Privacy policy

How ai-geletterd.nl processes personal data — legal bases, retention periods, subprocessors and your rights under the GDPR.

Version:
v1.0 (draft)
Effective from:
Last updated:

Draft — this text is still under legal review and not yet final.

This is an informational translation. The Dutch version is legally binding.

ai-geletterd.nl processes personal data carefully and in line with the General Data Protection Regulation (GDPR) and the Dutch implementing act (UAVG). This policy explains which data we process, why, on what legal basis, for how long and with which parties.

For your employees' data you (the employer-customer) are the controller and we are the processor; our Data Processing Agreement applies in addition. For our own contact, account and billing data we are the controller.

1. Controller

ai-geletterd.nl. Contact details and Chamber of Commerce number are available on request via the contact point named in this policy. For any privacy question, reach us through the privacy desk in the application.

2. What data and on what basis

Per activity we process the following data and legal bases (Article 6 GDPR):

  • Authentication and access — name, work email. Basis: performance of the contract (6(1)(b)). Retention: membership + 90 days.
  • Course delivery — enrolments, progress, assessment results. Basis: performance of the contract (6(1)(b)). Retention: membership + 90 days; completed items kept as evidence.
  • Certificate issuance — certificate data and signature. Basis: performance of the contract (6(1)(b)) and legal obligation/evidence for Article 4 of the AI Act (6(1)(c)). Retention: 7 years.
  • AI register — inventory of the customer's AI systems. Basis: performance of the contract (6(1)(b)). Retention: duration + 3 years.
  • Billing — company, VAT and payment data. Basis: contract (6(1)(b)) and fiscal obligation (6(1)(c)). Retention: 7 years (Dutch Turnover Tax Act 1968, Article 52).
  • Marketing email — email address. Basis: consent (6(1)(a)). Retention: until unsubscribe + 90 days proof of consent.
  • Product analytics (PostHog-EU) — in-app usage events. Basis: consent via the cookie banner (6(1)(a)). Retention: 12 months rolling.
  • Consent record — which version of the analytics banner you accepted. Basis: legal obligation to demonstrate consent (6(1)(c), Article 7(1) GDPR). Retention: life of the consent + 3 years.
  • Security and audit logging — events, no free text containing personal data. Basis: legitimate interest (6(1)(f)) and legal obligation (6(1)(c)). Retention: 3 years.

3. Special categories

We do not process special categories of personal data (Article 9 GDPR). Do not supply such data in free-text fields.

4. AI and your data

For features that use a language model, all traffic goes through a single controlled route. As part of that:

  • a PII scrubber removes identifiable personal data before sending;
  • Anthropic is contractually prohibited from training on customer data;
  • we prefer an EU endpoint; for any exceptional US fallback, SCC 2021/914 module 2 and a Transfer Impact Assessment apply.

5. Subprocessors and recipients

We engage only subprocessors from a fixed list (including Vercel, Supabase, Anthropic, Mollie, Resend, Sentry, PostHog-EU, Plausible, Upstash and Backblaze B2); the full list with role and location is in the Data Processing Agreement. We also query the European Commission's public VIES service to validate an EU VAT number; VIES is a recipient, not a processor, and receives only a VAT number with country code.

6. Transfers outside the EEA

All customer data is processed within the EU (Frankfurt primary, Amsterdam for cold backups). Exceptional transfer outside the EEA is only possible via the Anthropic fallback and is then covered by standard contractual clauses.

7. Your rights

You have the right of access, rectification, erasure, restriction, objection and data portability (Articles 15–22 GDPR). In the application, under Privacy, you can download an export and request erasure yourself. On erasure we pseudonymise identifying data but retain a certificate's signature, slug, dates and hash (7 years, Article 4 evidence) and the audit record (3 years); the verification page then shows "holder pseudonymised". You may also lodge a complaint with the Dutch Data Protection Authority.

8. Cookies

Our marketing site uses cookieless analytics only. In the application we load analytics only after your consent. See the cookie statement.

This privacy policy is a draft and will undergo legal review before going live.

Sources