- Akismet Anti-Spam: processes IP address, user agent, and content data for spam detection. See Automattic Privacy Policy.
- Joinchat (WhatsApp): uses local storage cookies to control chat display behavior. These cookies do not contain personal data.
- Access, rectification, erasure, restriction, portability, and objection.
- Name, email address, phone number.
- Message content and attachments submitted through contact forms.
- Identification and contact details of applicants.
- CVs, cover letters, and employment-related information voluntarily submitted.
- Company name, role, billing address, VAT information.
- Payment references, transaction details, and plan selection.
- Authentication and access logs (IP address, timestamps, device/browser metadata).
- Configuration preferences and system settings relevant to the Service.
- Customer business records and operational data stored in hosted instances.
- Backups, logs, and metadata required to operate the Service.
- Login and session cookies required for authenticated users.
- Technical cookies required for site operation.
- Akismet Anti-Spam: processes IP address, user agent, and content data for spam detection. See Automattic Privacy Policy.
- Joinchat (WhatsApp): uses local storage cookies to control chat display behavior. These cookies do not contain personal data.
- Access, rectification, erasure, restriction, portability, and objection.
Note: The cookie and plugin list above reflects our intended website configuration. A live-stack audit may identify additional technologies; this policy will be updated when the production WordPress environment is confirmed.
6. Data Retention
| Data category | Retention period |
|---|---|
| Contact form submissions | Up to 12 months |
| Recruitment data | Up to 12 months after hiring process ends |
| Billing and accounting records | 7 years (Dutch tax law) |
| Hosted backups | Up to 30 days unless otherwise agreed |
| Support communications | Up to 24 months |
7. Data Sharing and Subprocessors
We do not sell or rent personal data. Data is shared only with subprocessors necessary to deliver the Services:
| Subprocessor (category) | Purpose | Location |
|---|---|---|
| EU hosting provider (contracted) | Website and service hosting | EEA |
| Payment processor (contracted) | Billing and payments | EEA |
| Support ticketing provider (contracted) | Customer support | EEA |
| Automattic (Akismet) | Spam detection on forms | US — see §8 |
| WordPress / plugin vendors (as deployed) | CMS and site operation | Per vendor |
Contracted vendor identities will be confirmed during live-stack review. Enterprise customers may request subprocessor details under applicable agreements.
8. International Transfers
WebDraco does not intentionally transfer personal data outside the European Economic Area (EEA). Where exceptional transfers occur, appropriate safeguards such as Standard Contractual Clauses (SCCs) are applied.
9. Your Rights
Requests may be submitted to privacy@webdraco.com. We aim to respond within 30 days.
You also have the right to lodge a complaint with a supervisory authority. In the Netherlands, the supervisory authority is the Autoriteit Persoonsgegevens (autoriteitpersoonsgegevens.nl).
10. Security and Breach Notification
We apply technical and organizational security measures including encryption, access controls, and monitoring. In the event of a personal data breach, notifications will be made in accordance with GDPR requirements.
11. Governing Law and Jurisdiction
This Privacy Policy is governed by the laws of the Kingdom of the Netherlands. Any disputes shall be subject to the exclusive jurisdiction of the courts of the Netherlands.
12. Changes to This Policy
This Privacy Policy may be updated to reflect legal or operational changes. The current version is always available on our website.
Contact
WebDraco – Data Protection Office
Houtweg 212, 7823 PM Emmen, The Netherlands
KvK 99737132 · BTW-id NL005407522B88
📧 privacy@webdraco.com
“Your data belongs to you. We guard it with precision, integrity, and professional discipline.”
This Privacy Policy explains how WebDraco collects, uses, stores, and protects personal data in connection with the WebDraco website and all WebDraco software solutions and related services (collectively, the “Services”).
Effective Date: January 2026 · Version: 2.0
WebDraco
Legal form: eenmanszaak
Registered with the Kamer van Koophandel under KvK number 99737132
BTW-id: NL005407522B88
Address: Houtweg 212, 7823 PM Emmen, The Netherlands
Email: privacy@webdraco.com
1. Purpose of This Policy
This Privacy Policy describes how WebDraco (“WebDraco”, “we”, “our”, “us”) processes personal data when you visit our website, contact us, request a demo, apply for a position, subscribe to or purchase a Service, or use any WebDraco software delivered as cloud-hosted, managed, or self-hosted (on-premise) deployment.
