Privacy Statement

Chief IT B.V. respects your privacy. In this Privacy Statement, your right to privacy and our commitment to protecting your personal data are explained.

Chief IT B.V. is subject to European privacy legislation, including the General Data Protection Regulation (GDPR). This Privacy Statement is available on our website.

How and when this Privacy Statement applies

This Privacy Statement applies to all business processes within Chief IT. An explanation of our services can be found in the general terms and conditions.

The Privacy Statement provides information about data processing by Chief IT when we determine the purpose and means of the processing (Chief IT as data controller). It also provides information about data processing by Chief IT for Customers based on their instructions (the Customer as data controller and Chief IT as processor).

Personal data consists of information that can be used to identify you as a person, such as an email address, residential address, or telephone number. The processing of your personal data is necessary for our services. Do not use our website or services if you do not agree with the way we process personal data in accordance with this Privacy Statement.

Whose personal data does Chief IT process?

Chief IT processes personal data about job applicants and contact persons, and about software users of our Customers. In addition, we process personal data about individuals who are potential Customers (Leads) and who approach us via our website or other channels. Our statement on this matter can be found in the section regarding the data controller.

We also process data on behalf of our Customers, which is managed by the Customer. Our statement on this matter can be found in the section regarding the processor.

In this Privacy Statement, data subjects may also be referred to as individuals or you.

How Chief IT processes personal data in its role as data controller

When Chief IT determines the purpose and means of processing your personal data, this company is the data controller. This includes scenarios in which Chief IT collects personal data in a context where you are a job applicant, a representative of a Customer, a Lead, or a software user.

What are your rights?

The right to opt-out of receiving marketing communications

You have the right to opt-out of marketing communications from Chief IT and you can exercise this right by:

  • following the instructions to unsubscribe from the relevant marketing communication,
  • contacting us via the contact form

Please note that even if you choose not to receive marketing communications, you may still receive administrative communications from Chief IT, such as order confirmations and notices necessary to manage your account.

Basic rights

You have the right to access your personal data, the right to data portability, and the right to request that inaccuracies in your personal data be corrected. Furthermore, you have the right to submit a request for the deletion of your personal data, and to restrict or object to our processing thereof.

Use the contact form to submit all requests mentioned in this section. Finally, you have the right to file a complaint with the Dutch Data Protection Authority (Autoriteit Persoonsgegevens).

How Chief IT protects and stores personal data

How we secure your personal data 

Chief IT places the utmost importance on your trust. We are fully committed to preventing unauthorized access to, disclosure of, or other deviant processing of personal data. We will ensure the confidentiality, integrity, and availability of the personal data we process, in accordance with privacy legislation.

As part of our obligations, we use appropriate organizational, technical, and physical measures to protect the information we collect and process. The following measures are relevant in this regard:

Organizational

  • Internal supervision of the lawfulness of the processing and of the privacy policy.
  • Mandatory procedures for maintaining a register of processing activities.
  • Periodic awareness sessions with employees.
  • Data processing agreements with subcontractors who process data on behalf of Chief IT.

Technical

  • Classification of personal data in order to implement security measures according to the risk assessment.
  • Use of encryption where necessary as a risk-mitigating measure.
  • Restricting access to personal data to only those who need access.
  • Periodic self-assessments to analyze whether current measures are sufficient.

Physical

  • Our buildings are protected by means of appropriate access control.

How long we store your personal data 

Chief IT will only store your personal data for as long as is necessary for the stated purpose, also taking into account our obligation to answer questions or solve problems and to comply with legal requirements.

This means that Chief IT may retain your personal data for a reasonable period after you last had contact with us. When the collected personal data is no longer necessary, we will delete it.

How Chief IT protects and stores personal data as a processor 

Chief IT provides software and services to our Customers. These services include the processing of Customer data, including their personal data. The purposes of the processing are determined by our Customers, not by Chief IT, making the Customer the data controller. In these cases, Chief IT acts as a processor and processes the data on behalf of and according to the instructions of the Customer. The relationship between the Customer and Chief IT is governed by a data processing agreement.

Obligations of Customers and Chief IT

When the Customer acts as a data controller, the Customer will ensure the legal basis for the processing of personal data. The Customer is also responsible for the duty to inform the data subjects.

As a processor, Chief IT is obliged to process the data in accordance with privacy legislation. The Customer and Chief IT are obliged to cooperate to ensure the privacy of the data subjects. Chief IT will provide the information that the Customer needs to comply with applicable privacy legislation.

Changes to this Statement

When we amend this Privacy Statement, we will post the revised statement here, with an updated revision date. We encourage you to review the Statement regularly. In the event of significant changes, we may also notify you by other means, such as by sending an email or by posting a notice on our website.

Contacting us

If you have any comments or questions about our privacy statement, or about a possible breach of your privacy, please use the contact form. All your requests or complaints will be treated confidentially.