GDPR / Privacy Statement
idyn B.V.
1. Introduction
idyn B.V. (hereinafter: “we”, “us”, or “the Company”) is committed to protecting and respecting your privacy. This Privacy Statement explains how we collect, use, store, and share personal data in accordance with the General Data Protection Regulation (EU) 2016/679 (“GDPR”) and the Dutch Implementation Act (Uitvoeringswet AVG, “UAVG”).
Please read this statement carefully. If you have any questions, you can contact us using the details provided in Section 10.
2. Who We Are (Data Controller)
The data controller responsible for your personal data is:
idyn B.V.
Castle Dussen
Binnen 1
4271BV Dussen, The Netherlands
KvK (Chamber of Commerce) number: 18065643
Email: privacy@idyn.nl
3. Personal Data We Collect
We collect and process the following categories of personal data:
3.1 Contact Details
- Full name
- Email address
- Telephone number
- Postal address (if applicable)
3.2 Financial Data
- Bank account number (IBAN)
- Payment transaction data
- Invoice and billing information
- VAT number (for business customers)
3.3 Website and Usage Data
- IP address
- Browser type and version
- Pages visited and time spent
- Referring URLs
- Cookie identifiers (see our separate Cookie Policy)
4. Purposes and Legal Bases for Processing
We only process your personal data when we have a valid legal basis to do so under Article 6 GDPR. The table below sets out our processing purposes and the corresponding legal bases:
|
Purpose
|
Data Categories
|
Legal Basis
|
|
Managing business relationships and inquiries
|
Contact details
|
Legitimate interests (Art. 6(1)(f))
|
|
Performing contracts and delivering services
|
Contact details, Financial data
|
Contract performance (Art. 6(1)(b))
|
|
Processing payments and invoicing
|
Financial data
|
Contract performance (Art. 6(1)(b)); Legal obligation (Art. 6(1)(c))
|
|
Compliance with tax and accounting obligations
|
Financial data, Contact details
|
Legal obligation (Art. 6(1)(c))
|
|
Website analytics and improvement
|
Website/cookie data
|
Legitimate interests (Art. 6(1)(f)) / Consent (Art. 6(1)(a))
|
|
Direct marketing (newsletter, offers)
|
Contact details
|
Consent (Art. 6(1)(a)) / Legitimate interests
|
|
Security and fraud prevention
|
Contact details, Financial data, Website data
|
Legitimate interests (Art. 6(1)(f))
|
Where we rely on legitimate interests (Article 6(1)(f) GDPR) as our legal basis, you have the right to object to such processing. Please see Section 9 for details.
5. Cookies and Similar Technologies
Our website uses cookies and similar tracking technologies. We use:
- Functional cookies — strictly necessary for the website to operate correctly.
- Analytical cookies — to measure and analyse website usage (e.g. Google Analytics with IP anonymisation enabled).
- Marketing cookies — only placed with your prior consent.
You may manage your cookie preferences via our cookie consent banner or your browser settings. Withdrawing consent does not affect the lawfulness of processing prior to withdrawal. For full details, please refer to our Cookie Policy.
6. Sharing Your Personal Data
We do not sell your personal data. We may share your data with the following categories of recipients, only to the extent necessary:
- Payment service providers (e.g. banks, payment processors) — for processing financial transactions.
- IT and hosting providers — who process data on our behalf under a data processing agreement (verwerkersovereenkomst) as required by Article 28 GDPR.
- Accountants and auditors — where required for legal or regulatory compliance.
- Competent authorities — where we are legally obliged to disclose data (e.g. the Dutch Tax Authority, Belastingdienst).
All third-party processors are contractually bound to handle your data securely and in accordance with applicable law.
7. International Data Transfers
We endeavour to process all personal data within the European Economic Area (EEA). Where personal data is transferred outside the EEA, we ensure appropriate safeguards are in place, such as:
- Standard Contractual Clauses (SCCs) approved by the European Commission;
- Transfers to countries with an adequacy decision by the European Commission.
You may request a copy of the relevant transfer safeguards by contacting us at the address in Section 10.
8. Data Retention
We retain personal data only for as long as necessary for the purposes described in this statement, or as required by law. Our standard retention periods are:
- Contact details: up to 2 years after the end of our business relationship, unless a longer period is required.
- Financial and transaction data: 7 years, in accordance with Dutch tax and accounting obligations (Bewaarplicht, Article 52 AWR).
- Website / cookie data: up to 13 months from the date of collection.
After the applicable retention period, personal data is securely deleted or anonymised.
9. Your Rights Under the GDPR
As a data subject, you have the following rights under the GDPR and the UAVG:
- Right of access (Article 15 GDPR) — to obtain a copy of your personal data.
- Right to rectification (Article 16 GDPR) — to correct inaccurate or incomplete data.
- Right to erasure (Article 17 GDPR) — to request deletion of your data (‘right to be forgotten’).
- Right to restriction of processing (Article 18 GDPR).
- Right to data portability (Article 20 GDPR) — to receive your data in a structured, machine-readable format.
- Right to object (Article 21 GDPR) — in particular where processing is based on legitimate interests or for direct marketing purposes.
- Right to withdraw consent (Article 7(3) GDPR) — at any time, without affecting prior processing.
To exercise any of these rights, please submit a written request to privacy@idyn.nl. We will respond within one month. In order to ensure that the request for access has been made by you, we ask you to send a copy of your ID (Passport, ID-card or drivers license) along with the request. Make your ID photo, MRZ (machine Readable Zone, the strip with numbers at the bottom of the ID), ID number and Citizen Service (BSN) black. This is to protect your privacy.
If you are not satisfied with our response, you have the right to lodge a complaint with the Dutch Data Protection Authority (Autoriteit Persoonsgegevens):
Autoriteit Persoonsgegevens
Postbus 93374, 2509 AJ Den Haag
Website: www.autoriteitpersoonsgegevens.nl
10. Security
We implement appropriate technical and organisational measures to protect your personal data against unauthorised access, alteration, disclosure, or destruction. These include, where applicable, encryption, access controls, and regular security assessments. In the event of a data breach that is likely to result in a high risk to your rights and freedoms, we will notify you in accordance with Article 34 GDPR.
11. Contact Details
For any questions or requests regarding this Privacy Statement or the processing of your personal data, please contact:
idyn B.V. — Privacy Contact
Email: privacy@idyn.nl
Post: Castle Dussen, Binnen 1, 4271BV Dussen, The Netherlands
12. Changes to This Privacy Statement
We may update this Privacy Statement from time to time to reflect changes in our practices or applicable law. The current version will always be available on our website. Where changes are material, we will notify you by email or a prominent notice on our website prior to the change becoming effective.