Our Privacy Policy.
Privacy Statement
Last updated: 13 mar 2026
Reassurance Technologies, formerly known as GRASP Innovations (“GRASP”, “we”, “us”, or “our”) is committed to protecting the privacy and personal data of individuals who interact with us through our website, products, and services. This Privacy Statement explains how we collect, use, disclose, and protect personal data, and how individuals can exercise their rights under applicable data protection laws, including the EU General Data Protection Regulation (GDPR), the applicable U.S. state privacy laws (including the California Consumer Privacy Act as amended by the California Privacy Rights Act (CCPA/CPRA), and, where applicable, the U.S. Health Insurance Portability and Accountability Act (HIPAA).
This Privacy Statement is intended for external audiences, including website visitors, customers, partners, and other third parties. It does not replace or override contractual arrangements (such as Data Processing Agreements, service agreements, or HIPAA-related agreements).
1. Who We Are
Entity: Reassurance Technologies (formerly known as GRASP Innovations)
Website: https://www.reassurancetech.com/
Contact: constantijn@reassurancetech.com
2. Scope of This Privacy Statement
This Privacy Statement applies to personal data collected through:
Our website and online communications;
Business-to-business communications with customers, prospects, and partners;
Events, demonstrations, and inquiries;
Use of our products and services where GRASP determines the purposes and means of processing and therefore acts as a data controller.
Where GRASP processes personal data on behalf of customers (for example, as a processor under GDPR or as a Business Associate or Business Associate Subcontractor under HIPAA), the applicable customer or partner privacy notice applies, and GRASP processes such data solely in accordance with contractual instructions.
3. Categories of Personal Data We Collect
Depending on the context, we may collect the following categories of personal data:
Identification and contact data: name, business email address, phone number, job title, company name;
Communication data: content of emails, contact forms, or other correspondence;
Technical and usage data: IP address, browser type, device information, and website usage data;
Business relationship data: contractual information, billing details, and service-related communications.
GRASP does not intentionally collect personal data of children or minors through its website or marketing activities.
Sources of Personal Data
We collect personal data from the following categories of sources:
Directly from you, for example when you contact us, complete a contact form, request a demonstration, or communicate with us;
Automatically through your use of our website, including through cookies and similar technologies;
From business partners or service providers, where relevant to managing a business relationship;
From publicly available sources, such as professional networking platforms or company websites.
Sensitive Personal Information
Under the California Privacy Rights Act (CPRA), “Sensitive Personal Information” may include information such as precise geolocation, financial account details, government identifiers, health information, or similar sensitive data categories.
GRASP does not collect or process Sensitive Personal Information through its website or for marketing or general business contact purposes.
Accordingly:
GRASP does not use or disclose Sensitive Personal Information for purposes beyond those permitted by applicable law;
The right to limit the use of Sensitive Personal Information does not apply to our website activities.
If this changes, this Privacy Statement will be updated accordingly.
4. Purposes of Processing
We process personal data for the following purposes:
To respond to inquiries and communicate with you;
To manage business relationships with customers and partners;
To operate, maintain, and secure our website;
To provide, improve, and support our products and services;
To comply with legal, regulatory, and contractual obligations.
5. Legal Bases for Processing (GDPR)
Where GDPR applies, we process personal data based on one or more of the following legal bases:
Performance of a contract or steps taken at your request prior to entering into a contract;
Legitimate interests, such as managing business relationships and improving our services;
Compliance with legal obligations;
Consent, where required (for example, certain cookies or marketing communications).
Where processing is based on consent, you may withdraw your consent at any time.
6. Cookies and Similar Technologies
Our website may use cookies and similar technologies to ensure functionality, analyze usage, and improve user experience.
Where required by law, we obtain consent before placing non-essential cookies. Additional information is provided in our Cookie Statement.
7. Data Sharing and Disclosure
We may share personal data with:
Internal personnel on a need-to-know basis;
Trusted service providers and vendors supporting our operations (such as service providers, contractors, professional advisors, government authorities and business partners) , subject to appropriate contractual safeguards;
Professional advisors (such as legal or accounting advisors);
Public authorities, where required by law.
GRASP does not sell personal data.
8. International Data Transfers
Personal data may be transferred to and processed in countries outside your country of residence.
Where required (for example, transfers outside the EEA), GRASP implements appropriate safeguards such as Standard Contractual Clauses or equivalent lawful transfer mechanisms.
9. Data Retention
We retain personal data only for as long as necessary to fulfill the purposes described in this Privacy Statement or as required by law.
Retention periods may vary depending on the nature of the data and applicable legal obligations.
10. Your Rights
a. Rights under GDPR
Where GDPR applies, you may have the right to:
Access your personal data;
Rectify inaccurate data;
Request erasure or restriction of processing (subject to legal limitations);
Object to processing;
Request data portability;
Lodge a complaint with a supervisory authority.
b. Rights under U.S. State Laws
Depending on your U.S. state of residence, including California, you may have rights regarding personal data collected in a business context, including:
The right to know what personal information we collect, use, and disclose and know the categories of third parties to whom personal information is disclosed;
The right to request deletion of personal information , subject to statutory exemptions;
The right to opt out of the sale or sharing of personal data (note: GRASP does not sell personal data);
The right not to be discriminated against for exercising your rights;
The right to correct personal information.
Where required under applicable US state law, individuals may appeal a decision regarding your privacy request by contacting us using the details provided below.
c. HIPAA
Where GRASP processes Protected Health Information (PHI) on behalf of a Covered Entity, including where GRASP acts as a Business Associate or Business Associate Subcontractor, individual rights relating to PHI are governed by HIPAA and are exercised through the applicable Covered Entity or primary Business Associate, not directly through GRASP.
11. Data Security
We implement appropriate technical and organizational measures to protect personal data against unauthorized access, loss, or misuse, taking into account the nature of the data and the risks involved.
12. Changes to This Privacy Statement
We may update this Privacy Statement from time to time. The most current version will always be available on our website. Material changes will be communicated where required by law.
13. Contact Us
If you have questions about this Privacy Statement or wish to exercise your rights, please contact:
Email: constantijn@reassurancetech.com
Data Protection Authority
If you have complaints about the way we handle or process your personal data we would gladly like to help with finding a convenient solution. If, however, our help does not lead to a acceptable solution, you are entitled to file a complaint with the Dutch Data Protection Authority. You can contact the Dutch Data Protection Authority by visiting the website https://www.autoriteitpersoonsgegevens.nl/
Consent
By using our website, you hereby consent to our Privacy Policy and agree to its terms.