Privacy Policy
Version v1 · en
Privacy Policy
Version: 2026-05-20 — English courtesy translation. The Dutch version is authoritative.
NOT LEGALLY VALID — REASONABLE DRAFT ONLY. This document is shipped as a starting point and must be reviewed and adapted by a qualified legal professional before production use. Do not rely on it as legal advice.
This privacy policy describes how Risk at Work B.V. ("we", "us", "our") processes personal data through (a) our marketing and information website and (b) the Stocktimal service we provide as a product. Where we process personal data on behalf of a client organisation in connection with its use of Stocktimal, we act as a processor; in that case our Data Processing Addendum (DPA) applies in addition to this policy.
We comply with the General Data Protection Regulation (Regulation (EU) 2016/679, "GDPR") and the Dutch GDPR Implementation Act (UAVG).
Contents
Part C (data-subject rights, international transfers, security, complaints, contact, and changes) applies to both Part A and Part B.
Part A — Website visitors
This part describes the processing that takes place when you visit our marketing website without logging in to an account — for example when you read our product pages, request a demo, submit the contact form, or subscribe to a newsletter.
A.1 Controller
For the processing in Part A, Risk at Work B.V. is the controller.
A.2 Categories of personal data and purposes
| Category of data | Purpose | Legal basis (Art. 6 GDPR) |
|---|---|---|
| Name, email address, telephone number, organisation, job title (submitted through the contact form or demo request) | Responding to your question, following up on your demo request, preparing a commercial relationship | Art. 6(1)(b) (pre-contractual steps at your request) and 6(1)(f) (legitimate interest: acquisition and customer communication) |
| Email address and preferences (on newsletter sign-up) | Sending periodic newsletters and product updates | Art. 6(1)(a) (consent); you can unsubscribe at any time via the link in each newsletter |
| Content of your message or query | Substantive handling of your request | Art. 6(1)(b) / 6(1)(f) |
| IP address, user-agent, page requests, referring URL, timestamps | Security, error diagnosis, basic usage statistics | Art. 6(1)(f) (legitimate interest: security and quality assurance of the site) |
| Cookie identifiers (strictly necessary cookies and, subject to your consent, analytics cookies) | Operation of the site and aggregate usage insight | Strictly necessary cookies: art. 11.7a Dutch Telecommunications Act (no consent required). Other cookies: Art. 6(1)(a) (consent) and art. 11.7a Tw |
A.3 Cookies
Our cookie policy is available at /legal/cookies. It lists the cookies we place, whether they are first- or third-party, their purpose, and how long they are retained. You can change your cookie preferences at any time through the cookie banner or your browser settings.
A.4 Recipients of your data
We share your data only with:
- Our website hosting provider — hosts the website and processing infrastructure.
- Our email and marketing-automation provider — sends confirmations, demo follow-ups, and newsletters.
- Our analytics and error-tracking provider — collects aggregated statistics and technical error logs, subject to your cookie preferences.
- Professional advisers (such as lawyers or accountants) where reasonably necessary.
- Competent authorities where legally required.
An up-to-date list of our suppliers that process personal data is available on request at info@raw-analytics.nl. Each supplier is contractually bound by confidentiality and appropriate security obligations.
A.5 Retention periods
| Category | Retention period |
|---|---|
| Contact and demo requests without follow-up | 12 months after the last contact |
| Commercial correspondence leading up to or during a customer relationship | Duration of the relationship plus 7 years (tax retention obligation) |
| Newsletter subscriptions | Until you unsubscribe; thereafter at most 3 months to process the unsubscribe |
| Server access logs | 90 days, unless extended in connection with a security incident |
| Analytics data | At most 14 months, aggregated and pseudonymised |
A.6 Profiling and automated decision-making
We do not make decisions on the marketing website based solely on automated processing that produce legal effects concerning you or significantly affect you.
Part B — Stocktimal product users
This part describes the processing that takes place when you log in to Stocktimal and use the service — either as an individual user or as an employee of a client organisation that has subscribed to Stocktimal.
