Legal
The fine print.
Our legal documents are provided in English and apply to both the Dutch and English versions of this site. For contracts, the Dutch version of our terms prevails.
Privacy Statement
Lionheart Systems respects your privacy. We handle personal data in two roles: as controller for visitors, leads and contacts of our own website and business (Part A), and as processor for personal data we process on behalf of our clients under a Data Processing Agreement (Part B).
Part A — Lionheart as controller (our website, leads and contacts)
Who we are
Lionheart Systems, represented by Barry van Spronse, based in Oude-Tonge, the Netherlands. Contact: info@lionheartsystems.eu, +31 6 21 11 87 75. We have not appointed a Data Protection Officer; you can reach us directly for any privacy matter.
Data we collect
Contact details you provide (name, email, phone, company), the content of your messages and our correspondence, and limited technical usage data (such as IP address and browser type), subject to your cookie settings.
Purposes and legal bases
- Responding to enquiries and following up (pre-contractual steps / legitimate interest).
- Entering into and performing an agreement and providing our services (performance of a contract).
- Administration, invoicing and statutory records (contract and legal obligation).
- Improving our website and services / analytics (consent where cookies require it, or legitimate interest).
- Marketing to existing business contacts or with consent (legitimate interest / consent, with an opt-out in every message).
We do NOT rely on 'by using our website you agree' as a basis; we apply the appropriate basis per purpose.
AI support
We use AI to support internal work such as drafting, analysis and administration, and — when we act as processor for a client — recognising and classifying incoming messages. Our approach is GDPR-aligned, risk-based and human-in-the-loop.
- AI does not take autonomous decisions about you, and we do not carry out automated decision-making that produces legal effects or similarly significantly affects you within the meaning of Article 22 GDPR — a human reviews and decides.
- We send only the minimum data a task needs to an AI provider; in practice this can include minimal fragments such as a sender email address, a subject line and a short text fragment.
- We do NOT send attachments, photos, access tokens, passwords or full mailboxes.
- Where contractually agreed with the provider, the data is not used to train their models.
Website AI assistant (Leo)
On our website we offer an AI assistant called Leo, clearly identified as AI. If you choose to use it, your messages are processed to answer your question (via our own automation and an AI provider), with data minimisation and human oversight; Leo does not take decisions about you. Please do not share sensitive personal data through the chat.
Sharing and subprocessors
We do not sell personal data. We share data only with service providers needed to run our business and services (such as hosting, email delivery, database, automation and AI providers); our current providers are listed in our Subprocessor Overview.
Some are established outside the EU (for example in the United States); for those transfers we rely on appropriate safeguards under the GDPR (an EU-US Data Privacy Framework certification, or Standard Contractual Clauses with additional measures). You can request a copy of the safeguards via info@lionheartsystems.eu.
How long we keep data
- Invoicing and statutory financial records — 7 years.
- Contracts and agreement evidence — duration of the agreement plus 7 years.
- Leads and enquiries without an agreement — 24 months after last contact.
- Website/usage analytics — anonymised or deleted within a limited period (up to about 14 months).
- Marketing contacts — while the consent/relationship is valid, stopped on unsubscribe.
Cookies
Our website uses functional cookies necessary for the site to work. Analytics/cookie management is handled via our cookie tool (iubenda); any analytical cookies are placed only after your choice in the cookie banner where consent is required.
Security
We apply appropriate technical and organisational measures — encryption in transit (TLS/SSL), access limitation, credential hygiene, logging, backups and monitoring, and data minimisation in our AI and automation processes.
Your rights
Access, rectification, erasure, restriction, objection, data portability, and withdrawing consent where processing is based on consent. We aim to respond within one month.
- We may be unable to erase certain data while we are legally required to keep it (for example invoicing/financial records during the 7-year tax-retention period); in that case we restrict processing or anonymise as soon as possible.
- Withdrawing consent is not retroactive.
- You are not subject to decisions based solely on automated processing that produce legal effects or similarly significantly affect you.
