LEGAL
Privacy Statement
What personal data Rijker Advisory processes, why, and what rights you have.
1. Who is the data controller
Rijker Advisory (sole proprietorship, Dutch Chamber of Commerce no. 70443718), based in Amsterdam (business address available on request), is the data controller for personal data processed through this website and in the course of its services. Contact: rion@rijkeradvies.nl, +31 85 21 29 481.
2. What we process and why
2.1 Website visits
Rijker Advisory uses no cookies and no tracking on this website. There are no analytics scripts, no social media pixels, no advertising tags, and no embedded content that builds a profile.
For operational management, error detection, and security, only standard server logs are retained at the hosting provider (TransIP B.V.). These logs contain IP address, timestamp, requested URL, HTTP status code, user agent, and referrer. Logs are automatically overwritten after a maximum of 30 days, unless a specific security incident requires longer retention.
Legal basis: legitimate interest (Article 6(1)(f) GDPR) for security and availability of the website. For more information on cookies and logs, see the Cookie Statement.
2.2 Email and phone contact
When you contact us by email or phone, we process the data you provide: name, contact details, position, organisation, and the content of your message. This data is used to answer your question and, if an engagement follows, to perform that engagement.
Legal basis: performance of (pre-)contractual measures (Article 6(1)(b) GDPR) and legitimate interest for administration and record-keeping (Article 6(1)(f) GDPR).
2.3 Client engagements and case files
Under an engagement, we process data necessary to deliver the services: contact details of employees and counterparties, case documents supplied by the client, correspondence, contractual arrangements, invoicing data, and supporting evidence relevant to the engagement. The services comprise governance advice, governance forensics in the role of governance specialist, legal review, privacy and compliance support, sports and federation governance, and training.
Legal basis: performance of the contract (Article 6(1)(b) GDPR), and where applicable a legal obligation (Article 6(1)(c) GDPR) or the legitimate interest of the client (Article 6(1)(f) GDPR).
2.4 Governance forensics and integrity assignments
In governance forensics and integrity assignments, Rijker Advisory carries out an independent review of governance, compliance, and integrity systems at system, process, and policy level. Data processed includes organisational documentation, minutes, policy documents, contracts, correspondence, and supporting evidence supplied to Rijker Advisory by the client or by a certified partner, as well as personal data of directors, employees, and stakeholders to the extent that such data appears from that documentation. Rijker Advisory does not conduct its own interviews with natural persons; person-focused factual investigation is, where necessary, carried out by a holder of a Wpbr licence or by the client itself. The legal basis is performance of the contract (Article 6(1)(b) GDPR) and the legitimate interest of the client in a well-founded governance opinion (Article 6(1)(f) GDPR).
2.5 Special categories of personal data
Special categories of personal data (Article 9 GDPR) are only processed where strictly necessary for the performance of a specific engagement and on an explicit basis under Article 9(2) GDPR in combination with Articles 22 to 30 of the Dutch GDPR Implementation Act (UAVG). In DPO and governance forensics engagements this may occur when the client submits processing of special categories to Rijker Advisory. Processing takes place only with appropriate technical and organisational safeguards and a specific written engagement.
2.6 Personal data relating to criminal matters
Personal data relating to criminal convictions and offences (Article 10 GDPR and Articles 31 to 33 UAVG) is in principle not independently collected by Rijker Advisory on behalf of third parties. Where such data is submitted to Rijker Advisory by a client in the context of legal advice or a governance forensics engagement, processing may take place on the basis of Article 32(d) UAVG (establishment, exercise, or defence of legal claims) or, where applicable, Article 33 UAVG. Any such processing is strictly limited to what is necessary for the advice or review requested, subject to additional confidentiality and security safeguards, and to the retention periods of Article 20.11 of the general terms. Rijker Advisory does not itself qualify conduct as a criminal offence; that assessment is reserved to the competent authority.
