With a Click arranged in the Netherlands!

The fine print, here you can find them.

Responsible disclosure

We take great care and attention to the security and integrity of our systems and services. Nevertheless, there may of course be occasions when a vulnerability, vulnerability, exploit or other security risk is discovered (hereinafter "Security Risk"). We would like to ask you to report any security risks you find, subject to the policy below, to us as soon as possible. This allows us to continue to improve the security of our systems and services and to continually strive to provide the safest possible experience for our customers and users.

We ask you to:

  1. during your research:
    - not to use distributed denial of service attacks (DDoS);
    - not to use brute force attacks;
    - not to post malware;
    - not to use phishing and/or hacking tools;
    - not to make any changes to systems or the data stored therein;
    - not to use social engineering or attacks on physical security measures;
    - not to use spam;
  2. not go beyond what is strictly necessary during your research to share with us the security risks in accordance with this policy and not abuse them by, for example, accessing third-party data, overloading systems, or otherwise creating a nuisance for users of the systems;
  3. report the security risks and all your related findings at rd@klikonline.nl, including to the extent possible:
    - as clear a description of the security risk as possible;
    - the IP address or URL of the system in question; and
    - clearly described steps by which we can reproduce and/or determine the finding;
  4. keeping your findings strictly confidential and not sharing them with others until the security risk in question has been remedied; and
  5. delete any confidential data that may have come into your possession as a result of the investigation as soon as the relevant security risk has been remedied.

From us you can expect:

  1. if you follow the procedure described in this policy when investigating and reporting your findings, we will not attach any legal consequences to your report.
  2. all reports will be treated confidentially and that your personal information will not be shared with third parties without consent, unless required by law or court order.
  3. we mention you, if you wish and if there is (public) communication or publication about the security risk, as the discoverer of the security risk (N.B. it may happen that another person has discovered the security risk in question earlier, but that this has not yet been disclosed. In that case, that other person is considered the discoverer);
  4. we respond to your report within 7 days with our assessment of your findings and an expected date of resolution.
  5. we will work hard to reach a solution to the security risk and keep you informed about the progress of the solution; and
  6. we are, in principle, open to contributing to any publications of your findings after the security risk has been remedied.

We do not offer rewards for reporting security risks.

Always up to date, just at Clickonline

We hold you up to date!