Privacy Policy
Last updated:August 17, 2026
Who we are
This website and the four free tools on its subdomains are run by Holland Tech, LLC, based in Tulsa, Oklahoma, United States. In this policy "we" and "us" mean that company, and it is the data controller for everything described here.
You can reach us about anything on this page at hello@hollandtech.com. A person reads that address.
The short version
We collect almost nothing. Reading this website leaves no record we control: there are no cookies, no analytics and no tracking of any kind.
Two things do collect information, and only when you choose to use them. The contact form sends us what you type. The free tools store the answers you click, and your email address only if you ask for your results.
We do not sell anything to anyone, and we do not advertise.
What this website collects
Browsing hollandtech.com collects nothing about you. Pages are plain HTML and the fonts are served from this site rather than a third party, so no request leaves for anywhere else while you read.
If you send the contact form, we receive what you put in it: your name, your email address, your message, and, if you pick them, what you need help with and a budget range. That is delivered to us as an email. It is not written to any database.
The form carries one hidden field that a person never sees. If it is filled in, the submission is treated as automated and discarded. It exists to stop spam and collects nothing about you.
Our host processes the ordinary technical information any web server sees in order to deliver the page and absorb attacks. We do not build profiles from it and we have no analytics product reading it.
What the free tools collect
The four tools are the AI Scanner, the Data Readiness Assessment, the Cost Calculator and Proof, each on its own subdomain. They ask multiple-choice questions. None of them has a free-text box, so there is nothing to type that could be stored.
When you finish a run we store the options you chose and the scores they produced, as structured values rather than prose. That record carries no name and no email address unless you separately ask us to save your results.
If you do ask us to save or email your results, we store the address you give us together with which tool it came from. Nothing is gated behind an address, and every tool shows you its full result whether or not you hand one over.
The Scanner has one other place it can take an address. When it tells you a build is not worth doing, it links to a page describing the fix instead, and offers to tell you when a free file version of that fix exists. An address given there is stored the same way, with a note of which file you asked about, and it buys one message about one thing. The page reads identically if you skip it.
Runs are excluded by default from any published statistic. The consent flag on each record is off unless you turn it on, and we can only include a run in an aggregate if you have.
Proof runs a real extraction on a fixed sample document that ships with the page. There is no upload, and nothing you do there sends a document of yours anywhere.
Cookies, analytics and tracking
There are none. This site sets no cookies, runs no analytics, embeds no tracking pixels, loads no third-party scripts and has no advertising or social media trackers on any page.
That is why you will not find a cookie banner here. There is nothing to consent to.
The tools set no cookies either. Where one remembers your progress it does so in your own browser and it never leaves your device.
Why we process it, and on what basis
Where the GDPR or UK GDPR applies to you, these are the lawful bases we rely on.
- Answering you. We use what you send through the contact form to reply and, if it goes further, to scope work. Legal basis: taking steps at your request before entering a contract, and our legitimate interest in responding to enquiries.
- Running the tools. We store run records to make the tools work, to see which are useful and to improve how they score. Legal basis: our legitimate interest in operating and improving our own software.
- Emailing your results. We use the address you give us to send the results you asked for. Legal basis: your consent.
- Including a run in published statistics. Legal basis: your consent, which is off by default and which you can withdraw.
- Keeping the tools available. We apply rate limits to stop one visitor exhausting a shared service. Legal basis: our legitimate interest in security and availability.
- Client work. Where you become a client, processing is governed by the contract we sign. Legal basis: performance of that contract.
Who else handles it
We use a small number of service providers, each processing data on our instructions and none of them permitted to use it for their own purposes.
- Cloudflare: hosting, content delivery and the rate-limit counters for this site and all four tools.
- Supabase: the database that holds tool run records and saved email addresses.
- Resend: delivery of every email we send you. That is the enquiry the contact form generates, the results a tool sends when you ask for them, any message telling you a free file you asked about is ready, and the note telling us you asked.
- Anthropic: the model that writes the plain-language explanation beside your Scanner results, and that performs the sample extraction on Proof.
How long we keep it
We keep information for as long as it is doing something useful, and then we get rid of it.
You can ask us to delete anything of yours before these periods are up, and we will.
- Contact form enquiries: up to 24 months after we last heard from you.
- Tool run records: up to 24 months from the run.
- Email addresses you asked us to save: until you ask to be removed.
- Rate-limit counters: these expire on their own within the hour and hold no address in any readable form.
- Client records: for as long as the engagement runs, and afterwards for as long as tax and contract law require.
How it is protected
Everything is served over HTTPS. The database refuses connections from browsers outright: access control is on with no rule permitting public reads or writes, so every write goes through a server we control and there is no path from a visitor to the data.
The tools rate-limit by address, and the address is never stored. It is hashed one way before it is used, only part of that hash is kept, and what is kept is a counter that deletes itself.
Deliberately, we hold very little. The strongest protection on this site is that most of what you might worry about is never collected in the first place.
No system is perfectly secure, and we will not claim otherwise. If a breach affects your rights we will tell you and the relevant authority within the time the law allows.
Your rights, children, and changes
You can ask us what we hold about you, to correct it, to delete it, to restrict or object to what we do with it, or to receive it in a portable form. Where we rely on consent you can withdraw it at any time, and withdrawing it does not undo what was lawful beforehand. Write to us and we will answer within one month.
The GDPR page sets these rights out in full and explains how to make a request. If you are in the UK or the EEA you may also complain to your data protection authority.
This site is not aimed at children and the tools are business software. We do not knowingly collect information from anyone under 16. If you believe a child has sent us something, tell us and we will delete it.
If this policy changes we will change the date at the top. Where a change matters we will say so plainly rather than quietly reissuing the page. Questions go to hello@hollandtech.com.
Open for projects
Find the work worth doing.
Tell me what runs slow or costs too much or keeps breaking. If AI is the wrong answer I say so.
