Privacy statement

1. YourBI  

We are YourBI B.V., a Dutch company that trades under the name “YourBI”.   We operate in the European Economic Area (EEA) and we store our data on servers in West Europe or West US depending on our customers’ choice.   

2. General  

In this privacy statement we summarize which data we process about you and how we process it (Sections 3 - 5).  In this privacy statement you will also find more information about the rights you have in relation to your personal data and how to exercise them (Section 6).  We may change provisions of this privacy statement. If we do that, we will let you know. Nevertheless, we recommend that you periodically check yourself whether the privacy statement has been changed.  If you have any questions, concerns or comments about this privacy statement or if you wish to exercise your rights, please contact us by email at support@yourbi.nl.  

3. Which personal data do we process?  

If you use our services or visit our websites, we may process your personal data. Below we explain per role which personal data we may collect from you, why we process it and how long we store it.  

3.1 You use YourBI  

A. To offer you our service ‘YourBI’ and to make the service workable for you, we process the personal data mentioned below up to 2 years after your account has been terminated; your Session ID is kept for one day after your visit.  

We receive or generate the personal data mentioned below from you directly (for instance when you contact us or use our service). We use the data to create an account for you, to authorize you and to correspond with you about the service, your questions and any tickets you may submit. Our processing basis is the performance of an agreement. If you refuse to share your personal data with us for these purposes, we cannot provide you with our service. 

  • Name  

  • E-mail address  

  • Phone number  

  • Function  

  • Organization  

  • Content of any communications you have with us  

  • User ID  

  • Session ID  

  • YourBI tenant name (organization)  

  • Role within the YourBI software 

  • Powers and rights within the YourBI software  

  • Language  

  • Device information  

  • IP address  

  • Cookie ID / Log details  

  • Time of the visit  

  • Support requests  

  • Information with regards to the handling of any tickets    

    B. To secure our service, we process the personal data mentioned below up to 2 years after collecting it. We receive or generate the personal data mentioned below from you directly (when using our service). Our processing basis is our legitimate interest to secure our service.  

    • Name  

    • E-mail address 

    • IP address  

    • Date and time of logging in and out 

    • Role within the YourBI software  

    • Powers and rights within the YourBI software  

    • Actions performed on YourBI  

    C. To improve our service, we process the personal data mentioned below up to 2 years after collecting it. We receive or generate the personal data mentioned below from you directly (when using our service). Our processing basis is our legitimate interest to improve our service. Your interests are safeguarded because the data processing is limited.  

    • Name  

    • User ID  

    • Session ID  

    • YourBI tenant name  

    • IP address  

    • Browser information  

    • Location data (country / province level)  

    • Actions performed on YourBI  

    • Use of YourBI and problems encountered  

    • Language  

    • Device information  

    • Internet Service Provider (ISP)  

    • Length of the session  

    For more information on the placement of cookies when using the YourBI software, please refer to our cookie statement: https://www.yourbi.nl/cookie-policy/  

    D. If you use YourBI, we can send you marketing material such as newsletters and offers. To this end, we process the personal data mentioned below up to 4 years after we last had contact with you or, if that is later, you last performed an action on YourBI. We send such marketing communications in accordance with the applicable privacy legislation. We may also send you surveys, interactive forms, evaluations or feedback requests. Our processing basis is our legitimate interest to improve our service.  

    • Name  

    • E-mail address  

    • Phone number  

    • Function  

    • Organization  

    • Content of communications you have with us  

    • User ID  

    • Browser ID  

    • IP address  

    • Browser information  

    • Location data (country / province / city level)  

    • Role within the YourBI software  

    • Actions performed on and use of YourBI  

    • Language  

    • Demographic data  

    You can unsubscribe from receiving these (marketing) messages by following the unsubscribe instructions included in each newsletter or by contacting us via support@yourbi.nl. If you unsubscribe from receiving (marketing) materials, it will not affect our ability to send you emails about important matters and your account.  

    E. If you use YourBI, you can choose to fill in optional fields voluntarily. If you do this, our processing basis to process the entered personal data is our legitimate interest (to improve our services or to personalize your account). We receive the personal data mentioned below from you directly. This concerns the following personal data, processed up to 2 years after collection:  

    • Name (via completed questionnaires)  

    • Function (via completed questionnaires)  

    • Organization (via completed questionnaires)  

    • Answers provided (via completed questionnaires)  

    • Reviews given  

    3.2 You are a visitor to our website  

    A. To ensure that you can use our website, we process the personal data mentioned below during your visit to our website. We receive this personal data directly from you. Our processing basis is our legitimate interest in being able to show you a website that works.  

    • Language  

    This information can be shared with LinkedIn to set the language preference correctly. LinkedIn may process the data in the U.S., but uses standard contractual clauses approved by the European Commission.  

