Privacy Policy & Cookie Statement

Privacy Statement

Last Updated: September 18, 2026

At Digilize Agency, we value your privacy and are dedicated to safeguarding your personal data. This statement outlines how we collect, process, and protect your information in accordance with the General Data Protection Regulation (GDPR) and Dutch data protection laws.

1. Data We Collect

We collect the following types of personal data: Contact Information (name, email address, phone number, and company details when you contact us or engage our services). Website Usage Data (IP address, browser type, device information, and browsing behavior collected through cookies and analytics tools when you visit digilize.agency). Project-Related Data (information provided during web development or marketing projects, such as content preferences or business details). Marketing Data (subscription preferences and interaction data where available, if you opt into our newsletters or campaigns).

2. How We Collect Data

We gather personal data through: Website Forms (the "Contact Us" form on digilize.agency). Cookies and Tracking (Microsoft Clarity and Google Analytics to monitor site performance and user experience — see the Cookie Statement below). Direct Interactions (emails, phone calls, or meetings related to our services).

3. Purposes and Lawful Bases of Data Processing

We process your personal data for specific purposes, grounded in recognized GDPR lawful bases: Service Delivery — to provide web development, hosting, and marketing solutions (Contract Fulfillment, Art. 6(1)(b) GDPR). Customer Support & Inquiries — to respond to your communications (Legitimate Interest, Art. 6(1)(f) GDPR, to engage with prospects and answer direct inquiries effectively). Marketing & Newsletters — to send promotional materials (Consent, Art. 6(1)(a) GDPR, withdrawal available at any time). Website Analytics & Improvement — to monitor site performance and user experience (Consent, Art. 6(1)(a) GDPR, via our Cookie Banner for non-essential tracking). Security & Operations — to ensure network security and prevent fraud (Legitimate Interest, Art. 6(1)(f) GDPR, to protect our infrastructure from malicious activity).

4. Data Retention

We keep personal data only for the relevant purpose and applicable legal retention requirements. Accounting records subject to Dutch tax retention rules are generally kept for seven years; that period is not a blanket retention period for all Client content. Client-controlled project data follows the applicable DPA and instructions. Marketing contact data is used until withdrawal or objection, with a minimal suppression record retained where necessary to honour an opt-out. Website usage data follows the periods in the cookie information. Meeting notices specify transcript retention. Data no longer needed is deleted or genuinely anonymised, subject to justified legal holds and protected backup cycles.

5. Data Sharing & Sub-Processors

For our own website and business administration, we act as controller and use service providers as appropriate to the stated purpose, including Microsoft Clarity and Google Analytics where enabled with required consent. For Client projects we act as processor only to the extent set out in the project DPA; the project-specific register identifies the actual authorised subprocessors, purposes and locations. A local software library is not itself an external subprocessor. The AI catalogue below is not a list of every recipient of Client data. Meetings may use local or external transcription: before each transcribed meeting we identify the tool, recipients, location, purpose and retention and obtain participants' informed opt-in, with a non-transcribed alternative. External processing requires applicable confidentiality, DPA and transfer safeguards. Restricted transfers outside the EEA require a verified applicable adequacy decision or other valid Chapter V mechanism, including SCCs with necessary assessment and supplementary measures. Existing local-only or EU-only commitments continue to apply. Contact us for information about relevant recipients and safeguards, including a copy where applicable.

6. Your Rights

Under GDPR, you have the right to: Access (request a copy of your data), Rectification (correct inaccurate information), Erasure (request deletion of your data when no longer needed), Restriction (limit how we process your data), Portability (obtain your data in a structured format), Objection (oppose processing for marketing or based on legitimate interest), and Withdraw Consent (revoke consent at any time). To exercise these rights, email us at info@digilize.agency.

7. Security Measures

Our security practices include access restrictions, security updates and periodic internal security reviews, including AI-assisted code reviews. People working with us who handle personal data receive practical briefings on data handling, including what information may and may not be uploaded to external tools. Project-specific security commitments are documented in the applicable agreement and data processing agreement.

