Privacy Policy / Privacy Statement (Privacyverklaring)
Applies to: www.abcthemis.nl and all ABCThemis services
1. Who we are
This privacy statement explains, in plain language, how ABCThemis — the sole-trader legal practice of Dr Fanny Cornette — collects and uses personal data, and what rights you have. We take your privacy seriously and process personal data in line with the General Data Protection Regulation (GDPR / AVG) and the Dutch Implementation Act (UAVG).
For everything described in this statement, ABCThemis acts as the controller (verwerkingsverantwoordelijke) — the party that decides why and how your personal data is processed.
Contact details of the controller:
Trade name: ABCThemis (by Dr Fanny Cornette)
Legal form: Eenmanszaak (Dutch sole trader)
Location: Hilversum, The Netherlands
Chamber of Commerce (KvK): 74949152
VAT (BTW-id): NL002496382B66
Website: www.abcthemis.nl
No Data Protection Officer (DPO) is required. Given the scale and nature of the practice (no large-scale monitoring and no large-scale special-category processing as a core activity), a statutory DPO under Article 37 GDPR is not mandatory. For any question about your data you can contact us directly using the details above.
2. What this statement covers
This statement applies to personal data we process about:
- visitors to our website (including through the contact form and cookies);
- prospective clients who book a discovery call, complete the free Quick-Scans, or subscribe to our newsletter;
- clients and their contact persons, throughout an engagement (intake, correspondence, deliverables, invoicing);
- workshop participants who register for a Workshop.
Our services are aimed at businesses (B2B). Where a client is a one-person business (ZZP), the person and the business often coincide, so this statement is written to be understandable for individuals as well.
3. What personal data we collect
Depending on how you interact with us, we may process the following categories of personal data:
- Identity & contact data: name, business name, email address, phone number, postal/business address.
- Business & registration data: KvK number, VAT number, role/function.
- Engagement data: information you provide in the intake questionnaire, correspondence, and the content of documents you share with us so we can perform the service.
- Financial & transaction data: invoicing details and payment status. Card details for the Workshop are handled by our payment provider — we do not store them.
- Quick-Scan & marketing data: your answers to the self-assessment, your email address, and your newsletter consent status.
- Technical & usage data: IP address, device/browser information and cookie data when you use the website (see section 5).
Special categories of data
We do not seek to collect special categories of personal data (Article 9 GDPR) — such as health, religion or political opinions — about you. Please do not include such data in the free-text fields of our forms or in materials you send us unless it is strictly necessary for the service and we have agreed how to handle it.
4. Why we use your data, and on what legal basis
We only process personal data where we have a lawful basis under Article 6 GDPR. The table sets out our purposes and the matching basis.
| Purpose (what we do) | Data used | Legal basis (Art. 6 GDPR) |
|---|---|---|
| Answering enquiries and holding a free discovery call | Identity & contact data | Steps taken at your request before a contract — Art. 6(1)(b); or our legitimate interest in responding — Art. 6(1)(f) |
| Providing our services and managing the engagement (drafting, review, advice, workshops) | Identity, business, engagement data | Performance of the contract — Art. 6(1)(b) |
| Invoicing and keeping our accounts | Identity, business, financial data | Legal obligation (Dutch tax retention) — Art. 6(1)(c) |
| Free Quick-Scan (sending you the result) | Quick-Scan answers, email | Consent — Art. 6(1)(a); or legitimate interest — Art. 6(1)(f) |
| Newsletter and marketing emails | Email, consent status | Consent — Art. 6(1)(a) |
| Running the website and keeping it secure | Technical & usage data | Legitimate interest in a functioning, secure site — Art. 6(1)(f) |
| Referencing an engagement in our portfolio / testimonials | Business name, quote (if given) | Consent — Art. 6(1)(a); subject to confidentiality in our T&C |
| Handling complaints and establishing or defending legal claims | Any relevant data | Legitimate interest / legal obligation — Art. 6(1)(f)/(c) |
Where we rely on consent, you can withdraw it at any time (see section 10); withdrawal does not affect processing that already took place. Where we rely on legitimate interest, we have weighed our interest against your rights and freedoms, and you can object (section 10).
5. Cookies
Our website uses cookies and similar techniques. Strictly necessary cookies (needed to make the site work) are always active. Analytics, functional and marketing cookies are only placed after you consent through the cookie banner, in line with the Dutch Telecommunications Act (art. 11.7a) and the ePrivacy rules. You can change or withdraw your choice at any time.
Full details — which cookies, their purpose and duration — are in our separate Cookie Policy (Cookieverklaring).
6. Who we share your data with
We do not sell your personal data. We share it only where necessary, with:
Service providers acting on our instructions (our processors), each bound by a processor agreement (verwerkersovereenkomst):
- mijn.host — domain, website hosting and email (Netherlands, EU).
