Privacy Policy
Last updated: January 2025
Information We Collect
We collect several types of information to provide and improve our services:
Automatically Collected Information
When you visit our website, we automatically collect certain technical information including IP addresses (truncated and pseudonymised), browser type and version, operating system, device identifiers, referring website addresses, pages viewed, time spent on pages, and general geographic location data (country/region level only). This information is collected through cookies, web beacons, and similar tracking technologies.
Information You Provide
We collect information you voluntarily provide through our contact forms, including your name, email address, age range, and any questions or situations you describe. All such information is collected with your explicit consent.
Third-Party Analytics Data
We use third-party analytics services to understand website usage patterns. These services may collect information about your visits to our site and other websites to provide us with analytics reports.
How We Use Information
We process collected information for the following legitimate purposes:
- Service Provision: To respond to your enquiries and provide relevant pension savings information
- Website Analytics: To analyse usage patterns and improve our website functionality and content relevance
- Legal Compliance: To comply with applicable laws, regulations, and legal processes
- Security: To detect, prevent, and address technical issues and potential security threats
- Communication: To send you requested information about pension savings opportunities
- Research: To conduct statistical analysis and research to improve our services (using aggregated, non-personally identifiable data)
Legal Basis for Processing
Under the General Data Protection Regulation (GDPR), we process personal data based on the following legal grounds:
- Consent: When you provide information through our contact form
- Legitimate Interests: For website analytics, security, and improvement of services
- Legal Obligation: To comply with applicable financial services regulations and data protection laws
Information Sharing and Disclosure
Third-Party Service Providers: We may share information with trusted service providers who assist us in operating our website, conducting analytics, or responding to your enquiries. These providers are contractually required to maintain the confidentiality and security of your information.
Affiliate Partners: When you click on external links with tracking parameters, the destination websites may receive anonymised referral information. We do not share your personal information directly with these partners.
Legal Requirements: We may disclose information if required by law, regulation, legal process, or governmental request, or to protect our rights, property, or safety.
Business Transfers: In the event of a merger, acquisition, or sale of assets, your information may be transferred as part of the business transaction.
International Data Transfers
As we operate internationally, your personal data may be transferred to and processed in countries outside the European Economic Area (EEA). When we transfer data internationally, we ensure adequate protection through:
- European Commission adequacy decisions
- Standard Contractual Clauses approved by the European Commission
- Other legally recognised transfer mechanisms under applicable data protection laws
Cookies and Tracking Technologies
Essential Cookies: Required for basic website functionality and security. These cannot be disabled without affecting website performance.
Analytics Cookies: Help us understand how visitors interact with our website by collecting and reporting information anonymously.
Preference Cookies: Remember your choices and provide enhanced, personalised features.
Marketing Cookies: May be used to track visitors across websites for remarketing and affiliate tracking purposes.
You can control cookie preferences through your browser settings. However, disabling cookies may limit website functionality.
Data Retention
We retain personal information only for as long as necessary to fulfil the purposes outlined in this policy, unless a longer retention period is required by law. Specifically:
- Contact form submissions: Retained for up to 3 years for follow-up and regulatory compliance
- Website analytics data: Retained for up to 26 months in aggregated form
- Security logs: Retained for up to 12 months for security monitoring purposes
Your Rights Under Data Protection Laws
Depending on your location, you may have the following rights regarding your personal data:
- Access: Request a copy of personal data we hold about you
- Rectification: Request correction of inaccurate or incomplete personal data
- Erasure: Request deletion of your personal data in certain circumstances
- Restriction: Request limitation of processing of your personal data
- Portability: Request transfer of your personal data to another service provider
- Objection: Object to processing based on legitimate interests or for direct marketing
- Withdraw Consent: Withdraw consent for processing where consent is the legal basis
To exercise these rights, please contact us using the information provided in this policy. We will respond to your request within one month, or longer if the request is complex.
Data Security
We implement appropriate technical and organisational security measures to protect your personal data against unauthorised access, alteration, disclosure, or destruction. These measures include:
- Encryption of data in transit and at rest
- Regular security assessments and penetration testing
- Access controls and employee training on data protection
- Incident response procedures and breach notification protocols
While we strive to protect your personal data, no method of transmission over the internet or electronic storage is 100% secure. We cannot guarantee absolute security but are committed to using industry-standard practices.
Children's Privacy
Our services are not directed to individuals under 18 years of age. We do not knowingly collect personal information from children. If we become aware that we have collected personal information from a child without appropriate consent, we will take steps to delete such information promptly.
California Privacy Rights (CCPA)
California residents have additional rights under the California Consumer Privacy Act (CCPA):
- Right to know what personal information is collected and how it is used
- Right to delete personal information (subject to certain exceptions)
- Right to opt-out of the sale of personal information (we do not sell personal information)
- Right to non-discrimination for exercising privacy rights
Changes to This Policy
We may update this privacy policy periodically to reflect changes in our practices, technology, legal requirements, or other factors. Material changes will be prominently posted on our website with an updated effective date. Your continued use of our services after changes constitutes acceptance of the updated policy.
Supervisory Authority
If you are located in the European Economic Area and have concerns about our data processing practices, you have the right to lodge a complaint with your local data protection supervisory authority.
Contact Information
Data Controller: badkamernaarden.com
Email: For privacy-related enquiries, please use our contact form or refer to the external financial guidance resources linked on our website.
Response Time: We aim to respond to all privacy enquiries within 30 days.