Darvis Websites & Apps

Privacy statement

This is a translation for your convenience. If it differs from the Dutch privacy statement, the Dutch text prevails.

This privacy statement explains which personal data Darvis Websites & Apps processes, why we do so, how long we keep that data and which rights you have. It applies to this website, to our client environment and to the contact we have with you about our services.

Who is responsible for your data

The controller is Darvis, trading as Darvis Websites & Apps, located at Het Nieuwe Diep 33, 1781 AD Den Helder, the Netherlands, registered with the Dutch Chamber of Commerce (KvK) under number 60299703.

Questions about your data can be sent to info@darvis.nl or asked by phone on 085 004 14 63. We have no data protection officer; that obligation does not apply to an agency of our size and with our processing activities.

Which data we process and why

Contacting us. When you fill in the contact form, we process your name, phone number, email address, the topics you tick and the content of your message. We use that data to answer your question and to make you a quotation. When you call or email us directly, we process the same kind of data from that contact. The legal basis is your request to take steps before entering into a contract, and our legitimate interest in being able to answer questions.

Carrying out an assignment. When you become a client, we process company details, contact details of the people we work with, data about domain names, hosting and email, and the records around invoices and payments. The legal basis is the performance of the contract and, for our accounts, our legal obligation.

Client environment. When you have an account in our client environment, we process your name, email address, an encrypted password and the data that belongs to two-factor authentication or a passkey, plus the projects, tasks, invoices and questions in your environment. The legal basis is the performance of the contract.

Newsletter. Only if you tick the box yourself do we use your email address to send you something about our work now and then. The legal basis is your consent, which you can withdraw at any time through the unsubscribe link or a message to us.

Managing and securing our systems. Our servers record technical data, such as the IP address, the requested address, the time and the browser the request comes from. These log files are needed to fix faults and to recognise misuse. The legal basis is our legitimate interest in a working and secure service.

Website statistics and advertising. See the section on cookies below. We only measure after you have given your consent.

We never ask for special categories of personal data, and our services are not aimed at children.

Cookies, statistics and advertising

By default this website only places what is technically necessary: a cookie that handles your session and the security of forms, and a small item in your browser's storage that remembers the choice you made in the cookie notice. No consent is needed for that.

If you give consent, we measure visits with Google Analytics 4. We then see which pages are visited and how visitors use the site, so we can improve it. As long as you have not given consent, measuring is switched off and nothing is sent to Google. Google may process data outside the European Economic Area for this service; that happens on the basis of the EU-US Data Privacy Framework and the standard contractual clauses of the European Commission.

With the same consent we place the Meta Pixel of Meta Platforms Ireland Limited. It shows us which visits and enquiries come from our advertisements on Facebook and Instagram, and helps us target those advertisements better. Meta receives, among other things, your IP address, the page you are viewing and data from the cookie Meta places, and may link that to a profile you have on Facebook or Instagram. Meta and we are joint controllers for that collection; what Meta then does with the data itself falls under Meta's privacy policy. Here too: if you do not give consent, Meta's script is not loaded and nothing is sent to Meta. Meta may process data outside the European Economic Area, on the basis of the EU-US Data Privacy Framework and the standard contractual clauses of the European Commission.

You can change your choice whenever you like with the button below; it applies to the statistics and the advertising measurement together. If you decline, the site keeps working fully.

We also keep track of which pages are fetched by search engines and AI assistants. Of those visits we store only the name of the bot, the requested path and the date. They contain no personal data and do not concern human visitors.

Who we share data with

We do not sell your data and do not pass it on for other people's commercial purposes. We do use suppliers that process data on our behalf: the party that provides our servers and email, the registrar of your domain name, our accounting and invoicing software and the providers of the statistics and advertising measurement above. We conclude a data processing agreement with those parties, and where possible we choose processing within the European Economic Area.

We also provide data when the law requires us to, for example to the Dutch Tax and Customs Administration or to a competent authority.

When we process personal data inside your website, portal or software, you are the controller and we are the processor. The arrangements for that are set out in our data processing agreement (in Dutch).

How long we keep data

  • Enquiries that do not lead to an assignment: up to two years after the last contact, so we can still find an earlier conversation.
  • Data relating to an assignment: for the duration of the collaboration and up to seven years afterwards, because the Dutch tax retention obligation requires that for the accounts.
  • Account in the client environment: as long as you are a client, after which we delete the account.
  • Newsletter subscription: until you unsubscribe.
  • Technical log files: usually no longer than twelve months.

How we protect data

All traffic with this website and with the client environment runs over an encrypted connection. We store passwords encrypted, accounts can be protected with two-factor authentication or a passkey, and access to systems is limited to those who need it. We make backups and keep our software up to date. If you suspect a leak or a vulnerability, please report it to info@darvis.nl; we handle such a report with priority.

Your rights

You have the right to access your data and to have it corrected or deleted. You can also ask us to restrict processing, object to processing based on our legitimate interest, and receive your data in a common file format. You can always withdraw consent you have given; that does not affect what was processed before.

Send a request to info@darvis.nl. We respond within one month. To avoid giving data to the wrong person, we may ask you to identify yourself.

If we cannot resolve it together, you can file a complaint with the Dutch Data Protection Authority (Autoriteit Persoonsgegevens).

No automated decision-making

We do not make decisions about you based on automated processing and we do not create profiles.

Changes

If our services or the law change, we update this statement. The current version is always on this page.

Last updated on 10 September 2026.