Break-Glass Access
  • Purpose
  • Pricing
  • Documentation
  • Emergency Passport
  • Support
  • Get Pro
  • 🇳🇱 NL
Select Page
Privacy

Privacy Statement — Break-Glass Access / Noodtoegang

Version 1.0 — 2 July 2026

Contents

  • 1. Who we are (data controller)
  • 2. What data we process, for what purpose and on what basis
  • 3. What we do not do
  • 4. How long we retain data
  • 5. Who receives your data (processors and sub-processors)
  • 6. Transfers outside the EEA
  • 7. Cookies
  • 8. Security
  • 9. Your rights
  • 10. Changes

1. Who we are (data controller)

This privacy statement applies to the websites breakglassaccess.com and noodtoegang.nl, the associated portal, and the plugin Break-Glass Access / Noodtoegang ("the Plugin") and its related service ("the Service").

Data controller:

KVWB B.V., trading under the names Break-Glass Access and Noodtoegang, part of KVWB (Keurmerk Verantwoord Webbeheer). KvK: XXXXXXXX · XXXXXXXXXXXX, XXXX XX Groningen, the Netherlands Privacy contact: info@noodtoegang.nl

We process personal data carefully and in accordance with the General Data Protection Regulation (GDPR).

Important, about your own WordPress website. If you use the Plugin on your own website, you are the data controller for the personal data on and in that website and in the backups you make. We only process the data described below. A created backup is stored on your own server; we do not receive that backup.

↑ Back to contents

2. What data we process, for what purpose and on what basis

a. Visitors of the websites

Data Purpose Basis
Completed fields of the contact/request form (including name, e-mail address, message) Answering your question and contacting you Performance of / steps prior to a contract and legitimate interest (Art. 6(1)(b)/6(1)(f) GDPR)
Technical data (IP address, browser type, pages visited, time) via server logs and cache Security, troubleshooting and proper operation of the website Legitimate interest (Art. 6(1)(f) GDPR)
Cookie and preference data Operation and improvement of the website Consent or legitimate interest, see Chapter 7

b. Customers of the Pro version

Purchase and licensing of the Pro version are handled through our sales and licensing partner (Freemius). This involves, among other things: name, e-mail address, country, and payment and invoicing data. Payment data is processed by the payment service; we do not store full payment data ourselves.

  • Purpose: delivering and managing the licence, processing payment, sending invoices, providing support.
  • Basis: performance of the contract (Art. 6(1)(b) GDPR) and, for administration, a legal obligation (Art. 6(1)(c) GDPR).

c. Use of the Service (mail fallback and site registration)

If you enable the mail fallback in the Plugin (this is on by default, but you can turn it off), your website registers with our Service. We then receive and process:

Data Purpose Basis
The URL of your website Linking the Service to the correct website Performance of the contract / legitimate interest
A per-website unique site secret (technical key) Verifying requests from your website (HMAC), preventing misuse Legitimate interest (security)
The e-mail address(es) of the emergency user(s) to which an emergency code may be sent Being able to deliver an emergency code if your own website cannot send mail Performance of the contract / legitimate interest
The plugin version Compatibility and support Legitimate interest

If the Service delivers an emergency code by e-mail, it is sent only to the pre-registered addresses. The emergency code itself is not logged or stored by us.

If you turn the mail fallback off, the Plugin sends no data at all to the Service; everything then runs through the e-mail of your own website.

d. SMS delivery (Pro, where available)

If you use SMS delivery, we process the relevant mobile number, your licence data and the website URL for that purpose only, solely to perform that function. Basis: performance of the contract.

↑ Back to contents

3. What we do not do

  • We do not sell your data.
  • We do not use your data for profiling or automated decision-making with legal effect.
  • We do not log or store emergency codes.
  • We never ask for or store passwords or SMTP login details of your website.
  • We do not receive the content of your backups; those remain on your own server.

↑ Back to contents

4. How long we retain data

We do not retain data longer than necessary:

  • Contact form: until your question is handled and thereafter a maximum of 12 months, unless a customer or file relationship arises.
  • Customer/licence data: for the term of the licence and thereafter as long as necessary for support and warranty.
  • Administration and invoices: 7 years (statutory tax retention obligation).
  • Site registration with the Service (URL, secret, recipient addresses): as long as your website is registered. If you remove the registration or the Plugin, or turn off the mail fallback, we delete this data or remove it on request.
  • Technical logs: generally a maximum of a few months, for security and troubleshooting.