8. Automated Decision-Making

We do not use automated decision-making or profiling that produces legal or similarly significant effects concerning your personal data.

9. Data Breach Notification

When acting as controller, we notify the competent supervisory authority without undue delay and, where feasible, within 72 hours after becoming aware of a personal-data breach, unless it is unlikely to risk individuals' rights and freedoms. We notify affected individuals without undue delay where required by Article 34 GDPR. When acting as processor, we notify the Client without undue delay and meet any shorter deadline in its DPA, providing available information and updates to support its response.

10. Children's Privacy

Our services are directed at businesses and professionals. We do not knowingly collect personal data from children under 16. If we become aware that we have inadvertently collected such data, we will take steps to delete it promptly.

11. Changes to This Privacy Statement

We may update this notice to explain changes in processing or legal requirements. We identify the revision date and communicate material changes appropriately. Continuing to use the website is not consent to a new processing purpose. Where consent is required, we request it separately before that processing. Changes to project processing remain subject to the applicable DPA and notice or authorisation procedures.

12. Contact Us

For privacy-related questions, reach out to: Email: info@digilize.agency. Address: Digilize Agency, Nassaulaan 68a, Haarlem, 2011 PE. Phone: +31 23 369 9037. KvK: 96975903. VAT: NL867857572B01. We are supervised by the Dutch Data Protection Authority (Autoriteit Persoonsgegevens). If unsatisfied with our response, you may file a complaint at autoriteitpersoonsgegevens.nl.

AI Providers

We use AI tools in our work. This catalogue describes possible tools, not project-specific authorisation or a claim that each provider currently receives Client data. We minimise inputs. Personal data may be processed only after the actual provider, service plan, purposes, retention, locations, security and required contractual and transfer safeguards have been approved and documented. Pseudonymised data remains personal data; it is not interchangeable with genuinely anonymous data. A self-hosted model does not by itself send data to its model publisher. Actual Client-project recipients are documented in the relevant DPA register. On-site Odin and hosted Core have different processing locations; optional external features require separate documented approval.

ProviderPurposeData TransferredTransfer Basis
Anthropic — Claude modelsText and code generation as part of our service delivery; image generation where supported by the selected serviceNon-personal or genuinely anonymised content by default; personal data only within separately documented, authorised processingFor restricted transfers: verified applicable adequacy coverage or SCCs with the required assessment and safeguards; a provider DPA alone is insufficient
OpenAI — GPT modelsText and code generation as part of our service delivery; image generation where supported by the selected serviceNon-personal or genuinely anonymised content by default; personal data only within separately documented, authorised processingFor restricted transfers: verified applicable adequacy coverage or SCCs with the required assessment and safeguards; a provider DPA alone is insufficient
Google — Gemini modelsText and code generation as part of our service delivery; image generation where supported by the selected serviceNon-personal or genuinely anonymised content by default; personal data only within separately documented, authorised processingFor restricted transfers: verified applicable adequacy coverage or SCCs with the required assessment and safeguards; a provider DPA alone is insufficient. For Vertex AI, verify the selected endpoint and all processing and support-access locations
Meta — Llama modelsText and code generation as part of our service delivery; image generation where supported by the selected serviceNon-personal or genuinely anonymised content by default; personal data only within separately documented, authorised processingLocal inference does not itself transfer data to Meta. For external hosting, identify the actual host and verify its DPA and any required transfer safeguards
xAI — Grok modelsText and code generation, including via CursorNon-personal or genuinely anonymised content by default; personal data only within separately documented, authorised processingVerify the actual service, contracting entity, provider DPA and applicable transfer mechanism before personal-data use
Cursor — AnysphereAI-assisted software development; may route prompts and code to selected model providers. Privacy and no-training settings must be verified for the actual planSource code, prompts and project context, minimised and screened for secrets and personal data; confidential or personal content only under approved safeguardsVerify the Cursor DPA, onward model providers, processing locations and required transfer safeguards; privacy mode alone is not authorisation
Z.ai — GLM modelsText, code and media generationNon-personal or genuinely anonymised content by default; personal data only within separately documented, authorised processingNon-personal or genuinely anonymised content by default. Personal data requires a separately approved lawful transfer mechanism, provider DPA and necessary safeguards
DeepSeekText, code and media generationNon-personal or genuinely anonymised content by default; personal data only within separately documented, authorised processingNon-personal or genuinely anonymised content by default. Personal data requires a separately approved lawful transfer mechanism, provider DPA and necessary safeguards
Moonshot AI — Kimi modelsText, code and media generationNon-personal or genuinely anonymised content by default; personal data only within separately documented, authorised processingNon-personal or genuinely anonymised content by default. Personal data requires a separately approved lawful transfer mechanism, provider DPA and necessary safeguards
MiniMaxText, code and media generationNon-personal or genuinely anonymised content by default; personal data only within separately documented, authorised processingNon-personal or genuinely anonymised content by default. Personal data requires a separately approved lawful transfer mechanism, provider DPA and necessary safeguards

