Privacy Policy – 079-Schilderwerken
This privacy policy applies to all processing of personal data by 079-Schilderwerken, established in Zoetermeer, the Netherlands. We process personal data in accordance with the General Data Protection Regulation (GDPR) and related Dutch laws and regulations.
1. Data Controller
079-Schilderwerken
Established in Zoetermeer, the Netherlands
Email:
Phone: 06-48075395
079-Schilderwerken is the data controller within the meaning of the GDPR for the processing activities described in this privacy policy.
2. Purposes and Legal Bases for Processing
We process personal data solely for specified, explicit and legitimate purposes. Processing only takes place where there is a legal basis pursuant to Article 6 of the GDPR.
- Performance of a contract: preparing quotations, carrying out painting work and maintenance activities.
- Legal obligation: complying with tax and administrative retention obligations.
- Legitimate interest: internal business operations, communication with customers and improving the quality of services.
- Consent: if you voluntarily provide data via contact forms or otherwise give explicit consent.
3. Categories of Personal Data
We may process the following categories of personal data:
- Identification data: first and last name
- Contact details: address, email address, telephone number
- Project information: data relating to a home, building or work to be carried out
- Communication data: correspondence via email, telephone or contact forms
- Financial data: invoice and payment details
- Technical data: IP address and website usage data (where applicable)
4. Retention Periods
Personal data will not be retained for longer than necessary for the purposes for which it was collected, unless a legal retention obligation requires a longer retention period.
- Quotation data: a maximum of 12 months after the last contact
- Invoice and administrative data: 7 years (tax retention obligation)
- Contact details without a further customer relationship: a maximum of 6 months
5. Disclosure to Third Parties
We only provide personal data to third parties where this is necessary for the performance of our services or to comply with legal obligations.
We enter into data processing agreements in accordance with Article 28 of the GDPR with third parties that process personal data on our behalf.
Examples of categories of processors:
- Administrative service providers
- IT and hosting providers
- Email and communication services
Personal data is not sold or rented to third parties.
6. Transfers Outside the EEA
If personal data is processed outside the European Economic Area (EEA), this will only take place where an adequate level of protection is ensured in accordance with Chapter V of the GDPR (for example through Standard Contractual Clauses).
7. Cookies and Similar Technologies
Our website only uses functional cookies that are strictly necessary for the technical operation of the website.
We do not use analytical cookies, tracking cookies or marketing profiling.
Functional Cookies
- Necessary for the proper functioning of forms and website functionality
Email Tracking
Where applicable, limited technical information may be collected regarding the opening of emails. This processing only takes place on the basis of legitimate interest and is not used for automated decision-making or profiling.
8. Security of Personal Data
We implement appropriate technical and organisational security measures in accordance with Article 32 of the GDPR to protect personal data against loss, unauthorised access, alteration or disclosure.
9. Your Rights as a Data Subject
Under the GDPR, you have the following rights:
- Right of access (Article 15 GDPR)
- Right to rectification (Article 16 GDPR)
- Right to erasure (Article 17 GDPR)
- Right to restriction of processing (Article 18 GDPR)
- Right to data portability (Article 20 GDPR)
- Right to object (Article 21 GDPR)
You can submit your request to:
10. Right to Lodge a Complaint
If you believe that the processing of your personal data violates the GDPR, you have the right to lodge a complaint with the supervisory authority:
Dutch Data Protection Authority (Autoriteit Persoonsgegevens)
11. Automated Decision-Making
We do not use automated decision-making or profiling within the meaning of Article 22 of the GDPR that produces legal effects concerning you or similarly significantly affects you.
12. Changes to This Privacy Policy
We reserve the right to amend this privacy policy. The most recent version is always available on our website. We recommend that you consult this privacy policy regularly.


