Back to homepage

    Security & trust

    ISO 27001 certification in progress
    Iconicorp, trading as Selectronyx. What we actually do today with your data and this website, written for a supplier assessment rather than a brochure.
    Last updated: 19 September 2026

    1. Where we stand on certification

    ISO 27001 certification is in progress. Selectronyx is not yet certified and does not hold a SOC 2 report. SOC 2 is on the roadmap rather than in place. What follows is what we actually do today, so you can assess it yourself rather than take a badge on trust.

    StandardStatus
    ISO/IEC 27001In progress (not certified)
    SOC 2Not held

    2. Roles under the GDPR

    Iconicorp, trading as Selectronyx, is established in the Netherlands. The supervisory authority is the Autoriteit Persoonsgegevens. No Article 27 representative is required. We have not appointed a Data Protection Officer: Article 37 does not require one, because we do not carry out large-scale systematic monitoring of individuals and we do not process special-category data. Data-protection contact: privacy@selectronyx.com.

    Controller. We are the controller for site visitors, enquiries, FairSpec account holders as our customers, billing, and our own marketing.

    Processor. We are the processor for what customers put into the app: their BOM content, and their own users' account data. The customer is the controller for that. A request from a customer's user is forwarded to that customer rather than actioned by us as if we were the controller.

    3. Data handling

    Iconicorp, trading as Selectronyx, is established in Veldhoven, the Netherlands. The public website is hosted by Vercel. FairSpec application data is stored in MongoDB Atlas in an EU region. Some processors sit in the US; those transfers are listed in sections 6 and 8 and in the Privacy Policy.

    The website and its APIs are served over HTTPS.

    Retention, as published in the Privacy Policy and Terms:

    DataRetention
    Website enquiries and leads24 months after last contact
    Contact API and server logs30 days
    Instant Check IP hash (rate limiting)7 days; we do not store the raw IP address
    Instant Check MPN response cache7 days; keyed by part number only, not linked to an IP hash
    Instant Check usage aggregatesDaily counts with no IP and no MPN
    AnalyticsAggregate and non-identifying, retained per Simple Analytics settings
    FairSpec app usage analyticsUp to 365 days
    FairSpec app data (accounts, BOMs, results)As long as needed to provide the service and meet legal obligations; deletion on request (see section 9)

    Stripe processes payments for the application. We do not store full card numbers.

    5. Application security

    FairSpec accounts sign in with Google OAuth or email, as described in the Privacy Policy. Session and authentication tokens for signed-in users are held in HTTP-only cookies.

    Instant Check runs on the server. The browser submits a part number and receives a trimmed findings payload. FairSpec scores are not included, and scoring logic is not shipped to the page.

    • Part numbers are validated (3 to 64 characters, a limited character set). Unknown JSON fields are rejected.
    • Cloudflare Turnstile is required before a check runs.
    • Lookups are capped at 5 per hour per connection. Emailing a result is capped at 10 per hour per connection. Both counters are in-memory and best-effort on serverless hosting: they are not a global quota. Exceeding the cap returns HTTP 429.
    • The Instant Check shared secret, Turnstile secret, and contact-delivery keys are server environment variables. They are not sent to the browser.
    • The contact form validates fields and ignores submissions that fill a hidden honeypot. It does not use the Instant Check rate limiter.

    6. Sub-processors

    The canonical register is /platform/sub-processors. The same list is in section 5 of the Privacy Policy. Each processor acts on our instructions under a data-processing agreement with that vendor. Transfer mechanism is filled from a public DPF listing or from our published contractual fallback. Where neither is established, the cell says Under review. Octopart and DigiKey are not in this table — see section 7.

    NamePurposeRegionTransfer mechanism
    Vercel, Inc.Website and app hosting, edge delivery, logsUS / EUEU-U.S. DPF; SCCs as contractual fallback
    MongoDB AtlasApp database (accounts, BOMs, usage, audit logs, cache)EU regionNot applicable (EEA)
    Stripe, Inc.Payment processingUSEU-U.S. DPF; SCCs as contractual fallback
    Google LLCGoogle OAuth sign-inUSEU-U.S. DPF; SCCs as contractual fallback
    GoHighLevel / LeadConnector (HighLevel, Inc.)CRM, contact enquiries, demo booking, live chat, transactional notificationsUSEU-U.S. DPF; SCCs as contractual fallback
    Simple AnalyticsCookieless website analyticsEU (Netherlands)Not applicable (EEA)
    ResendTransactional email delivery (enquiry fallback)USEU-U.S. DPF; SCCs as contractual fallback
    CloudinaryImage and video delivery (CDN)US / EUEU-U.S. DPF; SCCs as contractual fallback
    CloudflareBot protection (Turnstile) for signup and the instant checkUS / EUEU-U.S. DPF; SCCs as contractual fallback

    The website's Montserrat font is self-hosted at build time (via next/font), so it does not cause a runtime request to Google Fonts and is not a data-sharing event.

    7. Component data sources

    Octopart and DigiKey are not in the sub-processor table because they do not receive personal data on the evidence in this repository. They are listed here so a reader who notices them missing from section 6 finds the reason without asking.

