Privacy Policy

Version:

1. Introduction

BDS Nederland (hereinafter: “we”, “us” or “our organisation”) attaches great importance to the protection of your personal data. In this privacy policy, we explain which data we collect, why we do so, how long we retain it, and what rights you have.

This policy applies to all personal data processed through our website https://bdsnederland.nl and has been drawn up in accordance with the General Data Protection Regulation (GDPR), the Dutch GDPR Implementation Act (UAVG), and other applicable Dutch and European privacy legislation.

2. Who is responsible for your data?

The controller within the meaning of the GDPR is:

BDS Nederland
Chamber of Commerce number: 54872839
Email address: info@bdsnederland.nl

3. What personal data do we process?

We process personal data in the following situations:

3.1 Donations

When you make a donation through our website, we process the following data:

  • Email address
  • Transaction data (amount, date, transaction reference, payment status)
  • Any other data passed on by your payment service provider

We do not directly process your name or payment details (such as bank account or credit card numbers) — this is handled by our payment service provider, who bears its own responsibility for this.

3.2 Newsletter

When you sign up for our newsletter, we process:

  • First and last name
  • Email address

3.3 Website Analytics

Our website uses Umami Analytics, a privacy-friendly analytics tool hosted entirely on our own server (self-hosted, no third party). Umami does not process personal data within the meaning of the GDPR: no cookies are placed and IP addresses are not stored or shared. All collected statistics are fully anonymised. No consent is therefore required for this use.

4. On what legal basis do we process your data?

We process your personal data solely on the basis of one or more of the following GDPR legal bases:

Donations – performance of a contract (Art. 6(1)(b) GDPR):
The processing of transaction data and your email address is necessary to process the donation and send you a confirmation.

Newsletter – consent (Art. 6(1)(a) GDPR):
We will only send you the newsletter after your explicit, free, and specific consent via an opt-in. You may withdraw this consent at any time.

Legal obligation – (Art. 6(1)(c) GDPR):
We may be required to retain certain financial data under fiscal and accounting legislation (such as the General Tax Act and Book 2 of the Dutch Civil Code).

5. How long do we retain your data?

We do not currently have a policy on deleting data after a set period of time.

6. Do we share your data with third parties?

We never sell your data to third parties. We may share your data with the following parties, solely to the extent necessary:

  • Payment service providers (such as Mollie, Stripe, or iDEAL providers):
    for processing your donation. These parties act as independent controllers or as processors and are bound by their own privacy regulations and/or a data processing agreement with us.
  • Newsletter provider (if applicable):
    for sending the newsletter. We enter into a data processing agreement with this party.
  • Government authorities:
    if we are legally required to do so.

All parties we work with are required to treat your data confidentially and may not use it for their own purposes.

7. Transfer outside the European Economic Area

We endeavour to process your personal data exclusively within the European Economic Area (EEA). If a service provider processes data outside the EEA, we ensure this takes place on the basis of appropriate safeguards, such as the Standard Contractual Clauses approved by the European Commission.

8. Security of your data

We take appropriate technical and organisational measures to protect your personal data against loss, misuse, unauthorised access, or disclosure. These include:

  • Encrypted connection via HTTPS (TLS)
  • Access controls for our systems and databases
  • Regular updates and security patches for our WordPress installation
  • Restricted access to personal data for staff on a need-to-know basis

9. Your rights as a data subject

Under the GDPR, you have the following rights:

  • Right of access (Art. 15 GDPR):
    you may request to know which data we process about you.
  • Right to rectification (Art. 16 GDPR):
    you may request that incorrect data be corrected.
  • Right to erasure (Art. 17 GDPR):
    you may request deletion of your data, unless a legal retention obligation applies.
  • Right to restriction of processing (Art. 18 GDPR):
    in certain circumstances you may request that processing be restricted.
  • Right to data portability (Art. 20 GDPR):
    you may request your data in a machine-readable format.
  • Right to object (Art. 21 GDPR):
    you may object to processing based on legitimate interest.
  • Right to withdraw consent (Art. 7(3) GDPR):
    you may withdraw your consent for the newsletter at any time without giving reasons.

You may exercise your rights by sending a request to info@bdsnederland.nl. We will respond within the statutory period of four weeks.

If you are not satisfied with how we have handled your request, you have the right to lodge a complaint with the Dutch Data Protection Authority (Autoriteit Persoonsgegevens).

10. Cookies and tracking

Our website does not use tracking cookies or third-party cookies for analytics purposes. Our analytics tool (Umami) is self-hosted and places no cookies. If we were to use cookies in the future for which consent is required, we will inform you via a cookie banner and update this policy accordingly.

11. Unsubscribing from the newsletter

You can unsubscribe from our emails by clicking the “Unsubscribe” link in our emails, but this does not remove your data from our systems. To do so, please send an email with your name and the email address you used to sign up to info@bdsnederland.nl.

12. Changes to this privacy policy

We may update this privacy policy from time to time, for example if our practices change or if legislation is amended. The most current version will always be available on our website. We recommend that you consult this policy periodically.

13. Contact

If you have any questions, comments, or requests regarding this privacy policy or the processing of your personal data, please contact us:

BDS Nederland
Email: info@bdsnederland.nl