Privacy policy

7770642318a2f24617f0cdae43ead96ec76dc0e7

Privacy Policy

Vriman B.V. (“Vriman”) (Dutch Chamber of Commerce / KvK: 63644606), established at Eduard van Beinumstraat 10, 1077CZ Amsterdam, is the controller within the meaning of the General Data Protection Regulation (“GDPR”) for the personal data we process about you. This privacy statement applies to the processing of personal data of: I. Website visitors II. Clients III. Third parties whose personal data we process in the context of our service provision IV. Job applicants V. Suppliers

Vriman considers the protection of your privacy important. Vriman has therefore drawn up this privacy statement, among other measures. The purpose of this privacy statement is to be transparent about the way Vriman collects, uses, and protects your personal data in accordance with Articles 13 and 14 of the GDPR.

What are personal data?

Under the GDPR, personal data means any information relating to an identified or identifiable natural person. This means that information either directly concerns someone or can be traced back to this person.

For what purposes do we process personal data?

We process your personal data only for specified, explicit, and legitimate purposes. Below you will find more information about the various purposes for each category of data subject.

I. WEBSITE VISITORS

1. To answer your questions when you contact us

What does this purpose entail? Our contact details are provided on our website so that you can reach out to us. When you contact us, we process the personal data provided by you in order to respond and answer your question. The legal basis for this processing is our legitimate interest in contacting you following your inquiry (Article 6(1)(f) GDPR).

Which personal data do we process for this purpose? We only process the personal data that you provide to us. This may include, for example: name, phone number, email address, and the information you provide in your message.

II. CLIENTS

We process personal data of clients, their employees, contact persons, and third parties engaged by them. The client is responsible for informing the third parties engaged by them of the content of this privacy statement. A copy of this privacy statement can be found on our website.

1. For executing our legal services and advice, including handling disputes and conducting legal proceedings

What does this purpose entail? For the execution of our legal services and advice (including handling disputes and conducting legal proceedings), we process personal data of the client or its contact persons. This enables us to deliver our services efficiently and effectively and to maintain contact with you (for example, regarding the progress of a file). The processing of personal data for this purpose is necessary for entering into or performing a contract with you (Article 6(1)(b) GDPR) and/or our legitimate interest in conducting our legal services and advisory work efficiently and effectively (Article 6(1)(f) GDPR).

Which personal data do we process for this purpose? This includes contact details (name, phone number, and email address) and any other information we deem necessary in the context of our service provision.

2. For our daily business operations

What does this purpose entail? For conducting our daily business operations, including preparing cost estimates, financial administration (such as invoicing, calculating and recording fees and expenses, making payments, collecting receivables, and paying our invoices), we process personal data of the client or its contact persons. The processing of personal data for this purpose is based on the performance of a contract (Article 6(1)(b) GDPR), our legitimate interest in the payment of our invoices (Article 6(1)(f) GDPR), and compliance with our statutory administrative obligations (Article 6(1)(c) GDPR).

Which personal data do we process for this purpose? For this purpose, we process your name, phone number, and email address. If you act on behalf of a partnership and/or are a client as a natural person, we also process financial data such as your bank account number and payment information.

3. For screening and establishing the identity of our clients

What does this purpose entail? Before we can commence our legal services and advice, we collect information to verify the identity of the client and the Ultimate Beneficial Owners (UBOs). This enables us to comply with our obligations under, for example, the Dutch Anti-Money Laundering and Anti-Terrorist Financing Act (Wet ter voorkoming van witwassen en financieren van terrorisme – Wwft) and the Regulation on the Legal Profession (Verordening op de advocatuur – Voda).

We are required to report unusual transactions to the Financial Intelligence Unit / Fiscal Information and Investigation Service (FIOD). In such cases, we must also provide other relevant transaction-related information. We also process your personal data for potential audits by the Dutch Bar Association (Nederlandse Orde van Advocaten). We do this because we are legally obligated to do so (Article 6(1)(c) GDPR). The processing of personal data for this purpose is based on the performance of a contract (Article 6(1)(b) GDPR) and compliance with our legal obligations (Article 6(1)(c) GDPR).

