Privacy Policy
Lansinkstraat 136
7481 JS Haaksbergen
The Netherlands
KvK Number: 96450940
1. Introduction
Emerald Elephant Solutions BV ("we", "our", or "us") is committed to protecting and respecting your privacy. This Privacy Policy explains how we collect, use, and protect your personal information when you use our website and services.
This policy applies to all personal data we process as a data controller under the General Data Protection Regulation (GDPR) and Dutch data protection laws.
2. Information We Collect
2.1 Information You Provide Directly
- Contact Information: Name, email address, phone number, company name, job title
- Contact form: What you enter on our contact page: name, email address, optionally organisation and telephone number, the subject and your message. We use this only to reply. It is not stored in a database: the message arrives in our mailbox and falls under the retention period for correspondence there.
- Communication Data: Information in emails, messages, and other communications with us
- Project Information: Details about your business needs, requirements, and project specifications
- Contract Data: Information necessary for contract execution and invoicing
2.2 Information We Collect Automatically
- Website usage data: our web server writes one line for every visit: your IP address, the time, the page requested, whether it succeeded, how much was sent, the page you came from, and the line your browser sends along itself. That last one contains the name and version of your browser and of your operating system. This happens in the server's log files and not through cookies. We do not measure how long you stay on a page, we do not recognise you between visits, and we do not build a profile from it.
- Origin of an action in PRISMA: when you act through a personal link we send you, for instance to submit hours, raise a change request or confirm a decision, we record the IP address it came from and the moment it happened. This serves a different purpose from the server log files above: it belongs to the action itself and exists so it can be established afterwards who did what and when. The address is copied into the project record in Redmine and becomes part of the record of that action there.
- Cookies: Small files stored on your device (see our Cookie Policy for details)
3. How We Use Your Information
3.1 Legal Bases for Processing
We process your personal data based on:
- Contract performance: To provide our consulting services
- Legitimate interests: To improve our services and communicate about our business
- Legal obligations: To comply with accounting, tax, and other legal requirements
- Consent: we currently send no newsletter and no marketing email. If we ever do, we will ask for consent beforehand.
3.2 Purposes of Processing
- Providing executive interim management, business consulting, and project management services
- Developing and delivering custom software solutions
- Communicating about our services and responding to inquiries
- Managing client relationships and contracts
- Invoicing and accounting
- Improving our website and services
- Complying with legal and regulatory requirements
4. Data Sharing and Disclosure
We do not sell your personal data. We may share your information with:
4.1 Service Providers
- IT service providers and hosting companies
- Accounting and legal advisors
- Subcontractors involved in project delivery (with your consent)
4.2 Legal Requirements
We may disclose your information when required by law, court order, or regulatory authority.
4.3 Business Transfers
In the event of a merger, acquisition, or sale of assets, your information may be transferred as part of that transaction.
5. Data Security
We take appropriate technical and organisational measures to protect your personal data:
- All traffic over an encrypted connection. The public site, our desk and every personal link are reachable over https only.
- Separated domains. The public site, our desk and the environment where clients perform their actions each run on their own hostname with their own session cookie. Access to one does not grant access to another.
- The desk sits behind authentication and is excluded from search engines.
- A nightly backup whose restore has been tested. A backup that has never been restored is an assumption; ours has been restored in full once and reconciled against the running data.
- A small number of people with access. We are a small company, and the number of people who can reach client data is correspondingly small and known.
- Updates and security headers on the server and in the application.
6. Data Retention
We retain your personal data only as long as necessary for the purposes outlined in this policy:
- Client data: For the duration of our business relationship plus 7 years for legal and accounting purposes
- Marketing data: we do not keep any. There is no mailing list and no file of prospects.
- Server log files: these rotate by size and go back weeks to months, depending on traffic. They serve security and fault-finding only, not analysis.
- Origin of an action in PRISMA: for as long as the project record the action belongs to is kept, because it forms part of it. This exists in two places: in PRISMA and in the project record in Redmine. If you ask for erasure, we remove it in both; see section 7.
7. Your Rights Under GDPR
You have the following rights regarding your personal data:
- Right of access: Request a copy of your personal data
- Right to rectification: Correct inaccurate or incomplete data
- Right to erasure: Request deletion of your data (right to be forgotten)
- Right to restrict processing: Limit how we use your data
- Right to data portability: Receive your data in a portable format
- Right to object: Object to processing based on legitimate interests
- Rights regarding automated decision-making: Not to be subject to automated decisions
We take no automated decisions about people. What PRISMA calculates and flags concerns projects and engagements: progress, cost, deviation. Nobody is assessed by a system.
To exercise these rights, please contact us using the information provided below.
8. International Data Transfers
Your personal data is processed within the European Union. Our server is in the Netherlands and our email runs through a provider in Germany.
We currently do not transfer personal data to countries outside the EU. Should that change, we will amend this statement accordingly and put in place the safeguards the GDPR requires before we do.
9. Cookies and Website Technologies
Our website uses cookies and similar technologies. For detailed information about our use of cookies, please refer to our separate Cookie Policy.
10. Third-Party Links
Our website may contain links to third-party websites. We are not responsible for the privacy practices of these external sites. We encourage you to read their privacy policies.
11. Changes to This Privacy Policy
We may update this Privacy Policy from time to time. We will notify you of any material changes by posting the new policy on our website and updating the "Last Updated" date below.
12. Children's Privacy
Our services are not directed to children under 16 years of age. We do not knowingly collect personal information from children under 16.
Contact Us About Privacy
If you have any questions about this Privacy Policy or wish to exercise your rights, please contact us:
Data Protection Officer: Paul R. Zwiers
Email: paul@e-e-solutions.nl
Phone: +31 53 - 781 00 81
Address: Lansinkstraat 136, 7481 JS Haaksbergen, The Netherlands
Response Time: We will respond to your request within 30 days as required by GDPR.
13. Supervisory Authority
If you believe we have not adequately addressed your privacy concerns, you have the right to lodge a complaint with the Dutch Data Protection Authority (Autoriteit Persoonsgegevens):
- Website: www.autoriteitpersoonsgegevens.nl
- Phone: 088 – 1805 250
- Address: Postbus 93374, 2509 AJ Den Haag
Last Updated: 2025-08-27
Version: 1.0