Our Privacy Policy.

Privacy Statement

Last updated: 13 mar 2026

Reassurance Technologies, formerly known as GRASP Innovations (“GRASP”, “we”, “us”, or “our”) is committed to protecting the privacy and personal data of individuals who interact with us through our website, products, and services. This Privacy Statement explains how we collect, use, disclose, and protect personal data, and how individuals can exercise their rights under applicable data protection laws, including the EU General Data Protection Regulation (GDPR), the applicable U.S. state privacy laws (including the California Consumer Privacy Act as amended by the California Privacy Rights Act (CCPA/CPRA), and, where applicable, the U.S. Health Insurance Portability and Accountability Act (HIPAA).

This Privacy Statement is intended for external audiences, including website visitors, customers, partners, and other third parties. It does not replace or override contractual arrangements (such as Data Processing Agreements, service agreements, or HIPAA-related agreements).

1. Who We Are

Entity: Reassurance Technologies (formerly known as GRASP Innovations)
Website: https://www.reassurancetech.com/
Contact: constantijn@reassurancetech.com

2. Scope of This Privacy Statement

This Privacy Statement applies to personal data collected through:

  • Our website and online communications;

  • Business-to-business communications with customers, prospects, and partners;

  • Events, demonstrations, and inquiries;

  • Use of our products and services where GRASP determines the purposes and means of processing and therefore acts as a data controller.

Where GRASP processes personal data on behalf of customers (for example, as a processor under GDPR or as a Business Associate or Business Associate Subcontractor under HIPAA), the applicable customer or partner privacy notice applies, and GRASP processes such data solely in accordance with contractual instructions.

3. Categories of Personal Data We Collect

Depending on the context, we may collect the following categories of personal data:

  • Identification and contact data: name, business email address, phone number, job title, company name;

  • Communication data: content of emails, contact forms, or other correspondence;

  • Technical and usage data: IP address, browser type, device information, and website usage data;

  • Business relationship data: contractual information, billing details, and service-related communications.

GRASP does not intentionally collect personal data of children or minors through its website or marketing activities.

Sources of Personal Data

We collect personal data from the following categories of sources:

  • Directly from you, for example when you contact us, complete a contact form, request a demonstration, or communicate with us;

  • Automatically through your use of our website, including through cookies and similar technologies;

  • From business partners or service providers, where relevant to managing a business relationship;

  • From publicly available sources, such as professional networking platforms or company websites.

Sensitive Personal Information

Under the California Privacy Rights Act (CPRA), “Sensitive Personal Information” may include information such as precise geolocation, financial account details, government identifiers, health information, or similar sensitive data categories.

GRASP does not collect or process Sensitive Personal Information through its website or for marketing or general business contact purposes.

Accordingly:

  • GRASP does not use or disclose Sensitive Personal Information for purposes beyond those permitted by applicable law;

  • The right to limit the use of Sensitive Personal Information does not apply to our website activities.

If this changes, this Privacy Statement will be updated accordingly.

4. Purposes of Processing

We process personal data for the following purposes:

  • To respond to inquiries and communicate with you;

  • To manage business relationships with customers and partners;

  • To operate, maintain, and secure our website;

  • To provide, improve, and support our products and services;

  • To comply with legal, regulatory, and contractual obligations.


5. Legal Bases for Processing (GDPR)

Where GDPR applies, we process personal data based on one or more of the following legal bases:

  • Performance of a contract or steps taken at your request prior to entering into a contract;

  • Legitimate interests, such as managing business relationships and improving our services;

  • Compliance with legal obligations;

  • Consent, where required (for example, certain cookies or marketing communications).

Where processing is based on consent, you may withdraw your consent at any time.


6. Cookies and Similar Technologies

Our website may use cookies and similar technologies to ensure functionality, analyze usage, and improve user experience.

Where required by law, we obtain consent before placing non-essential cookies. Additional information is provided in our Cookie Statement.


7. Data Sharing and Disclosure

We may share personal data with:

  • Internal personnel on a need-to-know basis;

  • Trusted service providers and vendors supporting our operations (such as service providers, contractors, professional advisors, government authorities and business partners) , subject to appropriate contractual safeguards;

  • Professional advisors (such as legal or accounting advisors);

  • Public authorities, where required by law.

GRASP does not sell personal data.

8. International Data Transfers

Personal data may be transferred to and processed in countries outside your country of residence.

Where required (for example, transfers outside the EEA), GRASP implements appropriate safeguards such as Standard Contractual Clauses or equivalent lawful transfer mechanisms.


9. Data Retention

We retain personal data only for as long as necessary to fulfill the purposes described in this Privacy Statement or as required by law.

Retention periods may vary depending on the nature of the data and applicable legal obligations.


10. Your Rights

a. Rights under GDPR

Where GDPR applies, you may have the right to:

  • Access your personal data;

  • Rectify inaccurate data;

  • Request erasure or restriction of processing (subject to legal limitations);

  • Object to processing;

  • Request data portability;

  • Lodge a complaint with a supervisory authority.

b. Rights under U.S. State Laws

Depending on your U.S. state of residence, including California, you may have rights regarding personal data collected in a business context, including:

  • The right to know what personal information  we collect, use, and disclose and know the categories of third parties to whom personal information is disclosed;

  • The right to request deletion of personal information , subject to statutory exemptions;

  • The right to opt out of the sale or sharing of personal data (note: GRASP does not sell personal data);

  • The right not to be discriminated against for exercising your rights; 

  • The right to correct personal information.

Where required under applicable US state law, individuals may appeal a decision regarding your privacy request by contacting us using the details provided below. 

c. HIPAA

Where GRASP processes Protected Health Information (PHI) on behalf of a Covered Entity, including where GRASP acts as a Business Associate or Business Associate Subcontractor, individual rights relating to PHI are governed by HIPAA and are exercised through the applicable Covered Entity or primary Business Associate, not directly through GRASP.

11. Data Security

We implement appropriate technical and organizational measures to protect personal data against unauthorized access, loss, or misuse, taking into account the nature of the data and the risks involved.

12. Changes to This Privacy Statement

We may update this Privacy Statement from time to time. The most current version will always be available on our website. Material changes will be communicated where required by law.

13. Contact Us

If you have questions about this Privacy Statement or wish to exercise your rights, please contact:

Email: constantijn@reassurancetech.com

Data Protection Authority

If you have complaints about the way we handle or process your personal data we would gladly like to help with finding a convenient solution. If, however, our help does not lead to a acceptable solution, you are entitled to file a complaint with the Dutch Data Protection Authority. You can contact the Dutch Data Protection Authority by visiting the website https://www.autoriteitpersoonsgegevens.nl/

Consent

By using our website, you hereby consent to our Privacy Policy and agree to its terms.