Contact info@lionheartsystems.eu; you also have the right to lodge a complaint with the Dutch Data Protection Authority (Autoriteit Persoonsgegevens).
Part B — Lionheart as processor (client data)
When we deliver services to a client we process personal data on the client's behalf and on the client's instructions. The client is the controller and determines the purposes and means and informs its own data subjects; Lionheart is the processor and technical administrator of the client's AI-supported workflows (the exact AI Act role is assessed per use case).
- Processing is governed by a Data Processing Agreement (DPA) between the client and Lionheart.
- We engage subprocessors (see the Subprocessor Overview) and pass on the same obligations; the transfers-outside-the-EU safeguards described above apply equally to client data, including any minimal fragments sent to an AI provider.
- We inform the client of intended material changes to subprocessors that process its data.
- We apply data minimisation, human-in-the-loop, and no automated decisions with legal effect.
If you are an end customer of one of our clients and have a question about your personal data, please contact that client (the controller); we will support them as processor.
Changes
We may update this statement when our services, systems or the law change; the current version is published on our website.
Contact
For questions about our legal policies or your rights, you can contact us via:
We aim to respond as soon as possible; for privacy requests we respond within one month at the latest.
Lionheart Systems - AI Act-ready governance.
Designed for speed, built by heart.
Last updated: July 5, 2026
Terms & Conditions
These Terms & Conditions apply to all offers, agreements and services provided by Lionheart Systems, represented by Barry van Spronse, based in Oude-Tonge, the Netherlands (info@lionheartsystems.eu, +31 6 21 11 87 75). They apply to business clients. By entering into an agreement with us, you accept these Terms.
Dutch law applies. If a Dutch-language version of these Terms is also published, the Dutch version prevails in the event of a discrepancy between language versions.
1. Definitions
- AI agents / AI automation: software workflows that use artificial intelligence to support tasks such as classification, prioritisation, drafting and data handling.
- Business-process automation: connecting and automating tools and workflows to reduce manual work.
- CRM integration: setting up and connecting customer-relationship systems and data.
- Web development: building and maintaining high-performance websites and web applications.
2. AI-supported services
- AI output is supportive and advisory; it does not take autonomous decisions.
- You (the client, a human) remain responsible for final decisions; a human reviews AI-prepared content before it is used externally.
- We provide no legal, tax, medical or other regulated professional advice unless expressly agreed in writing, and AI-generated content is not such advice.
- We do not deploy high-risk AI within the meaning of the EU AI Act without a prior assessment.
- Indicative AI Act roles are assessed per use case: the client is typically the deployer/controller and Lionheart the processor/technical administrator; the underlying AI model provider (for example Anthropic) is a separate provider.
3. Agreement and acceptance
Services typically consist of a one-off setup and/or a recurring (monthly) service, as described in the offer.
- An agreement is formed when you accept an offer or when we start performing at your request.
- Offers are non-binding and valid for the stated period, or 30 days if none is stated.
4. Client responsibilities
- Provide accurate, complete and lawful information and timely cooperation.
- Ensure you have a valid legal basis for any personal data you provide and comply with data-protection law as controller of that data.
- Do not use the services for unlawful, misleading or harmful purposes.
5. Third parties and subprocessors
We may engage subprocessors and third-party services (hosting, email delivery, database, automation and AI providers) to deliver the services; our current subprocessors are listed in our Subprocessor Overview.
We inform you of intended material changes to subprocessors that process your personal data so you can object on reasonable grounds.
6. Intellectual property and your data
- Unless agreed otherwise, Lionheart retains intellectual-property rights in its frameworks, tooling and generic components.
- On full payment you receive a non-exclusive, non-transferable licence to use the deliverables for your own business.
- Your data remains yours; we do not sell it and process it only to deliver the services and as set out in the DPA.
7. Payment
- Setup fees are due on signing/acceptance; recurring fees are billed in advance for each period.
- Payment term is 14 days from the invoice date unless otherwise agreed.
