Discuss your project
Home

Privacy statement

How we handle personal data and how you can exercise your rights.

Last updated: 12 September 2026

1. Who is responsible

Brindle IT is the controller for the personal data described here.

Name
Brindle IT
Address
Elektraweg 5, 3144 CB Maassluis, The Netherlands
Chamber of Commerce
92644788

We are not required to appoint a data protection officer and have not appointed one. Privacy questions go to the address above and are handled by us directly.

2. What this covers

This statement covers the website brindle-it.nl and the correspondence that starts from it. Work we do inside a client's own systems is governed by the agreement with that client, usually including a data processing agreement, and not by this statement.

3. What we process, why, and for how long

Contact form and email

If you send us a message we process your name, email address, and — if you fill them in — your company and phone number, plus whatever you write in the message itself.

  • Purpose: to answer you, and to have the conversation that follows.
  • Legal basis: Article 6(1)(b) GDPR where your message concerns a possible agreement, and otherwise Article 6(1)(f), our legitimate interest in answering people who contact us. The consent checkbox on the form records that you understood what the details are used for; it does not turn into a marketing permission.
  • Retention: 24 months after our last contact, and longer only where an agreement or a statutory retention obligation requires it.
  • Providing it: entirely voluntary. Without an email address we cannot reply, which is the only consequence.

Server logs

Our web server records each request: IP address, date and time, the page requested, the HTTP status, the referring page and the browser identification.

  • Purpose: keeping the site available and secure, and investigating abuse or errors.
  • Legal basis: Article 6(1)(f) GDPR.
  • Retention: 90 days, then deleted.

Analytics

Only if you accept it. We use Google Analytics 4 to see which pages are read and how people arrive. Nothing is loaded and no cookie is set until you press accept; if you decline or ignore the question, the Google script is never requested at all.

  • Purpose: understanding how the site is used.
  • Legal basis: your consent, Article 6(1)(a) GDPR and Article 11.7a of the Dutch Telecommunications Act. You can withdraw it at any time on the cookie page, as easily as you gave it.
  • Retention: 14 months in Google Analytics.

The cookie statement lists the individual cookies and what each one does.

4. Who else sees it

We do not sell personal data and we do not share it for anyone else's marketing. It reaches these categories of recipient only:

  • Our hosting provider, which operates the infrastructure the site runs on, under a data processing agreement.
  • Our email provider, which carries and stores the messages you send us, under a data processing agreement.
  • Google Ireland Limited, for analytics, and only where you have accepted it.

5. Transfers outside the European Economic Area

The website and its logs are hosted within the EEA. If you accept analytics, Google may process data in the United States. Google LLC is certified under the EU-US Data Privacy Framework, for which the European Commission has issued an adequacy decision, and Google's standard contractual clauses apply in addition. Declining analytics avoids the transfer entirely.

6. Your rights

Under the GDPR you may ask us to:

  • Access the personal data we hold about you (Art. 15)
  • Correct it if it is wrong or incomplete (Art. 16)
  • Delete it (Art. 17)
  • Restrict what we do with it (Art. 18)
  • Receive it in a portable, machine-readable form (Art. 20)
  • Object to processing based on our legitimate interest (Art. 21)
  • Withdraw consent you have given, without affecting what was lawful before (Art. 7(3))

Email info@brindle-it.nl and we will answer within one month. If a request is complex we may extend that by two months and will tell you why within the first month. We may ask for confirmation of your identity, but only as much as is needed to be sure we are not handing your data to someone else.

7. Complaints

If you think we are handling your data wrongly, tell us first — it is usually the fastest route. You also have the right to lodge a complaint with the Dutch supervisory authority, the Autoriteit Persoonsgegevens, or with the authority in the EU country where you live or work.

8. Security

The site is served over HTTPS only, with HSTS, so traffic between your browser and our server cannot be read in transit. Access to the server and to the mailbox is limited to the people who need it and protected by multi-factor authentication. Systems are patched on a regular schedule. These are the measures Article 32 GDPR requires us to take and to keep appropriate as circumstances change.

9. Automated decision-making

We do not use your personal data for automated decision-making or profiling that produces legal effects or similarly significant effects for you.

10. Children

This site is aimed at professional users. We do not knowingly collect personal data from children.

11. Changes

When this statement changes we update the date at the top. Material changes to what we do with data you have already given us will be communicated directly rather than only published here.

For questions about your personal data, contact info@brindle-it.nl.