Privacy & GDPR

Last updated: Jul 14, 2026

NetherlandsIT.nl — AdMun / KVK 84121998 Version: 3.0  |  Effective: 14 July 2026  |  Jurisdiction: Netherlands & EU
Privacy & GDPR Policy

Privacy, Data & Cookie Policy

This policy explains how NetherlandsIT collects, uses, stores, shares and protects your data across all of our products and services. It applies to every visitor, registered user, and customer — whether you use one of our platforms, several, or simply browse this website.

📅 Effective: 14 July 2026 🌎 Scope: Netherlands & EU/EEA 🔒 GDPR compliant by design
How to read this policy: The universal sections apply to everyone. Section 6 (Product-Specific Data) and Section 7 (Connected Platforms) apply only to the specific products or integrations you actually use. If you never use a given service, its data handling never applies to you.

1Who We Are

NetherlandsIT (also operating as AdMun and AdMun EU) is an IT and technology company registered in the Netherlands. We build a family of digital products across several industries, all governed by this single, unified privacy policy.

N

NetherlandsIT / AdMun

KVK: 84121998 • VAT: NL003915624B42
Oudemansstraat 315, 2522SW 's-Gravenhage, The Netherlands
info@netherlandsit.nlwww.netherlandsit.nl

For data you provide to us directly, we act as Data Controller under GDPR Art. 4(7). Where a business customer uses our platforms to process their own users' or employees' data, that customer is the Controller and we act as Data Processor under Art. 28, under a Data Processing Agreement.

2Our Products & Scope

This website is the central hub for the NetherlandsIT product family. One policy covers them all, but each product only collects what it needs. Our current and planned products include:

HR & Administration

Workforce, payroll & compliance admin.

E-commerce & Marketplace

Storefronts & marketplace tooling.

IT & Cloud Services

Software, hosting & integrations.

Remote Hub

Remote work & freelancer tools.

Security & Compliance

Risk, audit & compliance tooling.

Healthcare

Health-sector platforms — see sub-policy.

Product stages: Some products are live, some in beta or pre-registration. Beta/pre-registration products may collect additional diagnostic data to improve stability and features, relied on for our legitimate interest in developing the product; you may object at any time.

3Information We Collect

We collect only what is relevant to the service you use. The categories below are the maximum range across all products; any single product uses a subset.

3.1 Information you provide

  • Identity & contact details — name, email, phone, job title.
  • Organisation details — company name, registration/KVK number, business address.
  • Account credentials — username and securely hashed password.
  • Preferences — communication, language, notification settings.
  • Content you submit — support requests, feedback, uploads, and content you create or publish through our products.
  • Contract and service-agreement data.

3.2 Information collected automatically

  • IP address, browser type, operating system, device identifiers.
  • Pages visited, time spent, click paths, in-product activity.
  • Session data, referring URLs, in-product searches.
  • Feature usage, API call frequency, diagnostic logs.
  • Cookies, pixels, and local storage (see Section 13).

3.3 Information from third parties

  • Business verification data from official registries (e.g. KVK).
  • Authentication/profile data from identity or social login providers you connect (e.g. LinkedIn, Google) — see Section 7.
  • Data from integrated partners strictly where a product you use requires it (see Section 6).
Data minimisation: We do not store sensitive identifiers (BSN, IBAN, ID document numbers) in plain text in general databases. Where a regulated product genuinely requires them, they are encrypted and handled only by certified specialist processors — see Sections 6 and 9.

4How & Why We Use Your Information

We process personal data on these legal bases under GDPR Art. 6:

Contract — 6(1)(b)

Service Delivery

Providing, maintaining & securing the products you use.

Legal — 6(1)(c)

Compliance

Tax, accounting & sector-specific obligations.

Legit. Interest — 6(1)(f)

Security & Improvement

Fraud prevention, uptime & product improvement.

Consent — 6(1)(a)

Optional Features

Marketing, non-essential cookies, connected integrations.

5Marketing & Communications

With an appropriate legal basis (your consent, or our legitimate interest where you are an existing customer), we may use your name, email, phone, and general usage profile to send service announcements, product updates, newsletters, and relevant offers, and to tailor which are shown to you.

Marketing is sent in line with the Telecommunicatiewet. Opt out anytime via the unsubscribe link or by emailing info@netherlandsit.nl. Opting out never affects your access to services.

6Product-Specific Data Handling

The following applies only if and when you use the relevant product.