- On late payment we may, after notice, suspend the services and charge statutory commercial interest and reasonable collection costs.
8. Security and data processing (DPA)
We apply appropriate technical and organisational security measures.
Where we process personal data on your behalf, you are the controller and Lionheart is the processor; that processing is governed by a separate Data Processing Agreement (DPA), which prevails over these Terms for personal-data processing.
9. Liability
- Our total liability per event, and per year in aggregate, is limited to the fees you paid in the 12 months preceding the event giving rise to the claim.
- We are not liable for indirect, consequential or special damages, lost profit, lost data or third-party claims, except in case of intent or deliberate recklessness.
- Nothing excludes or limits liability that cannot be excluded or limited under mandatory applicable law.
10. Term and termination
Recurring services run for the agreed minimum term and renew as agreed; either party may terminate with the agreed notice.
On termination we make your data available in a common format on request and, after a reasonable period, delete or anonymise it unless retention is legally required.
11. Confidentiality
Each party keeps the other party's confidential information confidential and uses it only to perform the agreement. This survives termination.
12. Support and availability
- Support is provided within the scope described in the offer.
- Unless an explicit service-level agreement (SLA) is agreed, we do not guarantee uninterrupted availability; we make reasonable efforts to keep the Services available and to resolve issues promptly.
13. Changes to these Terms
We may update these Terms if our services, systems or the law change. The current version is published on our website; material changes affecting existing agreements are communicated where appropriate.
14. Disputes
Disputes are submitted to the competent Dutch court, unless the parties agree on an alternative dispute-resolution route.
Contact
For questions about our legal policies or your rights, you can contact us via:
We aim to respond as soon as possible; for privacy requests we respond within one month at the latest.
Lionheart Systems - AI Act-ready governance.
Designed for speed, built by heart.
Last updated: July 5, 2026
Cookie Policy
This cookie policy explains how Lionheart Systems uses cookies and similar technologies on www.lionheartsystems.eu.
What are cookies?
Cookies are small text files stored on your device when you visit a website. Similar technologies (such as local storage) are covered by this policy as well.
Consent
Cookies that are not strictly necessary are only placed after you make a choice in our cookie banner (managed via iubenda). You can accept, reject, or change your choice at any time via the cookie settings. We do not treat mere use of the website as consent.
Types of cookies we use
- Necessary cookies: required for the website to function and to remember your cookie choice (including the consent cookie set by our cookie tool). These cannot be switched off.
- Functional storage: preferences (such as a language choice) may be remembered in your browser via a functional cookie or local storage, where used.
- Analytical cookies: Google Analytics, placed only after your consent, to understand how our website is used. See our Privacy Statement for details.
We do NOT use advertising, targeting or social-media tracking cookies.
Third-party services
- Google Analytics — website statistics, only after consent via the cookie banner.
- iubenda — consent management (necessary).
- Leo, our website AI assistant, runs via our own systems and does not place third-party advertising cookies; anything you share in the chat is handled as described in our Privacy Statement.
Managing cookies
You can change your choice at any time via the cookie settings on our website, and manage or delete cookies in your browser settings. Blocking cookies may affect how the website works.
Questions
Contact us at info@lionheartsystems.eu.
Contact
For questions about our legal policies or your rights, you can contact us via:
We aim to respond as soon as possible; for privacy requests we respond within one month at the latest.
Lionheart Systems - AI Act-ready governance.
Designed for speed, built by heart.
Last updated: July 5, 2026
AI Act-ready governance
Lionheart Systems builds AI-supported automations and websites. We take a risk-based, human-in-the-loop approach to artificial intelligence, aligned with the EU AI Act and the GDPR. This describes how we work; it is not a certification and we do not claim to be fully compliant. We keep our governance under review.
Our approach
- Risk-based — we assess the risk of each AI use case and do not deploy high-risk AI (in the sense of the EU AI Act) without a prior assessment.
- Human-in-the-loop — AI supports, a human decides; AI output is advisory and is reviewed by a person before it is used for customer communication, quotes, payments or legal text.
