Privacy Policy

How we handle your data.

Last updated 11 August 2026 · Nederlandse versie

Who we are

Cockpit 360 is a service of Ilatt Beheer B.V., registered at Dr. Holtroplaan 19, 5652 XR Eindhoven, Netherlands, Chamber of Commerce number 17233721. We build personal business dashboards for entrepreneurs. For privacy questions, contact joel@ilatt.nl.

What we collect

If you only visit our website, we collect no personal data. We use no advertising or tracking cookies and no external analytics services.

If you use the contact form, your name, email address, company name and message are emailed to our own inbox. We do not store the form on the website and we use no external form service. We keep your message for as long as we are in conversation with you and delete it afterwards.

If you are a customer using a cockpit, we process data from the systems you connect yourself, such as your accounting software, calendar, mailbox, webshop or bank account. You choose which systems to connect and you can disconnect any of them at any time.

WHOOP data

If you connect your WHOOP account, we retrieve data through the official WHOOP API with your explicit consent. This covers recovery, sleep, strain and heart rate data.

You can revoke access at any time in your WHOOP account under connected apps. We then delete the WHOOP data stored on our systems within thirty days. If you want it removed sooner, email us and we will do it right away.

Health data is sensitive. We treat it more strictly than ordinary data: it is stored separately, it is never publicly accessible, and it does not leave our server.

Legal basis

For data from connected systems, including WHOOP, the legal basis is your explicit consent, given at the moment you create the connection. For customer data it is the performance of our contract. For your contact request it is our legitimate interest in replying to you.

Sharing

We share data with no one, unless the law requires it. We do not sell data. The cockpit runs on a server hosted by Hetzner Online GmbH in Nuremberg, Germany. Your data therefore stays within the European Union.

Retention

We keep your data for as long as you are a customer. After you leave, we delete it within thirty days, except for records we are legally required to keep, such as invoices.

Security

If we discover a data breach involving your data, we report it to the Dutch Data Protection Authority within 72 hours and inform you as soon as required.

All connections use HTTPS; requests to the insecure address are redirected automatically. The cockpit is only reachable after logging in. Server access requires a personal key; password login is disabled. A firewall allows only web and administrative traffic, intrusion attempts are blocked automatically, and security updates are installed automatically. Passwords, keys and tokens are stored outside the public directories and are readable only by the administrator. Files on the server itself are not protected by disk encryption. If a security incident affects your data, we will notify you as required by law.

Your rights

You may ask us what data we hold about you, have it corrected, have it deleted, or withdraw your consent. Email joel@ilatt.nl and you will hear from us within one month. Under the GDPR you may also file a complaint with the Dutch Data Protection Authority.

Changes

If this policy changes, we update the date at the top. We will notify you of any significant change.