Privacy Policy & Cookie Statement
Last updated: 26-07-26
Den Otter Consulting, located at Koningshoeven 13 in Den Bosch, the Netherlands, is committed to protecting your privacy. In this privacy statement, we explain how we handle personal data. This concerns both data we receive through our website, https://denottersolutions.com, and data about business contacts that we obtain from other sources and use to contact you about our services.
We process your personal data in accordance with the requirements of the General Data Protection Regulation (GDPR).
1. Identity of the Data Controller
Den Otter Consulting is the 'Data Controller' within the meaning of the GDPR. This means that we decide which personal data is processed, for which purposes and by which means. We trade under the name Den Otter Solutions; messages you receive from us are sent under that name.
Den Otter Consulting
Koningshoeven 13
5235 BW Den Bosch, The Netherlands
Chamber of Commerce number: 94619735
For privacy-related questions or to exercise your rights, you can contact us by email: rob@denottersolutions.com
2. What Personal Data Do We Process?
We process personal data because you provide it to us directly, because it is collected automatically during your visit to our website, or because we have obtained it from other sources in order to contact you as a business contact.
A. Data you provide to us directly:
This concerns the data you enter via the contact form on our website:
- Your name
- Your organisation name (if provided)
- Your email address
- Your phone number (if provided)
- The content of your message (including any personal data you provide in it)
B. Data you provide via an online scan:
On our website you can complete a free self-assessment: the Data Maturity Scan and the AI Readiness Scan. If you complete one of these scans, we process:
- Your name
- Your company name
- Your email address
- Your phone number (if provided)
- Your sector and the number of employees at your organisation
- Your answers to the questions in the scan, and the resulting score
We use this data to send you the report and our personal comments on it. Completing a scan is not a subscription to newsletters or sales email. If you are receiving a series of messages from us at that moment, that series stops as soon as you complete the scan.
C. Data we collect automatically:
When you visit our website, our servers automatically collect certain technical information for security and diagnostic purposes.
- Your IP address
- Browser type and operating system (User-Agent)
- The pages you visit and the time of your visit
D. Data about business contacts obtained from other sources:
We contact directors, executives and managers at Dutch companies with information about our services in the areas of data analysis, reporting and AI automation. For that purpose we process a limited set of business data that we have not received from you directly:
- Your name
- Your job title
- Your business email address
- The URL of your professional LinkedIn profile, where public
- Information about your organisation: Chamber of Commerce number, industry code, location, company size, and whether the organisation is registered in the Trade Register with a non-mailing indicator
- The outcome of our search for a business email address, including a finding that no address was located
- Information about our contact with you: which message was sent when, whether it was delivered, and whether and how you responded
Per organisation we may record details of more than one contact person, so that we can approach the most appropriate person. If you receive a message from us, the rights set out in this statement apply to you personally in full.
We do not collect data from behind a login or any restricted environment, and we do not process data that concerns you outside your professional capacity. We do not process special categories of personal data.
We obtain this data from the following types of sources:
- The Dutch Trade Register of the Chamber of Commerce
- Handelsdata, a commercial provider of business information that compiles data from the Trade Register and supplements it with public sources
- Public company websites and public professional profiles
- Icypeas, a business search service that determines the corresponding business email address from public and professional sources, based on your name and your employer's internet domain
Would you like to know exactly which source your data came from? Send an email to rob@denottersolutions.com and we will tell you.
3. Purposes and Legal Bases for Processing
We process your personal data exclusively for specific, predetermined purposes, and each processing activity is based on a legal basis from the GDPR.