- GDPR-aligned processing — we minimise data, apply appropriate security, and support data-subject rights.
- Transparency — we are open about where AI is used; our website AI assistant (Leo) is clearly identified as AI, and our AI does not send customer communication on its own.
Roles under the AI Act (indicative, per use case)
The client is typically the deployer and controller; Lionheart is the processor and technical administrator of the AI-supported workflows. The AI Act uses 'operator' as an umbrella term for providers, deployers, importers, distributors, product manufacturers and authorised representatives; the exact role is assessed per use case. The provider of the underlying general-purpose AI model (for example Anthropic) is a separate provider.
If Lionheart offers an AI-supported product to multiple clients under its own name, its role is re-assessed before onboarding.
How we govern AI
- We keep an AI register of our AI systems (purpose, model/provider, input, output, risk, human control).
- We ensure appropriate AI literacy for those who operate our AI (AI Act Article 4).
- We keep a model/vendor log.
- We apply data minimisation and never send access tokens, passwords or secrets to an AI provider.
- Where contractually agreed, data is not used to train models.
- Customer communication, quotes, payments and live changes require human approval.
- We handle incidents fail-loud (stop, record, roll back, assess).
- We review this governance regularly.
Risk classification
Our current AI features are supporting CRM/automation aids and a clearly-labelled website AI assistant. They are minimal/limited risk, not high-risk, and involve no prohibited practices (no social scoring, biometric identification, emotion recognition, or automated decisions with legal effect). Any high-risk use case triggers a new assessment before build.
GDPR
We apply purpose limitation, support data-subject rights, keep data no longer than necessary, and apply appropriate security measures (encryption in transit, access control, logging, backups) based on recognised good practices. We use subprocessors under a Data Processing Agreement; see our Privacy Statement and Subprocessor Overview.
What this is and is not
This is a description of our working method (AI Act-ready), not a legal certification or a claim of full compliance.
Contact
For questions about our legal policies or your rights, you can contact us via:
We aim to respond as soon as possible; for privacy requests we respond within one month at the latest.
Lionheart Systems - AI Act-ready governance.
Designed for speed, built by heart.
Last updated: July 5, 2026
Lionheart Systems is dedicated to providing an inclusive digital experience, adhering to WCAG 2.1 Level AA and the European Accessibility Act (EAA).
Visual Inclusivity
High contrast, scalable typography, and full alt-text architecture.
- • High contrast colors
- • Scalable text up to 200%
- • Full alt-text architecture
- • Clear focus indicators
Keyboard & Logic
Full support for mouse-less navigation, including skip-links.
- • Full keyboard support
- • Logical tab order
- • Skip-to-content links
- • No keyboard traps
Semantic Structure
Optimized for assistive technologies via ARIA labels and strict heading hierarchy.
- • Semantic HTML structure
- • ARIA labels and descriptions
- • Strict heading hierarchy
- • Descriptive link texts
Compliance Status
Compliance Status: Partially compliant. We are proactively working to minimize limitations in external embeds (such as Calendly) and our AI interfaces.
Known Limitations
- • Some external embedded content (such as Calendly) may have limited accessibility
- • AI chatbot interface is still being optimized for screenreaders
- • Video content does not yet have subtitles
Feedback and Contact
Accessibility is a dialogue. Experiencing barriers? Email us at info@lionheartsystems.eu with subject 'Accessibility'.
- Email: info@lionheartsystems.eu
- Subject: \"Accessibility\"
We strive to respond to accessibility-related questions within 7 days.
Technical Specifications
The accessibility of this website depends on the following technologies:
- • HTML5
- • CSS3
- • JavaScript (React)
- • ARIA (Accessible Rich Internet Applications)
Lionheart Systems - Inclusive by Design
Lionheart Systems is dedicated to providing an inclusive digital experience for all users. We regularly evaluate and improve the accessibility of our website and services.
Designed for speed, built by heart.
This statement was prepared in accordance with the European Accessibility Act (EAA) and is regularly updated.