Privacy statement
This statement describes how Deverence Group B.V. handles personal data, from your visit to this site to the data we process for as long as you are a customer. Concrete where we can be, legally precise where we must be.
TO CONFIRM This is a fully worked draft. The marked items are choices that have to be settled internally before this page goes live.
Who processes your data
Deverence Group B.V., based in Brummen and registered with the Dutch Chamber of Commerce under number 75827816, is the controller for the data processed through this website and in running our own business. RUAL is a registered trademark (1501953) of Deverence Group B.V.
Where we process personal data on a customer’s instruction, for example inside an application running on Core, we are the processor and the customer is the controller. That situation is covered by the data processing agreement, not by this statement.
What we process
Your visit to this site
Our web server records what it needs to serve and protect the site, such as the address requested, the time and the browser type. We use that for the operation and security of the site, not to follow you as a person.
Contact, demo requests and support
If you fill in a form or call us, we process what you give us yourself: your name, company, email address, phone number and the content of your question. We use it to answer you and to follow up, and for nothing else.
The customer relationship
For customers we process the contact details of the people we work with, data about the use and administration of the environment, and the paperwork that comes with a contract, such as quotations, invoices and support tickets.
Job applications
If you apply for a job with us we process your application and whatever you send with it. We share it only inside the team responsible for the vacancy.
Why we process it
- Performance of the contract: delivering the platform, the support and the services you buy.
- Legitimate interest: securing our systems, preventing abuse, improving the site and staying in touch with people who ask about us.
- Legal obligation: including the statutory retention period for invoices and accounts.
- Consent: only where we ask for it explicitly, for example for non-essential cookies. You can withdraw consent at any time.
Cookies and measurement
We measure visits to this site ourselves, on our own server, without a cookie and without an external analytics service: no Google Analytics, no other third party's measurement platform.
For every page you visit, we compute a pseudonymous hash from your IP address and your browser type, using a salt: a secret value generated fresh and at random each day, that we store nowhere, not in a database, not in a log file, and that disappears again whenever the server restarts. We do not store your IP address itself: it is only an input to that hash and is discarded straight afterwards. Because the salt changes daily and is never kept, the hash cannot be traced back to you as a person and cannot be linked to your visit on a different day.
If your browser signals through Sec-GPC (Global Privacy Control) that you do not want to be tracked, your visit is still counted, but we do not compute a hash for it: that visit is then linked to nothing else.
We use no cookies for this and write nothing to your browser's storage. So there is also no cookie category, no retention period per cookie and no choice to later change or withdraw: that choice does not exist, because we have no need for it.
The measured data only ever reaches Deverence Group B.V., processed on our own infrastructure in the Netherlands: no external analytics service is involved. On the way it sits briefly buffered on our own server, in practice usually a few seconds, waiting to be delivered onward. If that delivery is temporarily not possible, it stays in that buffer and we retry later; the buffer is capped at 100,000 events and never keeps anything longer than seven days and one hour. Whatever is older, or no longer fits, is cleared out automatically, without still being sent on.
How long we keep data
We keep data no longer than we need it for the purpose it was collected for, or for as long as the law requires us to. After that we delete it.
TO CONFIRM The concrete retention periods per category still have to be set: server logs, contact and demo requests, job applications, customer records and support tickets.
Who we share data with
We do not sell data and we do not share it with third parties for their own purposes. We do use suppliers who process on our behalf, such as our data centre and our office and accounting software. With any such supplier we conclude a processing agreement, and that party may do nothing with the data beyond what we instruct.
Which parties those are for customer environments is set out in the data processing agreement.
Where your data sits
Our clusters run on our own hardware in the BIT data centres in Ede, certified for ISO 27001, ISO 9001 and NEN 7510 and running entirely on green power. RUAL and our data centre partner are Dutch companies with no American parent, so the US CLOUD Act does not apply to what is stored here. How that is put together is explained on the hosting page.
How we secure data
Security sits in the platform itself: permissions per role, logging of administrative actions and an automatic alert whenever something sensitive happens to an account, such as a login from a new location or a change to the two-factor settings. Employees who may come into contact with customer data are screened by means of a Dutch certificate of conduct and are contractually bound to confidentiality. What else is switched on by default is described on the security page.
Your rights
- Access to the data we hold about you.
- Rectification if something is wrong.
- Erasure, as far as we are not legally required to keep it.
- Restriction of processing, and objection to processing based on legitimate interest.
- Portability of the data you supplied yourself.
- Withdrawal of your consent, without that invalidating what happened before.
If you want to exercise one of these rights, tell us. We respond as quickly as we can and at the latest within the statutory period of one month. If you disagree with how we handle your request, you can lodge a complaint with the Dutch Data Protection Authority.
Privacy contact
TO CONFIRM The email address for privacy requests still has to be decided, as does the question of whether RUAL appoints a data protection officer or names a fixed contact person.
Until then, privacy questions reach us at support@deverence.com and +31 (0)10 300 67 78.
Changes to this statement
If the way we process data changes, we update this statement. The date at the top shows when that last happened.
Want to know exactly what we hold about you?
Just ask. You will not get a form letter, you will get someone who looks it up for your environment.