Privacy and browser storage

Last updated: 11 August 2026. This policy explains which information DataCompagnie processes, why it is used, and what choices you have.

1. Controller and contact

DataCompagnie is responsible for personal information received through this website and private portal. The public privacy route can be used for questions before an account exists; signed-in customers can submit a tracked rights request from their account.

2. Information processed

Enquiries: name, email, optional company, message, and the selected service or profile skill with its contact context.
Files: an optional PDF, JPEG, or PNG attachment of no more than 5 MB.
Newsletter: the submitted email address.
Talent-pool applications: name, email, expertise, experience, location, availability, and message.
Technical security information: normal server logs may contain an IP address, time, requested page, and browser information.
Private portal: account status, verification and activation events, login attempts, conversation replies, attachment metadata, privacy requests, and audit events.

3. Purposes and legal bases

Contact details and messages are processed to answer a request and, where relevant, take steps before entering into a contract. Newsletter details are processed after a subscription. Talent-pool details are used to assess a possible future match. Customer details are shared with a talent only after case-specific permission. Limited technical log data may be processed for the legitimate interest of securing the website and investigating faults.

Form data is restricted to the protected admin area, database, and technically necessary hosting services.
New attachments receive a random, extensionless storage name in a protected upload directory that rejects direct web access.
Information is not sold and no advertising profiles are created.
Information is shared with another specialist only when the enquiry requires it and this has been made clear beforehand.
Cloudflare Turnstile receives technically necessary request and browser information to distinguish automated abuse from a person. The form will not submit when this required security check is unavailable.
The hosting/database provider stores the application data. The authenticated SMTP provider processes content-free notifications sent from [email protected]. Notification emails do not include request text, reply text, or attachment names.

4. Cookies and local browser storage

The website does not load advertising or analytics cookies. Form and admin pages use a necessary session cookie named dc_session for form security and sign-in. It expires when the browser session ends. The browser may also store two local preferences:

dcStorageNotice remembers that the storage notice was read.
dcAccentColor remembers the theme colour selected on the public website.

These preferences stay on your device. The theme colour can be reset from the theme-colour control; both preferences can be removed through browser settings.

5. Retention and security

Unverified requests are scheduled for deletion after 90 days. Verified requests that are explicitly unused or declined are kept for 3 years. Requests used commercially are kept for 7 years after closure or after the agreement is no longer current. Where commercial use is not yet known, the 7-year period is used. Pending talent-pool applications are scheduled for deletion one year after submission; rejected or archived applications one year after the latest status decision. Approved records remain while a possible match is relevant and are archived when that ends. The contents of completed, declined, or closed privacy-rights requests are removed after 3 years. A documented legal hold pauses automatic deletion. When a period expires, unnecessary message bodies, attachments, tokens, and account identifiers are removed; only minimal evidence required for legal or accounting purposes remains. Newsletter details are removed within 30 days after unsubscribe. Ordinary rate-limit records are removed after 2 days, expired or used access tokens after 7 days, sent notification records after 90 days, and audit events after 7 years.

Sessions expire after 60 minutes of customer inactivity (12 hours absolute) or 30 minutes of administrator inactivity (8 hours absolute). Tokens are single-use and time-limited. Attachments are checked for size, allowed MIME type, and basic file structure, then stored in a directory that rejects direct web access; the application does not claim full malware scanning. Access is recorded, but no internet service can guarantee absolute security.

6. Your rights

You may request access, correction, deletion, restriction, objection, or portability where the GDPR grants that right. Newsletter consent can be withdrawn at any time. Provide enough information to identify the relevant submission. Additional verification may be required before personal information is disclosed or deleted.

You may also lodge a complaint with the Dutch Data Protection Authority.