1. Introduction
With the following information, we provide you, as a data subject, with an overview of how we process your personal data and of your rights under applicable data protection laws.
In principle, our websites may be used without providing personal data. However, if you wish to make use of certain services offered by our company via our website, the processing of personal data may become necessary. Where such processing is required and no statutory legal basis applies, we will generally obtain your prior consent.
The processing of personal data—such as your name, address, or email address—is always carried out in accordance with the General Data Protection Regulation (GDPR) and in compliance with the applicable national data protection laws governing DEKOM B.V.. Through this Privacy Policy, we inform you about the scope and purposes of the personal data we collect, use, and process.
As the controller responsible for processing, we have implemented appropriate technical and organisational measures to ensure the most comprehensive protection possible of personal data processed via this website. Nevertheless, internet-based data transmissions may be subject to security vulnerabilities, and absolute protection cannot be guaranteed. For this reason, you are free to transmit personal data to us via alternative means, such as by telephone or by post.
You can also take simple and effective measures yourself to protect your data against unauthorised access by third parties. We therefore provide the following guidance on the secure handling of your data:
- Protect your account (login, user, or customer account) and your IT systems (computer, laptop, tablet, or mobile device) with strong passwords.
- Ensure that only you have access to your passwords.
- Use a separate password for each account.
- Do not reuse passwords across different websites, applications, or online services.
- In particular, when using publicly accessible or shared IT systems, always log out after each session.
Passwords should consist of at least 12 characters and be chosen so that they cannot be easily guessed. They should not contain commonly used words, your own name, or the names of relatives, but should include a combination of uppercase and lowercase letters, numbers, and special characters.
2. Controller
The controller within the meaning of the GDPR is:
DEKOM B.V.
Minervum 7457
4817 ZP Breda
Telephone: +31 76 8200 232
Email: info-nl@dekom.com
Authorised representative: Björn Heisterkamp
3. Data Protection Officer
DEKOM B.V. has not appointed a Data Protection Officer, as it is not required to do so under Article 37 of the GDPR.
4. Definitions
This Privacy Policy is based on the terminology used by the European legislator when adopting the GDPR. To ensure that this Privacy Policy is easy to read and understand, we explain the key terms used below.
a. Personal data
Any information relating to an identified or identifiable natural person.
b. Data subject
Any identified or identifiable natural person whose personal data are processed by the controller.
c. Processing
Any operation performed on personal data, whether or not by automated means.
d. Restriction of processing
The marking of stored personal data with the aim of limiting future processing.
e. Profiling
Any form of automated processing of personal data used to evaluate certain personal aspects relating to a natural person.
f. Pseudonymisation
Processing of personal data in such a way that the data can no longer be attributed to a specific data subject without additional information.
g. Processor
A natural or legal person that processes personal data on behalf of the controller.
h. Recipient
A natural or legal person to whom personal data are disclosed.
i. Third party
Any entity other than the data subject, controller, processor, or persons authorised to process the data.
j. Consent
Any freely given, specific, informed, and unambiguous indication of the data subject’s wishes.
5. Legal Basis for Processing
Where processing is based on consent, the legal basis is Article 6(1)(a) GDPR, in conjunction with the Dutch Telecommunications Act (Telecommunicatiewet) for consent-based storage or access to information on end-user devices.
Where processing is necessary for the performance of a contract or pre-contractual measures, the legal basis is Article 6(1)(b) GDPR.
Where processing is required to comply with a legal obligation, the legal basis is Article 6(1)(c) GDPR.
Where processing is necessary to protect vital interests, the legal basis is Article 6(1)(d) GDPR.
Where processing is necessary for the purposes of legitimate interests pursued by DEKOM B.V. or a third party, the legal basis is Article 6(1)(f) GDPR, provided that such interests are not overridden by the interests or fundamental rights and freedoms of the data subject.
6. Technology
6.1 SSL/TLS Encryption
This website uses SSL/TLS encryption to protect the transmission of confidential content. You can recognise an encrypted connection by the use of "https://" and a lock symbol in your browser.
6.2 Data Collection When Visiting the Website
When you use our website for informational purposes only, we collect only the data technically necessary to provide the service. This includes server log files containing, in particular, browser type, operating system, referrer URL, accessed pages, date and time of access, anonymised IP address, and internet service provider.
The legal basis for this processing is Article 6(1)(f) GDPR.
7. Cookies
We use cookies to make our website more user-friendly, to analyse usage, and to optimise our services. Details on storage duration and consent management are available via our consent management tool.
8. Content of Our Website
8.1 Customer Accounts and Contract Performance
Personal data are processed for contract performance pursuant to Article 6(1)(b) GDPR. Data are deleted after contract completion, subject to statutory retention obligations under Dutch commercial and tax law.
8.2 Contact Requests
Personal data submitted via contact forms or email are processed for the purpose of responding to enquiries. The legal basis is Article 6(1)(f) GDPR or Article 6(1)(b) GDPR where the enquiry relates to a contract.
8.3 Recruitment
Applicant data are processed for recruitment purposes. If no employment relationship is established, application data are deleted in principle no later than six months after rejection, unless longer retention is required to comply with legal obligations under Dutch equal treatment legislation. The legal basis is Articles 6(1)(b) and 88 GDPR in conjunction with the Dutch GDPR Implementation Act (*Uitvoeringswet AVG*).
9. Newsletter
Newsletters are sent based on consent pursuant to Article 6(1)(a) GDPR using the double opt-in procedure. You may withdraw your consent at any time.
Mailchimp is used as a processor. Where personal data are transferred to recipients outside the European Union (EU) or the European Economic Area (EEA), this is done only in compliance with Chapter V of the GDPR. In such cases, we ensure that appropriate safeguards are in place, such as an adequacy decision by the European Commission, standard contractual clauses, or other transfer mechanisms permitted under the GDPR
10. Social Media Presence
We maintain profiles on social media platforms. Where applicable, we act as joint controllers with the platform providers pursuant to Article 26 GDPR. Processing is based on Article 6(1)(f) GDPR or consent under Article 6(1)(a) GDPR.
11. Social Media Plugins
Social media plugins are activated only with your explicit consent pursuant to Article 6(1)(a) GDPR.
12. Web Analytics and Advertising
Analytics and advertising tools (including Google Analytics, Google Ads, and Matomo) are used only on the basis of consent pursuant to Article 6(1)(a) GDPR. Where data are transferred to third countries, this is based on adequacy decisions or appropriate safeguards.
13. Advertising
Advertising services are used only with your consent pursuant to Article 6(1)(a) GDPR.
14. Your Rights as a Data Subject
You have the rights of access, rectification, erasure, restriction of processing, data portability, withdrawal of consent, and the right to lodge a complaint with the competent supervisory authority.
In the Netherlands, the competent authority is the Autoriteit Persoonsgegevens.
15. Storage and Deletion of Personal Data
Personal data are stored only for as long as necessary to fulfil the respective purpose or to comply with statutory retention obligations.
16. Retention Periods
The applicable statutory retention periods under Dutch law determine the duration of storage.
17. Updates to This Privacy Policy
This Privacy Policy is currently valid and was last updated in January 2026. The current version is available on our website.