PRIVACY POLICY THE HQ
**Version: 1.0**
**September 2026**
—
ARTICLE 1 – GENERAL
1.1 Rijsterborgh Vastgoed, with its registered office at Eleanor Rooseveltlaan 255, Amstelveen (1183 CK), registered with the Chamber of Commerce under number 33104988, is responsible for the processing of personal data as set out in this privacy statement.
1.2 This privacy statement applies to all processing of personal data by Rijsterborgh Vastgoed (hereinafter: “The HQ”, “we” or “us”) in the context of its business activities in the field of office lettings and commercial property.
1.3 The HQ attaches great importance to the protection of your personal data and respects your privacy. We process personal data in accordance with the General Data Protection Regulation (GDPR) and other applicable privacy legislation.
1.4 This privacy statement was last amended on 25 September 2026.
—
ARTICLE 2 – CONTACT DETAILS
2.1 The HQ can be contacted via:
**Postal address:**
Eleanor Rooseveltlaan 255
1183 CK AMSTELVEEN
Netherlands
**Email address:** info@rijsterborgh.nl
**Telephone number:** 020 645 11 46
**Website:** www.the-hq.eu
2.2 If you have any questions regarding the processing of your personal data or this privacy statement, please contact us using the contact details above.
—
ARTICLE 3 – WHAT PERSONAL DATA IS PROCESSED
3.1 The HQ processes the following categories of personal data:
**a) Contact details:**
– Name (first name and surname)
– Email address
– Telephone number
3.2 The HQ does not process special categories of personal data as referred to in Article 9 of the GDPR (such as data relating to race, ethnic origin, political opinions, religious or philosophical beliefs, health, sexual behaviour or sexual orientation).
3.3 We do not collect personal data from minors under the age of 16 without the consent of a parent or guardian.
—
ARTICLE 4 – SOURCE OF PERSONAL DATA
4.1 The HQ obtains your personal data directly from you, via the following channels:
**a) Contact form on the website**
When you complete the contact form on our website, you provide your personal data to us voluntarily.
4.2 The HQ does not collect personal data from public sources or from third parties without your prior consent or another valid legal basis.
—
ARTICLE 5 – PURPOSES AND LEGAL BASES OF PROCESSING
5.1 The HQ processes your personal data exclusively for the following purposes:
**a) Contacting you and responding to enquiries**
– Handling your request or enquiry
– Responding to your enquiry or request
– Communicating about our services
– Handling complaints
*Legal basis:* Legitimate interest (Article 6(1)(f) of the GDPR) – responding to enquiries and maintaining customer relationships is a legitimate business interest. Where applicable: performance of a contract (Article 6(1)(b) of the GDPR).
**b) Marketing and retargeting**
– Sending newsletters and commercial communications
– Providing information about new services, offers and developments
– Carrying out marketing activities
*Legal basis:* Consent (Article 6(1)(a) of the GDPR). You have the right to withdraw your consent at any time.
5.2 The HQ does not process personal data for purposes other than those for which it was obtained, unless there is a legal basis for doing so or you have given your explicit consent.
5.3 The HQ does not use your personal data for automated decision-making or profiling that has significant consequences for you.
—
ARTICLE 6 – RETENTION PERIODS
6.1 The HQ does not retain personal data for longer than is necessary for the purposes for which it was collected or as required by law. The following retention periods apply:
**a) Customer and order data:** 7 years
*Legal basis:* Tax retention obligation pursuant to Article 2:10 of the Civil Code and Article 52 of the General Tax Act.
**b) Contact enquiries:** 2 years
*Legal basis:* Reasonable period for handling enquiries and any follow-up.
**c) Newsletter/marketing communications:** Until you unsubscribe
*Legal basis:* Consent remains valid until it is withdrawn.
6.2 Once the retention period has expired, your personal data will be permanently deleted or anonymised.
6.3 If you object to the processing or withdraw your consent, we will delete your data insofar as we are not required to retain it on another legal basis (such as a statutory retention obligation).
—
ARTICLE 7 – COOKIES AND SIMILAR TECHNOLOGIES
7.1 The HQ uses cookies on the website www.the-hq.eu. Cookies are small text files that are placed on your device when you visit our website.
7.2 The HQ uses only **functional cookies**. These are cookies that are technically necessary for the website to function correctly. These cookies:
– Ensure that the website works properly
– Remember your preferences and settings
– Improve the user experience
7.3 Functional cookies are placed on the basis of legitimate interest (Article 6(1)(f) of the GDPR). These cookies are necessary for the basic functionality of the website.
7.4 On your first visit to our website, a cookie banner will be displayed informing you about the use of cookies. You have the option to choose which cookies you accept.