HR & Administration
May process employee/worker records, payroll inputs, and — where legally required — BSN and IBAN, handled exclusively via certified payroll processors and never used for marketing. Retention follows statutory payroll obligations.
E-commerce & Marketplace
May process order details, delivery addresses, and transaction records. Payments are handled by PCI-DSS-compliant providers; we do not store full card numbers.
IT & Cloud / Remote Hub
May process project data, collaboration content, freelancer profiles, and connected-account tokens for integrations you authorise (see Section 7). Hosted within the EU/EEA.
Security & Compliance
May process audit logs, risk assessments, and compliance evidence you supply — access-controlled and used only for the compliance purpose engaged.
Healthcare
Health data is special category data under Art. 9, governed by our stricter Healthcare Privacy Sub-Policy →. Encrypted, strictly access-limited, never used for marketing or AI training.

7Connected Social Platforms

Some products let you connect a third-party account so we can perform actions you request, like publishing a post. Tap a platform to see exactly what we access, why, how long we keep it, and how to revoke. Only platforms you connect apply; if one isn't listed, we don't integrate with it.

in  LinkedInPublishing & profile

What we access: your LinkedIn profile identifier, basic profile fields, and an OAuth access token — the minimum the feature needs.

How we use it: solely to perform actions you initiate, such as publishing a post. We never sell, rent, or share it.

When collected: only when you take an action or to keep the connection active.

Retention: within LinkedIn's limits — member social-activity data max 48 hours; tokens kept only while active; all LinkedIn content deleted within 10 days if our API access ends.

Revoke & delete: LinkedIn → Settings & Privacy → Data privacy → Other applications → Permitted Services, or email us (Section 14).

♪  TikTokContent posting & login

What we access: via Login Kit and the Content Posting API — your TikTok user identifier, basic profile, and creator settings needed to post. Device/browser info may be shared with TikTok when using these tools.

How we use it: only to log you in and publish content you choose. We show TikTok's required consent declaration, and you manually select each post's visibility — no default.

When collected: at connection or posting; we respect TikTok's posting caps.

Retention: only as long as needed; deleted (including from our servers) on termination of our TikTok access.

Revoke & delete: TikTok → Settings and privacy → Security & permissions → Manage app permissions, or email us. EEA deletion honoured within 30 days.

f / ⌾  Meta (Facebook & Instagram)Pages, posting & login

What we access: app-scoped user ID, basic profile fields, and — where granted — Page/Instagram permissions to publish or manage content. We never store your login credentials or share tokens except with a service provider running the app.

How we use it: only for the services you request, exactly as described — no other purpose.

When collected: at connection and when you act through the integration.

Retention: deleted when no longer needed, on your request, if we stop the product, or if received in error. We honour Meta's deletion requests without undue delay.

Revoke & delete: Facebook → Settings → Business Integrations, or Instagram → Settings → Apps and Websites, or email us.

𝕏  X (formerly Twitter)Posting & login

What we access: your X account identifier, basic profile, and an OAuth token scoped to the actions you authorise.

How we use it: only to perform the actions you request; we don't build independent profiles or sell it.

When collected: at connection and when you post or act.

Retention: only as long as needed; tokens deleted on revocation.

Revoke & delete: X → Settings → Security and account access → Apps and sessions → Connected apps, or email us.

▶  Google & YouTubeLogin & content

What we access: for Google Sign-In, basic profile and email; for YouTube features, only the scopes the action needs. Use follows the Google API Services User Data Policy, including Limited Use.

How we use it: only to provide the feature you request; not for advertising, and not transferred except to provide/improve it, comply with law, or with your consent.

When collected: at sign-in and when you use a connected feature.

Retention: only as long as needed; tokens deleted on revocation.

Revoke & delete: myaccount.google.com/permissions, or email us.

Common to every integration: we request only the minimum a feature needs; act strictly on your instructions; never sell connected-platform data; keep it only as long as needed and within each platform's limits; and let you disconnect at any time. Each platform's own privacy terms also apply to your account with them.

8Third-Party Data Sharing

We share data only where necessary, with providers bound by DPAs under Art. 28:

  • Cloud & hosting — infrastructure providers operating within the EU/EEA.
  • Payment & finance — PCI-DSS-compliant payment/invoicing providers.
  • Payroll & statutory — certified payroll processors (HR product only).
  • Analytics & monitoring — performance, error tracking, usage analytics.
  • Connected platforms — services you explicitly link (Section 7).

