Privacy
Privacy statement
Last updated: 1 October 2026
1. Controller
Radegast BV, trading as SpinGras Data Services, Amsterdam, the Netherlands, registered with the Dutch Chamber of Commerce (KvK) under number 69469946, is the controller for the processing of personal data described in this statement. Contact: [email protected].
2. Personal data we process
- Contact data: name, email address and the content of your message when you contact us.
- Appointment data: name, email address and any information you provide when you schedule a meeting with us.
- Technical data: IP address and browser and device information, processed when you visit our website.
3. Purposes and legal bases
- Responding to enquiries and preparing proposals: taking steps at your request prior to entering into a contract (Art. 6(1)(b) GDPR).
- Scheduling and conducting meetings: taking steps at your request prior to entering into a contract (Art. 6(1)(b) GDPR).
- Delivering and securing the website: our legitimate interest in a reliable and secure website (Art. 6(1)(f) GDPR).
- Compiling anonymous visitor statistics: our legitimate interest in improving the website (Art. 6(1)(f) GDPR). These statistics do not identify individual visitors.
4. Processors and recipients
We use the following service providers, who process personal data on our behalf:
- Cloudflare: website hosting, delivery and security.
- Umami: website statistics.
- Cal.com: appointment scheduling.
- Proton: email.
We do not sell personal data and do not share it with third parties for their own purposes, unless we are legally required to do so.
5. Transfers outside the EEA
Some of these providers may process personal data outside the European Economic Area. Where this happens, the transfer is based on appropriate safeguards, such as an adequacy decision of the European Commission or the Standard Contractual Clauses.
6. Retention
We keep personal data no longer than necessary for the purposes for which it was collected, unless a longer period is required by law, such as the seven-year retention period for business records under Dutch tax law.
7. Cookies
We do not use cookies or similar technologies.
8. Security
We take appropriate technical and organisational measures to protect personal data against loss and unauthorised access.
9. Your rights
Under the GDPR you have the right to access, rectify and erase your personal data, to restrict its processing, to object to processing, and to data portability. To exercise these rights, email [email protected]. We respond within one month.
You also have the right to lodge a complaint with the Dutch Data Protection Authority (Autoriteit Persoonsgegevens).
10. Changes
We may amend this privacy statement. The current version is always published on this page.