Legal Document

Privacybeleid

GDPR-aligned Privacy Policy for bi.expert website, inquiries, and professional service interactions.

Last revised: May 26, 2026. This policy applies to all interactions with bi.expert unless a stricter written agreement applies.

1. Controller identity and GDPR context

bi.expert acts as data controller for personal data processed through its website, inquiry forms, direct communications and related business operations, unless a specific contract allocates processor/controller roles differently for a client engagement. Our privacy governance is designed to align with the EU General Data Protection Regulation (GDPR), Dutch UAVG implementation rules and applicable sector obligations.

For privacy questions, rights requests and data governance matters, contact our privacy function at [email protected]. General operational questions may be sent to [email protected]. Postal contact: Keurenplein 41, UNIT A6260, 1069 CD, Amsterdam, The Netherlands.

2. Categories of data, lawful bases and purposes

We may process identity and contact details, organization details, inquiry messages, project scope information, correspondence records, consent signals, language preferences, technical logs and security telemetry needed to operate and secure our services. For contracted projects, additional categories depend on the agreed scope and are documented contractually where required.

Our legal bases include performance of contract, pre-contractual steps requested by you, legitimate interests (including secure operations and service improvement), legal obligations, and consent where this is the appropriate basis. We assess proportionality and data minimization for each processing purpose.

3. Sharing, retention, international transfers and security

Personal data may be shared with vetted service providers acting under contractual obligations, such as hosting, email, IT support and professional advisory partners, strictly for legitimate business operations. We do not sell personal data and we require confidentiality and appropriate safeguards from processors and sub-processors.

Where transfers outside the EEA occur, we implement transfer safeguards recognized under EU law, such as Standard Contractual Clauses and supplementary measures where relevant. Retention periods are set by purpose, legal requirements and risk, and records are deleted or anonymized when no longer needed.

We maintain risk-based technical and organizational controls including access management, least privilege, logging, secure configuration and incident response procedures. Suspected personal data incidents can be reported to [email protected]. Where a reportable breach occurs, notifications are made in accordance with GDPR obligations.

4. Data subject rights and complaints

Where GDPR applies, individuals may request access, rectification, erasure, restriction, portability and objection, subject to legal limitations. Consent can be withdrawn at any time where consent is the legal basis. We may need to verify identity before acting on requests, and we document request handling for accountability purposes.

If you believe we have not handled your data appropriately, contact [email protected] first so we can resolve the issue quickly. You also retain the right to lodge a complaint with the Dutch Data Protection Authority (Autoriteit Persoonsgegevens) or your local EU supervisory authority.