| Activity & Purpose | Data Processed | Legal Basis (GDPR) |
|---|---|---|
| Responding to your enquiry: Contacting you, providing information or issuing a quotation in response to your request via the contact form. | Name, email address, phone number, content of the message. | Art. 6(1)(b) GDPR: Necessary for the performance of pre-contractual measures taken at your request. |
| Carrying out a scan you requested: Calculating your score and sending you the report and our comments. | Name, company name, email address, phone number, sector, company size, your answers and score. | Art. 6(1)(b) GDPR: Necessary for the performance of pre-contractual measures taken at your request. |
| Business contact: Contacting business decision-makers with information about our services, and recording your response to it. | Name, job title, business email address, LinkedIn profile URL, organisation details, sending and response data, and the content of any correspondence. | Art. 6(1)(f) GDPR: Necessary for the purposes of our legitimate interest (bringing our services to the attention of business decision-makers for whom they are relevant). We have documented a legitimate interest assessment for this, which is available on request. |
| Security and stability of the website: Monitoring, diagnosing and securing our website and servers against abuse, hacks or malfunctions. | IP address, browser information, time of visit. | Art. 6(1)(f) GDPR: Necessary for the purposes of our legitimate interest (ensuring the security and continuity of our systems). |
We keep the number of messages and the number of people involved as small as the purpose requires. Specifically:
- If your organisation is registered in the Dutch Trade Register with a non-mailing indicator, you will receive one single message from us and no follow-up. This indicator does not formally apply to email, but we treat it as a signal that you prefer unsolicited contact to be kept to a minimum. This limitation is technically enforced in our systems.
- We only contact business addresses of people in a role for which our services may be relevant.
- If you do not respond, the series stops by itself after a limited number of messages.
Every message we send you contains an unsubscribe link. One click is enough; you do not need to reply, you do not need to fill in any details and you do not need to give a reason. We then add your email address to a suppression record, so that you will receive no further messages from us. You can also unsubscribe by replying to any of our messages or by emailing rob@denottersolutions.com.
4. Retention Periods
We do not retain your personal data for longer than is strictly necessary to achieve the purposes for which your data is collected.
- Contact requests (potential clients): Data provided via the contact form is retained for the duration of our communication. If no client relationship is established, this data is deleted no later than 24 months after the last contact.
- Completed scans: Your answers, score and contact details are retained for up to 24 months after completion, unless a client relationship is established.
- Business contacts (outreach): Data about contacts we have approached is deleted no later than 18 months after the last contact.
- Business contacts we have not approached: Data we have collected but where no contact has taken place within 12 months is deleted after that period.
- Suppression record: If you unsubscribe, we retain only your email address, the reason and the date of your unsubscription. We retain this record indefinitely. Without it, we could approach you again, which is precisely what you wanted to prevent. We do not use this data for any other purpose.
- Client data: If you become a client, your data falls under our client administration. This data is retained in accordance with the statutory fiscal retention obligation of 7 years.
- Server logs (security): Technical logs, including IP addresses, are retained for security purposes for no longer than 14 days.
5. Sharing Data with Third Parties
We never sell your data to third parties for commercial purposes. Nor do we provide your data to third parties for their own marketing purposes. We only share your data with third parties ("Processors") when this is necessary for the provision of our services, or when we are legally obliged to do so.
- Hosting Provider: Our website and email services are hosted by Cloud86. This party processes the data (storage) on our behalf. We have concluded a valid data processing agreement (in accordance with Art. 28 GDPR) with this party, which obliges them to maintain confidentiality and adequate security.
- Storage and process automation: To manage our business contact data and to send messages, we use Supabase (storage, servers in Frankfurt) and n8n Cloud (servers in Germany). Both parties process this data solely on our behalf.
- CRM: If you respond to a message from us, we record your details in HubSpot (EU hosting) in order to follow up on the conversation. If you do not respond, your details do not enter our CRM.
- Determining business email addresses: To determine the business email address of a contact person we use Icypeas (France). In doing so we provide the name of the contact person and the internet domain of the organisation. Icypeas processes that data on our behalf and also maintains its own database of business profile data from public sources, for which Icypeas is itself the data controller.
- Email address validation: We check whether an email address exists and is active, in order to avoid sending messages to incorrect addresses. For this we use Icypeas and Verifalia. Verifalia processes data exclusively within the European Economic Area (Germany and the Netherlands) and does not retain submitted addresses for longer than the period we have configured.
- Automated text processing: We use a language model from Anthropic or OpenAI to summarise public company information and to classify incoming replies. No automated decision-making takes place that produces legal effects concerning you or similarly significantly affects you.
