We sell files online and we deliver them online, so security is not a feature we bolt on. This notice sets out our regulatory position, the measures in place, what happens if something goes wrong, and how to reach us if you find a hole.
Where we stand under the Cyberbeveiligingswet
The Cyberbeveiligingswet, or Cbw, is the Dutch implementation of the European NIS2 Directive. It places duties of care and duties to report on organisations that are designated as essential or important entities in the sectors the law lists.
We have not been designated as an essential or important entity by any Dutch ministry or supervisory authority, and no sectoral supervisor has been assigned to us. We are a small company outside the listed sectors, so the Cbw's mandatory regime does not currently apply to us.
We nevertheless registered voluntarily with the Nationaal Cyber Security Centrum, the national CSIRT, in July 2026 under KvK 95458859. The registration covers the company, and so every name it trades under, Digital Gemology included. Voluntary registration means we receive the NCSC's threat intelligence and advisories, and that the NCSC has a route to reach us directly if something that affects us is discovered. Our registration confirmation is on file and we will show it to a counterparty who asks.
We hold ourselves to the Cbw duty-of-care measures in proportion to our size, and we would follow its reporting rhythm in an incident, even though we are not obliged to. We would rather build to the standard now than discover we need it later.
How the site is built
Payments
Card details go straight to our payment provider, Stripe, which is certified to PCI DSS Level 1. We never see, transmit or store a card number.
Transport and headers
Every page and every download is served over TLS 1.2 or 1.3, with older and weaker protocols refused, and HSTS tells browsers never to try an insecure connection. Responses carry a Content Security Policy plus frame, referrer, permissions and content-type protections.
Edge
The site sits behind Cloudflare's network, which gives us DDoS protection, a web application firewall, and automated bot and threat filtering.
Files you download
The files we sell are geometry and data: STEP, STL, OBJ, GLB, FBX and 3DM models, GemCad cutting files, CSV tables and diagrams. They contain no macros, scripts or executable code, and we never ship an installer. If a file from us ever asks you to run something, it is not from us: tell us.
Supply chain
The site is plain HTML, CSS and vanilla JavaScript with no build step shipped to your browser, no bundler and no package tree. That is unusual, and it is deliberate: a dependency you never installed cannot be compromised. The typeface is served from our own domain rather than a third-party font service.
Risk management
- Our master geometry is kept apart from the public site, and the site only ever holds copies.
- The master files and the site are backed up automatically, away from the systems that serve the site.
- Changes to payments or to the handling of personal data are reviewed before they ship.
- Access to production systems is limited to the people who need it, with multi-factor authentication on the accounts that hold it.
- Third-party processors are tracked in a register, with the data protection agreements that go with them.
If something goes wrong
A personal data breach is assessed as soon as we become aware of it. Where the law requires it we notify the Dutch Data Protection Authority, the Autoriteit Persoonsgegevens, within 72 hours under Article 33 of the GDPR, and we tell the people affected without undue delay where Article 34 applies. We keep a breach register, and it exists whether or not there has ever been a breach to put in it.
A significant cyber incident would be handled on the Cbw rhythm: an early warning within 24 hours, a fuller notification within 72 hours, and a final report once we understand what happened. We would tell affected customers directly rather than leaving them to read about it.
Reporting a vulnerability
We welcome coordinated disclosure and we will not take legal action against anyone acting in good faith. Write to [email protected], or see our security.txt.
What we ask of you:
- Report privately and give us reasonable time to fix the issue before disclosing publicly.
- Do not access, change or delete data belonging to anyone else, and stop as soon as you have confirmed the issue exists.
- Do not download paid files you have not bought in order to prove a point. Showing us that you could is enough.
- No denial of service, no spam, no social engineering of our staff or suppliers, and no physical attacks.
What you get from us: an acknowledgement of every report, an honest answer about whether we consider it a vulnerability, and credit where you want it. We do not run a paid bug bounty at present, so please report because you want the hole closed rather than for a fee.
What we ask of our customers
- We will never ask for your password, and we will never ask for card details by email or message. Anyone who does is not us.
- If you receive something that claims to be from Digital Gemology and looks wrong, forward it to [email protected] rather than clicking it.
The plain-language version of much of this is in the security and privacy FAQ. How we handle personal data specifically is in the privacy policy.