Privacy statement

NFIR beeldmerk kleur
NFIR beeldmerk kleur

Privacy statement

1. Introduction

NFIR B.V. (further: NFIR) located at Laan van Zuid Hoorn 165, Rijswijk, is responsible for the processing of personal data as reflected in this privacy policy. NFIR strictly works in accordance with the Privacy Code of Conduct for Private Detective Agencies, section Private Detective Agencies of the Dutch Security Industry, under the supervision of the Dutch Data Protection Authority (DPA). If you have a complaint about NFIR, please see our complaints procedure.

2. What personal data does NFIR process?

NFIR processes your personal data because you use its services or because you have provided it to it yourself, for example by filling out forms on www.nfir.nl or printed, subscribing to the newsletter or communicating via e-mail or phone. There may be differences in the personal data being processed by each executive department. The personal data that NFIR could process are:

  • First and last name
  • Gender
  • Date of birth
  • Place of birth
  • Address details
  • Telephone number
  • E-mail address
  • IP address
  • Other personal data that you actively provide, for example in correspondence or by telephone.
  • Location details
  • Internet browser and device type
  • Bank account number

NFIR might also process the following special and/or sensitive personal data about you:

  • Race
  • Religion or philosophy of life
  • Political affiliation
  • Sexual life
  • Trade union membership
  • Health
  • Criminal history
  • Credit check
  • Data of persons under 16 years of age
  • Citizen service number (BSN).
  • Biometric data
  • Genetic data

3. For what purpose does NFIR process personal data?

NFIR processes your personal data primarily for the purpose of fulfilling orders you have given, billing and handling your payment, and to contact you regarding NFIR’s services. The execution of given assignments includes, among other things:

  • Performing ICT scans to ensure the appropriate level of security;
  • Conducting research on individuals from the perspective of digital forensics;
  • Finding evidence of computer hacking and/or theft;
  • Investigating (corporate) fraud;
  • Preventive advice to the client.

NFIR also processes your personal data for the purposes listed below:

  • Forming electronic file for the purpose of detective investigations;
  • Archiving investigation results;
  • Maintaining investigation records.

Personal data is also used through the NFIR website for the following purposes:

  • Personalizing the user experience;
  • Improving the site and service offerings;

In addition, NFIR may use your personal data for sending the NFIR Newsletter, as well as commercial communications, promotions, advertisements and/or surveys. NFIR is further required by law to process personal data needed to file tax returns.

With all this said, it is noted that the recorded data, in addition to the purposes for which it was explicitly collected, can also be used for doing statistics, managing incidents or conducting market research. However, in these cases, NFIR will conduct a compatibility analysis in accordance with applicable regulations. Processing will be permitted only if the original purpose is compatible with the new purpose or is authorized under an independent legal basis. In these cases, the user will be informed of the changes in the purpose or the legal basis for processing their data.

4. Does NFIR use automated decision making?

NFIR uses automated decision making only within the “Security Monitoring” service. These are decisions that are made by computer programs or systems, without a human (for example, an employee of NFIR) in between. In Security Monitoring, NFIR’s software assigns a classification to a particular event in the customer’s network and notifies the customer of that classification via email, text message or an app.

5. How long does NFIR retain personal data?

NFIR does not retain your personal data longer than is strictly necessary to fulfill the purposes for which your data is collected. NFIR uses the following retention periods for information:

NameAgePhone
Tom5012540515
Jerry4010281065
Halum12011511441

6. Does NFIR share personal data with third parties?

NFIR does not sell your personal data to third parties and only provides them to third parties if necessary for the execution of the agreement with you or to comply with a legal obligation and/or for the purpose of providing services to the user. With companies that process your data on behalf of NFIR, NFIR enters into a processing agreement to ensure the same level of security and confidentiality of your data. NFIR remains ultimately responsible for these processing operations.