    B. To secure our website, we process the personal data mentioned below up to 2 years after collecting it. The personal data listed below is generated when you use our website. Our processing basis is our legitimate interest to secure our website.  

    • IP address  

    • Browser and device information  

    • Log details  

    • Cookie ID  

    • Network and traffic data  

      C. To improve our website, we process the personal data mentioned below up to 2 years after collecting it. The personal data listed below is generated when you use our website. Our processing basis is our legitimate interest to improve our website. Your interests are safeguarded because data processing is limited and you can choose not to share the data by unchecking the “analytical cookies” box.  

      • Browser information  

      • Location data at country / province level  

      • Google user ID  

      • Device information  

      • The duration of your website visit and how you use our website  

      • Demographic data  

      The above data can be shared with Google Analytics, which can store data outside the EEA but guarantees to continue to comply with European privacy legislation.  

      D. We place tracking and advertising cookies if you visit our website and give us permission to do so in the cookie banner. The personal data listed below is generated when you use our website. The cookies process the information mentioned below up to 2 years after the collection of the data.  

      • IP address  

      • Device information  

      • The duration of your website visit and how you use our website  

      • Google advertising ID  

      • Browser ID  

      • HubSpot user ID  

      • Demographic data  

      • Location data  

      • Cookie preferences  

      • Cookie ID  

      The tracking cookies are placed by HubSpot, Google and LinkedIn. They can store the data outside the EEA, but guarantee to comply with European privacy legislation. 

      You can amend your settings via the cookie banner. For further information on the placement of cookies by our website, please refer to our cookie statement: https://www.yourbi.nl/cookie-policy/  

      E. If you ask us a question or make a request, we will process the personal data listed below up to 4 years after we last had contact with you. We receive or generate this personal data directly from you, when using our services or by contacting us. Our processing basis is our legitimate interest to respond to your questions and requests and to improve our services.  

      • Name  

      • E-mail address  

      • Phone number  

      • Content of any communications you have with us  

      • User ID  

      • Organization  

      • Language  

      • Conversation assessment (to improve our services)  

      • Date of registration and first visit (to improve our services)  

      • Date of last seen and last contact (to improve our services)  

      • Number of active web sessions (to improve our services)  

        We store the above personal data at HubSpot, Inc., which stores data outside of the EEA (in the United States). HubSpot complies with European privacy legislation through the use of Standard Contractual Clauses (SCCs) as approved by the European Commission.   

        F. If you register yourself for a newsletter on our website, we will process the data mentioned below until you unsubscribe from the newsletter. Our processing basis is consent, because you voluntarily sign up for the newsletter.  

        • Name  

        • E-mail address  

        You can unsubscribe from these newsletters by following the unsubscribe instructions included with each newsletter. If you unsubscribe from the newsletter, it will not affect our ability to send you emails about important matters and your account.  

        3.3 You apply for a job at YourBI  

        A. If you apply for a job at YourBI, we will process the personal data mentioned below up to 12 weeks after completing the application or up to 1 year if you request it. We receive the personal data mentioned below from you directly (for instance when you provide us with your curriculum vitae and other documents and when we communicate with you). We may also receive your personal data from other sources (such as your LinkedIn profile, your previous employer(s), educational institutions you attended, etc.). Our processing basis is our legitimate interest to process your application.  

        • Name  

        • Address  

        • E-mail address  

        • Phone number  

        • Your employer  

        • Your function  

        • Curriculum vitae and motivation letter  

        • Your profile picture  

        • Information about your availability and employability for work  

        • Information provided in the appropriate open fields and information you provide to us during an interview  

        • Information included on your LinkedIn profile  

        • Information provided to us by referees (such as your previous employer and/or educational institution)  

        3.4 If you work for a party with whom we intend to enter into a business relationship  

        A. We approach interesting parties, such as potential customers, with the aim of establishing a business relationship with them. If you act as contact person for such a party, we will process the personal data mentioned below up to 4 years after we last had contact with you. We receive or generate this personal data directly from you and/or from the organization you work for. Our processing basis is our legitimate interest to promote and grow our business by approaching and maintaining contact with prospective customers, suppliers and other business partners, and to manage and document those (potential) business relationships. You can always opt-out or object to such processing by contacting us via support@yourbi.nl.  

        • Name  

        • E-mail address  

        • Phone number  

        • Function  

        • Organization  

        • Content of communications you have with us  

        • Language  

        • Preference with respect to the receiving of marketing materials  

        3.5 We conduct business with the organization you work for 


        A. If the organization you work for entered into a contract with us (as customer or supplier), we may process the personal data below (i) for invoicing and payment processing purposes and to (ii) comply with accounting and tax obligations. We receive this personal data directly from you or from the organization you work for. Our processing basis are (i) to perform the agreement we concluded with your organization and (ii) to comply with legal obligations to which YourBI is subject. We keep this personal data for 7 years from the date of payment/invoice date.  

