Privacy statement
What happens to your data when you visit this website or send us a message.
Last updated on .
This is an English translation provided for convenience. The Dutch version is the binding text; in the event of any discrepancy, the Dutch version prevails.
1. Who is responsible
Ledger & Loom is responsible for the processing of personal data that takes place through this website. Our details:
Ledger & LoomOvertoom 433
Amsterdam
contact@ledgerandloom.nl
+31 6 13 48 48 63
Chamber of Commerce (KvK) 42156723
We have no data protection officer. Questions about privacy can be put directly to the address above.
2. The starting point: this website collects almost nothing
This is a static website. It has one form — the contact form, with which you can send us a message (§ 6) — you cannot create an account, and no cookie is placed on the public pages without your consent. We do count how often our pages are viewed, with a measurement that we run ourselves on our own server and that places no cookie and stores no IP address (§ 4). We build no profiles, take no automated decisions about individuals, and neither sell nor rent data to third parties. What is recorded is set out below.
3. Your visit to the website
As with almost any web hosting, our hosting provider's server records every visit in a log file. This includes:
- the IP address of your internet connection;
- the date and time of the request;
- the page or file requested;
- the status code the server returned;
- details of your browser and operating system;
- the page from which you came to us, if your browser passes it on.
An IP address is personal data. We do not use these log files to recognise or track visitors. They exist to keep the website working, to trace faults and to counter abuse; we consult them only when there is reason to.
Legal basis
Legitimate interest (Article 6(1)(f) of the General Data Protection Regulation): the interest in offering this website in an available and secure form.
Retention
The log files are kept by our hosting provider for a limited period and then deleted. We keep no separate copy ourselves and do not use them for analysis.
4. Visitor statistics
We count how often our pages are viewed. We do that counting ourselves, on our own server. No external statistics platform is involved: when you open a page, no request goes to any party other than ourselves, not even for the fonts. After loading, your browser reports once which page you opened and, if you came to us from another website, which website that was.
What is recorded
- the path of the page you opened (for example /approach), without any search or referral parameters that may have followed it;
- the date of the visit, not the time;
- the domain name of the website from which you came to us, if your browser passes it on — so only the name of that website, not the exact page and not the search query you typed there;
- a daily code with which our server can distinguish repeated views by one and the same visitor within a single day.
What is not recorded
- no cookie and no other storage on your device;
- no IP address: it is not stored;
- no name, email address or other detail that refers to you as a person;
- no profile, no tracking from one website to another, no advertising purposes.
The daily code
To see how many different visitors a day had, our server calculates an irreversible code from your IP address, the details your browser sends about itself, and a random number that is chosen afresh every day. Your IP address is not stored in the process. That random number is discarded at the end of the day and never reused; after that, the codes of that day can no longer be linked to anything. We delete the codes themselves within two days.
Legal basis
Legitimate interest (Article 6(1)(f) of the General Data Protection Regulation): the interest in knowing which topics on this website are read, so that we can maintain and improve it. We deliberately keep this measurement as limited as possible: no cookie, no IP storage, no profile. Because nothing is placed on or read from your device, we do not ask your consent for it; we explain that consideration in thecookie policy.
Retention
The daily files with the codes above are deleted within two days. What remains of a month is a file containing only figures: how many views per page, how many visitors per day, which domains referred to us. It contains no personal data. We keep those monthly files for no longer than24 months.
Not being counted
If Do Not Track or Global Privacy Control is switched on in your browser, the page reports nothing and your visit is not counted.
With your consent: returning visits
On top of the count above, we ask you once, on your first visit, whether we may recognise when you return. If you say yes, our server places a cookie containing a random number (see thecookie policy), and for every page you open after that it records that number together with the date and time, the path of the page, the website you came from and the language. Not your IP address, not your name, nothing about your device. This shows us which route visitors take through the website and whether they come back later. The number cannot be linked to anyone — not by us either — and is shared with no one.
Legal basis: your consent (Article 6(1)(a) of the General Data Protection Regulation). You can withdraw it at any time via Cookie preferenceat the foot of every page; we then delete the cookie and record nothing further. What was recorded until then, we keep for at most12 months. If you say no, or if Do Not Track or Global Privacy Control is switched on in your browser, the cookie is not placed and only the count above remains.
5. Pages behind a password
Our own administration page is not public; there the server first asks for a password. In addition, we can temporarily close a page. If a page is closed, a login screen appears and it can only be read with a password you have received from us.
Which data
Of the passwords we issue, we keep no readable version, only an irreversible encryption of it. Alongside it is a label we choose ourselves to know to whom a password was issued — that may be a name — and the date of issue. When someone signs in, the server places one cookie with a random session number; it disappears on signing out or closing the browser. See the cookie policy for the details. On the closed pages themselves we measure nothing.
