Avandigo

+31 6 19281412

+31 6 19281412

Avandigo

    Privacy Policy

    Effective date: 4 August 2026

    Last updated: 4 August 2026

    Version: 1.2.


    1. Who we are

    This website, avandigo.nl, is operated by Avandigo ("we", "us"), a sole proprietorship (eenmanszaak) registered in the Netherlands.

    • Registered address: Rouboslaan 36, 2252 TR Voorschoten, Netherlands
    • Chamber of Commerce (KvK) number: 82152659
    • Contact for privacy matters: info@avandigo.nl

    Avandigo is the controller for the personal data described in this policy, meaning we determine why and how it is processed. We have not appointed a Data Protection Officer; this is not required under Article 37 GDPR given the nature and scale of our processing.

    This policy covers data we collect through this website and through direct contact with us. It does not cover personal data we process on behalf of clients during a consulting engagement. In those cases the client is the controller and our processing is governed by a separate data processing agreement.

    Our services are directed at businesses, not consumers. This policy is published in English, the working language of our client base.


    2. What we collect and why

    When you contact us. If you submit our contact form, or reach us by email, WhatsApp or telephone, we process your name, email address, the content of your message and any files you attach. We do this to respond to you and to take steps at your request before entering into a contract. Legal basis: Article 6(1)(b) GDPR, pre-contractual steps, and Article 6(1)(f), our legitimate interest in handling business enquiries.

    When you become a client or prospect. We process your name, email address, company, role and our correspondence with you in order to manage the relationship, send proposals and administer engagements. Legal basis: Article 6(1)(b) GDPR, performance of a contract.

    When you subscribe to updates. We process your email address to send you updates, articles and information about our services. Legal basis: Article 6(1)(a) GDPR, your consent. You can withdraw it at any time.

    When you book a call. We process your name, email address and meeting details in order to arrange and confirm the meeting. Legal basis: Article 6(1)(b) GDPR, pre-contractual steps.

    When we invoice you. We process billing and transaction records to issue invoices and to meet our statutory accounting and tax obligations. Legal basis: Article 6(1)(c) GDPR, legal obligation.

    When you visit the site. Our hosting provider records your IP address, browser and device information, the pages you visit and how you reached us. This supports website security, error diagnosis and basic traffic measurement. Legal basis: Article 6(1)(f) GDPR, our legitimate interest in operating a secure and functioning website.

    When you submit a form. Google reCAPTCHA collects your IP address, device and browser signals and interaction data in order to distinguish human visitors from automated abuse. Legal basis: Article 6(1)(f) GDPR, our legitimate interest in protecting our forms against spam and abuse.

    We do not knowingly collect special categories of personal data (Article 9 GDPR). Please do not send us health, biometric, political, religious or similar data through this website.

    This website is not directed at children under 16 and we do not knowingly collect their data.


    3. Cookies and similar technologies

    We use a small number of cookies. Some are required for the website to function and stay secure. Others measure how the site is used, or protect our forms against automated abuse.

    We do not use advertising or retargeting pixels, and we do not use Google Analytics or any comparable third-party analytics platform.

    The cookies in use are:

    • dps_site_id (GoDaddy) identifies the hosting region serving the site, and expires at the end of your session.
    • _scc_session (GoDaddy) maintains your session while you browse, and expires at the end of your session.
    • cookie_warning_dismissed (Avandigo) records that you have seen our cookie notice, and expires after two months.
    • _tccl_visit (GoDaddy) measures a single visit for traffic statistics, and expires after one day.
    • _tccl_visitor (GoDaddy) distinguishes returning visitors for traffic statistics, and expires after one year.
    • __Secure-ENID (Google) is set by Google reCAPTCHA, which protects our forms against automated abuse, and expires after thirteen months.

    The traffic statistics cookies are set by our website platform and are not shared with third parties or used to track you across other websites. The reCAPTCHA cookie is set by Google and is necessary for our contact and subscription forms to function securely.