Which personal data do we process for this purpose? We process the name of your company and/or employer, first and last name, position, email address, phone number, transaction and payment details, and, where applicable, proof of identity. The passport photo and citizen service number (BSN) must be rendered invisible, for example using the KopieID app from the Dutch Ministry of the Interior and Kingdom Relations. This allows you to choose which data to redact yourself.

4. For maintaining our relationship

What does this purpose entail? We consider it important to maintain a good relationship with our clients. Therefore, we process your personal data, for example, when we invite you to events or when you register for them. In addition, we may use your data to send congratulations on a (personal) milestone or as a reference when submitting applications to Legal 500 or Chambers. Finally, we like to stay in touch to evaluate our services. The legal basis for sending event invitations is based on your consent (Article 6(1)(a) GDPR) and/or our legitimate interest in maintaining relationships with our clients, for instance by organizing courses or other events or sending congratulations (Article 6(1)(f) GDPR).

Which personal data do we process for this purpose? We process your contact details (name, phone number, and email address), date of birth, and other relevant information if and to the extent disclosed to us.

III. THIRD PARTIES

1. For executing our legal services and advice, including handling disputes and conducting legal proceedings

What does this purpose entail? For executing our legal services and advice (including handling disputes and conducting legal proceedings), we process personal data of third parties with whom we do not have a direct (contractual) relationship. These include, for example:

  • employees of clients, third parties, or opposing parties;
  • suppliers of clients, third parties, and opposing parties;
  • advisors of clients, third parties, and opposing parties;
  • other third parties engaged by clients, third parties, and opposing parties; and
  • other interested parties and/or stakeholders.

By processing your personal data, we can deliver our services efficiently and effectively. The processing of personal data for this purpose is necessary for our legitimate interest in conducting our legal services and advice efficiently and effectively (Article 6(1)(f) GDPR).

Which personal data do we process for this purpose? Contact details (name, email address) and data provided to us by clients or other third parties, or obtained from public sources in the context of our legal services and advice.

IV. APPLICANTS

1. For an effective and efficient recruitment and selection process

What does this purpose entail? For recruiting and selecting new employees or contractors (independent contractors working temporarily on an interim basis via a service agreement), we process personal data. We do this to assess whether the applicant or contractor is suitable for the open position.

By default, these personal data are retained for up to two months after the closing date of the job vacancy. This enables us to answer any questions you may have regarding the outcome of your application during this period. If the application leads to an appointment, the relevant personal data will be retained in accordance with our retention policy and our privacy policy for employees and/or contractors.

The legal basis is our legitimate interest in an efficient recruitment and selection process and in being able to respond to applicants regarding questions about the outcome of the application (Article 6(1)(f) GDPR). If, following the recruitment and selection procedure, we proceed to enter into an employment contract or agreement for services, we may process additional personal data in preparation for the performance of the contract (Article 6(1)(b) GDPR) and to comply with other statutory requirements (Article 6(1)(c) GDPR).

Which personal data do we process for this purpose? We process personal data that you provide to us. This includes your name, address, work experience, education, the personal data on your CV, personal data in your cover letter, and information from reference checks or results of a competency test.

When entering into an employment contract or agreement for services, additional data may be processed, such as Citizen Service Number (BSN), bank details (bank account number and account holder name), copy of proof of identity, and other data required when concluding an employment contract or service agreement.

V. SUPPLIERS

1. For processing orders and assignments

What does this purpose entail? For executing and settling our orders and assignments with you as a supplier, we process personal data of (employees of) our suppliers. This personal data helps us provide you with the correct information for placing an order or issuing an assignment. The legal basis for processing personal data for this purpose is entering into or performing a contract (Article 6(1)(b) GDPR).