Client personal data and confidential content must not be used to train providers' shared models. Before such content is submitted, we require binding suitable provider terms and verify the service configuration. Tools without the necessary safeguards may receive only content that is non-confidential and either non-personal or genuinely anonymised, and whose use is otherwise permitted.

Clients have the subprocessor objection rights in their DPA. For new arrangements under our Terms, general authorisation includes 30 calendar days' advance written notice of additions or replacements and an opportunity to raise reasonable documented data-protection objections. Disputed processing does not start pending resolution. If no compliant alternative is reasonably available, the affected service may end without a termination penalty and unused prepaid fees are refunded. Existing signed DPA procedures remain applicable.

Changing this catalogue does not amend a signed contract, grant new processing permission or replace required individual notices. Provider certification, contracting entities and processing regions must be verified for the actual service before use; this page is not a certification register.

Cookie Statement

Last Updated: September 11, 2026

Welcome to Digilize.agency. We use cookies to improve your browsing experience, analyze site traffic, and provide personalized content. This Cookie Statement explains what cookies are, how we use them, and how you can manage your preferences.

What Are Cookies?

Cookies are small text files placed on your device when you visit a website. They help us remember your preferences, enhance functionality, and collect data for analytics or marketing purposes.

Types of Cookies We Use

Essential Cookies

  • Description: Necessary for the website to work properly, enabling basic features like page navigation and access to secure areas.
  • Purpose: Ensure core functionality, such as security and accessibility.
  • Legal Basis: These do not require consent.

Functional Cookies

  • Description: Allow us to remember your preferences, like language or layout settings.
  • Purpose: Personalize your experience and enhance usability.
  • Legal Basis: Consent (manageable via our Cookie Consent Manager).

Analytics Cookies

  • Description: Collect anonymous data about how visitors use our site, such as page views and time spent.
  • Purpose: Help us improve our website by analyzing performance and user behavior.
  • Legal Basis: Consent (manageable via our Cookie Consent Manager).

Marketing Cookies

  • Description: Used to show relevant ads and measure the success of marketing campaigns.
  • Purpose: Deliver personalized advertisements and track their effectiveness.
  • Legal Basis: Consent (manageable via our Cookie Consent Manager).

Managing Your Cookie Preferences

You can control cookies via your browser settings, where you can block or delete them (note: this may impact site functionality). For guidance, check your browser's help section. You can also opt-out of non-essential cookies using our Cookie Consent Manager.

Third-Party Cookie Vendors

VendorPurposeData CollectedRetention
Microsoft ClarityBehavioral analytics (heatmaps)Mouse movements, clicks, scrolling, masked keystrokesUp to 1 year
Google Analytics 4Traffic analysisIP (anonymized), device info, page views, locations2 months (default)

To withdraw your consent at any time, please use the cookie settings manager located at the bottom of our website or your browser's tracking prevention features.

Updates

We may update this Cookie Statement occasionally. Please check back regularly to stay informed.