Peppol.nu Privacy Policy - Your Data Safe with Peppol.nu

PEPPOL.NU PRIVACY POLICY

Your personal data safe with Peppol.nu - transparency and protection of your privacy

When you visit our website or use our services, we collect personal data from you. We find it important to respect and protect your privacy as much as possible. This privacy policy explains what data we collect and for what purposes.

Safe & Protected

Your personal data is secured with appropriate technical and organizational measures. TLS certificate and firewall protect against abuse.

Transparent

Clear explanation of what data we collect, why we do this and how long we retain it. No hidden practices.

Your Rights

You have full control over your data. Access, correction, deletion and objection - we respect all your privacy rights.

Privacy Definitions

Controller
Solventis B.V., owner of Peppol.nu, determines purposes and means of data processing
Personal Data
Any information relating to an identified or identifiable natural person
Processing
Any operation with personal data: collecting, storing, using, providing or destroying
GDPR
General Data Protection Regulation - European privacy legislation since 2018

Identification & Responsibility

Who is Who?

Clear identification of parties and roles

Basics

You as Customer or Visitor

When we use 'you', 'your' or 'yourself' in this privacy policy, we mean you as:

  • Customer who uses our services
  • Visitor to our website Peppol.nu
  • Person who contacts us
  • User of our online services

Solventis B.V. as Controller

When we write 'we', 'us', or 'our', we mean Solventis B.V. as owner of Peppol.nu:

Contact Details Solventis B.V.:
Address: Gondelstraat 36, 2586 ES The Hague
Chamber of Commerce number: 94449503
Email: support@peppol.nu

Data Responsibility

Who is responsible for which personal data

Our Responsibility

Under privacy legislation, we are the 'controller' for recording the personal data of:

  • Our customers and website visitors
  • Persons who contact us
  • Users of our services
  • Persons who place reviews

Your Own Responsibility

Important: You are responsible for recording the personal data of your own customers when using our services. This privacy policy only addresses data that we process from you.

This means you must take care of:

  • Your own privacy policy for your customers
  • Lawful basis for processing
  • Compliance with your privacy obligations

Data Collection & Purposes

Website Visit

What data we collect when visiting our website

Cookies

Automatically Collected Data

We collect data about visitors to our website, depending on what your browser sends:

  • Number of visitors and page views
  • Referring pages and websites
  • Information about your device and operating system
  • Time and duration of website visit
  • IP address (anonymized)

Purpose of Data Collection

We use this data for:

Statistics & Improvement:
• Website statistics and analysis
• Improving user-friendliness
• Website optimization
• Solving technical problems

Cookies

For these analyses we place cookies. We do this based on the business interest to tailor our website as well as possible to visitors. In our cookie policy you can read exactly which cookies we use.

Contact Us

Data we record when contacted via form or email

Collected Contact Data

When you contact us, we record:

  • Email address
  • First and last name
  • Company name (if provided)
  • Content of your message/question

Technical Information

Sometimes we also record:

  • Web browser type and version
  • Mobile device information
  • API client data
  • Company from which you contact us

Purpose & Legal Basis

We use this data to answer your questions and provide support. This is part of the performance of our agreement and our legitimate interests to provide customer service.

Important: Never send unsolicited sensitive personal data, such as your password or full credit card number. If you do, we will notify you, delete your message and not process your message.

Use of Services

Data processing when using Peppol.nu services

Analysis for Service Provision

We find it important to tailor our services as well as possible to the wishes of our users. Therefore, we analyze anonymized data about our users.

Type of Analyses

This information helps us to:

  • Improve and optimize services
  • Develop new functionalities
  • Detect technical problems
  • Improve user experience
Anonymized Data: The data is anonymized and to a very limited extent traceable to individuals. We do not present data that is traceable to individual users.

Marketing & Communication

We also use these analyses for:

  • Writing blog posts
  • Marketing and communication activities
  • Presentation of trends and statistics about large groups of users

Algorithm Improvement

On a limited scale, we use data (such as a small collection of invoices) to improve our algorithms. We have taken extra safeguards to ensure that this data is handled carefully.

Placing Reviews

Data when leaving reviews on our website

Review Data

We are very happy with reviews about Peppol.nu. When placing a review, we record:

  • Your review text
  • Your gender
  • Your name
  • Company name (if provided)

Publication & Consent

We store your review in our database and publish it after your consent on our website.

Forward to Partners: We forward reviews about Peppol.nu to partners, who make the reviews findable for search engines and comparison websites.

Legal Basis

Processing of review data is based on your explicit consent and our legitimate interest to show our reputation and services to potential customers.

Other Purposes

Administrative and business purposes of data processing

Administrative Purposes

We use your email address, business address and/or name for:

  • Invoicing of our services
  • Collection of outstanding debts
  • Credit assessment
  • Accounting and administration

Complaints & Disputes

We also use this data to handle any complaints and/or disputes with you.

Legal Basis: We do this to properly execute our agreement and based on our legitimate interests to maintain healthy business operations.

Legal Obligations

Some data processing is required under laws and regulations, such as:

  • Invoice retention obligation (10 years)
  • Tax administration
  • Anti-money laundering regulations

Security & Data Sharing

Security of Personal Data

How we secure your personal data

Security

Technical Measures

To secure your personal data, we have taken appropriate technical measures:

  • TLS certificate for secure connections
  • Firewall protection against abuse
  • Encryption of sensitive data
  • Regular security updates
  • Access control and authentication

Organizational Measures

  • Security policies and procedures
  • Employee training
  • Limited access on 'need-to-know' basis
  • Incident response procedures
Risk-based Approach: The choice of security measures is based on available technology, implementation costs, the type of personal data and the associated risks.