↑ Back to contents

5. Who receives your data (processors and sub-processors)

We engage service providers that process data on our behalf. Where required, we conclude a data processing agreement with them. These include:

  • Hosting party of our websites and Service (ZXCS, vps0271.zxcs.nl) — storage and server management.
  • E-mail delivery service Mailgun (Sinch) — for sending (emergency) e-mail; processed in the EU region (mg.noodtoegang.nl).
  • Freemius — sales, licence management and payment processing of the Pro version.
  • SMS service (if you use SMS) — for sending SMS messages.
  • A statistics service ([STATISTICS SERVICE]) — for visitor statistics.

We only provide data to third parties beyond this where legally required (for example to a supervisory authority or under a court order).

↑ Back to contents

6. Transfers outside the EEA

Our e-mail delivery (Mailgun) is set to the EU region. Some parties (such as Freemius or an SMS service) may process data outside the European Economic Area, for example in the United States. In that case we ensure an appropriate basis for the transfer, such as an adequacy decision (for example the EU-US Data Privacy Framework) or the Standard Contractual Clauses (SCCs) of the European Commission.

↑ Back to contents

7. Cookies

Our websites use cookies and similar techniques that are necessary for the operation, the security and the acceleration (caching) of the site. For non-essential cookies (for example statistics via [STATISTICS SERVICE]) we ask, where required, for your consent via the cookie notice. You can refuse or delete cookies in your browser. In security e-mails we use no click or open tracking.

[Enter the exact cookie list here once known; then remove this line.]

↑ Back to contents

8. Security

We take appropriate technical and organisational measures to protect your data, including encrypted connections (HTTPS/TLS), signed and verified requests between your website and the Service (HMAC), access restricted to authorised persons, and deliberately not storing emergency codes, passwords or backup content. No security is fully watertight; in the event of a data breach we act in accordance with the statutory notification obligation.

↑ Back to contents

9. Your rights

You have the right to:

  • access your data;
  • have data corrected or completed;
  • have data erased ("right to be forgotten");
  • have processing restricted;
  • object to processing based on legitimate interest;
  • transfer your data (data portability);
  • withdraw a consent given (this takes effect from the moment of withdrawal).

Send your request to info@noodtoegang.nl. We respond within the statutory period (in principle one month). To prevent misuse, we may ask you to identify yourself.

If you disagree with how we handle your data, you can lodge a complaint with the Dutch Data Protection Authority (Autoriteit Persoonsgegevens, autoriteitpersoonsgegevens.nl), or with the supervisory authority in the country where you reside.

↑ Back to contents

10. Changes

We may amend this privacy statement. The current version is always available on our websites, with the date stated. Where appropriate, we will draw additional attention to important changes.

↑ Back to contents

KVWB B.V.
KvK: XXXXXXXX · XXXXXXXXXXXX, XXXX XX Groningen, the Netherlands
Privacy contact: info@noodtoegang.nl · breakglassaccess.com · noodtoegang.nl

Version 1.0 — 2 July 2026

Noodtoegang

De noodknop voor je website

Maak veilig zelf een volledige back-up van je WordPress-site — ook als de webbeheerder onbereikbaar is. Je wordt nooit beheerder.

Product

  • Doel
  • Prijzen
  • Documentatie
  • Support

Juridisch

  • Algemene voorwaarden
  • Privacyverklaring
  • Toegankelijkheidsverklaring
  • Disclaimer

Contact

Noodtoegang
Atoomweg 2
9743 AK Groningen
Nederland

info@noodtoegang.nl

© 2026 Noodtoegang · Alle rechten voorbehouden · English

★★★★★  Vertrouwd door webbeheerders · aanbevolen door het KVWB

Break Glass Access

The emergency button for your website

Securely make a full backup of your WordPress site yourself — even when the web manager is unreachable. You never become an administrator.

Product

  • Purpose
  • Pricing
  • Documentation
  • Support

Legal

  • Terms & Conditions
  • Privacy Policy
  • Accessibility Statement
  • Disclaimer

Contact

Break Glass Access
Atoomweg 2
9743 AK Groningen
Netherlands

info@breakglassaccess.com

© 2026 Break Glass Access · All rights reserved · Nederlands

★★★★★  Trusted by web managers · recommended by KVWB

  • Nederlands (Dutch)
  • English