    You can delete or block cookies through your browser settings at any time. Blocking them may prevent our forms from working.


    4. Who we share data with

    We do not sell personal data. We share it only with service providers who process it on our instructions under a data processing agreement, and with authorities where legally required.

    Our current processors are:

    • GoDaddy (GoDaddy.com LLC / GoDaddy Online Services Cayman Islands Ltd.) — website hosting, content management, contact form handling, customer records, email marketing, and website analytics
    • Google (Google Ireland Limited) — email, calendar and meeting scheduling
    • Notion (Notion Labs, Inc.) — internal documentation and project records
    • Meta (WhatsApp Ireland Limited) — where you choose to contact us via WhatsApp

    Our contact forms are protected by Google reCAPTCHA. Google's Privacy Policy and Terms of Service apply to that processing.

    Some images and video on this site are served from third-party content delivery networks operated by GoDaddy and its media suppliers. Loading them discloses your IP address to those providers.


    5. Transfers outside the European Economic Area

    Our website is hosted in the European Union (Frankfurt region). Some of our providers are nonetheless established in the United States or process data there. Where personal data is transferred outside the EEA, we rely on one or more of the following safeguards under Chapter V GDPR:

    • an adequacy decision, including the EU–US Data Privacy Framework where the provider is certified; or
    • the European Commission's Standard Contractual Clauses, together with supplementary measures where necessary.

    You may request a copy of the relevant safeguard by writing to info@avandigo.nl.

    GoDaddy, Google and Notion are each self-certified under the EU–U.S. Data Privacy Framework. You can verify their current status on the Data Privacy Framework List at dataprivacyframework.gov.


    6. How long we keep data

    Enquiries that do not lead to an engagement are kept for twelve months from our last contact with you.

    Client records and correspondence are kept for the duration of the engagement and for seven years afterwards. Invoices and accounting records are kept for seven years, as required by Article 52 of the Dutch General Tax Act.

    Marketing subscriptions are kept until you unsubscribe or withdraw your consent.

    Analytics cookies expire after one day and one year respectively, as set out in §3. Server and security logs are held by our hosting provider under its own retention terms; we do not have direct access to them.


    7. Your rights

    Under the GDPR you have the right to:

    • access the personal data we hold about you and receive a copy;
    • rectify data that is inaccurate or incomplete;
    • erase your data where a ground in Article 17 applies;
    • restrict processing in the circumstances set out in Article 18;
    • data portability for data you provided on the basis of consent or contract;
    • object to processing based on our legitimate interests, and to object to direct marketing at any time;
    • withdraw consent at any time, without affecting the lawfulness of processing carried out before withdrawal.

    To exercise any of these rights, write to info@avandigo.nl. We will respond within one month. We may ask you to confirm your identity first.

    If you are not satisfied with how we handle your data, you may lodge a complaint with the Dutch supervisory authority:

    Autoriteit Persoonsgegevens

    Postbus 93374, 2509 AJ Den Haag

    autoriteitpersoonsgegevens.nl

    You may also complain to the supervisory authority where you live or work.


    8. Security

    We apply technical and organisational measures appropriate to the risk, in line with Article 32 GDPR. These include encryption in transit, access control on all accounts, multi-factor authentication, and selection of providers that maintain recognised security certifications. No system can be made entirely secure, and we do not represent otherwise.


    9. Automated decision-making

    We do not carry out automated decision-making that produces legal effects concerning you or similarly significantly affects you, within the meaning of Article 22 GDPR.


    10. Changes to this policy

    We may update this policy. The version in force is the one published on this page, and the effective date is shown at the top. Material changes will be communicated where we are required to do so.


    Copyright © 2026 Avandigo - All Rights Reserved.

    Avandigo
    KvK 82152659

    • Privacy Policy
    • AI Transparency Statement

    This website uses cookies.

    We use cookies to keep the site working, to count visits, and to protect our forms against automated abuse via Google reCAPTCHA. Details in our Privacy Policy.

    DeclineAccept