Legal
Privacy statement
DevAware respects your privacy. This statement sets out what personal data we process, why, and what rights you have under the GDPR.
This is an English translation of the Dutch Privacyverklaring. In the event of any difference in interpretation, the Dutch version prevails. Written in accordance with articles 13 and 14 of the GDPR.
Section 01
Introduction
DevAware (“we”, “us”, “our”) respects your privacy and is required under the General Data Protection Regulation (GDPR) to inform you transparently about how we process your personal data.
This privacy statement describes what data we collect, how we use it, who we share it with, and what rights you have.
Section 02
Data controller
| Organisation | DevAware |
| Owner | Taylen Doesburg |
| Chamber of Commerce | 96090685 |
| Location | Goes, the Netherlands |
| info@devaware.nl | |
| Website | devaware.eu |
Questions about your personal data? Get in touch at info@devaware.nl.
Section 03
Two roles
This statement covers data we process as a controller: visitors to this website, people who get in touch, and people who book a call.
When we work on an engagement for a client, we are usually a processor and the client is the controller. For those processing activities we conclude a data processing agreement per engagement, and the terms of that agreement apply rather than this statement. If you are an employee of a client and have questions about your data, please contact your own employer.
Section 04
What data we collect
Contact form. When you complete our contact form we collect your name, email address and your message. We use this to answer your question and to get back to you.
Calendly bookings. When you book a slot through our Calendly link (calendly.com/tdoesburg-devaware/30min) the following is collected: name, email address, phone number (optional), and calendar details such as date and time. This data is processed by Calendly and used for appointment management and reminders.
LinkedIn API. DevAware uses the LinkedIn Member Data Portability API to retrieve profile data, connection data and activity data, with the user’s consent. This data is used solely for internal analysis and activity records within DevAware. Only Taylen Doesburg, as owner of DevAware, has access to it. No external staff or partners are granted access unless this statement is updated. You can request deletion at any time via info@devaware.nl. Use of LinkedIn services is also subject to LinkedIn’s own privacy policy.
Server logs. Our web server automatically records your IP address, browser and device details, the pages you visit, and the date and time of visits. This is used for security and maintenance purposes.
Cookies. We use no analytics cookies (such as Google Analytics) and no tracking cookies. We may use functional cookies for session data and security. These are essential to the proper working of the website.
Section 05
Legal basis for processing
| Data category | Legal basis | Reason |
|---|---|---|
| Contact form | Legitimate interest (art. 6(1)(f)) | Answering your question |
| Calendly bookings | Consent (art. 6(1)(a)) | Appointment management with your agreement |
| LinkedIn API | Consent (art. 6(1)(a)) | Internal analysis and activity records |
| Server logs | Legitimate interest (art. 6(1)(f)) | Website security and maintenance |
| Functional cookies | Legitimate interest (art. 6(1)(f)) | Essential website use |
Section 06
Who we share your data with
Your personal data is shared only with the following external services, and only where necessary.
| Service | Purpose | What is processed |
|---|---|---|
| Calendly | Scheduling and appointment management | Booking and reminder data |
| Hostinger | Web hosting | Server logs, website availability |
| Member Data Portability API, where applicable | See the separate LinkedIn data portability policy |
We do not sell or rent your data to third parties.
Section 07
Transfers outside the EEA
Some of the services we use are provided by parties established outside the European Economic Area, in particular in the United States. Where personal data is transferred outside the EEA, we rely on the mechanisms set out below, as permitted under Chapter V of the GDPR.
| Service | Established in | Transfer mechanism |
|---|---|---|
| Calendly LLC | United States | EU-US Data Privacy Framework, self-certified, with the European Commission’s standard contractual clauses as fallback |
| Ireland | LinkedIn Ireland UC is the controller for users in the EEA. Any onward transfer is governed by LinkedIn’s own safeguards | |
| Hostinger | European Union | Not applicable, no transfer outside the EEA |
A stricter rule applies to client engagements: personal data we process on a client’s behalf stays within the EU, including the language models used. See the data processing agreement concluded per engagement.
Section 08
How long we keep your data
| Data category | Retention period | Reason |
|---|---|---|
| Contact form messages | 1 year | Records and correspondence |
| Calendly bookings | 2 years | Calendar reference and planning |
| LinkedIn API data | Until consent is withdrawn | Internal analysis and activity records |
| Server logs | 30 days | Security and troubleshooting |
| Functional cookies | Until cleared from your browser | Session data |
Once the retention period has passed, your data is deleted, unless we are required to keep it for legal or statutory purposes.
Section 09
Your rights under the GDPR
You have the following rights in relation to your personal data:
- Access. You can ask us what data we hold about you.
- Rectification. You can ask us to correct inaccurate or incomplete data.
- Erasure. You can ask us to delete your data, subject to certain conditions.
- Restriction. You can ask us to restrict processing of your data.
- Portability. You can request your data in a common format for transfer to another service.
- Objection. You can object to certain ways in which we process your data.
- Automated decision-making. DevAware does not use automated profiling or automated decision-making.
To exercise a right, email info@devaware.nl stating clearly which right you wish to exercise, and include your name and email address. We respond within 30 days.
Section 10
Complaints and enforcement
If you have a complaint about how we handle your data, you can contact the Dutch Data Protection Authority (Autoriteit Persoonsgegevens), at autoriteitpersoonsgegevens.nl, info@ap.nl, or Bezuidenhoutseweg 30, 2594 AV The Hague.
We would of course appreciate the chance to resolve your complaint first. Get in touch at info@devaware.nl.
Section 11
Security of your data
We take the security of your personal data seriously and apply appropriate technical and organisational measures:
- Encryption. Data transfer over HTTPS.
- Access control. Restricted to necessary personnel.
- Server security. Through Hostinger’s security infrastructure.
- Regular checks. Security updates and monitoring.
Despite these precautions we cannot guarantee absolute security. Please use the internet with common sense.
Section 12
Links to external websites
This website may contain links to external websites such as Calendly and LinkedIn. This privacy statement applies only to devaware.eu. We are not responsible for the privacy practices of external sites.
Section 13
Changes to this statement
We may amend this privacy statement from time to time to comply with regulation or to reflect changed practices. The “last updated” date at the top shows when we last revised it.
In the event of significant changes we will inform you by email, where an address is available.
Section 14
Contact details
For questions, requests or comments about this privacy statement:
| Organisation | DevAware |
| info@devaware.nl | |
| Website | devaware.eu |
| Location | Goes, the Netherlands |
Related: terms and conditions, the contractual terms for DevAware quotations and services. Questions about this statement: info@devaware.nl