1. Who is responsible?
NorthBridge Group ICT Services B.V., trading as NorthBridge, is the controller for the processing described here.
Dutch Chamber of Commerce 71512551
Laan van 's-Gravenmade 74
2495 AJ The Hague
The Netherlands
info@north-bridge.nl
+31 70 782 08 40
You can also use this email address for a privacy question or request.
2. Website, logs and statistics
Technical logs
Our web server temporarily processes technical data including IP address, time, requested page, browser characteristics and, where available, the referring page. This is necessary to keep the website available and secure, investigate misuse and resolve technical faults. We rely on our legitimate interest in operating a reliable and secure website.
Privacy-friendly counts
Our VPS produces aggregated counts of page views, sessions, technical errors and predefined campaign codes. We do not place browser cookies or load an external analytics tracker for this purpose. Raw identifiers are not included in the statistics dashboard.
External links and media
NorthBridge hosts its own videos and map images. An external party such as Google Maps, LinkedIn or a news source receives data only when you deliberately follow an external link. The third party’s privacy terms then apply.
4. Contact, support and services
When you call, email, submit a contact request or ask for support, we use the information needed to respond. This may include your name, business contact details, organisation, role, the content of your request, appointments and technical or contractual correspondence.
The legal basis is performance of a contract or taking steps at your request before entering into one. We may also have a legitimate interest in security, quality and maintaining a reliable record of business arrangements. Information that must be retained by law is processed to meet that obligation.
Do not send passwords, secret keys or other authentication details through ordinary email or a public form. Agree a suitable route with us first for sensitive technical information.
5. Checks, report requests and events
An IT Quickscan or Digital Resilience Check can initially be completed in the browser. We process your email address, responses, result and necessary technical data only when you request a report or follow-up.
For an event we may process a name, business email address, organisation, role, attendee count and a voluntarily submitted question. We use these details for assessment, capacity, confirmation, preparation and relevant follow-up. A request does not automatically subscribe you to general marketing.
We rely on fulfilling your request and our legitimate interest in handling it carefully and securely. We do not make decisions based solely on automated processing that produce legal or similarly significant effects.
7. How long do we retain data?
We keep personal data no longer than necessary, unless a legal duty, ongoing contract or possible legal claim requires a longer period.
- Web server logs: approximately 14 days in the normal cycle.
- Aggregated web statistics: a rolling 30-day window without raw identifiers in the dashboard.
- Privacy preference: up to 12 months in local browser storage, after which we ask for a fresh choice.
- Google Ads conversion cookies: only after consent and for up to 90 days according to Google; browser restrictions may shorten this period.
- Contact and check requests without follow-up: normally deleted or anonymised within 90 days.
- Event registrations: for the stated activity period; generally within one month after the event where there is no follow-up.
- Support and client records: during the service and afterwards for as long as reasonably necessary for agreements, security, disputes and statutory administration.
8. Your rights
Depending on the circumstances, you may request access, correction, erasure, restriction or portability. You may object where processing is based on legitimate interests. Where processing is based on consent, you may withdraw it for the future.
Email info@north-bridge.nl. We may request additional information to verify your identity and normally respond within one month. You may also complain to the Dutch Data Protection Authority.
9. Security and changes
We use appropriate technical and organisational measures. What is appropriate depends on the type of data, the risk and the service involved. This public statement deliberately avoids details that could weaken security.
We review this statement at least annually and after material changes to our website, services, suppliers or legal duties.