Privacy statement
This statement explains which personal data Royaal Project processes through this website, why, on what legal basis, how long it is kept and what rights you have. It is written to meet the information duty in Articles 13 and 14 of the General Data Protection Regulation (GDPR, in Dutch the AVG).
Who is responsible
The controller for the processing described here is Royaal Project, a sole proprietorship established at Grevelingen 21, 6826 VE Arnhem, the Netherlands, registered with the Dutch Chamber of Commerce under number 64007995, VAT number NL001171906B20. For any question about this statement or about your data, contact info@royaalproject.nl.
What data is processed, and why
Contact form and email
When you use the contact form or send an email, the following is processed: your name, your email address, your organisation if you provide it, and the content of your message. This is used only to answer your enquiry and, where an engagement follows, to prepare and perform that engagement. The legal basis is the performance of a contract or the steps taken before entering into one (Article 6(1)(b) GDPR), and otherwise legitimate interest in responding to enquiries addressed to me (Article 6(1)(f)).
Booking an appointment
Appointments are scheduled through Motion (usemotion.com). If you book a call, the data you enter in that booking form, typically your name, email address and the subject of the call, is processed by Motion on my behalf and by me to hold the appointment. Basis: pre-contractual steps at your request (Article 6(1)(b)).
Website statistics
This site runs on WordPress.com and uses Jetpack Stats to count visits and see which pages are read. This produces aggregated statistics, and in that process a truncated IP address and technical browser data may be processed. No profiles are built and this data is not used for advertising. Basis: legitimate interest in understanding how the site is used (Article 6(1)(f)).
Newsletter
If you subscribe to updates, your email address and subscription date are processed to send you those updates. Basis: your consent (Article 6(1)(a)). You can withdraw consent at any time using the unsubscribe link in every message. If no newsletter is active, no such data is collected.
Who processes data on my behalf
I use a small number of suppliers that process personal data as processors under a data processing agreement: Automattic (WordPress.com and Jetpack) for hosting, the contact form and site statistics; MailPoet for email if a newsletter is active; Motion for appointment scheduling; and my email and office provider for correspondence and document handling. Some of these suppliers are established outside the European Economic Area. Where that is the case, transfers are based on the European Commission’s Standard Contractual Clauses and the supplementary measures those suppliers publish. Personal data is not sold and not shared with third parties for their own purposes.
How long data is kept
Enquiries that do not lead to an engagement are deleted within 12 months. Correspondence and records relating to an engagement are kept for the duration of the engagement and afterwards for as long as needed to meet legal obligations, including the seven-year retention period for administrative records under Dutch tax law. Newsletter data is kept until you unsubscribe. Statistics are retained in aggregated form.
Your rights
You have the right to ask for access to your personal data, to have it corrected or deleted, to have processing restricted, to object to processing based on legitimate interest, to receive your data in a portable form, and to withdraw consent where consent is the basis. Send your request to info@royaalproject.nl. I will respond within one month. If you are not satisfied with how your request is handled, you can lodge a complaint with the Dutch Data Protection Authority, the Autoriteit Persoonsgegevens.
Security
Appropriate technical and organisational measures are in place to protect personal data, including encrypted connections to this website, access control on my own devices and accounts, and multi-factor authentication where the supplier supports it. If a data breach occurs that is likely to present a risk to your rights, it is reported to the Autoriteit Persoonsgegevens and, where required, to you.
Changes to this statement
This statement may be updated when the website, the tools behind it or the applicable rules change. The version below applies until it is replaced. The general terms and conditions apply in addition to this statement for clients.
Version: 28 July 2026.