- Legal obligation: We may be required to share data in the context of legal proceedings or by order of a competent authority (such as the police).
With the parties that process data on our behalf, processing terms have been agreed, either in a separate data processing agreement or in the data processing provisions of their terms and conditions.
Our website, email, contact database and sending workflow operate within the European Economic Area: the Netherlands and Germany. For determining and validating email addresses and for automated text processing, processing may take place outside the EEA; where it does, this is based on the European Commission's Standard Contractual Clauses.
6. Security of Personal Data
We take the protection of your data seriously and have implemented appropriate technical and organisational measures (TOMs) to prevent misuse, loss, unauthorised access, unwanted disclosure and unlawful alteration.
- The connection to our website is secured using SSL/TLS encryption (recognisable by https:// and the lock icon in your browser).
- Access to systems in which personal data is stored (such as the email inbox) is restricted and secured.
- Access to our contact database is exclusively via personal accounts with two-factor authentication.
7. Your Rights (Data Subject Rights)
You have control over your personal data at all times. Under the GDPR, you have the following rights:
- Right of Access (Art. 15 GDPR): You have the right to request an overview of the personal data we process about you.
- Right to Rectification (Art. 16 GDPR): If your data is incorrect, you have the right to have it corrected.
- Right to Erasure (Art. 17 GDPR): You can request that we delete your personal data (under certain conditions, e.g. if the data is no longer necessary for its purpose).
- Right to Restriction (Art. 18 GDPR): You have the right to temporarily suspend the processing of your data.
- Right to Object (Art. 21 GDPR): You can object to the processing of your data on the basis of our legitimate interest (see the table in section 3). If you object to business contact, we will stop without question.
- Right to information about the source (Art. 14 GDPR): If you did not provide the data to us yourself, you have the right to be told which source it came from.
To exercise your rights, you can send an email to rob@denottersolutions.com. To prevent misuse, we may ask you to adequately identify yourself. We will respond to your request within the statutory period of one month.
You also have the right to file a complaint with the Dutch supervisory authority, the Autoriteit Persoonsgegevens (Dutch Data Protection Authority).
8. Changes to this Privacy Statement
We may amend this privacy statement from time to time, for example in the event of changed business operations or legislation. The most current version can always be found on our website.
Cookie Statement — Den Otter Solutions
Last updated: 19-07-26
1. What are Cookies?
Cookies are small text files placed on your computer, tablet or mobile phone by a website. These files store information about your visit.
2. The Dutch Cookie Law (Telecommunications Act)
The Dutch Telecommunications Act (Art. 11.7a) requires that website visitors give "consent" for the placement and reading of most types of cookies. This is why you see a "cookie banner" on many websites.
However, the law makes an important exception for cookies that have no or minimal impact on your privacy. These are:
- Functional (necessary) cookies: Cookies that are strictly necessary for the website to function technically or to deliver a service requested by you (e.g. a cookie that manages your session).
- Analytical cookies (with minimal impact): Cookies used to measure website visits, provided they are configured in a privacy-friendly manner (e.g. anonymised).
For these two categories, no consent and no cookie banner is required.
3. Cookies on denottersolutions.com
Den Otter Solutions values a clear, fast and privacy-friendly website.
Our website https://denottersolutions.com therefore uses only functional (necessary) cookies. We do not use analytical cookies (such as Google Analytics) or marketing or tracking cookies (such as those from Facebook or LinkedIn).
Because we only use cookies that fall under the legal exception, your consent (via a cookie banner) is not legally required.
4. Overview of Cookies Used
Below you will find an overview of the only cookie placed by our website to ensure its technical operation.
| Cookie Name | Provider | Purpose | Expiry |
|---|---|---|---|
| PHPSESSID (or similar, e.g. JSESSIONID) | denottersolutions.com (First-party) | Managing the technical user session to ensure the stability of the website. | End of browser session |
5. Blocking Cookies
You can always block the placement of cookies (including functional ones) through your internet browser settings. You can find instructions in the help section of your browser. Please note that blocking this necessary cookie may negatively affect the operation of the website.