Skip to content
NorthBridge
Services
Explore all services →
Advisory & changeIT ArchitectureMigrationGenerative AI
Cloud & workplaceCloud & InfrastructureModern WorkplaceData sovereignty
Resilience & operationsSecurity & digital resilienceNetwork & SecurityManaged Services & governance
Frameworks & legislationDutch Cybersecurity Act (NIS2)
ApproachCase studiesAbout usContactSupportIT Quickscan
NL/EN

Privacy & cookies

Your data deserves a clear explanation.

This statement explains which personal data NorthBridge uses, why it is needed, how long it is retained and which tracking choices we deliberately do not make.

Version 1.2 · 17 August 2026

On this pageControllerWebsite and statisticsCookies and trackingContact and servicesChecks and reportsEventsRecipients and transfersRetentionYour rightsSecurity and changes

1. Who is responsible?

NorthBridge Group ICT Services B.V., trading as NorthBridge, is the controller for the processing described here.

Dutch Chamber of Commerce 71512551
Laan van 's-Gravenmade 74
2495 AJ The Hague
The Netherlands
info@north-bridge.nl
+31 70 782 08 40

You can also use this email address for a privacy question or request.

2. Website, logs and statistics

Technical logs

Our web server temporarily processes technical data including IP address, time, requested page, browser characteristics and, where available, the referring page. This is necessary to keep the website available and secure, investigate misuse and resolve technical faults. We rely on our legitimate interest in operating a reliable and secure website.

Privacy-friendly counts

Our VPS produces aggregated counts of page views, sessions, technical errors and predefined campaign codes. We do not place browser cookies or load an external analytics tracker for this purpose. Raw identifiers are not included in the statistics dashboard.

Organic LinkedIn referrals

When a NorthBridge organic LinkedIn post links to the website, the link may carry a predefined campaign and content code. The VPS then counts only in aggregate which valid NorthBridge-issued code led to a website visit or successful request. LinkedIn platform statistics and website outcomes remain separate. We do not place a LinkedIn tag or browser cookie for this, and do not use browser scraping.

The official LinkedIn API is not connected at this stage. Only after formal approval, a limited technical test and a separate decision may we process platform statistics through that API. We will not use member profiles for this website analysis.

After a successful IT Quickscan, Digital Resilience Check or contact request, the VPS additionally records only the request type, page language, UTC time and a random non-reversible transaction code. These technical event records are kept for no more than 35 days; reports and the administration portal contain aggregate counts only.

External links and media

NorthBridge hosts its own videos and map images. An external party such as Google Maps, LinkedIn or a news source receives data only when you deliberately follow an external link. The third party’s privacy terms then apply.

3. Cookies and additional measurement

Cookieless statistics on our VPS remain the baseline. Google Ads may additionally measure whether a requested IT Quickscan report, Digital Resilience Check report or contact form was submitted successfully, but only after your active consent. Without that consent, we do not load the Google tag, make a request to Google or read or write advertising cookies.

The preference panel separates necessary storage from marketing measurement. Accept all, reject all and preferences are equally available choices. You can change or withdraw your choice at any time through Cookie preferences in the website footer. Refusal does not restrict ordinary access to the website or its forms.

Cookie and vendor inventory

  • northbridge_consent_v1 — NorthBridge local browser storage; remembers only your necessary and marketing choice for up to 12 months. It contains no name, email address or form content.
  • _gcl_* — Google Ads cookies used to relate an advertising interaction to a completed conversion; only after marketing consent, for up to 90 days according to Google. Browser restrictions may shorten this period.
  • Google tag and conversion event — only after marketing consent. The event records solely which of the three predefined forms was completed successfully. NorthBridge does not send a name, email address, telephone number, message, check responses or report content to Google through this event.

Google Analytics, remarketing, ad personalisation, enhanced conversions and offline conversion imports remain disabled in this first measurement phase. Consent for analytics and ad personalisation remains denied even after marketing consent.

For permitted conversion measurement, Google processes technical information including browser and device information, IP address, page URL, time and available advertising-click or conversion identifiers. See Google’s Privacy Policy and Google’s explanation of cookies.