Which personal data do we process for this purpose? We process your contact details (name, phone number, and email address). If you operate as a partnership, we also process address details and financial data, such as bank account number and payment information.

Your rights

You have the right to be well-informed about what we do with your data and why we need your data. We do this by means of this privacy statement. In addition to the right to transparent information, you have the following rights:

  • Right of access (if you want to know what personal data we collect about you);
  • Right to rectification (we are happy to update any personal data that is no longer correct);
  • Right to be forgotten / erasure (in certain cases, you can ask us to delete your personal data);
  • Right to restriction of processing (in certain cases, you may ask us to restrict the processing of your personal data);
  • Right to data portability under certain circumstances (if you wish, we can transfer your personal data to another party or provide you with a copy of your personal data);
  • Right to object (in certain cases, you may object to the use of your personal data).

If you wish to exercise any of your rights, you can contact us by emailing info@vriman.com. To prevent misuse, we may ask you to adequately identify yourself before processing your request. Circumstances may arise where we cannot, or cannot fully, comply with your request. If such a circumstance arises, we will notify you. We will always respond to your request within one month.

With whom do we share personal data?

Vriman does not sell or trade your personal data to third parties. Vriman may be obliged under specific laws and regulations to provide certain personal data to third parties, such as government agencies. In addition, we may share your personal data with third parties to protect our own rights or the rights of others.

Internally, only our employees have access to personal data to the extent relevant to their job duties (on a need-to-know basis), and all our employees have a confidentiality clause in their employment contract.

We also engage processors who process personal data on our behalf. We conclude data processing agreements with them that comply with the requirements of the GDPR, for example regarding the reporting of data breaches and implementing appropriate technical and organizational measures. In addition, personal data may be shared with:

  • A dispute resolution body and/or competent judicial authority. This may apply to personal data of clients, suppliers, and/or third parties.
  • Potential new shareholders and their advisors.
  • Accounting firm and the Bar Association (Orde van Advocaten). For carrying out our (annual) audits. This may apply to personal data of clients, suppliers, and/or third parties.
  • IT service providers. During maintenance, management, and support of our systems and applications, they may have limited access to various personal data.
  • Other service providers involved in our service delivery, such as external advisors, lawyers, and accountants. This may apply to clients, suppliers, and/or third parties.
  • Bailiffs and administrators/trustees. We provide them with your name, contact details, financial data, and employment details. This may apply to clients, suppliers, and/or third parties.
  • Insurers. We provide them with your name, contact details, and financial data. This may apply to clients, suppliers, and/or third parties.

How long do we retain your personal data?

We retain your personal data for as long as necessary for the purpose for which we use your personal data and/or for as long as the law obliges us to retain the personal data. The exact period varies from a few months to many years, for example because it is required for our accounting. We have determined the retention periods per processing activity in our retention policy.

We retain personal data of job applicants for a maximum of 2 months after the recruitment and selection procedure. With your consent, we will retain your data for an additional 12 months for potential future vacancies.

Consent

If we process your data based on your consent, you always have the right to withdraw your consent. You can easily do so by sending an email to info@vriman.com. In that case, unless we have another legal basis for the processing, we will no longer use your data for this purpose.

How do we protect your data?

Under Article 32 of the GDPR, we are obliged to take appropriate technical and organizational measures to prevent the loss of personal data or unlawful processing. To this end, we have implemented physical, administrative, organizational, and technical measures. We periodically evaluate these technical and organizational measures and adjust them where necessary. Our organization is structured to do everything possible to prevent data breaches. If a data breach occurs, we will act in accordance with our data breach protocol.

Contact and complaints

If you have questions about this privacy statement or wish to exercise your rights as a data subject, you can contact us via info@vriman.com.

In case of complaints regarding, for example, the way we use your data or how we respond to privacy-related questions, you can submit a complaint to the Dutch Data Protection Authority (Autoriteit Persoonsgegevens).

Amsterdam, March 2024