Legal
Security
Last reviewed 16 September 2026.
Draft — not yet reviewed by counsel. This page describes what the hollend.com website does, verified against the code in this repository. It has not been reviewed by a lawyer and does not yet cover Hollend’s business operations off the website.
What this page covers
Every statement below describes the hollend.com website and is verifiable from the source code and the response headers this site serves. It does not describe Hollend’s internal business systems, and it is not a certification.
Transport
The site is served over HTTPS only. It sends Strict-Transport-Security: max-age=31536000; includeSubDomains, so browsers refuse to load it over plain HTTP after the first visit. TLS certificates are issued and renewed by Google Cloud.
Browser protections
- A Content Security Policy with a per-request nonce. Scripts run only from this origin and only with that nonce;
unsafe-inlineis not permitted for scripts. frame-ancestors 'none'andX-Frame-Options: DENY, so the site cannot be framed for clickjacking.X-Content-Type-Options: nosniffandReferrer-Policy: strict-origin-when-cross-origin.- A
Permissions-Policythat switches off camera, microphone, geolocation, payment and USB access.
What this site stores
Nothing. The website holds no database and no credentials. Enquiries are passed straight to Hollend’s API over HTTPS and are not retained by the web front end. The container runs as an unprivileged user with no access to Hollend’s internal systems.
Sign-in
The website never handles your password. Selecting Login hands you to Hollend’s secure portal, which verifies credentials and issues the session. This site can see only whether a session already exists in your browser, and treats that as a display detail, not as permission to show anything.
How changes reach production
Changes are held in version control and deployed through Google Cloud Build. Each release is deployed with no live traffic, health-checked on a private URL, and only then promoted. A release that fails its check never receives visitors.
Where information is held
This site runs in Google Cloud’s us-central1 region, in the United States, and is therefore subject to the laws of that country. The Privacy notice says what that means for you. Nothing personal is stored by the website itself — enquiries pass straight through to Hollend’s API over HTTPS.
Browser storage
One key, holding your own choice in the cookie settings panel. It stays in your browser, is never transmitted to us, and can be cleared from Cookie Settings in the footer. No advertising or analytics cookies are set and no third-party tracking scripts are loaded, which is why no cookie banner appears.
If something goes wrong
Where a breach of security safeguards creates a real risk of significant harm, we will notify affected individuals and report to the Office of the Privacy Commissioner of Canada as PIPEDA requires, and keep a record of the breach.
Accessibility
The site targets WCAG 2.2 Level AA. Text and interface colours were measured against that standard rather than judged by eye: the brand teal is used for fills, and a darker derived tone carries any text, because the brand teal itself does not reach the required contrast on a light background. Contrast is re-checked automatically on every build. We have not yet commissioned an independent audit, and say so rather than imply certification.
Reporting a vulnerability
Email info@hollend.com with enough detail to reproduce the issue. Please give us a reasonable chance to fix it before disclosing it publicly. We do not currently run a paid bounty programme.
