Audit readiness
Third-party audit readiness pack
Last updated: 24 July 2026
This pack answers the questions a client's security, IT or procurement team usually asks before signing. It is a plain-language snapshot of how Collaby BV (trading as From Cold To Warm) hosts data, controls access, handles incidents and meets its GDPR obligations. For anything not covered here, email hello@fromcoldtowarm.com.
Honest scope. We are a small, focused company. We are not (yet) ISO 27001 or SOC 2 certified, and we say so rather than imply otherwise. What follows is what we actually do. We are happy to complete a reasonable security questionnaire and to sign our DPA.
1. Company and contact
| Legal entity | Collaby BV (BE 0744.962.770) |
|---|---|
| Location | Steenbergstraat 25, 3078 Kortenberg, Belgium |
| Security contact | Dylan Mendes — hello@fromcoldtowarm.com |
| Role in most engagements | Data processor acting on the client's documented instructions |
2. Where data lives (residency)
The core application, database and automation run on dedicated infrastructure hosted by Hetzner Online GmbH within the European Union (Germany/Finland). The primary database is self-hosted on that infrastructure rather than on a shared third-party SaaS database, which keeps client data within a controlled, EU-based environment. Some specialised functions (advertising delivery, AI processing, scheduling) rely on the sub-processors listed in section 6.
3. Technical and organisational security measures
- All traffic encrypted in transit over TLS/HTTPS (managed by a Caddy reverse proxy).
- Data hosted on EU infrastructure (Hetzner, Germany/Finland); the primary database is self-hosted rather than on a shared third-party platform.
- Host firewall (ufw) restricting inbound traffic to ports 22, 80 and 443 only.
- Brute-force protection (fail2ban) and automatic security updates (unattended-upgrades).
- SSH key-based administrative access only; no password login.
- Least-privilege access: production access is limited to the controller.
- Daily encrypted server backups.
- Documented incident-response and breach-notification process (notification of affected clients without undue delay, and of the supervisory authority within 72 hours where required).
4. Access control
Administrative access is limited to the controller and uses SSH key-based authentication (no password login). Production access follows the principle of least privilege. Access to a client's advertising accounts, CRM and communication tools is granted by the client, used only to deliver the service, and revoked at the end of the engagement.
5. Data handling and minimisation
- We process business contact and account data, not special-category data.
- Target lists are focused and tiered, which limits the volume of data processed.
- Data is kept accurate and current, and deleted or returned at the end of an engagement (see the DPA).
- Our legal basis for account-based marketing is documented in our legitimate interest assessment.
6. Sub-processors
The service relies on the following sub-processors, each under a data protection agreement:
| Sub-processor | Purpose | Location |
|---|---|---|
| Hetzner Online GmbH | Cloud hosting, application server and database (self-hosted Supabase, n8n, CRM) | Germany / Finland (EU) |
| Cloudflare, Inc. | DNS, CDN, TLS and inbound email routing | USA (SCCs / EU-US DPF) |
| PostHog Inc. (EU Cloud) | Website product analytics (consent-gated) | EU (Frankfurt) |
| LinkedIn Ireland Unlimited Company | Advertising delivery and matched audiences | Ireland (EU) / USA (SCCs) |
| Meta Platforms Ireland Ltd. | Advertising delivery and custom audiences | Ireland (EU) / USA (SCCs) |
| Google Ireland Ltd. | Advertising delivery and measurement | Ireland (EU) / USA (SCCs / EU-US DPF) |
| Anthropic PBC | AI processing for message contextualisation | USA (SCCs) |
| Calendly LLC | Meeting scheduling | USA (SCCs / EU-US DPF) |
| Data enrichment providers | Business contact and firmographic enrichment (list to be finalised per engagement) | EU / USA (SCCs) |
Non-EU transfers rely on adequacy decisions, EU Standard Contractual Clauses, and/or the EU-US Data Privacy Framework.
7. Incident response and business continuity
We take daily encrypted backups of the server. In the event of a personal data breach affecting a client, we notify the client without undue delay and provide the information needed for the client to meet its GDPR notification obligations (within 72 hours of awareness where required). Automatic security updates and brute-force protection are in place to reduce the likelihood of incidents.
8. Compliance documents
Privacy policy
What we process, why, and your rights.
Data processing agreement
Article 28 GDPR terms, signable per engagement.
Legitimate interest assessment
Our documented balancing test for ABM.
Terms and conditions
The framework governing our services.
9. What we ask of clients
Security is shared. Clients are responsible for the lawful basis of the data they provide, for meeting transparency obligations towards their own contacts, for keeping the access they grant us scoped appropriately, and for the commercial follow-up of the signals we deliver.