2.7 Scope in relation to the Wpbr
Rijker Advisory does not perform person-focused investigative activities within the meaning of Article 1(1)(e) and (f) of the Dutch Private Security Organisations and Detective Agencies Act (Wet particuliere beveiligingsorganisaties en recherchebureaus, Wpbr). This means: on request of a third party and in connection with an interest of that third party, collecting and analysing data relating to specific natural persons. Where an engagement requires such person-focused activities, that part is carried out by a holder of a Wpbr licence; Rijker Advisory limits itself in such engagements to the non-person-focused part (systems, processes, policy, structural findings) and to legal and governance advice. This delineation is further set out in Articles 1.6, 13.9, and 20.12 of Rijker Advisory's general terms.
2.8 DPO service
Where Rijker Advisory acts as external Data Protection Officer for an organisation, Rijker Advisory acts on the basis of Article 37 GDPR as an independent DPO and not as a processor. The independence and confidentiality obligations of Article 38 GDPR apply.
3. Recipients of personal data
Personal data is not shared with third parties unless necessary for the engagement, legally required, or unless you have expressly consented. Categories of possible recipients:
- Hosting provider TransIP B.V. (server infrastructure and logs).
- Email and office software vendors (processors).
- Bookkeeper and accountant for administration.
- Wpbr licence holders that, in a specific engagement, carry out the person-focused investigative part.
- Counterparty or disciplinary tribunal, where this follows from a specific engagement.
- Supervisory authorities, where legally required.
Data processing agreements meeting Article 28 GDPR are in place with all processors.
4. Transfers outside the EEA
Rijker Advisory aims to process data within the European Economic Area. Where transfer outside the EEA is unavoidable (for example, in international engagements or with certain cloud services), it takes place only on the basis of a valid GDPR transfer mechanism, including European Standard Contractual Clauses (SCCs), additional technical and organisational measures, and a Transfer Impact Assessment where required.
5. Retention periods
- Server logs: maximum 30 days, then automatically overwritten.
- Email and contact correspondence without engagement: maximum 12 months.
- Client files: seven (7) years after closing the engagement, in line with the Dutch tax retention obligation and the limitation periods under Article 3:310 of the Dutch Civil Code.
- Invoices and accounting records: seven (7) years under Article 52 of the Dutch General State Taxes Act.
- Governance forensics and integrity files: per the category-specific schedule of Article 20.11 of the general terms (final report and formal deliverables 7 years; supporting evidence and chain-of-custody 7 years; working papers 12 months; security and incident logs 12 months; legal hold for as long as necessary).
6. Security
Rijker Advisory takes appropriate technical and organisational measures to safeguard personal data. These include encrypted storage, encrypted transport (TLS), access on a need-to-know basis, multi-factor authentication for critical systems, periodic reviews, and an incident response procedure. Security is calibrated to the sensitivity of the data and the risks to data subjects.
7. Your rights
Under the GDPR you have the following rights in relation to your personal data:
- Right of access to the data processed about you.
- Right to rectification of inaccurate or incomplete data.
- Right to erasure ("right to be forgotten"), where the GDPR allows.
- Right to restriction of processing.
- Right to data portability for data processed on the basis of consent or contract.
- Right to object to processing based on legitimate interest.
- Right to withdraw a given consent, without affecting the lawfulness of prior processing.
Requests may be submitted by email to rion@rijkeradvies.nl. For identification purposes, additional data may be requested. Requests are handled within the statutory period of one (1) month, extendable by a maximum of two (2) months for complex requests.
8. Complaint to the supervisory authority
You have the right to lodge a complaint with the Dutch Data Protection Authority (autoriteitpersoonsgegevens.nl) or with the supervisory authority in the EU Member State where you reside, work, or where the alleged infringement took place.
9. Changes
Rijker Advisory may amend this privacy statement. The current version is always available on this page, with version number and date. We recommend consulting this statement periodically.
10. Version history
This version 3.1 (15 September 2026, 18:50 CEST) replaces version 3.0 (15 September 2026, 18:35 CEST) and version 2.0 (September 2026). The changes relative to v2.0 are: correction of the legal basis for processing special categories and criminal-matter personal data (Article 10 GDPR and Articles 31 to 33 UAVG); clarification of the scope of services in relation to the Wpbr (person-focused investigative activities excluded); and clarification that Rijker Advisory performs governance forensics in the role of governance specialist, without conducting its own personal interviews. Prior versions are available as dated PDF snapshots via rion@rijkeradvies.nl.