Privacy and browser storage
Last updated: 11 August 2026. This policy explains which information DataCompagnie processes, why it is used, and what choices you have.
1. Controller and contact
DataCompagnie is responsible for personal information received through this website and private portal. The public privacy route can be used for questions before an account exists; signed-in customers can submit a tracked rights request from their account.
2. Information processed
3. Purposes and legal bases
Contact details and messages are processed to answer a request and, where relevant, take steps before entering into a contract. Newsletter details are processed after a subscription. Talent-pool details are used to assess a possible future match. Customer details are shared with a talent only after case-specific permission. Limited technical log data may be processed for the legitimate interest of securing the website and investigating faults.
4. Cookies and local browser storage
The website does not load advertising or analytics cookies. Form and admin pages use a necessary session cookie named dc_session for form security and sign-in. It expires when the browser session ends. The browser may also store two local preferences:
These preferences stay on your device. The theme colour can be reset from the theme-colour control; both preferences can be removed through browser settings.
5. Retention and security
Unverified requests are scheduled for deletion after 90 days. Verified requests that are explicitly unused or declined are kept for 3 years. Requests used commercially are kept for 7 years after closure or after the agreement is no longer current. Where commercial use is not yet known, the 7-year period is used. Pending talent-pool applications are scheduled for deletion one year after submission; rejected or archived applications one year after the latest status decision. Approved records remain while a possible match is relevant and are archived when that ends. The contents of completed, declined, or closed privacy-rights requests are removed after 3 years. A documented legal hold pauses automatic deletion. When a period expires, unnecessary message bodies, attachments, tokens, and account identifiers are removed; only minimal evidence required for legal or accounting purposes remains. Newsletter details are removed within 30 days after unsubscribe. Ordinary rate-limit records are removed after 2 days, expired or used access tokens after 7 days, sent notification records after 90 days, and audit events after 7 years.
Sessions expire after 60 minutes of customer inactivity (12 hours absolute) or 30 minutes of administrator inactivity (8 hours absolute). Tokens are single-use and time-limited. Attachments are checked for size, allowed MIME type, and basic file structure, then stored in a directory that rejects direct web access; the application does not claim full malware scanning. Access is recorded, but no internet service can guarantee absolute security.
6. Your rights
You may request access, correction, deletion, restriction, objection, or portability where the GDPR grants that right. Newsletter consent can be withdrawn at any time. Provide enough information to identify the relevant submission. Additional verification may be required before personal information is disclosed or deleted.
You may also lodge a complaint with the Dutch Data Protection Authority.