4. Contact, support and services

When you call, email, submit a contact request or ask for support, we use the information needed to respond. This may include your name, business contact details, organisation, role, the content of your request, appointments and technical or contractual correspondence.

The legal basis is performance of a contract or taking steps at your request before entering into one. We may also have a legitimate interest in security, quality and maintaining a reliable record of business arrangements. Information that must be retained by law is processed to meet that obligation.

Do not send passwords, secret keys or other authentication details through ordinary email or a public form. Agree a suitable route with us first for sensitive technical information.

5. IT Quickscan and Digital Resilience Check

You can view the on-screen result without providing personal data. Only when you request a PDF report do we process your email address, the answers provided, the calculated result and the technical data needed to handle the request reliably.

We use this information to create and deliver the requested report and to respond specifically to that request. Requesting a report does not subscribe you to a general newsletter. We rely on fulfilling your request and our legitimate interest in careful follow-up and service security.

6. Events and round-table sessions

For an event, we process your name, business email address, organisation, role, number of places requested and any optional short explanation. We do not request personal data about a possible second attendee in the request form.

We use this information only to assess the request, manage capacity, communicate the final format and practical details personally, and where appropriate confirm a place. An event registration is not a newsletter subscription.

We rely on fulfilling your registration and our legitimate interest in organising a safe, relevant and well-run event. We do not share an attendee list. Where needed, we request separate, voluntary consent in advance for photography, recordings, testimonials or a separate mailing.

Use the free-text field only for the broad outline of your question. Do not include IP addresses, hostnames, vulnerability details, credentials or other sensitive technical information.

7. Who receives personal data?

NorthBridge does not sell personal data. We share it only where necessary for the purposes explained here, to meet a legal obligation or with your consent.

  • hosting and infrastructure providers;
  • Zendesk for support, report requests and configured forms;
  • Google Ads, only after your consent, for the limited conversion measurement described above;
  • LinkedIn, only after a future formally approved API connection for aggregated statistics from our company page and organic posts; no connection is active now;
  • email, telephony and collaboration providers;
  • professional advisers or competent authorities where legally necessary.

We put suitable arrangements in place with processors. Where processing takes place outside the European Economic Area, we use a valid transfer mechanism and appropriate safeguards. You may ask us for information about safeguards relevant to a specific processing activity.

8. How long do we retain data?

We keep personal data no longer than necessary, unless a legal duty, ongoing contract or possible legal claim requires a longer period.

  • Web server logs: approximately 14 days in the normal cycle.
  • Aggregated web statistics: a rolling 30-day window without raw identifiers in the dashboard.
  • Technical backend-success records: no more than 35 days; reports contain aggregate counts only.
  • Privacy preference: up to 12 months in local browser storage, after which we ask for a fresh choice.
  • Google Ads conversion cookies: only after consent and for up to 90 days according to Google; browser restrictions may shorten this period.
  • Aggregated LinkedIn platform statistics: only after formal API approval and activation, for no more than 12 months in NorthBridge reporting. Website outcomes remain cookieless aggregated VPS counts.
  • Round-table registration for 18 September 2026: the registration list and separate registration details will be removed by 18 October 2026, unless you arrange a follow-up or a longer statutory retention period applies.
  • Contact and check requests without follow-up: normally deleted or anonymised within 90 days.
  • Support and client records: during the service and afterwards for as long as reasonably necessary for agreements, security, disputes and statutory administration.

9. Your rights

Depending on the circumstances, you may request access, correction, erasure, restriction or portability. You may object where processing is based on legitimate interests. Where processing is based on consent, you may withdraw it for the future.

Email info@north-bridge.nl. We may request additional information to verify your identity and normally respond within one month. You may also complain to the Dutch Data Protection Authority.

10. Security and changes

We use appropriate technical and organisational measures. What is appropriate depends on the type of data, the risk and the service involved. This public statement deliberately avoids details that could weaken security.

We review this statement at least annually and after material changes to our website, services, suppliers or legal duties.

© NorthBridge
Privacy & cookiesTerms and conditionsCode of ConductSustainability