    Lookups are server-side. The Instant Check browser never calls them. What is sent is a manufacturer part number (and, when provided, a manufacturer name). Visitor IP (raw or hashed), User-Agent, session or account identifiers, email, referrer, and per-user request IDs are not in that outbound request. Cached responses are keyed by part number and are not stored against a user record.

    Requests to Octopart use the Nexar API. The data source a reader will recognise — and the name we use — is Octopart. DigiKey is used as an independent second source for RoHS corroboration in the app.

    NamePurposeApplies toWhat is sent
    OctopartManufacturer, lifecycle, compliance and distributor information for Instant Check and FairSpec analysesWebsite Instant Check + AppManufacturer part number (and optional manufacturer name). Server-side only.
    DigiKeyIndependent second-source RoHS corroborationAppManufacturer part number. Server-side only.

    8. International transfers

    Transfers to the United States occur. The providers that cause them are:

    • Vercel, Inc.US / EU. EU-U.S. DPF; SCCs as contractual fallback.
    • Stripe, Inc.US. EU-U.S. DPF; SCCs as contractual fallback.
    • Google LLCUS. EU-U.S. DPF; SCCs as contractual fallback.
    • GoHighLevel / LeadConnector (HighLevel, Inc.)US. EU-U.S. DPF; SCCs as contractual fallback.
    • ResendUS. EU-U.S. DPF; SCCs as contractual fallback.
    • CloudinaryUS / EU. EU-U.S. DPF; SCCs as contractual fallback.
    • CloudflareUS / EU. EU-U.S. DPF; SCCs as contractual fallback.

    Where a provider is certified under the EU-U.S. Data Privacy Framework, that certification may currently be relied on. This page does not rest on the DPF alone. Standard Contractual Clauses (Commission Implementing Decision (EU) 2021/914, Module Two) are annexed to the Data Processing Agreement as the contractual fallback. If the DPF were withdrawn, the contractual fallback would remain; the table in section 6 and the register would be updated.

    MongoDB Atlas (EU region) and Simple Analytics (Netherlands) do not, on the register, involve a transfer out of the EEA.

    9. Data subject rights

    Where we are the controller, you may exercise:

    • access (Art. 15)
    • rectification (Art. 16)
    • erasure (Art. 17)
    • restriction of processing (Art. 18)
    • data portability (Art. 20)
    • objection (Art. 21), including to processing based on legitimate interests

    Email privacy@selectronyx.com. We respond within one month. There is no self-serve export or deletion button on this website. Where processing is based on consent, you may withdraw it the same way; withdrawal does not affect processing already carried out.

    Where we are the processor, a request from a customer's user is forwarded to that customer rather than actioned by us as if we were the controller.

    You also have the right to lodge a complaint with the Dutch supervisory authority, the Autoriteit Persoonsgegevens (autoriteitpersoonsgegevens.nl).

    10. Breach

    Where we are the processor, we notify the customer without undue delay after becoming aware of a personal data breach (Art. 33(2)), with the information reasonably required for that customer to meet Article 33.

    Where we are the controller, we notify the Autoriteit Persoonsgegevens within 72 hours of becoming aware of a personal data breach, unless the breach is unlikely to result in a risk to the rights and freedoms of natural persons (Art. 33(1)).

    11. Data Processing Agreement

    The customer Data Processing Agreement is published at /platform/dpa. It sets out the Article 28(3) terms, annexes the Standard Contractual Clauses as the contractual fallback for restricted transfers, incorporates the sub-processor register at /platform/sub-processors by URL, and gives 30 days' notice of a sub-processor change with a right to object.

    It is a template for counsel to review. It is not a certification, and it is not legal advice.

    12. Cookies and similar technologies

    This section is what a clean-profile load of the production site measured in September 2026, before any consent was given. The site does not show a consent banner.

    Homepage (www.selectronyx.com), before any user action:

    • Simple Analytics script https://scripts.simpleanalyticscdn.com/latest.js (from the site layout; loads on every page)
    • Simple Analytics noscript gif beacon, when JavaScript is off
    • Cloudinary CDN requests for page images and the homepage hero video (res.cloudinary.com)
    • First-party Next.js / Vercel JavaScript
    • Montserrat via next/font, self-hosted at build time — no runtime request to Google Fonts
    • No cookies were set on that homepage load
    • No Google Ads, Meta Pixel, or GoHighLevel scripts on that homepage load

    Other pages, still with no consent banner:

    • Instant Check (/part-check) loads Cloudflare Turnstile (https://challenges.cloudflare.com/turnstile/v0/api.js) when the widget mounts
    • The GoHighLevel booking calendar on Contact loads only after you click to open it

    Simple Analytics is cookieless and is described in the Privacy Policy as legitimate interests. It still loads without a prior consent choice. This page does not claim that non-essential scripts wait for consent.

    FairSpec authentication cookies are strictly necessary for signed-in users.

    13. Reporting a vulnerability

    Email privacy@selectronyx.com with enough detail for us to reproduce the issue. We read this mailbox and aim to acknowledge reports. We do not operate a paid bug-bounty programme. Please do not access other customers' data or disrupt the service in order to demonstrate a finding.

    The same contact is published at /.well-known/security.txt (RFC 9116).