Privacy statement
NIYA Consultancy & Advies is committed to handling your personal data with care. This statement explains which data we process, why, for how long, and what rights you have.
Draft. This statement is complete in substance; the exact processors (mail, booking and analytics services) will be confirmed once they go live. Items marked [to be confirmed] will be filled in before publication.
1. Who is responsible?
The controller for the data processing is:
- NIYA Consultancy & Advies
- Rechtzaad 15, 4703 RC Roosendaal, the Netherlands
- Chamber of Commerce (KvK): 88870030
- Email: [email protected]
For questions about this privacy statement or your data, contact us at [email protected].
2. What data do we process, for what purpose, and on what legal basis?
We only process the data you provide yourself or that is technically necessary to run the website. Per situation:
Contact (form, email, WhatsApp, phone)
- Data: name, email address, phone number (if you provide it) and the content of your message.
- Purpose: to answer your question and, if you wish, prepare a service engagement.
- Legal basis: performance of, or steps prior to, a contract (Art. 6(1)(b) GDPR) and our legitimate interest in responding (Art. 6(1)(f)).
- Retention: as long as needed to handle your request and up to 12 months after the last contact; longer for a client or engagement relationship, in line with our statutory retention obligation (7 years for administration).
Booking an introductory call (booking tool)
- Data: name, email address and the time slot you choose.
- Purpose: scheduling and confirming an (online) appointment.
- Legal basis: performance of, or steps prior to, a contract (Art. 6(1)(b) GDPR).
- Retention: up to 12 months after the appointment.
- Processor: [to be confirmed — name of booking tool, under a data-processing agreement].
AI Act Check
- Data: your answers are processed solely in your browser and are not sent to us. Only if you request the report do we process your email address (and, with your consent, your answers to compile the report).
- Purpose: to send you the requested report.
- Legal basis: performance at your request (Art. 6(1)(b) GDPR); for storing your answers: your consent (Art. 6(1)(a)).
- Retention: up to 12 months, or until you request deletion.
Newsletter
- Data: your email address.
- Purpose: to send you periodic substantive updates.
- Legal basis: your consent (Art. 6(1)(a) GDPR), given via double opt-in. You can unsubscribe from every newsletter with one click.
- Retention: until you unsubscribe or withdraw your consent.
- Processor: [to be confirmed — name of email service, under a data-processing agreement].
Website visits (analytics and log files)
- Data: anonymised or aggregated visit statistics; in server logs a (partly masked) IP address, browser type and pages requested.
- Purpose: to improve the website and safeguard its security and availability.
- Legal basis: our legitimate interest in a well-functioning, secure website (Art. 6(1)(f) GDPR). We aim for a privacy-friendly, cookieless analytics solution (for example Plausible or Matomo) so that a cookie banner is not needed. Should we use analytics that does require consent, we will ask for it beforehand.
- Retention: statistics up to 24 months; server logs up to 12 months.
- Processors: [to be confirmed — hosting provider and analytics service, under a data-processing agreement].
3. Cookies
This website places no tracking or advertising cookies. We use only functional and, where possible, cookieless statistics. Should we later choose analytics or embedded services that place cookies, we will ask for your consent beforehand via a cookie banner and update this overview.
4. Sharing with third parties
We do not sell your data. We share it only with the processors named above who help us deliver these services, and only under a data-processing agreement. Disclosure to other parties happens solely where legally required. In principle we process your data within the European Economic Area (EEA); where processing takes place outside it, we ensure appropriate safeguards.
5. Security
We take appropriate technical and organisational measures to protect your data against loss or unlawful processing, including encrypted connections (HTTPS) and access on a need-to-know basis.
6. Your rights
You have the right to access, rectify or erase your personal data. You also have the right to restriction of processing, the right to object, and the right to data portability. Where you have given consent, you may withdraw it at any time; this does not affect the lawfulness of processing before withdrawal.
You can submit a request via [email protected]. We respond within four weeks. To be sure the request comes from you, we may ask for additional identification.
7. Filing a complaint
If you disagree with how we handle your data, we would like to hear from you. You also always have the right to lodge a complaint with the Dutch Data Protection Authority (Autoriteit Persoonsgegevens) via autoriteitpersoonsgegevens.nl.
8. Changes
We may update this privacy statement. The most recent version is always available on this page.
Last updated: July 2026.