Last Updated: September 18, 2026
At Digilize Agency, we value your privacy and are dedicated to safeguarding your personal data. This statement outlines how we collect, process, and protect your information in accordance with the General Data Protection Regulation (GDPR) and Dutch data protection laws.
We collect the following types of personal data: Contact Information (name, email address, phone number, and company details when you contact us or engage our services). Website Usage Data (IP address, browser type, device information, and browsing behavior collected through cookies and analytics tools when you visit digilize.agency). Project-Related Data (information provided during web development or marketing projects, such as content preferences or business details). Marketing Data (subscription preferences and interaction data where available, if you opt into our newsletters or campaigns).
We gather personal data through: Website Forms (the "Contact Us" form on digilize.agency). Cookies and Tracking (Microsoft Clarity and Google Analytics to monitor site performance and user experience — see the Cookie Statement below). Direct Interactions (emails, phone calls, or meetings related to our services).
We process your personal data for specific purposes, grounded in recognized GDPR lawful bases: Service Delivery — to provide web development, hosting, and marketing solutions (Contract Fulfillment, Art. 6(1)(b) GDPR). Customer Support & Inquiries — to respond to your communications (Legitimate Interest, Art. 6(1)(f) GDPR, to engage with prospects and answer direct inquiries effectively). Marketing & Newsletters — to send promotional materials (Consent, Art. 6(1)(a) GDPR, withdrawal available at any time). Website Analytics & Improvement — to monitor site performance and user experience (Consent, Art. 6(1)(a) GDPR, via our Cookie Banner for non-essential tracking). Security & Operations — to ensure network security and prevent fraud (Legitimate Interest, Art. 6(1)(f) GDPR, to protect our infrastructure from malicious activity).
We keep personal data only for the relevant purpose and applicable legal retention requirements. Accounting records subject to Dutch tax retention rules are generally kept for seven years; that period is not a blanket retention period for all Client content. Client-controlled project data follows the applicable DPA and instructions. Marketing contact data is used until withdrawal or objection, with a minimal suppression record retained where necessary to honour an opt-out. Website usage data follows the periods in the cookie information. Meeting notices specify transcript retention. Data no longer needed is deleted or genuinely anonymised, subject to justified legal holds and protected backup cycles.
For our own website and business administration, we act as controller and use service providers as appropriate to the stated purpose, including Microsoft Clarity and Google Analytics where enabled with required consent. For Client projects we act as processor only to the extent set out in the project DPA; the project-specific register identifies the actual authorised subprocessors, purposes and locations. A local software library is not itself an external subprocessor. The AI catalogue below is not a list of every recipient of Client data. Meetings may use local or external transcription: before each transcribed meeting we identify the tool, recipients, location, purpose and retention and obtain participants' informed opt-in, with a non-transcribed alternative. External processing requires applicable confidentiality, DPA and transfer safeguards. Restricted transfers outside the EEA require a verified applicable adequacy decision or other valid Chapter V mechanism, including SCCs with necessary assessment and supplementary measures. Existing local-only or EU-only commitments continue to apply. Contact us for information about relevant recipients and safeguards, including a copy where applicable.
Under GDPR, you have the right to: Access (request a copy of your data), Rectification (correct inaccurate information), Erasure (request deletion of your data when no longer needed), Restriction (limit how we process your data), Portability (obtain your data in a structured format), Objection (oppose processing for marketing or based on legitimate interest), and Withdraw Consent (revoke consent at any time). To exercise these rights, email us at info@digilize.agency.
Our security practices include access restrictions, security updates and periodic internal security reviews, including AI-assisted code reviews. People working with us who handle personal data receive practical briefings on data handling, including what information may and may not be uploaded to external tools. Project-specific security commitments are documented in the applicable agreement and data processing agreement.
We do not use automated decision-making or profiling that produces legal or similarly significant effects concerning your personal data.
When acting as controller, we notify the competent supervisory authority without undue delay and, where feasible, within 72 hours after becoming aware of a personal-data breach, unless it is unlikely to risk individuals' rights and freedoms. We notify affected individuals without undue delay where required by Article 34 GDPR. When acting as processor, we notify the Client without undue delay and meet any shorter deadline in its DPA, providing available information and updates to support its response.
Our services are directed at businesses and professionals. We do not knowingly collect personal data from children under 16. If we become aware that we have inadvertently collected such data, we will take steps to delete it promptly.
We may update this notice to explain changes in processing or legal requirements. We identify the revision date and communicate material changes appropriately. Continuing to use the website is not consent to a new processing purpose. Where consent is required, we request it separately before that processing. Changes to project processing remain subject to the applicable DPA and notice or authorisation procedures.
For privacy-related questions, reach out to: Email: info@digilize.agency. Address: Digilize Agency, Nassaulaan 68a, Haarlem, 2011 PE. Phone: +31 23 369 9037. KvK: 96975903. VAT: NL867857572B01. We are supervised by the Dutch Data Protection Authority (Autoriteit Persoonsgegevens). If unsatisfied with our response, you may file a complaint at autoriteitpersoonsgegevens.nl.
