Phil & Flo privacy statement
Privacy statement: About our privacy policy
Phil & Flo cares deeply about your privacy. We therefore process only data that we need for (improving) our service delivery and handle carefully the information we have collected about you and your use of our services. We never make your data available to third parties for commercial purposes.
This privacy policy applies to the use of the website and the services accessible through it offered by Phil & Flo. The effective date of these terms is 01-01-2021, with the publication of a new version, all previous versions lose their validity. This privacy policy describes what data about you is collected by us, what this data is used for, and with whom and under what conditions this data may potentially be shared with third parties. We also explain to you how we store your data and how we protect your data against misuse, and what rights you have regarding the personal data you have provided to us.
If you have any questions about our privacy policy, you can contact our privacy contact person. You will find their contact details at the end of our privacy policy.
About data processing
Below you can read how we process your data, where we store it (or have it stored), what security techniques we use, and who has access to the data.
CRM
Pipedrive
Our website is integrated with Pipedrive. Personal data that you provide to us for our service delivery is shared with this party. Only we have access to your data to be able to contact you; they will never use your data for any other purpose. Our website uses security measures, which consist of the application of SSL encryption and a strong password policy.
Email and mailing lists
MailChimp / Gmail / Active Campaign
Our website uses MailChimp, Active Campaign and Gmail, a third party that handles email traffic from our website and the sending of any newsletters. All confirmation emails you receive from our website and web forms are sent via Gmail servers. MailChimp and Gmail will never use your name and email address for their own purposes. At the bottom of each email sent automatically via our website you will see the 'unsubscribe' link. If you click on it, you will no longer receive emails from our website. This could seriously impair the functionality of our website! Your personal data is stored securely by MailChimp and Gmail. MailChimp uses cookies and other internet technologies that provide insight into whether emails are opened and read. MailChimp and Gmail reserves the right to use your data to further improve the service and to share information with third parties in that context.
Billing
Visma
For keeping our administration and accounting, we use the services of Visma. We share your name, address, place of residence and details relating to your order. This data is used for administering sales invoices. Your personal data is transmitted and stored securely. Visma has taken the necessary technical and organisational measures to protect your data against loss and unauthorised use. Visma is required to maintain confidentiality and will treat your data confidentially. Visma does not use your personal data for any purpose other than as described above.
Purpose of data processing
General purpose of processing
We use your data exclusively for the purposes of our service delivery. This means that the purpose of processing always directly relates to the assignment you provide. We do not use your data for (targeted) marketing. If you share data with us and we use this data to contact you at a later time – other than at your request – we will ask you for explicit consent. Your data is not shared with third parties, except to fulfil accounting and other administrative obligations. All of these third parties are bound by confidentiality under the agreement between them and us or by oath or legal obligation.
Automatically collected data
Data that is automatically collected by our website is analytical and cannot be traced to any individual; we also do not store IP data, in accordance with GDPR. This data such as web browser and operating system is not personal data.
Cooperation with tax and criminal investigations
In certain cases, Phil & Flo may be required on the basis of a legal obligation to share your data in connection with tax or criminal investigations by government authorities. In such a case, we are forced to share your data, but we will oppose this within the possibilities the law provides us.
Retention periods
We retain your data as long as you are a client of ours. This means that we retain your customer profile until you indicate that you no longer wish to use our services. If you tell us this, we will also treat it as a deletion request. Under applicable administrative obligations, we must retain invoices with your (personal) data; we will therefore retain this data for as long as the applicable period runs. However, employees will no longer have access to your customer profile and documents that we have prepared as a result of your assignment.
Your rights
Under current Dutch and European legislation, as a data subject you have certain rights regarding the personal data processed by or on our behalf. We explain below what these rights are and how you can exercise them.
To prevent misuse, we generally send copies of your data only to the email address already known to us. If you wish to receive the data at a different email address or by post, for example, we will ask you to verify your identity. We maintain a record of processed requests, and in the case of a deletion request we record anonymised data. All copies of your data are provided to you in the machine-readable data format we use within our systems.
You have the right to lodge a complaint with the Data Protection Authority at any time if you suspect we are using your personal data incorrectly.
Right of access
You always have the right to access the data we process (or have processed) that relates to you or can be traced back to you. You can make a request to this effect to our privacy contact person. You
will receive a response to your request within 30 days. If your request is granted, we will send you a copy of all your data to your known email address, together with an overview of the processors holding this data, specifying the category under which we have stored this data.
Right to rectification
You always have the right to have the data we process (or have processed) that relates to you or can be traced back to you corrected. You can make a request to this effect to our privacy contact person. You will receive a response to your request within 30 days. If your request is granted, we will send you confirmation to your known email address that the data has been corrected.
Right to restrict processing
You always have the right to restrict the processing of data we process (or have processed) that relates to you or can be traced back to you. You can make a request to this effect to our privacy contact person. You will receive a response to your request within 30 days. If your request is granted, we will send you confirmation to your known email address that the data will no longer be processed until you lift the restriction.
Right to data portability
You always have the right to have the data we process (or have processed) that relates to you or can be traced back to you transferred to another party. You can make a request to this effect to our privacy contact person. You will receive a response to your request within 30 days. If your request is granted, we will send you copies of all your data that we have processed or that have been processed by other processors or third parties on our behalf to your known email address. In such cases, we will in all likelihood be unable to continue providing the service, as the secure linking of databases can no longer be guaranteed.
Right to object and other rights
In applicable cases, you have the right to object to the processing of your personal data by or on behalf of Phil & Flo. If you object, we will immediately suspend data processing pending resolution of your objection. If your objection is upheld, we will provide you with copies of the data we process (or have processed) and subsequently permanently cease processing.
You also have the right not to be subject to automated individual decision-making or profiling. We do not process your data in a way that this right applies. If you believe this is the case, please contact our privacy contact person.
Cookies
Google Analytics
Cookies from the American company Google are placed on our website as part of the "Analytics" service. We use this service to track and receive reports on how visitors use the website. This processor may be obliged under applicable legislation to disclose this data. We collect information about your browsing behaviour and share this data with Google. Google can interpret this information in conjunction with other datasets and thereby track your movements on the internet. Google uses this information to provide, amongst other things, targeted advertising (Adwords) and other Google services and products.
Third-party cookies
Where third-party software solutions use cookies, this is mentioned in this privacy statement.
Third parties
Digital marketing service providers
Our carefully selected partners and service providers may process personal data on our behalf, as described below:
We occasionally engage digital marketing agencies to carry out marketing activities on our behalf. These activities may result in compliance-focused processing of personal data. Our designated data processors include:
(i) Prospect Global Ltd (trading as Sopro) Reg. UK Co. 09648733. You can reach Sopro and view their privacy policy at: http://sopro.io. Sopro is registered with the ICO Reg: ZA346877. Their data protection officer can be reached at: dpo@sopro.io
Changes to the privacy policy
We reserve the right at any time to amend our privacy policy. However, you will always find the most up-to-date version on this page. If the new privacy policy affects the way we process data relating to you that we have already collected, we will notify you of this by email.
Privacy department contact details
Phil & Flo Creative Studio VOF
Oude Boteringestraat 71
9712GG Groningen Netherlands
T 0031(0)85 273 8331
Privacy contact person
Mr P. de Graaf