Open Commerce B.V. is an e-commerce and platform consultancy based in Rijswijk, the Netherlands. This policy explains what we do with personal data in the situations where we decide ourselves why and how that data is used. That covers visitors to this website, people who contact us, contact persons at our clients, suppliers and delivery partners, podcast guests, people who apply to work with us, and users of our OCToDo application.
The short version:
The sections below give the detail. If anything is unclear, email privacy@opencommerce.agency and we will explain it in plain terms.
We often work in systems that belong to our clients, such as their webshop, their ERP, or their support desk. When we do that, we act on our client's instructions and our client decides what happens with the personal data in those systems. In legal terms our client is the controller and we are a processor. This policy does not apply to that data. What we may and may not do with it is set out in the data processing agreement we sign with each client.
If you are a customer of one of our clients and you have a question about your data, contact that company directly. If you are not sure who to contact, email us and we will point you in the right direction.
Open Commerce B.V. Steenplaetsstraat 6, unit 4.14 2288 AA Rijswijk The Netherlands
Chamber of Commerce (KvK): 82713413 Telephone: +31 70 701 3914 Email: privacy@opencommerce.agency
We are the controller for the processing described in this policy.
We are not required to appoint a Data Protection Officer under Article 37 of the GDPR, and we have not appointed one. Our core activity is consultancy, not large-scale monitoring of people and not large-scale processing of special category data. We have recorded the reasoning behind this in our internal records and review it when our activities change. Questions about data protection go to privacy@opencommerce.agency, where they are handled by our leadership team.
What we process: IP address, browser and device type, pages viewed, referring page, approximate location derived from IP, and the date and time of your visit.
Why: to keep the website available and protected against abuse, and to understand which pages are read so we can improve them.
Legal basis: for security and availability, our legitimate interest in a working and protected website (Article 6(1)(f) GDPR). For statistics that go beyond simply counting visitors, and for anything connected to advertising, your consent (Article 6(1)(a) GDPR), which you give or refuse through the cookie banner. See section 5.
Who is involved: Cloudflare provides protection and delivery for the website and keeps security logs. Matomo Cloud provides our day to day visitor statistics. Google Analytics and Google Tag Manager are used only to measure the results of our advertising on Google Ads.
Retention: Cloudflare security logs are kept for up to 30 days. Matomo statistics for up to 24 months. Google Analytics data for 24 months.
This covers the contact form, our email addresses, the telephone number, and the booking link for an introductory call.
What we process: your name, business email address, telephone number if you give it, the company you work for, and the content of your message or the notes from our conversation.
Why: to answer your question, to see whether we can help you, and to prepare a proposal.
Legal basis: the steps leading up to a contract at your request (Article 6(1)(b) GDPR), or our legitimate interest in responding to people who approach us (Article 6(1)(f) GDPR).
Retention: if no engagement follows, we delete the correspondence 24 months after our last contact with you. If an engagement follows, the terms in 2.3 apply.
What we process: name, job title, business email address and telephone number, the company you work for, correspondence, meeting notes and summaries, and where relevant the recording and transcript of an online meeting. For invoicing we also process the billing details your organisation provides.
Why: to deliver the engagement, to keep an accurate record of what was decided and advised, to invoice, and to meet our own tax and accounting obligations.
Legal basis: performance of the contract with your organisation (Article 6(1)(b) GDPR), our legal obligations for financial administration (Article 6(1)(c) GDPR), and our legitimate interest in keeping a defensible record of advice given and agreements reached (Article 6(1)(f) GDPR).
Retention: correspondence and project records for 7 years after the engagement ends. This follows the statutory retention obligation for financial administration in article 52 of the Dutch General Tax Act, and the period during which claims relating to our work can still be brought. Invoices and the underlying administration: 7 years, because tax law requires it.
We record and automatically transcribe advisory meetings for two reasons. The first is practical: it means we can pay attention to the conversation instead of to our notes, and write an accurate summary afterwards. The second is that our work consists largely of advice and decisions taken in conversation. If a question later arises about what was advised, what was agreed, or what information we were given, the recording is the record that settles it. Written notes cannot do that, because notes are one party's account of the conversation.
We use one recording and transcription tool per meeting, either TLDV or the note-taking function in Google Workspace.
What we process: audio, video where the camera is on, the automatic transcript, and the written summary.
Why: to produce accurate summaries of advisory conversations, and to have a reliable record of what was said and agreed if that later becomes relevant, including in a dispute.
Legal basis: our legitimate interest in an accurate and verifiable record of our advisory work (Article 6(1)(f) GDPR). Recording of advisory sessions is also set out in the engagement terms we agree with your organisation, so that everyone knows in advance that this is how we work.
How we handle it: the recording indicator is visible to everyone in the meeting, and we say at the start that recording is on. If you would rather not be recorded, tell us and we will switch it off and take notes by hand instead. There is no consequence for you or for the meeting if you do that. You can also ask us afterwards to delete a recording. We will discuss that with you, and we will delete it unless the recording relates to a matter that is actively in dispute.
Retention: we delete the recording and the automatic transcript 24 months after the engagement with your organisation ends. The written summary stays in the project record and follows the 7 year term in 2.3. If a dispute is running when the 24 months expire, we keep the relevant recording until the dispute is resolved.
What we process: name, business contact details, company details, Chamber of Commerce and VAT number where applicable, contract data, and invoicing data.
Why: to enter into and perform agreements, to route work to the right people, and to pay invoices.