- cotechno — website pages, funnels, lead capture, email sequences and Workshop checkout (EU-based provider, France).
- Calendly — scheduling your free discovery call (United States).
- Eventbrite — registration and ticketing for open-enrolment Workshops (United States).
Payment providers, which handle your payment as independent controllers under their own terms (not on our instructions):
- Stripe — Workshop payments (iDEAL, SEPA), through Stripe Payments Europe (Ireland). Card details are entered directly with Stripe; we do not see or store them.
- PayPal — Workshop payments, through PayPal (Europe) S.à r.l. et Cie, S.C.A. (Luxembourg). Payment details are handled directly by PayPal; we do not see or store them.
Other recipients:
- Our bookkeeper or accountant, if engaged, to meet our accounting and tax obligations.
- Competent authorities, or our professional advisers, where we are legally required to disclose, or where necessary to establish, exercise or defend a legal claim.
Some of these providers are based outside the EEA; the safeguards that apply are set out in section 7.
7. Transfers outside the EEA
We aim to keep personal data within the European Economic Area (EEA). Some of our providers are based outside the EEA — mainly in the United States — or may access data from there. Where that happens, we make sure an appropriate safeguard is in place: either an EU adequacy decision (including the EU–US Data Privacy Framework, which covers certified US companies) or the European Commission's Standard Contractual Clauses (SCCs — approved model contract terms).
- Stripe (payments): contracts within the EEA through Stripe Payments Europe (Ireland); any access from the United States is covered by the EU–US Data Privacy Framework and/or SCCs.
- PayPal (payments): contracts within the EEA through PayPal (Europe) S.à r.l. et Cie, S.C.A. (Luxembourg); transfers to PayPal in the United States are covered by Binding Corporate Rules (BCR — internal group rules approved by a supervisory authority) and SCCs.
- Calendly (scheduling your discovery call): based in the United States; transfers are covered by the EU–US Data Privacy Framework and SCCs.
- Eventbrite (workshop registration and ticketing): based in the United States; transfers are covered by the EU–US Data Privacy Framework and SCCs.
- Google (only if our mailbox/calendar runs on Google): based in the United States; transfers are covered by the EU–US Data Privacy Framework and SCCs.
8. How long we keep your data
We keep personal data only as long as necessary for the purposes above, then delete or anonymise it. Our standard periods:
| Data / category | Retention period | Reason |
|---|---|---|
| Invoices and accounting records | 7 years | Dutch statutory tax-retention obligation (fiscale bewaarplicht) |
| Client engagement files (intake, correspondence, deliverables) | 7 years after the engagement ends | To provide the service and defend possible claims |
| Discovery-call / enquiry data (no engagement) | 6 months | Follow-up, then deletion |
| Quick-Scan lead data | 6 months | To send the result and (with consent) follow up |
| Newsletter data | Until you unsubscribe, then removed | Consent-based |
| Website / cookie data | See Cookie Policy | Per each cookie's lifespan |
9. How we protect your data
We take appropriate technical and organisational measures to protect your data against loss and unlawful processing — for example access controls, strong authentication, up-to-date software, encrypted connections (HTTPS), and data minimisation. We only give access to data to those who need it to do their work, and our processors are contractually bound to protect it too.
10. Your rights
Under the GDPR you have the following rights regarding your personal data:
- Access — to know what data we hold about you and to receive a copy;
- Rectification — to correct inaccurate or incomplete data;
- Erasure — to have your data deleted in certain cases ("right to be forgotten");
- Restriction — to limit our processing in certain cases;
- Data portability — to receive data you gave us in a structured, machine-readable format;
- Objection — to object to processing based on our legitimate interest, and at any time to direct marketing;
- Withdraw consent — where we rely on consent, you can withdraw it at any time.
These rights are yours as a matter of law; they are not conditional. To exercise them, contact us using the details in section 1. We respond within one month (extendable by two months for complex requests, of which we will inform you). We may ask you to confirm your identity. Exercising your rights is free unless a request is manifestly unfounded or excessive.
11. Questions or complaints
If you have a question or a complaint about how we handle your data, please contact us first — we are happy to help. You also have the right to lodge a complaint with the Dutch supervisory authority:
Autoriteit Persoonsgegevens (AP)
Postbus 93374, 2509 AJ Den Haag
www.autoriteitpersoonsgegevens.nl
12. Automated decision-making
We do not use automated decision-making or profiling that produces legal or similarly significant effects on you (Article 22 GDPR). Decisions in our services are made by a person.
13. Minors
Our services and website are aimed at businesses and are not directed at children. Under Dutch law (UAVG), the age of valid consent for online services is 16. We do not knowingly collect data from anyone under 16; if you believe we have, please contact us and we will delete it.
14. Changes to this statement
We may update this statement to reflect changes in our services or the law. The current version is always published on our website, with the version date shown at the top. For material changes we will make a visible notice on the site.