WebDraco acts as the commercial entity responsible for operations, contracts, billing, support, and data protection compliance. Ownership of the intellectual property underlying the software solutions remains with the Author.
Our data processing practices are designed to align with the principles of the General Data Protection Regulation (GDPR – Regulation (EU) 2016/679) and applicable Dutch and EU privacy laws. This statement describes our intended approach and does not constitute a guarantee of compliance in all circumstances.
2. Data Controller and Contact Information
WebDraco is the Data Controller for processing related to website interactions, marketing, sales, billing, recruitment, account management, and customer communications.
For certain cloud-hosted or managed Services, WebDraco may also act as a Data Processor, processing data on behalf of the Customer (the Data Controller). In such cases, a separate Data Processing Agreement (DPA) governs that relationship.
Contact: privacy@webdraco.com
3. Personal Data We Collect
Depending on your interaction with WebDraco, we may collect and process the following categories of personal data:
a) Website and Contact Forms
Contact form submissions are used exclusively to respond to inquiries and are not used for marketing without explicit consent.
b) Recruitment and Careers
Recruitment data is processed solely for candidate evaluation and hiring purposes and is accessible only to authorized personnel.
c) Account, Billing, and Commercial Data
d) Service Usage and Technical Data
e) Hosted Operational Data (Cloud / Managed Services)
Such data is processed solely on behalf of the Customer and subject to an applicable DPA where required.
4. Legal Bases for Processing
| Purpose | GDPR Legal Basis |
|---|---|
| Contact requests and account management | Contractual necessity (Art. 6(1)(b)) |
| Recruitment and candidate evaluation | Legitimate interest (Art. 6(1)(f)) |
| Billing and invoicing | Legal obligation (Art. 6(1)(c)) |
| Service delivery and support | Contractual necessity (Art. 6(1)(b)) |
| Marketing communications | Consent (Art. 6(1)(a)) |
| Security and fraud prevention | Legitimate interest (Art. 6(1)(f)) |
5. Cookies and Website Technologies
Our website uses essential cookies required for basic functionality.
Comments are disabled on this website.
We also use the following plugins:
Note: The cookie and plugin list above reflects our intended website configuration. A live-stack audit may identify additional technologies; this policy will be updated when the production WordPress environment is confirmed.
6. Data Retention
| Data category | Retention period |
|---|---|
| Contact form submissions | Up to 12 months |
| Recruitment data | Up to 12 months after hiring process ends |
| Billing and accounting records | 7 years (Dutch tax law) |
| Hosted backups | Up to 30 days unless otherwise agreed |
| Support communications | Up to 24 months |
7. Data Sharing and Subprocessors
We do not sell or rent personal data. Data is shared only with subprocessors necessary to deliver the Services:
| Subprocessor (category) | Purpose | Location |
|---|---|---|
| EU hosting provider (contracted) | Website and service hosting | EEA |
| Payment processor (contracted) | Billing and payments | EEA |
| Support ticketing provider (contracted) | Customer support | EEA |
| Automattic (Akismet) | Spam detection on forms | US — see §8 |
| WordPress / plugin vendors (as deployed) | CMS and site operation | Per vendor |
Contracted vendor identities will be confirmed during live-stack review. Enterprise customers may request subprocessor details under applicable agreements.
8. International Transfers
WebDraco does not intentionally transfer personal data outside the European Economic Area (EEA). Where exceptional transfers occur, appropriate safeguards such as Standard Contractual Clauses (SCCs) are applied.
9. Your Rights
Requests may be submitted to privacy@webdraco.com. We aim to respond within 30 days.
You also have the right to lodge a complaint with a supervisory authority. In the Netherlands, the supervisory authority is the Autoriteit Persoonsgegevens (autoriteitpersoonsgegevens.nl).
10. Security and Breach Notification
We apply technical and organizational security measures including encryption, access controls, and monitoring. In the event of a personal data breach, notifications will be made in accordance with GDPR requirements.
11. Governing Law and Jurisdiction
This Privacy Policy is governed by the laws of the Kingdom of the Netherlands. Any disputes shall be subject to the exclusive jurisdiction of the courts of the Netherlands.
12. Changes to This Policy
This Privacy Policy may be updated to reflect legal or operational changes. The current version is always available on our website.
Contact
WebDraco – Data Protection Office
Houtweg 212, 7823 PM Emmen, The Netherlands
KvK 99737132 · BTW-id NL005407522B88
📧 privacy@webdraco.com
“Your data belongs to you. We guard it with precision, integrity, and professional discipline.”