Finally, the user should know that NFIR (and that NFIR reserves the right) to disclose their information in the following cases: (i) When required by a judicial or administrative authority; (ii) as necessary to exercise your rights in accordance with the terms and conditions of NFIR and this Privacy Statement; (iii) as necessary to comply with the law; (iv) if such data could be useful in protecting the rights of third parties; (v) when appropriate to protect the rights, property or safety of NFIR, its officers, subsidiaries, affiliates, directors, officers, employees, users or the general public; and (vi) when reasonable grounds exist related to public safety, national defense or public health.

7. Does NFIR use cookies or similar techniques?

NFIR uses the following types of cookies:

  • Functional cookies that collect technical data;
  • Analytical cookies for the purpose of improving the website and services;
  • Tracking cookies for recording personal preferences and marketing purposes;

The user should know that in order to visit the website, it is not necessary to allow the installation of cookies sent by the website. This may only be required in connection with certain services. The user can delete cookies from the hard drive of his/her computer, block access to his/her computer through his/her browser or choose the corresponding option when asked about the possibility of using cookies for these purposes and in accordance with the Cookie Policy. More information on the use of cookies can be found in the cookie statement.

8. Viewing, modifying or deleting data

You have the right to see, correct or delete your personal data that NFIR holds. In addition, you have the right to withdraw your possible consent to data processing or object to the processing of your personal data by NFIR and you have the right to data portability. Which means that you can request NFIR to send you the personal data that NFIR has available from you in a computer file to you or another organization named by you. The above rights do not apply if your personal data was collected and processed for the purpose of conducting digital forensic investigations. That data can only be removed if per a request of client of the digital forensics investigation to delete all examined data and the reports.

You may request access, correction, deletion or data reconciliation of your personal data or request to withdraw your consent or object to the processing of your personal data to [email protected]. To ensure that the request for inspection was made by you, NFIR will ask you to send a copy of your identification with the request. Make sure your personal photo, the MRZ (machine readable zone, the strip of numbers at the bottom of the passport), passport number and Citizen Service Number (BSN) are made black. This is to protect your privacy. NFIR will respond within twenty business days to your request. NFIR would also like to remind you that you have the opportunity to file a complaint to the national regulator, the Data Protection Authority. This can be done through the following link: https://autoriteitpersoonsgegevens.nl/nl/contact-met-de-autoriteit-personal data/tip-ons

9. How we secure personal data

NFIR takes the protection of your data seriously and takes appropriate technical and organizational measures to prevent misuse, loss, unauthorized access, unwanted disclosure and unauthorized modification. If you have the impression that your data is not secure or there are indications of misuse, please contact NFIR’s Data Protection Officer (FG) using the contact details below.

NFIR does not guarantee absolute privacy when using the website, as the possibility that unauthorized third parties may gain knowledge of it cannot be excluded. The user acknowledges that the existing technical means providing security are not impenetrable and that even when taking all reasonable security measures it is possible to suffer manipulation, destruction and/or loss of information. If a security incident is detected that poses a significant risk to the data owner, this event will be immediately reported to the appropriate supervisory authority, along with the corrective and palliative measures taken and/or to be taken.

NFIR is not responsible for the loss or deletion of data by users. Similarly, NFIR accepts no responsibility for any damage caused by computer viruses.

Finally, users must also take measures to protect their information. NFIR stresses that you take every precaution to protect your personal information while using the internet. As a minimum, you are advised to regularly change your password, using a combination of letters and numbers, and make sure you are using a secure browser.

10. Contact details

For questions regarding the processing of your personal data, please contact NFIR’s FG. Contact information is:

Address:

Laan van Zuid Hoorn 165
2289 DD Rijswijk
Netherlands

Phone number: +31 (0) 88 – 323 02 05
Email address: [email protected]

SECURITY INCIDENT AT YOUR ORGANIZATION?

The next 30 minutes are crucial!

The first 30 minutes after a cyber security incident are crucial because a quick and adequate response can limit the damage. In addition, further spread of the attack can be prevented and essential evidence can be secured for further investigation.

Our Computer Emergency Response Team (CERT) is available 24/7 to support businesses and organizations during IT security incidents.

SECURITY INCIDENT AT YOUR ORGANIZATION?

The next 30 minutes are crucial!