We use AI tools in our work. This catalogue describes possible tools, not project-specific authorisation or a claim that each provider currently receives Client data. We minimise inputs. Personal data may be processed only after the actual provider, service plan, purposes, retention, locations, security and required contractual and transfer safeguards have been approved and documented. Pseudonymised data remains personal data; it is not interchangeable with genuinely anonymous data. A self-hosted model does not by itself send data to its model publisher. Actual Client-project recipients are documented in the relevant DPA register. On-site Odin and hosted Core have different processing locations; optional external features require separate documented approval.
| Provider | Purpose | Data Transferred | Transfer Basis |
|---|---|---|---|
| Anthropic — Claude models | Text and code generation as part of our service delivery; image generation where supported by the selected service | Non-personal or genuinely anonymised content by default; personal data only within separately documented, authorised processing | For restricted transfers: verified applicable adequacy coverage or SCCs with the required assessment and safeguards; a provider DPA alone is insufficient |
| OpenAI — GPT models | Text and code generation as part of our service delivery; image generation where supported by the selected service | Non-personal or genuinely anonymised content by default; personal data only within separately documented, authorised processing | For restricted transfers: verified applicable adequacy coverage or SCCs with the required assessment and safeguards; a provider DPA alone is insufficient |
| Google — Gemini models | Text and code generation as part of our service delivery; image generation where supported by the selected service | Non-personal or genuinely anonymised content by default; personal data only within separately documented, authorised processing | For restricted transfers: verified applicable adequacy coverage or SCCs with the required assessment and safeguards; a provider DPA alone is insufficient. For Vertex AI, verify the selected endpoint and all processing and support-access locations |
| Meta — Llama models | Text and code generation as part of our service delivery; image generation where supported by the selected service | Non-personal or genuinely anonymised content by default; personal data only within separately documented, authorised processing | Local inference does not itself transfer data to Meta. For external hosting, identify the actual host and verify its DPA and any required transfer safeguards |
| xAI — Grok models | Text and code generation, including via Cursor | Non-personal or genuinely anonymised content by default; personal data only within separately documented, authorised processing | Verify the actual service, contracting entity, provider DPA and applicable transfer mechanism before personal-data use |
| Cursor — Anysphere | AI-assisted software development; may route prompts and code to selected model providers. Privacy and no-training settings must be verified for the actual plan | Source code, prompts and project context, minimised and screened for secrets and personal data; confidential or personal content only under approved safeguards | Verify the Cursor DPA, onward model providers, processing locations and required transfer safeguards; privacy mode alone is not authorisation |
| Z.ai — GLM models | Text, code and media generation | Non-personal or genuinely anonymised content by default; personal data only within separately documented, authorised processing | Non-personal or genuinely anonymised content by default. Personal data requires a separately approved lawful transfer mechanism, provider DPA and necessary safeguards |
| DeepSeek | Text, code and media generation | Non-personal or genuinely anonymised content by default; personal data only within separately documented, authorised processing | Non-personal or genuinely anonymised content by default. Personal data requires a separately approved lawful transfer mechanism, provider DPA and necessary safeguards |
| Moonshot AI — Kimi models | Text, code and media generation | Non-personal or genuinely anonymised content by default; personal data only within separately documented, authorised processing | Non-personal or genuinely anonymised content by default. Personal data requires a separately approved lawful transfer mechanism, provider DPA and necessary safeguards |
| MiniMax | Text, code and media generation | Non-personal or genuinely anonymised content by default; personal data only within separately documented, authorised processing | Non-personal or genuinely anonymised content by default. Personal data requires a separately approved lawful transfer mechanism, provider DPA and necessary safeguards |
Client personal data and confidential content must not be used to train providers' shared models. Before such content is submitted, we require binding suitable provider terms and verify the service configuration. Tools without the necessary safeguards may receive only content that is non-confidential and either non-personal or genuinely anonymised, and whose use is otherwise permitted.
Clients have the subprocessor objection rights in their DPA. For new arrangements under our Terms, general authorisation includes 30 calendar days' advance written notice of additions or replacements and an opportunity to raise reasonable documented data-protection objections. Disputed processing does not start pending resolution. If no compliant alternative is reasonably available, the affected service may end without a termination penalty and unused prepaid fees are refunded. Existing signed DPA procedures remain applicable.
Changing this catalogue does not amend a signed contract, grant new processing permission or replace required individual notices. Provider certification, contracting entities and processing regions must be verified for the actual service before use; this page is not a certification register.
Last Updated: September 11, 2026
Welcome to Digilize.agency. We use cookies to improve your browsing experience, analyze site traffic, and provide personalized content. This Cookie Statement explains what cookies are, how we use them, and how you can manage your preferences.
Cookies are small text files placed on your device when you visit a website. They help us remember your preferences, enhance functionality, and collect data for analytics or marketing purposes.
You can control cookies via your browser settings, where you can block or delete them (note: this may impact site functionality). For guidance, check your browser's help section. You can also opt-out of non-essential cookies using our Cookie Consent Manager.
| Vendor | Purpose | Data Collected | Retention |
|---|---|---|---|
| Microsoft Clarity | Behavioral analytics (heatmaps) | Mouse movements, clicks, scrolling, masked keystrokes | Up to 1 year |
| Google Analytics 4 | Traffic analysis | IP (anonymized), device info, page views, locations | 2 months (default) |
To withdraw your consent at any time, please use the cookie settings manager located at the bottom of our website or your browser's tracking prevention features.
We may update this Cookie Statement occasionally. Please check back regularly to stay informed.