Responsible Disclosure

We have a responsible disclosure policy. This means that we:

  • Actively search for vulnerabilities in our system
  • Are open to reports of vulnerabilities by others
  • Resolve reported vulnerabilities as quickly as possible

More information about security can be found on our security page.

Data Sharing

With whom we share your data and why

Within Solventis B.V.

Within Solventis B.V., different people have access to your data. These can only be employees of Solventis B.V. who need the data for the performance of their function.

Principles for Sharing

Minimal Sharing: We share as little personal data as possible with others. We will never sell or rent your personal data.

When Do We Share Data?

We only share your data:

  • With your explicit consent
  • For performance of our agreement
  • When legally obligated
  • For protection of vital interests
  • Based on legitimate interests

Processors & Partners

We may share your personal data with our partners who provide certain services for us (legally speaking: processors). Which partners these are, you can read on our partners page.

Safeguards with Partners

  • Good agreements about confidentiality and security
  • Processing agreements compliant with GDPR
  • Standard Contractual Clauses with partners outside EU/EEA
  • Additional security measures where necessary
Note: The Peppol.nu website contains various links to websites of other companies and institutions. Solventis B.V. is not responsible for compliance with privacy legislation by these companies.

Retention & Your Rights

Retention Periods

How long we retain your data

General Principle

We do not retain your personal data longer than necessary for the purpose for which we recorded them.

Legal Obligations

Tax Authority: Invoices containing your personal data must be retained for 10 years. We comply with these legal terms.

Specific Retention Periods

We apply the following terms:

  • Customer data: As long as the customer relationship exists + 3 years
  • Invoice data: 10 years (legally required)
  • Contact forms: 2 years after last contact
  • Website analytics: 26 months
  • Reviews: As long as relevant for business operations
  • Marketing data: Until withdrawal of consent

Automatic Deletion

We have established processes to automatically delete data when the retention period has expired, unless there is a legal ground to retain them longer.

Your Privacy Rights

What rights you have regarding your personal data

Important

Your Rights Under GDPR

According to privacy legislation, you have a number of rights. You can ask us to:

  • Access: What personal data we have about you
  • Rectification: Correct your data if it is incorrect
  • Erasure: Delete your data ('right to be forgotten')
  • Restriction: Restrict the processing of your data
  • Portability: Transfer your data to another party

Objection & Consent

Objection: You can object to the recording of your personal data.

Withdraw Consent: If you have given us consent for certain processing, you can always withdraw that consent.

Exercise of Rights

After withdrawing your consent, we will delete your data. We may possibly refrain from this if we also need your data for another purpose, for which no consent is required.

How to Exercise Rights?

If you want to exercise your rights, you can email us via info@solventis.nl or send a letter to:

Solventis B.V.
attn. Peppol.nu Privacy
Gondelstraat 36
2586 ES The Hague

Processing Requests

  • We may ask you to identify yourself
  • You will receive a response within one month
  • In certain cases we may refuse your request
  • We will then clearly explain why we do so

Complaints & Changes

Privacy Complaints

What you can do if you have a privacy complaint

Report Complaint to Us

If you have a complaint about how we handle your personal data, we ask you to first report this complaint to us via info@solventis.nl.

When Can You File a Complaint?

You can do this, for example, if you suspect that:

  • Your data has been misused
  • There has been a data breach
  • Your privacy rights have been violated
  • We do not handle your data correctly
Solve Together: We will then work with you to find a solution and handle your complaint carefully and within a reasonable time.

Data Protection Authority

You also always have the right to file a complaint with the Data Protection Authority. You can do this on the website www.autoriteitpersoonsgegevens.nl.

No Mandatory Order

You do not have to complain to us first before going to the Data Protection Authority. You can pursue both avenues simultaneously.

Privacy Policy Changes

How we inform you about changes to this policy

When Do We Change the Policy?

We may occasionally change this privacy policy. We do this, for example, when:

  • We want to record more or different data from you
  • New services are introduced
  • Laws and regulations change
  • We adjust our working methods

How Do We Inform You?

Well in Advance: If we change the policy, we always let you know well in advance by email or via our website.

Important Changes

For important changes that may affect your rights:

  • We inform you at least 30 days in advance
  • We clearly explain what changes
  • We give you the opportunity to object
  • We may ask for your consent where necessary

Version History

Each version of this privacy policy gets a version number and date. The current version is:

Version 1, January 2025

Contact & Questions

Do you have questions about this privacy policy?

Support

Ask Questions

Do you have questions about this privacy policy or about how we handle your personal data? Please ask them via info@solventis.nl.

Quick Response: We strive to answer your questions within one business day.

Contact Options

  • Email: info@solventis.nl
  • Post: Solventis B.V., Gondelstraat 36, 2586 ES The Hague
  • Website: Via the contact form on Peppol.nu

How Can We Help You?

We are happy to help you with questions about:

  • Your privacy rights and how to exercise them
  • What data we have about you
  • How we use your data
  • Security of your data
  • Changes to this privacy policy

Company Details

Solventis B.V.
Owner of Peppol.nu
Gondelstraat 36, 2586 ES The Hague
CoC: 94449503
Email: info@solventis.nl

Questions about privacy or data protection?

We stand for transparency and protection of your privacy. Do you have questions about how we handle your personal data or do you want to exercise your privacy rights? Please feel free to contact us!

Peppol.nu - Your privacy is our priority
Version 1, January 2025