7.5 You can refuse or delete cookies via your browser settings. Please note that refusing functional cookies may result in certain parts of the website not functioning, or not functioning properly.
7.6 The HQ does not use third-party tracking cookies, analytical cookies or marketing cookies.
—
ARTICLE 8 – DISCLOSURE TO THIRD PARTIES
8.1 The HQ will not disclose your personal data to third parties unless:
– This is necessary for the performance of a contract with you
– This is required by law
– You have given your explicit consent
8.2 The HQ does not sell your data to third parties and will only disclose it if this is necessary for the performance of our contract with you or to comply with a legal obligation.
8.3 If we use data processors (such as hosting providers or IT service providers) who process personal data on our behalf, we enter into a data processing agreement with these parties in accordance with Article 28 of the GDPR to ensure that they process your personal data in a secure and careful manner.
—
ARTICLE 9 – DATA PROCESSING OUTSIDE THE EEA
9.1 The HQ processes your personal data exclusively within the European Economic Area (EEA).
9.2 Your personal data will not be transferred to countries outside the EEA.
—
ARTICLE 10 – SECURITY
10.1 The HQ takes the protection of your personal data seriously and has implemented appropriate technical and organisational measures to protect your personal data against loss, unlawful use, unauthorised access, unauthorised disclosure and unauthorised alteration.
10.2 The HQ applies the following security measures:
**a) SSL/HTTPS certificate**
Our website uses an SSL (Secure Sockets Layer) certificate. This ensures a secure, encrypted connection between your browser and our server. You can recognise this by the padlock icon in the address bar and the prefix “https://” in the URL.
**b) Access control**
Access to personal data is restricted to staff who require such access to carry out their duties.
**c) Up-to-date software**
We ensure that all systems, software and security measures are kept up to date.
10.3 Despite these measures, we cannot guarantee absolute security. Should a data breach nevertheless occur, we will report this to the Dutch Data Protection Authority in accordance with our legal obligations and, where necessary, to the data subjects concerned.
10.4 If you suspect that your data is not secure or there are indications of misuse, please contact us at info@rijsterborgh.nl.
—
ARTICLE 11 – YOUR RIGHTS AS A DATA SUBJECT
11.1 Under the GDPR, you have the following rights in relation to your personal data:
**a) Right of access (Article 15 of the GDPR)**
You have the right to access the personal data we process about you.
**b) Right to rectification (Article 16 of the GDPR)**
You have the right to have inaccurate or incomplete personal data corrected or supplemented.
**c) Right to erasure/‘right to be forgotten’ (Article 17 of the GDPR)**
You have the right to have your personal data erased, unless a legal exception applies (such as a statutory retention obligation).
**d) Right to restriction of processing (Article 18 of the GDPR)**
You have the right to restrict the processing of your personal data.
**e) Right to data portability (Article 20 of the GDPR)**
You have the right to receive your personal data in a structured, commonly used and machine-readable format and to transmit it to another party.
**f) Right to object (Article 21 of the GDPR)**
You have the right to object to the processing of your personal data, in particular where the processing is based on a legitimate interest or for direct marketing purposes.
**g) Right to withdraw consent (Article 7(3) of the GDPR)**
If the processing is based on your consent, you have the right to withdraw that consent at any time. This does not affect the lawfulness of the processing carried out on the basis of your consent prior to its withdrawal.
**h) Right not to be subject to automated decision-making (Article 22 of the GDPR)**
You have the right not to be subject to a decision based solely on automated processing which produces legal effects concerning you. The HQ does not use such automated decision-making.
11.2 To exercise your rights, please contact us via:
– Email: info@rijsterborgh.nl
– Telephone: 020 645 11 46
– In writing: Eleanor Rooseveltlaan 255, 1183 CK Amstelveen
11.3 To prevent misuse, we may ask you to provide adequate proof of your identity. We may ask you to provide a copy of your identity document. Please black out your passport photograph, MRZ (machine-readable zone, the strip of numbers at the bottom of the passport), passport number and Citizen Service Number (BSN) on this copy. This is to protect your privacy.
11.4 We will respond to your request as soon as possible, but no later than within one month. Depending on the complexity of the request and the number of requests, this period may be extended by two months if necessary. We will inform you of this within one month of receiving your request.
11.5 In principle, these services are free of charge. If your request is manifestly unfounded or excessive, in particular because it is repetitive, we may charge a reasonable fee or refuse to comply with your request.
—
ARTICLE 12 – COMPLAINTS
12.1 Should you have a complaint regarding the processing of your personal data, please contact us directly. We will endeavour to find a solution together.
12.2 You have the right at any time to lodge a complaint with the Dutch Data Protection Authority. This is the supervisory authority responsible for data protection in the Netherlands.
**Dutch Data Protection Authority**