Privacy statement
I take privacy seriously, and not only because the law asks me to. I work with patient organisations, hospitals and pharmaceutical companies, and much of what people share with me is personal. This page explains, in plain language, what happens to your data when you visit stefanbos.eu or contact me.
If anything here is unclear, just email me. I would rather explain it than have you guess.
Last updated:
1. Who is responsible for your data
Stefan Bos Consulting, trading under the names Stefan Bos Consulting and inventar.nl.
- Address: Het Spectrum 50, 8254 AT Dronten, the Netherlands
- Email: hello@stefanbos.eu
- Chamber of Commerce (KvK): 68215797
- VAT identification number: NL001217693B90
I am a sole trader. There is no data protection officer, because I am not required to appoint one. All privacy questions come to me directly at the address above.
This statement applies to the website stefanbos.eu and to the advisory, speaking and web design work I carry out under the names above.
2. What data I collect, and why
When you contact me
If you use the contact form or email me, I receive your name, your email address, the organisation you mention, and whatever you choose to write in your message.
I use this to answer you, and where relevant to prepare a proposal or an agreement.
Legal basis: taking steps at your request before entering into a contract (Article 6(1)(b) GDPR), or my legitimate interest in responding to professional enquiries (Article 6(1)(f) GDPR).
When we work together
For clients, I process contact details, invoicing details, contract terms and correspondence.
Legal basis: performance of a contract (Article 6(1)(b) GDPR), and legal obligation for the financial records I am required to keep (Article 6(1)(c) GDPR).
When you visit the website
My hosting provider automatically keeps standard server logs, which include IP addresses. These exist to keep the site running securely and to diagnose faults. I do not use them to identify individual visitors.
Legal basis: legitimate interest in a secure and functioning website (Article 6(1)(f) GDPR).
Website statistics
I want to know roughly how many people visit and which pages they find useful. I measure this with Burst Statistics, a tool that runs inside my own website on my own server.
This means:
- your visit is never sent to Google, Meta or any advertising network
- no third party company receives your data, because there is no third party involved
- nothing is stored on your device: no tracking cookies, no local storage
- visits are counted using an anonymous code that is regenerated every day, so no cookie is stored, no device fingerprint is taken, and nobody can be recognised from one day to the next
- if your browser sends a Do Not Track signal, your visit is not recorded at all
Because this measurement is aggregated and does not identify you, no consent banner is needed and none is shown. I made that choice deliberately. Accessibility is the subject I work on professionally, and consent pop-ups are one of the most common barriers on the web for people using a keyboard, a screen reader or limited hand function. A site that does not need one is a better site.
Legal basis: legitimate interest in understanding how my website performs (Article 6(1)(f) GDPR).
Search Console
I use Google Search Console to see which search terms lead people to this site. Search Console reports on Google's own search results in aggregated form. It does not place a tracker on this website and it does not tell me who you are.
3. A note on health information
Because of the work I do, some people who contact me want to share their own medical situation, or that of someone close to them.
Please do not send medical or health details through the contact form. Health data receives special protection under Article 9 GDPR, and a website form is not the right place for it.
If you do send me such information anyway, I treat it as confidential, I do not share it with anyone, and I delete it as soon as it is no longer needed for the conversation we are having. If health information needs to form part of professional work we do together, we agree that separately and in writing first.
4. Cookies
This website does not place tracking, advertising or profiling cookies, and it does not use a cookie banner because it does not need one.
WordPress may place a small number of strictly functional cookies, for example if you log in to the site as an administrator. These are necessary for the website to work and do not require consent under Article 11.7a of the Dutch Telecommunications Act.
If I ever add something that does require consent, such as an embedded video from an external platform, I will ask for your permission first and update this page.
5. Who else processes your data
I keep the list of parties involved as short as I reasonably can.
| Party | Role | Where data is held |
|---|---|---|
| Hostinger | Website hosting and server logs | European Economic Area, currently France, with backups in Lithuania |
| Titan | Email service for hello@stefanbos.eu, provided through Hostinger | As set out in the applicable data processing agreement |
| MoneyMonk | Bookkeeping and invoicing | Netherlands |
Website statistics do not appear in this table, because Burst Statistics runs on my own hosting rather than on someone else's platform. No separate company receives that data.
I have a data processing agreement in place with each party listed above. I do not sell your data, and I do not share it with anyone for marketing purposes.
I may share information where I am legally required to do so, for example with the tax authorities.
Transfers outside the European Economic Area
My website, its server logs and my website statistics are processed within the European Economic Area.
My email is provided through Titan, the email platform supplied with my Hostinger account. Titan operates distributed infrastructure and does not publish a single fixed storage location. This processing takes place in accordance with the applicable Hostinger and Titan data processing agreements and the accompanying sub-processor list, and where any processing occurs outside the European Economic Area it is subject to the safeguards required by Chapter V of the GDPR.
If your organisation has a specific requirement about where correspondence with me is stored, please tell me before you send it and we will agree a suitable route.
6. How long I keep things
| Data | Retention |
|---|---|
| Enquiries that do not lead to work | 12 months, then deleted |
| Client correspondence and contracts | 7 years after the end of the engagement |
| Invoices and financial records | 7 years, as required by Dutch tax law |
| Server logs | Up to 30 days |
| Website statistics | Aggregated and not traceable to you |
7. Your rights
Under the GDPR you have the right to:
- ask what personal data I hold about you and receive a copy
- have inaccurate data corrected
- have your data deleted
- restrict how I use your data
- object to processing based on legitimate interest
- receive your data in a portable format
- withdraw consent at any time, where processing is based on consent
Email hello@stefanbos.eu and I will respond within one month. I may ask you to confirm your identity first, so that I do not hand your data to someone else.
If you are not satisfied with how I handle your request, you are entitled to lodge a complaint with the Dutch Data Protection Authority, the Autoriteit Persoonsgegevens. I would appreciate the chance to sort it out with you first.
8. Security
The website runs over an encrypted HTTPS connection. Access to my systems is protected with strong, unique passwords and two factor authentication. I keep software and plugins up to date.
No system is perfect. If a data breach occurs that poses a risk to you, I will report it to the Autoriteit Persoonsgegevens within 72 hours and inform you directly where the law requires it.
9. Automated decision making
I do not use automated decision making or profiling. Every decision in my work is made by a human being, which in this case is me.
10. Links to other websites
This site links to other websites, including LinkedIn and the organisations I work with. Once you follow such a link, this privacy statement no longer applies. Please check the privacy statement of the site you land on.
11. Changes to this statement
I update this page whenever my website or my working practice changes in a way that affects your data. The date at the top always shows the most recent version.
12. Questions
Email hello@stefanbos.eu. Real answers from a real person, usually within a couple of working days.