The first 30 minutes after a cyber security incident are crucial because a quick and adequate response can limit the damage. In addition, further spread of the attack can be prevented and essential evidence can be secured for further investigation.

Our Computer Emergency Response Team (CERT) is available 24/7 to support businesses and organizations during IT security incidents.

Op basis van meer dan 600 succesvol uitgevoerde pentesten.

Top 10 meest voorkomende cyber kwetsbaarheden bij Nederlandse Gemeenten

Download gratis whitepaper
De besproken kwetsbaarheden worden wereldwijd misbruikt, zo ook bij de Nederlandse gemeenten. Het doel van deze paper is gemeenten inzicht te geven in huidige dreigingen en hen te helpen bij het verbeteren van  beveiligingsmaatregelen. NFIR streeft naar transparantie om de weerbaarheid van gemeenten te verhogen en cyberaanvallen proactief tegen te gaan.

* geen registratie nodig, direct downloaden

Voer hier de inhoud in. Lorem ipsum dolor sit amet, consectetur adipiscing elit. Ut elit tellus, luctus nec ullamcorper mattis, pulvinar dapibus leo. Lorem ipsum dolor sit amet, consectetur adipiscing elit. Ut elit tellus, luctus nec ullamcorper mattis, pulvinar dapibus leo.

Pen tests

Penetration test?

Pen tests

Penetration test?

Pen tests

Penetration test?

Wat is MDR?

Managed Detection and Response (MDR) is een gespecialiseerde cybersecuritydienst die organisaties proactief beschermt tegen cyberdreigingen door een combinatie van geavanceerde technologie en menselijke expertise. Deze dienst biedt 24/7 monitoring, diepgaande analyse en proactieve dreigingsopsporing, met als doel het snel detecteren, onderzoeken en actief reageren op incidenten om de impact te minimaliseren en datalekken of ransomware-aanvallen te voorkomen, vanuit de aanname dat inbreuken onvermijdelijk zijn.

Wat is Security Monitoring

Security Monitoring is een essentieel onderdeel van Managed Detection and Response (MDR) en omvat de continue, 24/7 bewaking van de IT-omgeving van een organisatie, inclusief netwerken, systemen, applicaties, endpoints en cloudomgevingen. Het maakt gebruik van geavanceerde technologieën zoals AI en machine learning om loggegevens te filteren en te analyseren, verdachte activiteiten te detecteren en afwijkingen te identificeren.

Deze geautomatiseerde detecties worden vervolgens gevalideerd en geprioriteerd door menselijke beveiligingsspecialisten, die context en expertise toevoegen om vals-positieven te verminderen en echte dreigingen te onderscheiden. Het doel is om real-time inzicht te bieden in de beveiligingsstatus, kwetsbaarheden te identificeren en een snelle respons op incidenten mogelijk te maken, wat cruciaal is voor naleving van regelgeving zoals NIS2 en DORA.

Pentesten

Penetratietest laten uitvoeren?

 

Pentesten

Penetratietest laten uitvoeren?

 

Pen tests

Penetration test?

Pen tests

Penetration test?

Pen tests

Penetration test?

Pentesten

Penetratietest laten uitvoeren?

 

What is MDR?

Managed Detection and Response (MDR) is a specialized cybersecurity service that proactively protects organizations from cyber threats through a combination of advanced technology and human expertise. This service provides 24/7 monitoring, in-depth analysis and proactive threat detection, with the goal of quickly detecting, investigating and actively responding to incidents to minimize impact and prevent data breaches or ransomware attacks, based on the assumption that breaches are inevitable.

What is Security Monitoring

Security Monitoring is an essential component of Managed Detection and Response (MDR) and involves the continuous, 24/7 monitoring of an organization's IT environment, including networks, systems, applications, endpoints and cloud environments. It uses advanced technologies such as AI and machine learning to filter and analyze log data, detect suspicious activity and identify anomalies.

These automated detections are then validated and prioritized by human security specialists, who add context and expertise to reduce false positives and distinguish true threats. The goal is to provide real-time visibility into security status, identify vulnerabilities and enable rapid incident response, which is critical for regulatory compliance such as NIS2 and DORA.