        • Identification and contact information for the billing contact person  

        • Invoice and payment details  

        • Correspondence  

        • Signature  


        B. If the organization you work for entered into a contract with us (as customer or supplier), we may process the personal data below for communication purposes, contract management, relationship management, account management and customer relationships purposes (“customer relationship management”). We receive or generate this personal data directly from you in the context of our customer relationship or from the organization you work for; certain data is generated by us. Our processing basis is our legitimate interest to effectively maintain our customer relationships.  

        • Name  

        • E-mail address  

        • Phone number  

        • Function  

        • Organization  

        • Content of communications you have with us  

        • Language  

        • Preference with respect to the receiving of marketing materials 

        • Signature   

        3.6 Internal operations  

        A. We may use your personal data (for instance when it is contained in certain documents) for internal knowledge management and collaboration purposes (for example, for recording and sharing information among YourBI teams), tracking statistics and performance, work and project management, structuring workflows and tasks, and planning and prioritizing product roadmaps. Our processing basis is our legitimate interest in organizing and improving our internal operations. These activities help us to operate efficiently, maintain and improve the quality, security and continuity of our services, and develop our products in line with customer needs.  

        Where we use your personal data for these purposes, we do so only to the extent reasonably necessary and proportionate, and we take steps to minimize the use of directly identifiable information where possible (for example by redacting or aggregating data).  

        3.7 Legal proceedings  

        A. We may use and retain your personal data to establish, exercise or defend legal claims in legal proceedings (for example, in the context of a dispute with the organization you work for). All personal data described in this privacy statement may be processed and retained in the case of a claim or legal proceedings. Our processing basis is our legitimate interest to be able to defend YourBI in such case. We may retain your personal data for as long as necessary to establish, exercise or defend actual or potential legal claims. 

        3.8 Government requests and court orders  

        A. We may receive requests from government authorities or court orders which oblige us to share certain personal data we process of you with them or a party designated in the order. We will inform you of such orders prior to sharing your personal data, unless the order forbids us from doing so. All personal data described in this privacy statement may be included in the request, but only insofar YourBI is obliged to provide the personal data. Our processing basis is to comply with such legal obligation. We store the personal data until the order has been fulfilled and any terms of appeal or objection have expired.  

        3.9 Audits  

        A. We may be subject to audits for certifications or by our customers or conduct internal audits to verify if we comply with our various requirements. If we process your personal data, this personal data may be processed by the auditor if this is strictly necessary for the audit. We will anonymize or pseudonymize your data as much as possible before sharing it with the auditor. All personal data described in this privacy statement may be included in the audit, but only insofar necessary. Our processing basis is compliance with a legal obligation to conduct audits or our legitimate interest to operate our business, to comply with legislation, to gain certifications and to verify that we comply with modern security requirements. We store the personal data for up to 2 years after the audit took place or, if storing personal data is an audit requirement, up to 2 years after expiry of such term.  

        3.10 Complying with GDPR requests  

        A. You may exercise your rights under the GDPR (see Section 6). We must process your personal data, such as your identification details, when complying with your request. We will only process the personal data which is necessary to comply with your request. Our processing basis is to comply with a legal obligation to comply with GDPR requests. In case your personal data is processed for this purpose, the processed personal data will be stored until 5 years after the request has been handled.

4. Sharing your personal data  

4.1 Our data processors  

We may ask others to assist us in providing our services and websites. These “processors” can therefore process your personal data on our behalf. We agree with these processors that they may only use your personal data to enable our services.  We may use the following types of processors:  

  • parties that host our services and websites, store data and manage and maintain our servers and databases;  

  • developers and suppliers of software and questionnaires;  

  • analytical software suppliers to improve our services;  

  • providers of relationship management software.  

4.2 Sharing your personal data with third parties  

We only share your personal data with third parties if this:  

  1. is described in this privacy statement and we have a valid basis for this;  

  2. is reasonably necessary or appropriate to comply with legal obligations; 

  3. is necessary to comply with legal requests from authorities; 

  4. is necessary to respond to any claims;  

  5. is necessary to protect the rights, property or safety of us, our users, our employees or the public;  

  6. is necessary to protect ourselves or our users from fraudulent, offensive, inappropriate or unlawful use of our services.  

We will notify you immediately if a government agency makes a request relating to your personal data, unless we are not allowed to do so by law.  

Our websites may also contain links to websites of others. If you provide your personal data on these third party pages, the privacy policy of this third party applies. We are not responsible for the content of the privacy policy of these parties and the way in which these parties process your personal data. We encourage you to review their privacy policy before providing any personal information to them.  

