Legal

Privacy statement

How DT Business Automation B.V. handles personal data — on this website and in the services and applications we deliver.

Last updated on 15 September 2026.

1. Who is responsible for your data

The controller for the processing described in this statement is:

DT Business Automation B.V.
Jan Meertensstraat 26
3065 PB Rotterdam, The Netherlands
Chamber of Commerce (KVK) number 85931357
VAT identification number NL863791360B01
Email: info@dt-businessautomation.nl

We are not required to appoint a data protection officer and have not done so. Privacy questions can be sent to the email address above.

2. This website

This website is deliberately kept simple. We place no tracking cookies, use no analytics software such as Google Analytics, and load no advertising networks, social media trackers or externally hosted fonts. That is also why there is no cookie banner on this site: none is needed.

Our hosting provider does, like virtually every web server, keep standard log files of requested pages. These may contain the IP address, the time of the request, the page requested and the browser type. This data is used solely for the technical operation and security of the website and is never used to track or profile visitors.

  • Purpose: technical operation, availability and security of the website.
  • Legal basis: legitimate interest (Article 6(1)(f) GDPR) — a secure, functioning website.
  • Retention: server logs are kept briefly, as a rule for no more than a few weeks.

3. Contacting us

If you email us, we process the data you provide yourself: your name, email address, possibly your company name and telephone number, and the content of your message.

  • Purpose: answering your question and, where appropriate, issuing a quotation or proposal.
  • Legal basis: performance of, or steps prior to entering into, a contract (Article 6(1)(b) GDPR), or legitimate interest in handling your enquiry.
  • Retention: correspondence that does not lead to an assignment is kept for a maximum of two years. If it does lead to an assignment, the period under section 4 applies.

4. Clients and assignments

When we work for you, we process contact and company data relating to you and the employees involved in the project: name, role, email address, telephone number, invoicing and address details, and the correspondence and documents belonging to the assignment.

  • Purpose: performing the agreement, project communication, invoicing, support and our administration.
  • Legal basis: performance of the contract (Article 6(1)(b) GDPR) and compliance with a legal obligation (Article 6(1)(c) GDPR) for financial records.
  • Retention: invoices and related records are kept for seven years under Dutch tax law. Other project data is kept no longer than necessary for support and warranty.

5. Access to client systems

In development and maintenance work we sometimes gain access to systems containing personal data of your customers or staff — a CRM environment, a website or a database, for example. In that situation we act as a processor and you are the controller.

We process such data solely on your instructions and for the agreed work, apply appropriate technical and organisational measures, and never use the data for our own purposes. Where the GDPR requires it, we enter into a data processing agreement with you. Wherever possible we work with test data rather than real personal data.

6. Applications and platforms by DT Business Automation

DT Business Automation B.V. also develops and publishes its own applications and online platforms. Each application has its own specific privacy policy setting out exactly what data that application processes, why, and which service providers are involved. That policy is available within the application itself and in its App Store and Google Play listing.

As a general principle, for everything we build:

  • We collect only data that is necessary for the application to function.
  • We do not sell personal data and do not trade it with third parties for advertising.
  • Data is stored within the European Economic Area wherever possible.
  • Access is restricted per user, so that a person can only reach their own data.
  • Users can have their account and associated data deleted.

7. Sharing with others

We do not sell your data. We do engage service providers necessary to carry out our work, who process data on our behalf. These include:

  • our hosting and domain provider, for this website and our email;
  • our email and office software;
  • hosting and cloud services on which we build and maintain applications;
  • our accountant and accounting software, for financial administration.

Data processing agreements are in place with these parties where required. We may also disclose data where legally obliged to do so, for example to the Dutch Tax Administration or at the order of a competent authority.

We aim to process data within the European Economic Area. Where a supplier processes data outside the EEA, this takes place on the basis of a valid transfer mechanism, such as an adequacy decision of the European Commission or the Standard Contractual Clauses.

8. Security

We take appropriate technical and organisational measures to protect your data against loss and unauthorised access: encrypted connections (HTTPS), two-factor authentication on our accounts, least-privilege access, separated development and production environments, and timely updates. No measure offers absolute certainty, but we keep reviewing our practices.

9. Automated decision-making

We do not take decisions producing legal effects or similarly significant effects based solely on automated processing, and we do not build profiles of you.

10. Your rights

Under the GDPR you have the following rights:

  • Access — to find out what personal data we hold about you.
  • Rectification — to have incorrect data corrected or completed.
  • Erasure — to have your data deleted, insofar as no statutory retention obligation applies.
  • Restriction — to have processing temporarily suspended.
  • Objection — to object to processing based on a legitimate interest.
  • Portability — to receive your data in a common digital format.
  • Withdrawal of consent — where processing is based on consent, you may withdraw it at any time.

Send a request to info@dt-businessautomation.nl. We respond within one month. To prevent us disclosing data to the wrong person, we may ask you to substantiate your identity.

If your request concerns data we manage as a processor on behalf of a client, we will refer you to that organisation, as they are the controller in that case.

11. Complaints

If you disagree with how we handle your data, please tell us first — most matters are resolved quickly. You also always have the right to lodge a complaint with the Dutch supervisory authority, the Autoriteit Persoonsgegevens, at autoriteitpersoonsgegevens.nl.

12. Changes

We may amend this privacy statement, for instance if our services or the applicable rules change. The current version is always published on this page, with the date of the most recent change at the top.

This is an English translation provided for convenience. The Dutch version is the authoritative text.