a dispute about its accuracy or about our legal basis is being sorted out. Article 18.
- Portability. Receive the data you gave us in a structured, commonly used, machine readable format, and have it sent to another provider where that is technically possible. This covers data we process by automated means on the basis of consent or a contract. Article 20.
- Objection. Object to processing based on our legitimate interests. We then stop, unless we can show compelling grounds that override your interests. For direct marketing there is no balancing at all: object and we stop. Article 21.
- Withdraw consent. Withdraw consent at any time, as easily as you gave it, for anything we do on the basis of consent, including optional cookies and optional telemetry. This does not make the processing before withdrawal unlawful. Article 7(3).
- Human review. Ask a person to look again at an automated decision that significantly affects you, give your view, and contest the outcome. Article 22.
- Complain and go to court. See below.
How to use them
Write to [privacy contact address], or use our contact page and say that it is a privacy request.
We answer within one month. If a request is complicated, or you have sent several, we may take up to two further months, and we will tell you within the first month if that happens. Article 12(3). Requests are free. We only charge, or refuse, where a request is clearly unfounded or excessive, and we explain why if we do, and you can complain about that refusal. Article 12(5).
We may need to check that you are who you say you are, so that we do not hand your data to someone else. We ask for the least we can, usually a reply from the email address on the account. We will not ask for your BSN, and we do not need a full copy of your passport.
Complaining to the Autoriteit Persoonsgegevens
If you think we are handling your data wrongly, please tell us first. We would rather fix it than argue about it.
You do not have to come to us first. Under article 77 of the GDPR you have the right to lodge a complaint with the Dutch supervisory authority at any time:
Autoriteit Persoonsgegevens Postbus 93374, 2509 AJ Den Haag, the Netherlands autoriteitpersoonsgegevens.nl
If you live or work in another EU country, you can complain to the supervisory authority there instead.
You also have the right to an effective judicial remedy under article 79 of the GDPR, which means you can take us to the competent Dutch court, and the right to claim compensation for damage caused by a breach of the GDPR under article 82.
Changes to this policy
We update this policy when our services, our suppliers, or the law change. The date at the top always shows the current version. If a change matters to you, for example a new purpose or a new type of recipient, we will tell you before it takes effect, by email or by a notice on the site, and we will ask for your consent again where consent is what the change rests on.
How to contact us
- Privacy questions and requests: [privacy contact address]
- Data protection officer, once appointed: [data protection officer contact]
- Everything else: our contact page
- By post: [registered legal name], [registered address]
If your question is about a particular product or service, tell us which one. It gets to the right team faster.
Related pages: Cookie Policy, Terms of Service, Warranty, Accessibility. Our software licence terms cover what you may do with CalyOS and the software on your machine.
The rest of the paperwork.
Terms, privacy, warranty and the software licence sit side by side. If a document does not answer you, a human will.