Privacy & security

This page explains which personal data Mechanis processes, why, and how we protect it. It also explains how to report a security problem.

Last updated: 24 August 2026

1. Who we are

Mechanis is a Dutch company that builds automation and AI systems for B2B businesses. We are the data controller for the processing described here.

Trading nameMechanis, a trading name of yowal
VAT identification numberNL004961248B75
Chamber of Commerce (KVK)92559433
Registered addressto be completed — see note below
General contactyoran@mechanis.tech
Privacy enquiriesprivacy@mechanis.tech
Security reportssecurity@mechanis.tech

We provide our full postal address on request via yoran@mechanis.tech.

2. This website does not track you

mechanis.tech carries no analytics or tracking software whatsoever. No Google Analytics, no Tag Manager, no advertising pixels from LinkedIn, Meta or anyone else. The site sets no cookies of its own.

Web fonts are served from our own server rather than from Google, so your IP address is not shared with any third party when you view this site.

One exception: if you click Book a call, the Calendly scheduling widget opens. Only at that moment does Calendly software load, and it may set cookies. If you do not click, nothing loads.

3. What we process

When you get in touch or book a call

Your name, email address, company name and whatever you write in your message. Legal basis: performance of a contract or steps taken prior to entering into one (Article 6(1)(b) GDPR). We use this only to answer your question and hold the conversation.

When you are a client

Contact details, billing details, and the data needed to build and maintain the agreed systems. Legal basis: performance of the contract, and for invoicing a legal obligation (Article 6(1)(c) GDPR).

Server logs

Our web server records IP address, timestamp, requested page and browser type as standard. This is needed to diagnose faults and detect abuse. Legal basis: legitimate interest (Article 6(1)(f) GDPR). These logs are never used to profile visitors.

4. Parties that process data for us

TransIP (Netherlands) Web hosting and email. Data stays within the EU.
Calendly (United States) Only if you book a call yourself. Transfer to the US takes place under the EU-US Data Privacy Framework and the European Commission's standard contractual clauses.

We have a data processing agreement with every party that processes personal data on our behalf. We do not sell your data and do not use it for advertising.

5. How long we keep data

Enquiries with no follow-up12 months
Server logs6 months maximum
Client filesup to 2 years after the engagement ends
Invoices and accounts7 years (statutory retention period)

6. Your rights

You have the right to access, rectify or erase your data. You may also restrict processing, object to it, and request your data in a portable format.

Send your request to privacy@mechanis.tech. We respond within 30 days. If you are unhappy with how we handle it, you may lodge a complaint with the Dutch data protection authority, the Autoriteit Persoonsgegevens.

7. Security and reporting vulnerabilities

We take the following measures:

Reporting a vulnerability

Think you have found a security problem in mechanis.tech? Report it to security@mechanis.tech. We acknowledge every report within three working days.

We ask that you:

If you follow these terms, we will not pursue legal action. Our contact details are also published in /.well-known/security.txt in line with RFC 9116.

We are a small company and do not run a bug bounty programme, so we cannot pay a reward. We are happy to credit you if you would like that.

8. Changes

We update this statement when our services or the applicable rules change. The date at the top shows the most recent revision.