5. Protection of your personal data  

We have taken appropriate technical and organizational security measures to protect your personal data. We have in any case taken the following measures:  

  • We have physically and digitally secured our servers so that people cannot view your personal data without our consent.  

  • We use security to ensure that data is sent encrypted between our services, the websites and our servers.  

  • Vulnerabilities in the services and on the websites are addressed as quickly as possible.  

  • We have implemented physical and electronic measures designed to prevent unauthorized access, loss or misuse of personal data as much as possible.  

We would like to point out that the internet is never completely secure. So be careful what you share via the internet. If in doubt, contact us first.  

6. Your rights 

You have certain rights regarding your personal data. The rights that we describe below are not absolute rights. We will always consider whether we can reasonably meet your request. If this is not possible, or if it would, for example, be at the expense of the privacy of others, we can refuse your request. If we refuse a request, we will let you know why we have done so.  

6.1 Right to access  

You have the right to ask us the following: 

  • why we process your personal data;  

  • what types of personal data we process about you;

  • what types of parties we share your personal data with;  

  • how long we store your personal data;  

  • where the personal data comes from; 

  • whether we use automated decision-making.  

You may also request a copy of your personal data processed by us. Do you want additional copies? Then we can charge a reasonable fee for this.   

6.2 Right to rectification  

If the personal data processed by us is incorrect or incomplete, you can request us to adjust or supplement your personal data. You can also amend certain personal data we hold about you via your account. If we approve your request, we will, insofar as this is reasonably possible, inform the parties to whom we have provided your personal data.  

6.3 Right to erasure of data

Do you no longer want us to process certain personal data about you? Then you can request us to delete some or all of your personal data. If we have accidentally processed data unlawfully or a specific law prescribes that we must delete personal data, we will delete the personal data. If the personal data is necessary for the settlement of a legal procedure or a (legal) dispute, we will only delete the personal data after the procedure or dispute has ended. If we approve your request, we will, insofar as this is reasonably possible, inform the parties to whom we have provided your personal data. 

6.4 Restriction of processing  

If you believe that we are not processing your personal data correctly, or if you believe that we are processing your personal data unlawfully, or if you believe that we no longer need it, you can request us to restrict the processing of your personal data. If we restrict the processing of your personal data at your request, we may still use that personal data for the settlement of legal proceedings or a (legal) dispute.  

6.5 Right to data portability  

You have the right to receive the personal data which you have provided to us, in a structured, commonly used and machine-readable format and have this personal data transmitted to another party (where technically feasible). You only have this right to data portability when the processing is based on your consent or when this is necessary for the performance of an agreement, and the processing is carried out by automated means. We refer to Section 3 of this privacy statement for further information on our processing activities.  

6.6 Right to object  

When the processing of your personal data is based on our ‘legitimate interest’ (see Section 3 of this privacy statement for more information), you have the right to object to such processing on grounds relating to your particular situation. When exercising your right to object, we will review the processing of your personal data. We will stop with the processing of your personal data on this ground, unless we have very good reasons to continue the processing which outweighs your interests, or that relate to a legal claim. When you object to processing for direct marketing purposes, the personal data shall no longer be processed for such purposes.  

6.7 Automated individual decision-making  

We do not make decisions based solely on automated processing. 

6.8 Withdrawal of consent  

You may withdraw your consent at any time by clearing voluntarily completed fields, amending your account settings or by contacting us. Please note that when you withdraw your consent, this does not affect the lawfulness of the processing based on consent before its withdrawal. 

 6.9 Exercising your rights  

You can send the above requests to support@yourbi.nl.  Before we respond to your request, we must first make sure that it is your personal data. We usually do this by having you log in to your YourBI account. If you do not have an account or if we cannot confirm your identity in this way, we will try to verify your identity by email or telephone. If that also fails, we can ask for a copy of a valid ID. In that case, do not forget to shield your social security number (BSN), MRZ (Machine Readable Zone) and passport photo.  

We aim to deal with your request or complaint within one month. If it is not possible to make a decision within one month, we will notify you (within one month) of the reasons for the delay and when the decision is expected to be made. This can never be longer than 3 months after receipt of the request.  

6.10 Dutch Data Protection Authority / Autoriteit Persoonsgegevens  

Do you have a complaint about our processing? Then contact us. We are happy to help you. Should we nevertheless not come to an agreement, you also have the right to file a complaint with the privacy supervisor, the Dutch Data Protection Authority (Autoriteit Persoonsgegevens). You can contact the Dutch Data Protection Authority via https://autoriteitpersoonsgegevens.nl/.  

7. Contact  

If you have any questions, concerns or comments about this privacy statement, please contact us by email at support@yourbi.nl.  


