Legal · GDPR

Privacy Policy

RenDealsLast updated:

Placeholders: Complete every field before publishing. This policy is drafted for a company established in the Netherlands and reflects the EU General Data Protection Regulation (GDPR) and the Dutch implementation act (UAVG). Because your data flows, sub-processors, and retention periods depend on how you actually operate, have a Dutch lawyer or privacy adviser review it before it goes live.

This Privacy Policy explains how RenDeals collects, uses, shares, and protects your personal data, and the rights you have under the GDPR. It applies to your use of the RenDeals website and platform (the "Platform").

01Data controller

The data controller responsible for your personal data is , a company established in the Netherlands, registered with the Dutch Chamber of Commerce (KvK) under number , with registered address at . For any privacy matter, contact us at .

Data Protection Officer (DPO):

02Data we collect

CategoryExamples
Identity & contactName, company name, job title, e-mail, phone number, business address
Account dataUsername, password (stored hashed), account preferences
Transaction & listing dataProject details, interests, messages, documents you upload
Billing dataBilling details, invoices, VAT/tax number (as needed for fees)
Technical dataIP address, device and browser type, log records, cookie identifiers
Usage dataPages viewed, features used, interactions on the Platform

We collect data you provide directly (e.g. when registering, listing a project, or contacting us) and data collected automatically as you use the Platform. We do not intentionally collect special categories of data (such as health or biometric data) through the Platform.

03Purposes & legal bases

Under Article 6 of the GDPR, we process personal data on the following legal bases:

Where we rely on legitimate interests, we have balanced those interests against your rights and freedoms. You may ask us for more information about this balancing at any time.

04Sharing & processors

We may share personal data with:

We do not sell your personal data.

05International transfers

Your personal data is primarily hosted within the European Economic Area (EEA) . Transfers of personal data within the EEA are not subject to additional transfer restrictions under the GDPR.

If we ever transfer personal data to a country outside the EEA — for example to a sub-processor located abroad — we will do so only where an adequate level of protection is ensured, on the basis of an EU adequacy decision or appropriate safeguards such as the European Commission's Standard Contractual Clauses (SCCs), together with any supplementary measures required.

06Retention

We keep personal data only for as long as necessary for the purposes described above and to meet legal, tax, and accounting obligations, after which it is deleted or anonymised.

07Security

We take appropriate technical and organisational measures to protect personal data against unauthorised access, loss, or misuse — including access controls, encryption in transit and at rest where appropriate, multi-factor authentication for administrative access, and regular review of our security practices. No system is completely secure, but we work to protect your data in line with the GDPR.

08Data breaches

If a personal data breach occurs that is likely to result in a risk to your rights and freedoms, we will notify the Dutch Data Protection Authority (Autoriteit Persoonsgegevens) without undue delay and, where feasible, within 72 hours of becoming aware of it. Where the breach is likely to result in a high risk to you, we will also inform you directly, in accordance with Articles 33 and 34 of the GDPR.

09Cookies

We use cookies and similar technologies to operate the Platform, remember your preferences, and analyse usage. Under the Dutch Telecommunications Act (Telecommunicatiewet) and the GDPR, we place non-essential cookies (such as analytics or marketing cookies) only with your consent. Our cookie banner lets you accept or reject non-essential cookies, with the "reject" option shown as clearly as the "accept" option, and you can change your choice at any time.

10Your rights

Under the GDPR, you have the right to:

11How to exercise your rights

You can submit a request by writing to . We will respond within one month, which may be extended by up to two further months for complex or numerous requests, in which case we will let you know. There is normally no charge for exercising your rights.

12Children

The Platform is a business-to-business service intended for professionals and is not directed at children. Under the Dutch UAVG, the age of digital consent is 16. We do not knowingly collect personal data from anyone under that age.

13Changes to this policy

We may update this Privacy Policy from time to time. When we make material changes, we will post the updated version on the Platform and revise the "last updated" date above.

14Contact & complaints

For any question about this policy or your personal data, contact at or .

If you are not satisfied with our response, you have the right to lodge a complaint with the Dutch Data Protection Authority, the Autoriteit Persoonsgegevens (AP), at autoriteitpersoonsgegevens.nl, or with the supervisory authority in your own EU/EEA country of residence.