Secure/evidence seizure - Secure phones, laptops & devices

NFIR offers support in the execution of digital evidence seizures. Depending on the situation, we can assist you directly with this based on our license as a Private Investigation Agency, granted by the Ministry of Justice and Security, or in cooperation with a bailiff.

We ensure that a snapshot is taken of relevant assets so that they can be examined at a later date if necessary. A non-exhaustive list of devices where we provide support includes:

  • Phones
  • Laptops
  • Tablets
  • NAS systems
  • Cameras
  • Cloud storage (Google Drive, Dropbox, Microsoft 365, OneDrive, SharePoint, etc.)
  • And many more, as long as it contains a 0 or a 1

In addition to securing and preserving potential evidence, NFIR also provides support in analyzing it. We can investigate both technical and tactical issues.

Examples:

  • Technical issue: "Was the device hacked at the time of the situation?"
  • Tactical issue: "Is there evidence to suggest possible forgery of these documents?"

Are you in need of these or any of our other services? If so, please contact us here. We will make sure you get a concrete answer to your questions as soon as possible.

What is surety or evidence seizure?

Evidence seizures and sureties are legal measures used to secure evidence or property in legal proceedings.

Evidence seizure is a procedure in which a party, often with court approval, seizes documents, digital data or other evidence. This is done to prevent such information from being lost, destroyed or otherwise inaccessible. Evidence seizures are often used in civil cases, such as intellectual property disputes or fraud investigations.

Securing has a broader application and can refer to securing goods, property or financial resources to protect rights or to fulfill a legal obligation. This can include criminal, civil or administrative law contexts. Consider seizing assets in bankruptcies or blocking bank accounts in cases of suspected money laundering.

Both measures aim to prevent important documents or resources from disappearing before a judge can rule on a case.

Pentest consultation

Pentesten

Penetratietest laten uitvoeren?

 

Pentesten

Penetratietest laten uitvoeren?

 

Pentesten

Penetratietest laten uitvoeren?

 

Pentesten

Penetratietest laten uitvoeren?

 

Pen tests

Penetration test?

Voer hier de inhoud in. Lorem ipsum dolor sit amet, consectetur adipiscing elit. Ut elit tellus, luctus nec ullamcorper mattis, pulvinar dapibus leo. Lorem ipsum dolor sit amet, consectetur adipiscing elit. Ut elit tellus, luctus nec ullamcorper mattis, pulvinar dapibus leo.

Voer hier de inhoud in. Lorem ipsum dolor sit amet, consectetur adipiscing elit. Ut elit tellus, luctus nec ullamcorper mattis, pulvinar dapibus leo. Lorem ipsum dolor sit amet, consectetur adipiscing elit. Ut elit tellus, luctus nec ullamcorper mattis, pulvinar dapibus leo.

Has my company been hacked (Compromise assessment)?

A complete check-up of your digital environment!

The crown jewels of many companies today are digital. That no third parties are secretly accessing that important database? Or have been watching that one server for ages? NFIR helps with a compromise assessment!

During a compromise assessment, NFIR's experts take a close look at all or part of your network, depending on your requirements. We will thoroughly investigate whether there is or has been intrusion by unauthorized parties on your systems. We do this using Threat Intelligence reports and already known Indicators of Compromise; indicators that indicate that something may be amiss.

This is different from a pen test, which can be used preventively to look for security vulnerabilities. In a compromise assessment, NFIR looks for actual misuse of these potential leaks.

If you have doubts about the integrity of your network, perhaps because of a previous incident or hard to pinpoint alerts from your monitoring systems, NFIR is here for you!

Pentest consult

zekerstellen/bewijsbeslag - Veiligstellen telefoons, laptops & apparaten

NFIR biedt ondersteuning bij het uitvoeren van digitaal bewijsbeslag. Afhankelijk van de situatie kunnen wij u hier direct bij assisteren op basis van onze vergunning als Particulier Onderzoeksbureau, verleend door het Ministerie van Justitie en Veiligheid, of in samenwerking met een deurwaarder.

