Privacy Policy
Last Updated: 04 August 2026
1. Data Controller Information
The entity responsible for processing your personal data (the “Data Controller”) is:
Foundation Name: Free ICT Europe Foundation (Stichting Free ICT Europe)
Registered Address: Gasthuispolderweg 24 | 2807 LL | Gouda | The Netherlands
Chamber of Commerce (KvK) Number: 60202661
Contact Email: contact@freeict.eu
Website: https://freeict.eu
Data Protection Officer (DPO): N/A (Direct inquiries to contact@freeict.eu)
2. Personal Data We Collect & Legal Basis
We process personal data in compliance with Article 6 of the EU General Data Protection Regulation (GDPR). Depending on your interaction with our website, we process the following categories:
| Data Category | Purpose of Processing | Legal Basis (GDPR Art. 6) |
|---|---|---|
| Contact & Form Data (Name, email, organization, job title, message) | Answering contact form submissions, managing inquiries, delivering updates, and handling advocacy interactions. | Article 6(1)(b): Necessary for pre-contractual steps or executing user requests; and Article 6(1)(f): Legitimate interest in responding to incoming inquiries. |
| Account / Profile Data | Creating and managing registered user or member accounts (if applicable). | Article 6(1)(b): Performance of a contract / membership terms. |
| Technical & Log Data (IP address, browser type, OS, timestamp) | Server security, preventing malicious access/attacks, debugging, and system stability. | Article 6(1)(f): Legitimate interest in maintaining web infrastructure security. |
| Analytics & CRM Data (HubSpot & Matomo tracking data) | Understanding site traffic, campaign performance, user engagement, and managing contact records via our CRM platform. | Article 6(1)(a): Explicit Consent (where cookies/trackers are enabled); or Article 6(1)(f): Legitimate interest in privacy-friendly traffic measurement. |
3. Storage and Retention Periods
We retain personal data only for as long as necessary to fulfill the purposes for which it was collected, or to comply with statutory legal obligations:
- Contact Form & CRM Records (HubSpot): Retained for as long as active communication continues or up to 2 years after the last interaction, unless longer retention is required for contractual, membership, or statutory advocacy records.
- Server Access Logs: Retained for 30 days by our web host for security troubleshooting and error monitoring, after which they are automatically deleted.
- Analytics Data (Matomo & HubSpot): Raw visitor log data is retained for 13 months to enable year-over-year advocacy metrics before automatic deletion. Aggregated, non-personal reporting metrics are retained indefinitely.
- Financial & Invoice Records: Retained for 7 to 10 years in accordance with Dutch statutory tax law (Rijksbelastingdienst requirements).
4. Recipients and Data Processors
We do not sell, rent, or trade your personal data. We share data only with trusted service providers acting as Data Processors under strict Data Processing Agreements (DPAs) pursuant to Article 28 GDPR:
- Web Hosting Provider: TransIP B.V. (Netherlands) – Primary web hosting and infrastructure; data remains within the EU.
- Email & SMTP Delivery: TransIP B.V. (Netherlands) – Processes transactional email routing.
- Analytics Provider: Matomo Analytics (Self-hosted on our EU server infrastructure).
- CRM & Marketing Automation: HubSpot, Inc. (USA) – Powers our contact forms, live chat, lead management, and marketing communication tools.
5. Third-Country Transfers (Outside the EEA)
Our primary CRM database, contact records, and website data processed via HubSpot are hosted on secure servers located strictly within the European Union (Germany).
However, because HubSpot, Inc. operates a global infrastructure, temporary routing or technical processing of data outside the European Economic Area (EEA) (such as to the United States) may occur for system operations, security delivery networks, or technical support.
To ensure a high level of data protection in full compliance with Chapter V of the GDPR, any international data access or transfer to HubSpot, Inc. is governed by standard legal safeguards:
- HubSpot, Inc.’s certification under the EU-U.S. Data Privacy Framework (DPF), and/or
- Standard Contractual Clauses (SCCs) incorporated into HubSpot’s Data Processing Agreement (DPA), complemented by strict technical and organizational measures.
6. Cookies and Tracking Technologies
We prioritize visitor privacy. Essential functional cookies necessary for site operation and security are loaded automatically.
Non-essential cookies—including HubSpot analytics, tracking scripts, and user interaction cookies—are blocked by default until you grant explicit, granular consent via our Cookie Banner in accordance with the ePrivacy Directive and GDPR. You can update, change, or revoke your consent preferences at any time via the “Cookie Settings” link in our website footer.
7. Your Rights Under the GDPR
Under Chapter III of the GDPR, you hold the following rights regarding your personal data:
- Right of Access (Art. 15): Request confirmation of whether we process your data and obtain a free copy of the personal data held.
- Right to Rectification (Art. 16): Request immediate correction of inaccurate or incomplete personal data.
- Right to Erasure / “Right to be Forgotten” (Art. 17): Request deletion of your personal data when it is no longer necessary for processing purposes.
- Right to Restriction of Processing (Art. 18): Request that we restrict data processing under specific legal conditions.
- Right to Data Portability (Art. 20): Receive your personal data in a structured, commonly used, and machine-readable format.
- Right to Object (Art. 21): Object to processing carried out based on legitimate interests (Art. 6(1)(f)).
- Right to Withdraw Consent (Art. 7(3)): Withdraw consent at any time without affecting the lawfulness of processing conducted prior to withdrawal.
To exercise any of these rights, you can submit your request directly via our HubSpot Privacy & Data Subject Request Form
or send an email to contact@freeict.eu.
8. Right to Lodge a Complaint
If you believe our processing of your personal data violates the provisions of the GDPR, you have the right to lodge a complaint with a Lead Supervisory Authority. In the Netherlands, the relevant authority is:
Autoriteit Persoonsgegevens (AP)
Postbus 93374 | 2509 AJ DEN HAAG
Telephone: (+31) – (0)70 – 888 85 00
Website: https://autoriteitpersoonsgegevens.nl
