Effective date: 4 August 2026
Last updated: 4 August 2026
Version: 1.2.
This website, avandigo.nl, is operated by Avandigo ("we", "us"), a sole proprietorship (eenmanszaak) registered in the Netherlands.
Avandigo is the controller for the personal data described in this policy, meaning we determine why and how it is processed. We have not appointed a Data Protection Officer; this is not required under Article 37 GDPR given the nature and scale of our processing.
This policy covers data we collect through this website and through direct contact with us. It does not cover personal data we process on behalf of clients during a consulting engagement. In those cases the client is the controller and our processing is governed by a separate data processing agreement.
Our services are directed at businesses, not consumers. This policy is published in English, the working language of our client base.
When you contact us. If you submit our contact form, or reach us by email, WhatsApp or telephone, we process your name, email address, the content of your message and any files you attach. We do this to respond to you and to take steps at your request before entering into a contract. Legal basis: Article 6(1)(b) GDPR, pre-contractual steps, and Article 6(1)(f), our legitimate interest in handling business enquiries.
When you become a client or prospect. We process your name, email address, company, role and our correspondence with you in order to manage the relationship, send proposals and administer engagements. Legal basis: Article 6(1)(b) GDPR, performance of a contract.
When you subscribe to updates. We process your email address to send you updates, articles and information about our services. Legal basis: Article 6(1)(a) GDPR, your consent. You can withdraw it at any time.
When you book a call. We process your name, email address and meeting details in order to arrange and confirm the meeting. Legal basis: Article 6(1)(b) GDPR, pre-contractual steps.
When we invoice you. We process billing and transaction records to issue invoices and to meet our statutory accounting and tax obligations. Legal basis: Article 6(1)(c) GDPR, legal obligation.
When you visit the site. Our hosting provider records your IP address, browser and device information, the pages you visit and how you reached us. This supports website security, error diagnosis and basic traffic measurement. Legal basis: Article 6(1)(f) GDPR, our legitimate interest in operating a secure and functioning website.
When you submit a form. Google reCAPTCHA collects your IP address, device and browser signals and interaction data in order to distinguish human visitors from automated abuse. Legal basis: Article 6(1)(f) GDPR, our legitimate interest in protecting our forms against spam and abuse.
We do not knowingly collect special categories of personal data (Article 9 GDPR). Please do not send us health, biometric, political, religious or similar data through this website.
This website is not directed at children under 16 and we do not knowingly collect their data.
We use a small number of cookies. Some are required for the website to function and stay secure. Others measure how the site is used, or protect our forms against automated abuse.
We do not use advertising or retargeting pixels, and we do not use Google Analytics or any comparable third-party analytics platform.
The cookies in use are:
The traffic statistics cookies are set by our website platform and are not shared with third parties or used to track you across other websites. The reCAPTCHA cookie is set by Google and is necessary for our contact and subscription forms to function securely.
You can delete or block cookies through your browser settings at any time. Blocking them may prevent our forms from working.
We do not sell personal data. We share it only with service providers who process it on our instructions under a data processing agreement, and with authorities where legally required.
Our current processors are:
Our contact forms are protected by Google reCAPTCHA. Google's Privacy Policy and Terms of Service apply to that processing.
Some images and video on this site are served from third-party content delivery networks operated by GoDaddy and its media suppliers. Loading them discloses your IP address to those providers.
Our website is hosted in the European Union (Frankfurt region). Some of our providers are nonetheless established in the United States or process data there. Where personal data is transferred outside the EEA, we rely on one or more of the following safeguards under Chapter V GDPR:
You may request a copy of the relevant safeguard by writing to info@avandigo.nl.
GoDaddy, Google and Notion are each self-certified under the EU–U.S. Data Privacy Framework. You can verify their current status on the Data Privacy Framework List at dataprivacyframework.gov.
Enquiries that do not lead to an engagement are kept for twelve months from our last contact with you.
Client records and correspondence are kept for the duration of the engagement and for seven years afterwards. Invoices and accounting records are kept for seven years, as required by Article 52 of the Dutch General Tax Act.
Marketing subscriptions are kept until you unsubscribe or withdraw your consent.
Analytics cookies expire after one day and one year respectively, as set out in §3. Server and security logs are held by our hosting provider under its own retention terms; we do not have direct access to them.
Under the GDPR you have the right to:
To exercise any of these rights, write to info@avandigo.nl. We will respond within one month. We may ask you to confirm your identity first.
If you are not satisfied with how we handle your data, you may lodge a complaint with the Dutch supervisory authority:
Autoriteit Persoonsgegevens
Postbus 93374, 2509 AJ Den Haag
You may also complain to the supervisory authority where you live or work.
We apply technical and organisational measures appropriate to the risk, in line with Article 32 GDPR. These include encryption in transit, access control on all accounts, multi-factor authentication, and selection of providers that maintain recognised security certifications. No system can be made entirely secure, and we do not represent otherwise.
We do not carry out automated decision-making that produces legal effects concerning you or similarly significantly affects you, within the meaning of Article 22 GDPR.
We may update this policy. The version in force is the one published on this page, and the effective date is shown at the top. Material changes will be communicated where we are required to do so.
We use cookies to keep the site working, to count visits, and to protect our forms against automated abuse via Google reCAPTCHA. Details in our Privacy Policy.