 

Privacy statement

1. YourBI  

We are YourBI B.V., a Dutch company that trades under the name “YourBI”.   We operate in the European Economic Area (EEA) and we store our data on servers in West Europe or West US depending on our customers’ choice.   

2. General  

In this privacy statement we summarize which data we process about you and how we process it (Sections 3 - 5).  In this privacy statement you will also find more information about the rights you have in relation to your personal data and how to exercise them (Section 6).  We may change provisions of this privacy statement. If we do that, we will let you know. Nevertheless, we recommend that you periodically check yourself whether the privacy statement has been changed.  If you have any questions, concerns or comments about this privacy statement or if you wish to exercise your rights, please contact us by email at support@yourbi.nl.  

3. Which personal data do we process?  

If you use our services or visit our websites, we may process your personal data. Below we explain per role which personal data we may collect from you, why we process it and how long we store it.  

3.1 You use YourBI  

A. To offer you our service ‘YourBI’ and to make the service workable for you, we process the personal data mentioned below up to 2 years after your account has been terminated; your Session ID is kept for one day after your visit.  

We receive or generate the personal data mentioned below from you directly (for instance when you contact us or use our service). We use the data to create an account for you, to authorize you and to correspond with you about the service, your questions and any tickets you may submit. Our processing basis is the performance of an agreement. If you refuse to share your personal data with us for these purposes, we cannot provide you with our service. 

  • Name  

  • E-mail address  

  • Phone number  

  • Function  

  • Organization  

  • Content of any communications you have with us  

  • User ID  

  • Session ID  

  • YourBI tenant name (organization)  

  • Role within the YourBI software 

  • Powers and rights within the YourBI software  

  • Language  

  • Device information  

  • IP address  

  • Cookie ID / Log details  

  • Time of the visit  

  • Support requests  

  • Information with regards to the handling of any tickets    

    B. To secure our service, we process the personal data mentioned below up to 2 years after collecting it. We receive or generate the personal data mentioned below from you directly (when using our service). Our processing basis is our legitimate interest to secure our service.  

    • Name  

    • E-mail address 

    • IP address  

    • Date and time of logging in and out 

    • Role within the YourBI software  

    • Powers and rights within the YourBI software  

    • Actions performed on YourBI  

    C. To improve our service, we process the personal data mentioned below up to 2 years after collecting it. We receive or generate the personal data mentioned below from you directly (when using our service). Our processing basis is our legitimate interest to improve our service. Your interests are safeguarded because the data processing is limited.  

    • Name  

    • User ID  

    • Session ID  

    • YourBI tenant name  

    • IP address  

    • Browser information  

    • Location data (country / province level)  

    • Actions performed on YourBI  

    • Use of YourBI and problems encountered  

    • Language  

    • Device information  

    • Internet Service Provider (ISP)  

    • Length of the session  

    For more information on the placement of cookies when using the YourBI software, please refer to our cookie statement: https://www.yourbi.nl/cookie-policy/  

    D. If you use YourBI, we can send you marketing material such as newsletters and offers. To this end, we process the personal data mentioned below up to 4 years after we last had contact with you or, if that is later, you last performed an action on YourBI. We send such marketing communications in accordance with the applicable privacy legislation. We may also send you surveys, interactive forms, evaluations or feedback requests. Our processing basis is our legitimate interest to improve our service.  

    • Name  

    • E-mail address  

    • Phone number  

    • Function  

    • Organization  

    • Content of communications you have with us  

    • User ID  

    • Browser ID  

    • IP address  

    • Browser information  

    • Location data (country / province / city level)  

    • Role within the YourBI software  

    • Actions performed on and use of YourBI  

    • Language  

    • Demographic data  

    You can unsubscribe from receiving these (marketing) messages by following the unsubscribe instructions included in each newsletter or by contacting us via support@yourbi.nl. If you unsubscribe from receiving (marketing) materials, it will not affect our ability to send you emails about important matters and your account.  

    E. If you use YourBI, you can choose to fill in optional fields voluntarily. If you do this, our processing basis to process the entered personal data is our legitimate interest (to improve our services or to personalize your account). We receive the personal data mentioned below from you directly. This concerns the following personal data, processed up to 2 years after collection:  

    • Name (via completed questionnaires)  

    • Function (via completed questionnaires)  

    • Organization (via completed questionnaires)  

    • Answers provided (via completed questionnaires)  

    • Reviews given  

    3.2 You are a visitor to our website  

    A. To ensure that you can use our website, we process the personal data mentioned below during your visit to our website. We receive this personal data directly from you. Our processing basis is our legitimate interest in being able to show you a website that works.  

    • Language  

    This information can be shared with LinkedIn to set the language preference correctly. LinkedIn may process the data in the U.S., but uses standard contractual clauses approved by the European Commission.  

