Privacy Policy

Clear, transparent information about how we handle your personal data.

Overview

We provide IT and accounting-adjacent services (helpdesk, compliance, GDPR consultancy). To deliver these services we may process personal data of clients, users, suppliers, applicants, and website visitors. This policy explains what we collect, why and how we process it, on which legal bases we rely, and the rights you can exercise. We operate under the GDPR (EU), the Dutch Implementation Act (AVG), the Telecommunications Act, and other relevant laws. The GDPR principles—lawfulness, fairness & transparency; purpose limitation; data minimisation; accuracy; storage limitation; integrity & confidentiality; accountability—guide our processing. We act as a data controller for our own operations and, where contracted, as a data processor for clients under a processing agreement.

Organisation

Name: Finovatec

Address: Brouwer 1, 5521 DK Eersel, Netherlands

Chamber of Commerce (KvK): 98376268

Privacy Contact

Email: privacy@finovatec.com

Data Protection Officer (in function) available via the above email.

Data We Process

Depending on the services we provide, we may process:

  • Contact: name, role, business email, phone, correspondence
  • Account & login: username, encrypted password, user logs
  • IT & support: configs, logs, tickets, IP addresses, technical info
  • Financial: invoicing data, bank account numbers, VAT, payment history
  • Compliance & audit: security settings, audit reports, access logs
  • Communication: emails, chat/call records, conversation notes
  • Website: cookie IDs, IP, browser info, click behaviour

Categories depend on the specific engagement and lawful purpose.

Use & Sharing

Purposes & legal bases. We process personal data to: perform contracts and deliver services; communicate with you; manage billing/administration; ensure compliance and security (incl. incident handling); conduct marketing and relationship management (only with consent or where permitted within an existing customer relationship); and improve services through analysis/feedback. Depending on the purpose, we rely on GDPR Art. 6 bases such as contract, legal obligation, consent, or legitimate interests. Special categories are processed only when permitted by law with added safeguards.

Sharing. We do not sell your personal data. Where necessary, we share data with trusted IT/hosting suppliers, consultants/subcontractors, government bodies/regulators, and professional advisers—under appropriate agreements and safeguards and only to the extent necessary.

International transfers. Transfers outside the EEA occur only where adequate protection exists or where appropriate safeguards (e.g., Standard Contractual Clauses) are in place. Supplier compliance with GDPR/AVG is assessed in advance.

Security & Retention

Security. We use technical and organisational measures such as encrypted connections, strong authentication, need-to-know access controls, logging/monitoring, staff training, and regular audits. Privacy by design/default is embedded in our processes. Suspected data breaches follow our notification procedure; the Dutch DPA is notified within 72 hours where required.

Retention. We keep data only as long as necessary or legally required. Typical periods: contractual/ticket data up to 10 years after contract end (tax/legal obligations); log/security data as short as possible, usually up to 2 years (longer if needed for incidents or claims); marketing data for as long as you remain subscribed (you can unsubscribe at any time).

Your Rights

You have the following rights under GDPR: to be informed; access; rectification; erasure; restriction; data portability; objection (incl. direct marketing); and human oversight for automated decisions. If processing is based on consent, you may withdraw consent at any time without affecting prior lawful processing. We will respond as soon as possible and within one month. We do not use profiling or make decisions based solely on automated processing, except limited risk-based blocking by third-party systems (e.g., Microsoft). If this changes, we will inform you and ensure your right to human intervention. You may also lodge a complaint with the Dutch Data Protection Authority. /p>

Cookies & Contact

Cookies. We use functional cookies (essential), limited analytics (anonymised statistics), and—only with your explicit consent—tracking/marketing cookies. Manage your preferences via our cookie banner or your browser settings. Learn more

Privacy Questions

Email: privacy@finovatec.com

Prefer a call? See our Contact page.

General Enquiries

Email: info@finovatec.com

Phone:

Request a Fee Proposal

Last updated: November 2025