Wij zorgen ervoor dat een momentopname wordt gemaakt van relevante goederen, zodat deze indien nodig op een later moment onderzocht kunnen worden. Een niet-uitputtende lijst van apparaten waarbij wij ondersteuning bieden, omvat:

  • Telefoons
  • Laptops
  • Tablets
  • NAS-systemen
  • Camera’s
  • Cloudopslag (Google Drive, Dropbox, Microsoft 365, OneDrive, SharePoint, etc.)
  • En nog veel meer, zolang het maar een 0 of een 1 bevat

Naast het veiligstellen en bewaren van mogelijk bewijsmateriaal, biedt NFIR ook ondersteuning bij het analyseren ervan. Wij kunnen zowel technische als tactische vraagstukken onderzoeken.

Voorbeelden:

  • Technisch vraagstuk: “Was het apparaat gehackt ten tijde van de situatie?”
  • Tactisch vraagstuk: “Is er bewijs dat wijst op mogelijke vervalsing van deze documenten?”

Heeft u behoefte aan deze of een van onze andere diensten? Neem dan hier contact met ons op. Wij zorgen ervoor dat u zo snel mogelijk een concreet antwoord krijgt op uw vragen.

Wat is zekerstellen of bewijsbeslag?

Bewijsbeslag en zekerstellen zijn juridische maatregelen die worden gebruikt om bewijs of eigendommen veilig te stellen in juridische procedures.

Bewijsbeslag is een procedure waarbij een partij, vaak met toestemming van de rechter, beslag legt op documenten, digitale gegevens of andere bewijsmiddelen. Dit wordt gedaan om te voorkomen dat deze informatie verloren gaat, vernietigd wordt of anderszins onbereikbaar wordt. Bewijsbeslag wordt vaak ingezet in civiele zaken, bijvoorbeeld bij geschillen over intellectueel eigendom of fraudeonderzoeken.

Zekerstellen heeft een bredere toepassing en kan slaan op het veiligstellen van goederen, eigendommen of financiële middelen ter bescherming van rechten of ter uitvoering van een juridische verplichting. Dit kan onder andere gebeuren in strafrechtelijke, civielrechtelijke of bestuursrechtelijke contexten. Denk aan het in beslag nemen van activa bij faillissementen of het blokkeren van bankrekeningen bij vermoedens van witwassen.

Beide maatregelen hebben als doel te voorkomen dat belangrijke stukken of middelen verdwijnen voordat een rechter zich over een zaak kan uitspreken.

Is mijn bedrijf gehackt? (Compromise assessment)

Een volledige check-up van uw digitale omgeving!

De kroonjuwelen van veel bedrijven zijn tegenwoordig digitaal. Dat er geen derde partijen stiekem toegang hebben tot die belangrijke database? Of al tijden mee zitten te kijken op die ene server? NFIR helpt met een compromise assessment!

Tijdens een compromise assessment nemen de experts van NFIR uw netwerk geheel of gedeeltelijk, afhankelijk van uw wens, onder de loep nemen. We gaan goed onderzoeken of er op uw systemen sprake is of is geweest van intrusie door ongeautoriseerde partijen. Dit doen wij aan de hand van Threat Intelligence rapporten en reeds bekende Indicators of Compromise; indicatoren die erop wijzen dat er mogelijk iets niet in de haak is.

Dit is anders dan een pentest, welke preventief kan worden ingezet om te zoeken naar beveiligingslekken. Bij een compromise assessment gaat NFIR op zoek naar daadwerkelijk misbruik van deze mogelijke lekken.

Als u twijfelt aan de integriteit van uw netwerk, misschien vanwege een eerder incident of vanwege moeilijk te duiden waarschuwingen van uw monitoring systemen, staat NFIR voor u klaar!

SECURITY INCIDENT AT YOUR ORGANIZATION?

The next 30 minutes are crucial!

The first 30 minutes after a cyber security incident are crucial because a quick and adequate response can limit the damage. In addition, further spread of the attack can be prevented and essential evidence can be secured for further investigation.

Our Computer Emergency Response Team (CERT) is available 24/7 to support businesses and organizations during IT security incidents.