    B. To secure our website, we process the personal data mentioned below up to 2 years after collecting it. The personal data listed below is generated when you use our website. Our processing basis is our legitimate interest to secure our website.  

    • IP address  

    • Browser and device information  

    • Log details  

    • Cookie ID  

    • Network and traffic data  

      C. To improve our website, we process the personal data mentioned below up to 2 years after collecting it. The personal data listed below is generated when you use our website. Our processing basis is our legitimate interest to improve our website. Your interests are safeguarded because data processing is limited and you can choose not to share the data by unchecking the “analytical cookies” box.  

      • Browser information  

      • Location data at country / province level  

      • Google user ID  

      • Device information  

      • The duration of your website visit and how you use our website  

      • Demographic data  

      The above data can be shared with Google Analytics, which can store data outside the EEA but guarantees to continue to comply with European privacy legislation.  

      D. We place tracking and advertising cookies if you visit our website and give us permission to do so in the cookie banner. The personal data listed below is generated when you use our website. The cookies process the information mentioned below up to 2 years after the collection of the data.  

      • IP address  

      • Device information  

      • The duration of your website visit and how you use our website  

      • Google advertising ID  

      • Browser ID  

      • HubSpot user ID  

      • Demographic data  

      • Location data  

      • Cookie preferences  

      • Cookie ID  

      The tracking cookies are placed by HubSpot, Google and LinkedIn. They can store the data outside the EEA, but guarantee to comply with European privacy legislation. 

      You can amend your settings via the cookie banner. For further information on the placement of cookies by our website, please refer to our cookie statement: https://www.yourbi.nl/cookie-policy/  

      E. If you ask us a question or make a request, we will process the personal data listed below up to 4 years after we last had contact with you. We receive or generate this personal data directly from you, when using our services or by contacting us. Our processing basis is our legitimate interest to respond to your questions and requests and to improve our services.  

      • Name  

      • E-mail address  

      • Phone number  

      • Content of any communications you have with us  

      • User ID  

      • Organization  

      • Language  

      • Conversation assessment (to improve our services)  

      • Date of registration and first visit (to improve our services)  

      • Date of last seen and last contact (to improve our services)  

      • Number of active web sessions (to improve our services)  

        We store the above personal data at HubSpot, Inc., which stores data outside of the EEA (in the United States). HubSpot complies with European privacy legislation through the use of Standard Contractual Clauses (SCCs) as approved by the European Commission.   

        F. If you register yourself for a newsletter on our website, we will process the data mentioned below until you unsubscribe from the newsletter. Our processing basis is consent, because you voluntarily sign up for the newsletter.  

        • Name  

        • E-mail address  

        You can unsubscribe from these newsletters by following the unsubscribe instructions included with each newsletter. If you unsubscribe from the newsletter, it will not affect our ability to send you emails about important matters and your account.  

        3.3 You apply for a job at YourBI  

        A. If you apply for a job at YourBI, we will process the personal data mentioned below up to 12 weeks after completing the application or up to 1 year if you request it. We receive the personal data mentioned below from you directly (for instance when you provide us with your curriculum vitae and other documents and when we communicate with you). We may also receive your personal data from other sources (such as your LinkedIn profile, your previous employer(s), educational institutions you attended, etc.). Our processing basis is our legitimate interest to process your application.  

        • Name  

        • Address  

        • E-mail address  

        • Phone number  

        • Your employer  

        • Your function  

        • Curriculum vitae and motivation letter  

        • Your profile picture  

        • Information about your availability and employability for work  

        • Information provided in the appropriate open fields and information you provide to us during an interview  

        • Information included on your LinkedIn profile  

        • Information provided to us by referees (such as your previous employer and/or educational institution)  

        3.4 If you work for a party with whom we intend to enter into a business relationship  

        A. We approach interesting parties, such as potential customers, with the aim of establishing a business relationship with them. If you act as contact person for such a party, we will process the personal data mentioned below up to 4 years after we last had contact with you. We receive or generate this personal data directly from you and/or from the organization you work for. Our processing basis is our legitimate interest to promote and grow our business by approaching and maintaining contact with prospective customers, suppliers and other business partners, and to manage and document those (potential) business relationships. You can always opt-out or object to such processing by contacting us via support@yourbi.nl.  

        • Name  

        • E-mail address  

        • Phone number  

        • Function  

        • Organization  

        • Content of communications you have with us  

        • Language  

        • Preference with respect to the receiving of marketing materials  

        3.5 We conduct business with the organization you work for 


        A. If the organization you work for entered into a contract with us (as customer or supplier), we may process the personal data below (i) for invoicing and payment processing purposes and to (ii) comply with accounting and tax obligations. We receive this personal data directly from you or from the organization you work for. Our processing basis are (i) to perform the agreement we concluded with your organization and (ii) to comply with legal obligations to which YourBI is subject. We keep this personal data for 7 years from the date of payment/invoice date.  