B.1 Role allocation: controller and processor
Within Stocktimal we operate in two roles:
- We are controller for the data we need to keep the platform operational, secure, and billed: your account and login credentials, invoicing and subscription data, application and security logs, and product analytics. For this processing, this policy applies.
- We are processor for personal data that your organisation (the "client organisation") enters into or generates within Stocktimal and which relates to its own customers, employees, or other data subjects. For that processing, your client organisation is the controller and our DPA applies, available at /legal/dpa/v1. Data-subject requests concerning such data will be forwarded to the client organisation.
B.2 Categories of personal data and purposes (role: controller)
| Category of data | Purpose | Legal basis |
|---|---|---|
| Account data: email address, display name, language preference, time zone, organisation (tenant) membership, and roles within it | Authentication and authorisation; provision of the service to you | Art. 6(1)(b) (performance of the user agreement) |
| Authentication data: hashed password credentials or identity-provider credentials, MFA secrets, signed session and refresh tokens, login events (timestamp, IP, user-agent, outcome) | Secure login and session management, fraud and abuse detection | Art. 6(1)(b) and 6(1)(f) (legitimate interest: platform security) |
| Billing and subscription data: company name, VAT number, billing address, selected plan, invoices, payment status | Invoicing, accounting, collections | Art. 6(1)(b) and 6(1)(c) (legal obligation — accounting and tax law) |
| Operational logs and telemetry: system and application logs, audit events, performance and error metrics | Availability, security, troubleshooting, capacity planning | Art. 6(1)(f) (legitimate interest: secure and reliable service) |
| Product analytics: feature-usage statistics on an aggregate or pseudonymised level | Product improvement, planning of new functionality | Art. 6(1)(f) |
| Support correspondence: messages, tickets, and attachments you send us | Handling your support request | Art. 6(1)(b) and 6(1)(f) |
B.3 Content you enter into Stocktimal (role: processor)
When you or your colleagues upload or create content in Stocktimal — for example projects, documents, notes, files, or comments — that content may contain personal data. We process such data on the instructions of your client organisation. The purposes, retention periods, and legal bases are determined by the client organisation. For questions about this data you can contact your organisation; requests sent to us will be forwarded to the client organisation.
B.4 Cookies and similar technologies in the product
Stocktimal uses strictly necessary cookies or tokens for authentication (login, session persistence, CSRF protection) and for remembering your UI preferences. These cookies are functionally required to deliver the service and fall within article 11.7a(3) of the Dutch Telecommunications Act (no consent required). We do not place third-party tracking cookies for advertising purposes inside the product.
B.5 Recipients of your data
To deliver Stocktimal we engage suppliers (referred to as "sub-processors" for the components where we act as processor). Sub-processors process personal data only on our instructions and are contractually bound by confidentiality and equivalent security obligations.
The current list of sub-processors is available at /trust/sub-processors. In addition, we share data, where necessary and on a valid legal basis, with:
- Professional advisers (lawyers, accountants, auditors) under confidentiality.
- Competent authorities where legally required.
- An acquirer, in case of a merger or acquisition involving us; in that event the safeguards described here continue to apply.
B.6 Retention periods
| Category | Retention period |
|---|---|
| Account data | Duration of the agreement plus 90 days after termination (export period); thereafter we delete your account and related data, subject to legal retention obligations |
| Invoices and accounting records | 7 years (Dutch tax retention obligation, art. 52 AWR) |
| Operational logs and audit events | 90 days for routine logs; up to 12 months for security- and audit-relevant events |
| Error-tracking records | 90 days |
| Support tickets | 24 months after ticket closure |
| Back-ups | In accordance with our regular back-up cycle, typically up to 35 days; back-ups are encrypted and accessible only for restoration |
| Content entered by your organisation (processor role) | According to instructions from your client organisation; on termination as set out in the DPA |
B.7 Profiling and automated decision-making
We do not make decisions about you within Stocktimal based solely on automated processing that produce legal effects concerning you or significantly affect you. Where we apply anomaly detection to protect accounts, human review is always involved in any follow-up action.