To prevent anyone guessing passwords, the server keeps track for at most fifteen minutes of how many login attempts have recently been made. It does so by means of an irreversible code calculated from the IP address; the IP address itself is not stored.
Purpose, legal basis and retention
The purpose is to grant access to those we have invited, and to secure that access. Legal basis: our legitimate interest in keeping non-public pages non-public (Article 6(1)(f)). We remove an access as soon as it is no longer needed; you can also ask us to do so.
6. Contact via the form, by email or by telephone
You can send us a message via the contact form on the Contact page, directly by email, or by telephone. The form is our own and runs on our own server; no external sending service is involved.
Which data
Your name, your email address or telephone number, the organisation you work for if you mention it, and the content of your message. If you send the form, the following is sent with it: the page from which you sent it and, if you came to us from another website, the address of that website — without any search or referral parameters that may have followed it. Both are fields in the form itself and not in a script, so that you can see what is sent. The form places no cookie and reads nothing from your device.
Where your message ends up
A message via the form arrives in two places: as an email in our mailbox, and as a file on our own server, outside the part that is reachable over the internet. That second copy exists so that requests can be found again, and to prevent a message being lost if the email does not arrive.
To prevent the form being flooded automatically, the server keeps a daily count of how many messages come from a single connection. It does so with the same kind of irreversible daily code as the visitor measurement (§ 4): your IP address is not stored, and the code disappears within 2 days.
Purpose and legal basis
Answering your message and, if an engagement results from it, preparing and performing the contract (Article 6(1)(b)). For correspondence that does not lead to an engagement, we rely on our legitimate interest in being able to answer and retrieve business messages (Article 6(1)(f)).
Retention
We keep correspondence for as long as it is relevant to the contact or the engagement it belongs to. The copy of a form message on our server is deleted after 12 months. Data that forms part of our administration is kept for as long as the statutory retention obligation requires.
We do not use your data to send you unsolicited offers. There is no newsletter.
7. Data you provide to us within an engagement
This statement concerns this website. It does not concern the data that a client makes available to us within an engagement.
In advisory, research and build engagements it may occur that we process a client's data, for instance administrative or operational files. Separate arrangements apply to that: for each engagement, a data processing agreement records which data is involved, what it is used for, how long it is kept and what happens to it afterwards. Those arrangements belong to the engagement and are separate from this website.
If you would like to know how that is arranged in a specific engagement, you can request it from us.
8. Who else can see your data
We do not share data with third parties for commercial purposes. Like any organisation, however, we use suppliers who process data in the course of providing their service:
- the hosting provider that makes this website available and keeps the log files;
- the party that provides our business email.
With such suppliers, the arrangements are made that the General Data Protection Regulation prescribes for processors. If a supplier processes data outside the European Economic Area, that must take place under the safeguards the Regulation sets for it. Beyond that, we provide data to third parties only when a legal obligation compels us to.
9. Security
This website is offered over a secure connection (https); what you send via the contact form also travels over that connection to our own server. The contact form is the only form on this website; there is no payment function. Please bear in mind that a message — including a message via the form — reaches us partly by email, and that ordinary email is not a secure channel. Do not send us sensitive data by these routes.
10. Your rights
With regard to the personal data we process about you, you have the following rights:
- Access
- You can ask which data we process about you and why.
- Rectification
- You can have incorrect data corrected or incomplete data completed.
- Erasure
- You can ask for your data to be deleted, insofar as we are not legally obliged to keep it.
- Restriction
- You can have processing suspended while a request or objection of yours is being handled.
- Objection
- You can object to processing that we base on a legitimate interest.
- Portability
- You can receive the data you provided to us yourself in a common file format.
You exercise these rights by sending a message tocontact@ledgerandloom.nl. To avoid providing data to the wrong person, we may ask you to make your identity plausible. We respond within the period the Regulation sets for this.
A message you send us via the form or by email can be found by us under your name or email address; the above applies to it in full. Beyond that, we keep no visitor records: neither the data in the server log files, nor the figures from our own measurement, nor the visits under a visitor number can be linked by us to a person. If your request concerns only those log files, we will ask you for the details with which the relevant lines can be found. If we cannot identify you without those additional details, we may refuse the request (Article 11 of the Regulation).
11. Complaint
If you disagree with the way we handle your data, we would like to hear it from you first. In addition, you have the right to lodge a complaint with the Autoriteit Persoonsgegevens, the Dutch supervisory authority, viaautoriteitpersoonsgegevens.nl.
12. Changes to this statement
If anything changes about this website or the way we handle data, we will amend this statement. The date at the top of this page shows when that last happened.