        • Identification and contact information for the billing contact person  

        • Invoice and payment details  

        • Correspondence  

        • Signature  


        B. If the organization you work for entered into a contract with us (as customer or supplier), we may process the personal data below for communication purposes, contract management, relationship management, account management and customer relationships purposes (“customer relationship management”). We receive or generate this personal data directly from you in the context of our customer relationship or from the organization you work for; certain data is generated by us. Our processing basis is our legitimate interest to effectively maintain our customer relationships.  

        • Name  

        • E-mail address  

        • Phone number  

        • Function  

        • Organization  

        • Content of communications you have with us  

        • Language  

        • Preference with respect to the receiving of marketing materials 

        • Signature   

        3.6 Internal operations  

        A. We may use your personal data (for instance when it is contained in certain documents) for internal knowledge management and collaboration purposes (for example, for recording and sharing information among YourBI teams), tracking statistics and performance, work and project management, structuring workflows and tasks, and planning and prioritizing product roadmaps. Our processing basis is our legitimate interest in organizing and improving our internal operations. These activities help us to operate efficiently, maintain and improve the quality, security and continuity of our services, and develop our products in line with customer needs.  

        Where we use your personal data for these purposes, we do so only to the extent reasonably necessary and proportionate, and we take steps to minimize the use of directly identifiable information where possible (for example by redacting or aggregating data).  

        3.7 Legal proceedings  

        A. We may use and retain your personal data to establish, exercise or defend legal claims in legal proceedings (for example, in the context of a dispute with the organization you work for). All personal data described in this privacy statement may be processed and retained in the case of a claim or legal proceedings. Our processing basis is our legitimate interest to be able to defend YourBI in such case. We may retain your personal data for as long as necessary to establish, exercise or defend actual or potential legal claims. 

        3.8 Government requests and court orders  

        A. We may receive requests from government authorities or court orders which oblige us to share certain personal data we process of you with them or a party designated in the order. We will inform you of such orders prior to sharing your personal data, unless the order forbids us from doing so. All personal data described in this privacy statement may be included in the request, but only insofar YourBI is obliged to provide the personal data. Our processing basis is to comply with such legal obligation. We store the personal data until the order has been fulfilled and any terms of appeal or objection have expired.  

        3.9 Audits  

        A. We may be subject to audits for certifications or by our customers or conduct internal audits to verify if we comply with our various requirements. If we process your personal data, this personal data may be processed by the auditor if this is strictly necessary for the audit. We will anonymize or pseudonymize your data as much as possible before sharing it with the auditor. All personal data described in this privacy statement may be included in the audit, but only insofar necessary. Our processing basis is compliance with a legal obligation to conduct audits or our legitimate interest to operate our business, to comply with legislation, to gain certifications and to verify that we comply with modern security requirements. We store the personal data for up to 2 years after the audit took place or, if storing personal data is an audit requirement, up to 2 years after expiry of such term.  

        3.10 Complying with GDPR requests  

        A. You may exercise your rights under the GDPR (see Section 6). We must process your personal data, such as your identification details, when complying with your request. We will only process the personal data which is necessary to comply with your request. Our processing basis is to comply with a legal obligation to comply with GDPR requests. In case your personal data is processed for this purpose, the processed personal data will be stored until 5 years after the request has been handled.

4. Sharing your personal data  

4.1 Our data processors  

We may ask others to assist us in providing our services and websites. These “processors” can therefore process your personal data on our behalf. We agree with these processors that they may only use your personal data to enable our services.  We may use the following types of processors:  

  • parties that host our services and websites, store data and manage and maintain our servers and databases;  

  • developers and suppliers of software and questionnaires;  

  • analytical software suppliers to improve our services;  

  • providers of relationship management software.  

4.2 Sharing your personal data with third parties  

We only share your personal data with third parties if this:  

  1. is described in this privacy statement and we have a valid basis for this;  

  2. is reasonably necessary or appropriate to comply with legal obligations; 

  3. is necessary to comply with legal requests from authorities; 

  4. is necessary to respond to any claims;  

  5. is necessary to protect the rights, property or safety of us, our users, our employees or the public;  

  6. is necessary to protect ourselves or our users from fraudulent, offensive, inappropriate or unlawful use of our services.  

We will notify you immediately if a government agency makes a request relating to your personal data, unless we are not allowed to do so by law.  

Our websites may also contain links to websites of others. If you provide your personal data on these third party pages, the privacy policy of this third party applies. We are not responsible for the content of the privacy policy of these parties and the way in which these parties process your personal data. We encourage you to review their privacy policy before providing any personal information to them.  