We never sell your personal data. We may disclose data to competent authorities where required by law or court order, and personal data may transfer to a successor entity in a merger or acquisition, subject to equivalent protection.

9Sensitive & Special Category Data

Strict handling: Special category data (health, Art. 9) and sensitive identifiers (BSN, IBAN, ID documents) are processed only for a specific legal or service purpose, on an explicit legal basis, never stored in plain text in general databases, and never shared with marketing or analytics tools.

All such data is encrypted with AES-256 at rest and TLS 1.3 in transit (Art. 32), with access limited to authorised personnel or certified processors on a need-to-know basis.

10AI & Automated Processing

Some products include AI features. Where we improve AI models, we use anonymised or aggregated data wherever possible; special category and sensitive data are excluded from model training. Where an automated decision would have a significant legal effect, you have the right not to be subject to it on a solely automated basis (Art. 22) and may request human review. AI output is advisory only.

11Data Retention

We keep personal data only as long as needed, then delete or anonymise it:

  • Account data — for the life of your account, then deleted after closure (subject to legal holds).
  • Financial / payroll records — retained as required by Dutch tax law (typically 7 years).
  • Connected-platform data & tokens — only while the integration is active and within each platform's limits (see Section 7); deleted on revocation.
  • Marketing data — until you opt out or after a period of inactivity.

12International Data Transfers

We primarily process and host data within the EU/EEA. Where a service or connected platform (e.g. a US-based social provider) involves transfer outside the EEA, we rely on an appropriate safeguard under GDPR Chapter V — such as an adequacy decision or the European Commission's Standard Contractual Clauses — so your data keeps an equivalent level of protection.

13Cookies & Tracking Technologies

We use cookies governed by Telecommunicatiewet Art. 11.7a and GDPR Art. 5.

Always Active

Strictly Necessary

Authentication, sessions, security.

Consent Required

Analytics

Usage measurement & performance.

Consent Required

Marketing

Retargeting & personalisation.

Consent Required

Functional

Language & personalisation settings.

Manage preferences via the Cookie Preference Centre in the footer. Withdrawing consent doesn't affect prior lawful processing.

14Your Rights & Data Requests

Under GDPR Chapter III you have the rights to: access (Art. 15), rectification (Art. 16), erasure (Art. 17, subject to legal retention), restriction (Art. 18), portability (Art. 20), objection including to direct marketing (Art. 21), and human review of automated decisions (Art. 22).

To exercise a right, click a button below — your email app opens with the subject and a short template already filled in. Just add your details and send. We respond within 30 calendar days.

Include in your email: your full name, the email on your account, your phone (optional), and any connected platform your request relates to. To protect your privacy, we may verify your identity first.

Or email info@netherlandsit.nl. You may also complain to the Autoriteit Persoonsgegevens.

15Children's Privacy

Our products are intended for business users and adults. We do not knowingly collect personal data from children under 16 without appropriate parental or guardian consent as required by GDPR Art. 8. If you believe a child has provided us data, contact us and we will delete it.

16Security & Data Breaches

We apply industry-standard measures — Zero-Trust architecture, AES-256 at rest, TLS 1.3 in transit, and role-based access controls (Art. 32). In a breach we notify the Autoriteit Persoonsgegevens within 72 hours (Art. 33) and affected individuals where there is high risk (Art. 34). No system is perfectly secure, and while we work hard to protect your data, we cannot guarantee absolute security against every threat.

17Changes to This Policy

We may update this policy as our products and legal obligations evolve. Material changes are announced with a prominent notice on this website and, where they significantly affect registered users' rights, by email where practical. The "Effective Date" at the top shows the latest revision, and prior versions are available on request.

18Governing Law, Jurisdiction & Contact

This policy is governed by Dutch and EU law, including GDPR 2016/679. Disputes fall under the courts of 's-Gravenhage (The Hague), The Netherlands. EU ODR: ec.europa.eu/consumers/odr.

N

Privacy Contact — NetherlandsIT / AdMun

Email: info@netherlandsit.nl
Address: Oudemansstraat 315, 2522SW 's-Gravenhage, The Netherlands
Supervisory Authority: Autoriteit Persoonsgegevens


© 2026 NetherlandsIT / AdMun — KVK 84121998 — registered in The Netherlands.
Privacy & GDPR Policy v3.0 — Effective 14 July 2026 — Terms of Service | Healthcare Sub-Policy | Disclaimer