Skip to content
Security

Security

Last updated: June 2026

This website is a marketing site, not an application. There are no accounts and we do not process customer data. Below you can read where the site runs, how we secure it, and which processors we use.

Hosting and data location

This website runs on Vercel, a professional cloud hosting platform with edge locations within the EU. Vercel is the hosting and infrastructure partner for servicemanagementpartner.nl. Static pages are served from Vercel's edge network; server-side rendered pages run in the nearest available EU region.

We do not store any application or customer data on this website. There are no user accounts and no logged-in environment. The only data we actively process is what you submit yourself through the contact form.

Our role under the GDPR in advisory work

Service Management Partner is a consultancy that helps organizations improve service management. In that capacity we typically work inside the customer's own environments: their ticketing system, their IT tooling, their documentation. We store as little customer data as possible on our own infrastructure.

The customer remains the data controller for the data in their own systems. When we temporarily access customer data to carry out our advisory work, we act as a processor and document that in a data processing agreement where the situation requires it. Confidentiality is included as standard in our agreements, which we enter into under the NLdigital Voorwaarden 2025.

Access to customer environments

We always work with accounts the customer creates and manages. We ask only for the rights we need for the specific task, the principle of least privilege. We do not use shared passwords and do not store customer credentials in our own systems. After an engagement or assignment ends, we ask the customer to revoke access.

Confidentiality

Confidentiality is arranged as standard in our service agreement. We operate under the NLdigital Voorwaarden 2025, which includes obligations around confidentiality, data processing and liability. The terms are available on request via info@servicechanger.com.

What data we process through this website

We process only what you submit yourself through the contact form:

  • your name
  • your email address
  • your organization
  • the content of your message

We use that data solely to reply to your message. A submission is delivered by email to info@servicechanger.com. We do not sell this data and do not share it for advertising purposes. You can read more in our privacy statement.

Retention periods

We retain contact form messages no longer than necessary to handle your question or assignment. If no engagement or follow-up results, we delete the message within a reasonable period. Business correspondence is retained for as long as legal obligations require, generally seven years for tax purposes.

Transport and headers

The site is reachable over HTTPS only. We set a number of security headers, including:

  • HTTP Strict Transport Security (HSTS)
  • a strict Content-Security-Policy
  • X-Frame-Options: DENY
  • X-Content-Type-Options: nosniff
  • Referrer-Policy
  • Permissions-Policy

Sub-processors

We work with a small number of processors that are needed to run the website and to deliver contact-form messages.

NameRoleLocation
Vercel Inc.Website hosting and edge networkEU edge where available
Email and SMTP providerDelivery of contact form messagesEU

We share the full, current list of processors on request via info@servicechanger.com.

What happens when there is an incident

If we discover a security incident that affects personal data, we take the following steps:

  1. We inform involved parties as quickly as possible.
  2. We take measures to limit further damage.
  3. We report to the Dutch Data Protection Authority (Autoriteit Persoonsgegevens) if the GDPR requires it (within 72 hours of discovery).
  4. We document the incident and the measures taken.

Responsible disclosure

Found a vulnerability? Let us know before you act on it, so we can fix it. Contact details and the rules are in our security.txt. You can also email us directly at info@servicechanger.com.

We ask you not to publish publicly or misuse the vulnerability before we have had the chance to investigate and resolve it. Responsible disclosure carried out in good faith will not result in legal action from our side.

GDPR

ServiceChanger B.V. (KvK 97221309) is the data controller for the data you provide through this website. The competent supervisory authority is the Dutch Data Protection Authority (Autoriteit Persoonsgegevens). If you have a complaint about how we handle your data, you can take it there.

Frequently asked questions about security

Does Service Management Partner store customer data?
No. As a consultancy, Service Management Partner typically works inside the customer's own systems. We store as little customer data as possible on our own infrastructure. The only data we actively process is what comes in through the contact form.
How is access to customer environments arranged?
We always work with accounts the customer creates and manages, based on least privilege. We do not use shared passwords. After an engagement ends, we ask the customer to revoke access.
What happens if there is a security incident?
We inform involved parties as quickly as possible, take measures to limit further damage, and report to the Dutch Data Protection Authority (Autoriteit Persoonsgegevens) if the GDPR requires it.
How do I report a vulnerability?
Via our security.txt at /.well-known/security.txt or directly by email to info@servicechanger.com. We ask you not to publish publicly before we have had the chance to investigate.