From Cold To Warm
Win big accounts How it works FAQ Get in touch
Book a call

Audit readiness

Third-party audit readiness pack

Last updated: 24 July 2026

This pack answers the questions a client's security, IT or procurement team usually asks before signing. It is a plain-language snapshot of how Collaby BV (trading as From Cold To Warm) hosts data, controls access, handles incidents and meets its GDPR obligations. For anything not covered here, email hello@fromcoldtowarm.com.

Honest scope. We are a small, focused company. We are not (yet) ISO 27001 or SOC 2 certified, and we say so rather than imply otherwise. What follows is what we actually do. We are happy to complete a reasonable security questionnaire and to sign our DPA.

1. Company and contact

Legal entityCollaby BV (BE 0744.962.770)
LocationSteenbergstraat 25, 3078 Kortenberg, Belgium
Security contactDylan Mendes — hello@fromcoldtowarm.com
Role in most engagementsData processor acting on the client's documented instructions

2. Where data lives (residency)

The core application, database and automation run on dedicated infrastructure hosted by Hetzner Online GmbH within the European Union (Germany/Finland). The primary database is self-hosted on that infrastructure rather than on a shared third-party SaaS database, which keeps client data within a controlled, EU-based environment. Some specialised functions (advertising delivery, AI processing, scheduling) rely on the sub-processors listed in section 6.

3. Technical and organisational security measures

  • All traffic encrypted in transit over TLS/HTTPS (managed by a Caddy reverse proxy).
  • Data hosted on EU infrastructure (Hetzner, Germany/Finland); the primary database is self-hosted rather than on a shared third-party platform.
  • Host firewall (ufw) restricting inbound traffic to ports 22, 80 and 443 only.
  • Brute-force protection (fail2ban) and automatic security updates (unattended-upgrades).
  • SSH key-based administrative access only; no password login.
  • Least-privilege access: production access is limited to the controller.
  • Daily encrypted server backups.
  • Documented incident-response and breach-notification process (notification of affected clients without undue delay, and of the supervisory authority within 72 hours where required).

4. Access control

Administrative access is limited to the controller and uses SSH key-based authentication (no password login). Production access follows the principle of least privilege. Access to a client's advertising accounts, CRM and communication tools is granted by the client, used only to deliver the service, and revoked at the end of the engagement.

5. Data handling and minimisation

  • We process business contact and account data, not special-category data.
  • Target lists are focused and tiered, which limits the volume of data processed.
  • Data is kept accurate and current, and deleted or returned at the end of an engagement (see the DPA).
  • Our legal basis for account-based marketing is documented in our legitimate interest assessment.

6. Sub-processors

The service relies on the following sub-processors, each under a data protection agreement:

Sub-processorPurposeLocation
Hetzner Online GmbHCloud hosting, application server and database (self-hosted Supabase, n8n, CRM)Germany / Finland (EU)
Cloudflare, Inc.DNS, CDN, TLS and inbound email routingUSA (SCCs / EU-US DPF)
PostHog Inc. (EU Cloud)Website product analytics (consent-gated)EU (Frankfurt)
LinkedIn Ireland Unlimited CompanyAdvertising delivery and matched audiencesIreland (EU) / USA (SCCs)
Meta Platforms Ireland Ltd.Advertising delivery and custom audiencesIreland (EU) / USA (SCCs)
Google Ireland Ltd.Advertising delivery and measurementIreland (EU) / USA (SCCs / EU-US DPF)
Anthropic PBCAI processing for message contextualisationUSA (SCCs)
Calendly LLCMeeting schedulingUSA (SCCs / EU-US DPF)
Data enrichment providersBusiness contact and firmographic enrichment (list to be finalised per engagement)EU / USA (SCCs)

Non-EU transfers rely on adequacy decisions, EU Standard Contractual Clauses, and/or the EU-US Data Privacy Framework.

7. Incident response and business continuity

We take daily encrypted backups of the server. In the event of a personal data breach affecting a client, we notify the client without undue delay and provide the information needed for the client to meet its GDPR notification obligations (within 72 hours of awareness where required). Automatic security updates and brute-force protection are in place to reduce the likelihood of incidents.

8. Compliance documents

Privacy policy

What we process, why, and your rights.

Data processing agreement

Article 28 GDPR terms, signable per engagement.

Legitimate interest assessment

Our documented balancing test for ABM.

Terms and conditions

The framework governing our services.

9. What we ask of clients

Security is shared. Clients are responsible for the lawful basis of the data they provide, for meeting transparency obligations towards their own contacts, for keeping the access they grant us scoped appropriately, and for the commercial follow-up of the signals we deliver.

Back to legal documents

From Cold To Warm

An AI-native agency helping B2B companies land bigger clients by blending human creativity with programmatic ABM.

How it works Get in touch Legal
© 2026 From Cold To Warm