Legal

Privacy Policy

We protect personal data with the same discipline we apply to our operations. This policy explains what we collect, why we use it and what rights you have.

1. Who we are

Nassau420 B.V. is the controller responsible for the personal data described in this policy.

Nassau420 B.V.
Forward Operating Base (FOB420)
Sionsweg 1a
6564 CR Heilig Landstichting
The Netherlands

Email: info@nassau420.nl
Chamber of Commerce number: 91001072

2. Personal data we process

We process personal data that you provide directly, data created through our business relationship and limited technical data generated when you use our website.

  • Contact details, such as your name, email address and phone number.
  • Professional details, such as your organisation, unit, role and enquiry.
  • Messages, proposal requests, bookings and other correspondence.
  • Newsletter consent and unsubscribe information.
  • Website data, such as pages viewed, approximate location, device type, browser and security logs.
  • Aggregated advertising data from platforms such as Meta, including campaign reach and performance.

Please do not send classified information, operationally sensitive information or special-category personal data through our public website.

3. Why we use personal data

We use personal data for the following purposes and legal bases:

  • To answer enquiries, prepare proposals and arrange services. This is necessary to take steps at your request or perform a contract.
  • To manage business relationships, improve our services and protect our organisation. We rely on our legitimate interests where these do not override your rights.
  • To send our newsletter when you have given consent. You can withdraw consent at any time.
  • To keep our website secure, prevent abuse and diagnose technical problems. We rely on our legitimate interests in security and continuity.
  • To comply with legal, accounting and regulatory duties.

We do not sell personal data. We do not use personal data for solely automated decisions that produce legal or similarly significant effects.

4. Website analytics and cookies

Our website uses Cloudflare for delivery, protection and privacy-focused web analytics. We also use a self-hosted Umami instance to understand website use. These tools help us measure page visits, traffic sources and website performance.

We do not use website analytics to identify individual visitors. The site may store a necessary language preference and temporary session information so that your choices and protected page access work correctly. If we add non-essential advertising or tracking cookies, we will request consent where required.

5. Newsletter

We only add you to our newsletter when you actively opt in. Newsletter messages include an unsubscribe option. Withdrawing consent does not affect processing that took place before withdrawal.

6. Social media and advertising

When you interact with Nassau420 on Facebook, Instagram or another platform, that platform processes personal data under its own privacy policy. Nassau420 may receive messages, public interactions and aggregated campaign results from those platforms.

We may use Meta tools to manage campaigns and measure their overall performance. We do not receive your Meta password or full private account data through these tools.

7. Who receives personal data

Access is limited to people and suppliers who need the data for their work. Our processors may include:

  • Cloudflare for website hosting, delivery, security and analytics.
  • Attio for customer relationship management.
  • Resend and Google Workspace for email and communications.
  • Umami, hosted under our control, for website analytics.
  • Professional advisers and competent authorities where legally required.

We require processors to protect personal data and use it only for agreed purposes.

8. International transfers

Some suppliers may process personal data outside the European Economic Area. Where required, we use an adequacy decision, Standard Contractual Clauses or another lawful transfer mechanism, together with appropriate safeguards.

9. How long we keep data

We keep personal data only as long as needed for the purpose for which it was collected. Enquiries and CRM records are reviewed when the relationship ends or becomes inactive. Newsletter data is kept until you unsubscribe, after which we may retain minimal suppression data to respect your choice. Financial and contractual records may be kept for the statutory retention period, generally seven years in the Netherlands. Security logs are kept only as long as reasonably necessary for security and incident response.

10. Security

We use technical and organisational measures appropriate to the risk, including access controls, encrypted connections, protected accounts, backups and limited access to systems. No internet service can guarantee absolute security. If a personal data breach creates a legal notification duty, we will notify the competent authority and affected people as required.

11. Your rights

Under the GDPR, you may have the right to access, correct, erase or restrict your personal data, object to processing, receive portable data and withdraw consent. Some rights depend on the legal basis and circumstances.

Send a request to info@nassau420.nl. We may ask for information needed to verify your identity. You may also lodge a complaint with the Dutch Data Protection Authority, the Autoriteit Persoonsgegevens, at autoriteitpersoonsgegevens.nl.

12. Children

Our public website and services are not directed at children. If you believe a child has provided personal data without proper permission, contact us so we can investigate and remove it where appropriate.

13. Changes to this policy

We may update this policy when our services, suppliers or legal duties change. The current version is always published on this page with its latest update date.