B.8 Deletion at your request
As an individual user you can request deletion of your account through the account settings or via info@raw-analytics.nl. If you are a member of a client organisation, deletion may affect contributions you have made to that organisation; in such cases we coordinate in advance with the client organisation in accordance with its instructions.
Part C — Common provisions
C.1 Your rights
Under the GDPR you have the following rights with respect to your personal data:
- Right of access (Art. 15 GDPR) — you can request a copy of the personal data we hold about you.
- Right to rectification (Art. 16) — you can ask us to correct inaccurate or incomplete data.
- Right to erasure (Art. 17, "right to be forgotten") — you can request deletion where the legal conditions are met.
- Right to restriction of processing (Art. 18).
- Right to data portability (Art. 20) — for data you have provided to us on the basis of consent or a contract, in a structured, commonly used, and machine-readable format.
- Right to object (Art. 21) — to processing based on our legitimate interests.
- Right to withdraw consent (Art. 7(3)) — for processing based on consent; withdrawal does not affect the lawfulness of earlier processing.
- Right not to be subject to solely automated decision-making (Art. 22).
You can send a request to info@raw-analytics.nl. We respond within one month of receipt, extendable by a further two months where the request is complex or where we receive multiple requests. To verify your identity we may ask you for additional information.
Where the request concerns personal data for which a client organisation is the controller (see §B.1 and §B.3), we forward the request to the client organisation without undue delay.
C.2 International transfers
We aim to process personal data within the European Economic Area (EEA). Where a sub-processor or supplier is located outside the EEA and no European Commission adequacy decision applies, we base the transfer on the European Commission's Standard Contractual Clauses (Decision 2021/914), supplemented with appropriate additional measures (such as encryption, pseudonymisation, and policies on government access requests) where these are required on the basis of a transfer impact assessment. Up-to-date information per sub-processor is available at /trust/sub-processors.
C.3 Security
We implement appropriate technical and organisational measures to protect personal data, including:
- Encryption in transit (TLS 1.2 or higher) for all traffic to our services.
- Encryption at rest (AES-256 or equivalent) for personal data in production systems and back-ups.
- Role-based access control under a least-privilege principle, with individual accounts and mandatory multi-factor authentication for administrative access.
- Periodic review and automatic revocation of access rights.
- Logging and monitoring of access to personal data, with alerting on anomalies.
- Documented incident-response procedures, with a 48-hour notification to client organisations for any personal data breach affecting their data.
- Periodic security reviews and penetration testing.
- Security training for all personnel, on onboarding and periodically thereafter.
A more detailed overview of our measures is available at /trust.
C.4 Personal data breaches
If a personal data breach occurs that affects you, we will notify you without undue delay where the GDPR requires us to do so. Where we act as processor for a client organisation, we notify the client organisation within 48 hours; the client organisation then assesses the notification obligations to data subjects and the Supervisory Authority.
C.5 Complaints
If you are not satisfied with the way we process your personal data, we would like to hear from you first at info@raw-analytics.nl. You also have the right to lodge a complaint with the Supervisory Authority. In the Netherlands, this is the Dutch Data Protection Authority (Autoriteit Persoonsgegevens), P.O. Box 93374, 2509 AJ The Hague, autoriteitpersoonsgegevens.nl.
C.6 Contact
For questions about this privacy policy or about the processing of your personal data:
- Email: info@raw-analytics.nl
- Post: Risk at Work B.V., in Prinsenbeek (Netherlands)
- Chamber of Commerce number: 72356219
C.7 Changes
We may update this privacy policy from time to time, for example when laws or regulations change or when our services change. We will announce material changes on the website and, where possible, by email to account holders. Earlier versions are archived and remain available on request.
C.8 Language
This privacy policy is published in Dutch and is available in an English courtesy translation. In the event of any inconsistency between the language versions, the Dutch version prevails.