Draft
Privacy statement
This is a content draft, not a final agreement. It requires qualified review of the English legal and commercial wording before publication.
Status of this statement
Updated on 25 September 2026. This draft describes our chosen approach. Final supplier agreements, account settings and verification of deletion periods are incomplete. It is therefore not yet a final production privacy statement.
Who is responsible
Van Bostelen Software, trading as VB Websites, is responsible for personal data about our own applicants, customers and contacts. Our address is Emmakade 123, 2411 JH Bodegraven, Netherlands. KVK: 42127942. VAT ID: NL005517908B88. For privacy questions: support@vbwebsites.nl.
This statement covers our business website, applications, intake, payment, support and administration. You are normally responsible for visitors to your own customer website. We process, for example, quote requests and attachments on your behalf under the processor agreement. Your business privacy statement also applies to that processing.
Data we receive
You give us business and contact details, package and domain choices, text, photographs and other content, payment information and correspondence. Your employer or colleague may supply business contact details. For business checks, we consult public information from the KVK Business Register, such as trading name, activities and business address. For a sole trader, these may be personal data.
Payment services provide payment status and information needed for invoices, direct debits and refunds. Hosting and security services process technical information, such as IP address, time, browser and error messages. Do not send unnecessary medical information, identity documents, passwords or full payment-card details.
Why we may use data
- Application, website, domain, payment and support: to take steps at your request before a contract or perform it where you are personally the contracting party, for example as a sole trader (GDPR Article 6(1)(b)).
- Contact with employees and representatives of business customers, and checking public business details: our legitimate interest in dealing with the right business and providing the service (Article 6(1)(f)). We limit this to relevant business information.
- Invoices and tax records: our legal retention obligations (Article 6(1)(c)). Payments and refunds also form part of the contract.
- Security, preventing abuse and resolving faults: our legitimate interest in protecting customers and systems. We limit access and the amount of technical data.
- Limited statistics without tracking cookies, where enabled: our legitimate interest in assessing operation and reliability, following a balancing assessment. Where consent is required, we ask first. You can withdraw consent without making earlier lawful processing unlawful.
Required contact, business, billing and domain details are necessary to handle your application or order; without them, we cannot provide the relevant service. Extra photographs and information are optional unless needed for your chosen content. A person reviews applications. Automatic intake checks identify missing details and technical problems. Ask for a human review if an outcome is incorrect.
Who receives data
We share only what is needed with the suppliers on our processors and services list. Our server and the storage of customer files are with suppliers inside the European Economic Area (EEA). A network and security supplier supports networking, security and selected storage and mail services. A domain and mailbox supplier provides our domain and support mailbox; customer domains and Professional mail are planned. We use AI services from suppliers in the United States to write and translate website texts and in our design process, each with no more than the approved intake details needed for that. We provide the names of the suppliers within a category on request.
Mollie is an independent controller for ordinary payment services, as explained in Mollie's privacy roles. Banks and registries may also have their own statutory responsibilities. We provide data to competent authorities where legally required.
Data outside Europe
A server or storage setting inside the European Economic Area (EEA) does not mean all processing stays within the EEA. International suppliers may provide support or other processing elsewhere. Transfers outside the EEA must use a valid mechanism, such as an applicable adequacy decision or European standard contractual clauses, with additional measures where necessary.
The supplier list identifies the known locations per category and safeguards still requiring confirmation. Ask our support address for the names of the suppliers, for an explanation or for a copy of the applicable safeguards. Account-specific contracts and transfers must be recorded before production use; this draft does not confirm an unknown agreement.
How long we keep data
The periods below are our chosen retention schedule. Technical enforcement and additional supplier retention periods are still being checked.
- Rejected, expired or unpaid applications: 90 days, then deletion or irreversible anonymisation. A minimal, justified suppression record may be needed longer to prevent abuse.
- Invoices, credit notes and tax-related payment records: seven years.
- Active intake, approved content and photographs: the contract term plus 90 days. Hosted website versions: at most the latest five, none older than 12 months; deleted within 30 days of termination.
- Support and operational audit records: up to 24 months after resolution or the end of the contract.
- Automated email content: deleted after confirmed delivery; within seven days where delivery remains unresolved. Technical mail information without message content: 30 days.
- Failed work files from writing website texts: up to 24 hours. Technical records of that without content: 24 months.
- Primary technical logs: seven days; metrics: fourteen days; the private technical archive: 90 days. The measurement service retains measurement data for three months.
- Operational backups: a rolling 35-day period. Older copies expire as replaced; after a restore, we reapply earlier deletion requests.
A specific legal duty or dispute may require us to retain only the necessary data for longer, with restricted access. Data processed on behalf of a customer follows that customer's instructions and the processor agreement. Our periods do not replace an independent payment or registration service's own legal retention duties.
Your rights and complaints
You may request access, correction, erasure, restriction and, where applicable, a portable copy of your data. You may object to processing based on legitimate interests and withdraw consent. Email your request to support@vbwebsites.nl. We verify your identity only as necessary; do not send an identity document without being asked.
We respond without undue delay and normally within one month. If a lawful extension is necessary because of complexity or the number of requests, we explain this within that first month. If our customer is responsible for the data, we forward your request and help that customer.
You can directly complain to the Dutch Data Protection Authority (Autoriteit Persoonsgegevens) and use your statutory remedies. You do not have to complain to us first. More information: AP guidance on privacy rights.