ABOUT Akreus
I'm Hendrik De Backer, the consultant behind Akreus. I help companies keep their web platforms and products secure and compliant – and when you work with Akreus, you work directly with me: no account managers, no juniors.
I know web projects from the inside. I have worked with Scrum since 2004, and in 2006 I co-founded XIO, a full-service Drupal agency that was later acquired by Wijs. Since 2018 I have been a certified DPO for HR-tech companies. Building, selling, running and securing web projects: I have done all of it, for clients such as bpost, Securex, Ghent University and Fluvius. Today I run Akreus from Slovenia: an EU company, so working together is simple wherever you are in the EU.
How I work: I adopt your problem as my own (remember Winston Wolf?), translate legal and technical requirements into concrete next steps, and stay until it is actually solved – not just documented.
SERVICES
Three ways to work with me, each with a concrete result.
DPO-as-a-service
I act as your official Data Protection Officer, on a monthly retainer. You get a DPO who understands both GDPR and the technology behind your product.
- Registered as your DPO with the supervisory authority
- Records of processing, DPIAs and data processing agreements kept up to date
- Support with data subject requests, data breaches and customer due-diligence questionnaires
- A single point of contact for your team, your clients and the authorities
NIS2 & AI Act readiness check
Find out which EU rules apply to you and what you need to do about them.
- Scope assessment: are you an essential or important entity under NIS2, or a supplier to one? Which of your AI systems are high-risk under the AI Act?
- Gap analysis against the requirements that apply to you
- A written report with a prioritised, practical action plan
Web application security scan
An outside-in security check of your website, web application or API against the OWASP Top 10.
- Automated scan with Qualys Web Application Scanning
- Every finding manually reviewed – no raw tool output, no false-positive noise
- A prioritised fix report your developers can act on, plus a re-scan after the fixes
Need a Scrum team started or rebooted? That's possible too.
SCRUM & PRODUCT OWNERSHIP
Privacy and security only work when they are built into how your team delivers – not bolted on just before release. That is where Scrum and compliance meet.
I have worked with Scrum since 2004, as a Certified ScrumMaster and, since 2009, as a Certified Scrum Product Owner. Thousands of hours of hands-on Scrum experience, which I put to work for teams building products in regulated environments:
- Team kick-off or reboot – get a new team running, or get a stuck one moving again.
- Interim product owner – for products where GDPR, NIS2 or the AI Act set hard requirements.
- Compliance by design – privacy and security requirements in the backlog and in your Definition of Done, so you can show what you did and when.


GDPR & EU COMPLIANCE
I am a certified Data Protection Officer, trained by the Data Protection Institute, and I offer outsourced DPO services – with a focus on HR, recruitment and SaaS companies. You get a DPO who understands both the law and the technology behind your product.
I have been the long-standing DPO of HR-Technologies and its sister companies Actonomy and Thalento, and I advised the sales and management team of XIO, after its acquisition by Wijs, on GDPR issues in the web agency business.
Beyond GDPR: the new EU digital rules
GDPR is no longer the only EU regulation that affects your website, product or IT. I help you find out which rules apply to you, what they require in practice, and how to get there without drowning in paperwork:
- NIS2 – cybersecurity risk management and incident reporting for essential and important entities, and the suppliers they rely on (Slovenia: ZInfV-1; Belgium: the NIS2 law).
- EU AI Act – strict rules for high-risk AI, which explicitly includes AI used in recruitment and HR.
- Cyber Resilience Act – security requirements for software and connected products sold in the EU.
Do you use AI to screen, rank or match candidates?
Then the AI Act almost certainly classifies that system as high-risk. That brings obligations for the vendor that builds it – risk management, data governance, documentation, human oversight – and for the employer or agency that uses it. As the DPO of companies that build exactly this kind of HR technology, I know where GDPR and the AI Act meet, and how to prepare without stalling your product.
CLIENTS
A selection of the organisations I have worked for, through XIO and Akreus:
- HR & HR technology – Adecco, Securex, HR-Technologies, Actonomy, Thalento
- Industry & energy – Bekaert, Cockerill Maintenance & Ingénierie, Fluvius (formerly Eandis), Unilin / Quick-Step
- Automotive – Fiat Automobiles Group Belgium (now Stellantis), Mercedes-Benz BeLux
- Media & logistics – bpost, De Persgroep (now DPG Media)
- Public sector & education – Flemish Government (Vlaamse Gemeenschap), Ghent University, Ghent University Hospital (UZ Gent)
... and many others.
WEB APPLICATION SECURITY
Do you know how your website or web application holds up against the most common attacks? Most breaches don't need advanced hacking – they exploit the well-known weaknesses listed in the OWASP Top 10: broken access control, injection, security misconfiguration, outdated components.
I scan your web applications with Qualys Web Application Scanning, review every finding by hand, and give you a prioritised report your developers can act on right away. After the fixes, I scan again to confirm the issues are gone.
Regular, documented security testing is also evidence you can show under NIS2, the Cyber Resilience Act and in the security questionnaires of your enterprise clients.
I am a member of the OWASP Foundation, the nonprofit community behind the Top 10 and many of the industry's security standards.
CONTACT
Tell me briefly what you are working on – a DPO question, a NIS2 or AI Act check, a security scan or a Scrum team that needs a (re)start. I'll get back to you personally.
AKREUS, računalniške storitve, d.o.o.
Okrožno sodišce Krško - 7.500,00 €
Tax SI62078950 - ID 6452299000
Jeperjek 29, 8295 Tržišče, Slovenia
PRIVACY & COOKIES
Controller
AKREUS, računalniške storitve, d.o.o., Jeperjek 29, 8295 Tržišče, Slovenia – info@akreus.si
What I collect and why
- When you email me: your name, email address and whatever you write, used only to answer you and, if we work together, to manage our business relationship (legal basis: steps prior to a contract / legitimate interest, art. 6(1)(b) and (f) GDPR). Kept as long as needed for that purpose and for statutory accounting obligations.
- Server logs: the web server records technical data such as IP address, browser and requested pages, to keep the site running and secure (legitimate interest, art. 6(1)(f) GDPR). Logs are kept for a limited time only.
- Analytics – only with your consent: if you accept analytics cookies, the site loads Google Tag Manager and Google Analytics 4 (Google Ireland Ltd.) to see how visitors use the site (consent, art. 6(1)(a) GDPR). Google may process data in the United States. Without your consent, no analytics scripts are loaded and no analytics cookies are set.
- Fonts and icons are hosted on this server. The page does not load anything from third parties unless you accept analytics.
Cookies and local storage
Your cookie choice is stored in your browser's local storage (key akreus-consent) so the banner does not reappear. If you accept analytics, Google Analytics sets its own cookies (_ga, _gid and similar).
Change your cookie settings at any time.
Your rights
You have the right to access, rectify and erase your data, to restrict or object to processing, to data portability, and to withdraw your consent at any time. Email info@akreus.si. You can also lodge a complaint with the Slovenian supervisory authority, the Information Commissioner (Informacijski pooblaščenec), or with the authority in your own EU country.
No selling, no profiling
I do not sell your data, and I do not use it for automated decision-making or profiling.
Last updated: October 2026