5. Protection of your personal data  

We have taken appropriate technical and organizational security measures to protect your personal data. We have in any case taken the following measures:  

  • We have physically and digitally secured our servers so that people cannot view your personal data without our consent.  

  • We use security to ensure that data is sent encrypted between our services, the websites and our servers.  

  • Vulnerabilities in the services and on the websites are addressed as quickly as possible.  

  • We have implemented physical and electronic measures designed to prevent unauthorized access, loss or misuse of personal data as much as possible.  

We would like to point out that the internet is never completely secure. So be careful what you share via the internet. If in doubt, contact us first.  

6. Your rights 

You have certain rights regarding your personal data. The rights that we describe below are not absolute rights. We will always consider whether we can reasonably meet your request. If this is not possible, or if it would, for example, be at the expense of the privacy of others, we can refuse your request. If we refuse a request, we will let you know why we have done so.  

6.1 Right to access  

You have the right to ask us the following: 

  • why we process your personal data;  

  • what types of personal data we process about you;

  • what types of parties we share your personal data with;  

  • how long we store your personal data;  

  • where the personal data comes from; 

  • whether we use automated decision-making.  

You may also request a copy of your personal data processed by us. Do you want additional copies? Then we can charge a reasonable fee for this.   

6.2 Right to rectification  

If the personal data processed by us is incorrect or incomplete, you can request us to adjust or supplement your personal data. You can also amend certain personal data we hold about you via your account. If we approve your request, we will, insofar as this is reasonably possible, inform the parties to whom we have provided your personal data.  

6.3 Right to erasure of data

Do you no longer want us to process certain personal data about you? Then you can request us to delete some or all of your personal data. If we have accidentally processed data unlawfully or a specific law prescribes that we must delete personal data, we will delete the personal data. If the personal data is necessary for the settlement of a legal procedure or a (legal) dispute, we will only delete the personal data after the procedure or dispute has ended. If we approve your request, we will, insofar as this is reasonably possible, inform the parties to whom we have provided your personal data. 

6.4 Restriction of processing  

If you believe that we are not processing your personal data correctly, or if you believe that we are processing your personal data unlawfully, or if you believe that we no longer need it, you can request us to restrict the processing of your personal data. If we restrict the processing of your personal data at your request, we may still use that personal data for the settlement of legal proceedings or a (legal) dispute.  

6.5 Right to data portability  

You have the right to receive the personal data which you have provided to us, in a structured, commonly used and machine-readable format and have this personal data transmitted to another party (where technically feasible). You only have this right to data portability when the processing is based on your consent or when this is necessary for the performance of an agreement, and the processing is carried out by automated means. We refer to Section 3 of this privacy statement for further information on our processing activities.  

6.6 Right to object  

When the processing of your personal data is based on our ‘legitimate interest’ (see Section 3 of this privacy statement for more information), you have the right to object to such processing on grounds relating to your particular situation. When exercising your right to object, we will review the processing of your personal data. We will stop with the processing of your personal data on this ground, unless we have very good reasons to continue the processing which outweighs your interests, or that relate to a legal claim. When you object to processing for direct marketing purposes, the personal data shall no longer be processed for such purposes.  

6.7 Automated individual decision-making  

We do not make decisions based solely on automated processing. 

6.8 Withdrawal of consent  

You may withdraw your consent at any time by clearing voluntarily completed fields, amending your account settings or by contacting us. Please note that when you withdraw your consent, this does not affect the lawfulness of the processing based on consent before its withdrawal. 

 6.9 Exercising your rights  

You can send the above requests to support@yourbi.nl.  Before we respond to your request, we must first make sure that it is your personal data. We usually do this by having you log in to your YourBI account. If you do not have an account or if we cannot confirm your identity in this way, we will try to verify your identity by email or telephone. If that also fails, we can ask for a copy of a valid ID. In that case, do not forget to shield your social security number (BSN), MRZ (Machine Readable Zone) and passport photo.  

We aim to deal with your request or complaint within one month. If it is not possible to make a decision within one month, we will notify you (within one month) of the reasons for the delay and when the decision is expected to be made. This can never be longer than 3 months after receipt of the request.  

6.10 Dutch Data Protection Authority / Autoriteit Persoonsgegevens  

Do you have a complaint about our processing? Then contact us. We are happy to help you. Should we nevertheless not come to an agreement, you also have the right to file a complaint with the privacy supervisor, the Dutch Data Protection Authority (Autoriteit Persoonsgegevens). You can contact the Dutch Data Protection Authority via https://autoriteitpersoonsgegevens.nl/.  

7. Contact  

If you have any questions, concerns or comments about this privacy statement, please contact us by email at support@yourbi.nl.