Legal basis: performance of the contract (Article 6(1)(b) GDPR) and our legal obligations (Article 6(1)(c) GDPR).
Retention: 7 years after the end of the relationship for anything forming part of our administration.
What we process: name, job title, employer, business contact details, and the audio, video and transcript of the recording.
Why: to produce and publish the episode or session, to promote it, and to reuse parts of it in later publications such as clips, quotes and articles.
Legal basis: performance of the agreement we make with you about taking part, including the release you confirm in writing before recording (Article 6(1)(b) GDPR).
Retention: published material stays available for as long as we publish it.
What we process: the data in your application, including your CV, motivation, contact details, and the notes we make during interviews or a practical exercise.
Why: to assess whether you fit the role.
Legal basis: our legitimate interest in filling a vacancy (Article 6(1)(f) GDPR), and your consent if you allow us to keep your details for longer (Article 6(1)(a) GDPR).
Retention: we delete your application within 24 months of the end of the procedure.
What we process: your name, business email address, the company you work for, and whether you opened a message or clicked a link.
Why: to send you our insights and updates, and to see whether they are being read so we can write better ones.
Legal basis: your consent (Article 6(1)(a) GDPR). Where we email existing clients about services comparable to those we already provide, we rely on the exception for existing customer relationships in article 11.7 of the Dutch Telecommunications Act.
Who is involved: HubSpot, which is also our customer relationship management system.
Retention: until you unsubscribe. After that we keep a minimal record of your unsubscribe so that we do not email you again by mistake.
Every message contains an unsubscribe link. You can also reply and ask.
OCToDo is our own application, used to plan and track work. Only Open Commerce staff and the partners and freelancers contracted to work with us have accounts. Clients do not log in.
What we process when you log in: you sign in with your Google account. From that account we receive only your name and email address, which we use to verify who you are and to link your account to your work. We do not read your mail, your calendar, your files or your contacts, and we do not request access to them.
What we process when you use the app: the tasks, notes, comments and time entries you create, and a log of changes so that we can see who changed what and when.
Why: to run the app, to plan and track work, to keep a reliable record of how a project progressed, and to invoice accurately. We do not use the change log to assess individual performance.
Legal basis: performance of your employment contract or engagement with us (Article 6(1)(b) GDPR), and our legitimate interest in a reliable project record (Article 6(1)(f) GDPR).
Where it runs: Google Cloud Platform and OVH Cloud in the European region.
Retention: account data for as long as you have an account, and up to 24 months afterwards to preserve the change log. Task content follows the project record term in 2.3.
We use other companies to run our business. Where they process personal data on our behalf, we have a data processing agreement in place with them. We do not sell personal data and we do not share it for anyone else's marketing.
The categories of recipients are:
Our website and content management system do not receive personal data from you beyond what is needed to serve the pages you request.
For advertising on LinkedIn we and LinkedIn each determine part of the processing, which makes us joint controllers for that part. The division of responsibility follows LinkedIn's joint controller addendum. LinkedIn's own privacy policy explains what it does with the data it collects through this.
You can ask us for the current list of the processors and sub-processors we use, and we will provide it.
Some of the providers we use are established outside the European Economic Area, or use infrastructure outside it. Where personal data leaves the EEA, we make sure the transfer rests on a valid basis under Chapter V of the GDPR. That is either an adequacy decision by the European Commission for the country concerned, or the European Commission's Standard Contractual Clauses combined with additional technical and organisational measures where those are needed. We reassess this when the legal position changes.
For our use of Anthropic, the transfer rests on the European Commission's Standard Contractual Clauses, which form part of the data processing addendum between us. We do not rely on an adequacy decision for that transfer.
Open Commerce works with an independent partner organisation in the United States. That organisation has no access to our client data or our internal systems, and we have no access to theirs, beyond the specific data needed for a project we work on together. Where such access is needed, it is agreed in writing and limited to what the project requires.
You can ask us which providers are involved and which basis applies to each. Email us and we will tell you.
A cookie is a small file placed on your device when you visit a website. We also use comparable techniques such as pixels and scripts, and everything in this section applies to those as well.
We manage cookies through Cookiebot. The first time you visit, you choose which categories you allow. Nothing beyond the strictly necessary cookies is placed before you make that choice. You can change or withdraw your choice at any time via the cookie settings link in the footer of every page, and Cookiebot shows the full list of cookies we place, what each one does, who provides it and how long it lasts.
The categories are:
Necessary. Needed for the website to work and to protect it against abuse. These are placed without your permission because the site cannot function without them.
Statistics. These tell us how many people visit which pages and how they move through the site. We use Matomo for this.
Marketing. These measure the results of our advertising and allow advertising to be targeted. Google Analytics, Google Tag Manager and LinkedIn sit in this category. We only place these if you allow it.
Refusing cookies does not restrict your access to any part of this website.
We take appropriate technical and organisational measures against loss and unlawful processing, including:
No system is completely secure. If something goes wrong and your data is affected, we act on it, record it in our breach register, and notify you and the Dutch Data Protection Authority where the law requires it.
You have the following rights in relation to the data we hold about you.
To use any of these rights, email privacy@opencommerce.agency. We respond within one month. If your request is complicated we may need up to two extra months, and we will tell you if that happens. We may ask you to confirm your identity first, so that we do not hand your data to someone else.
We do not use automated decision-making or profiling. No decision affecting you is made about you by software alone.
You are not obliged to give us your personal data. If you do not give us what we need to answer your question, deliver an engagement or pay an invoice, we may not be able to do those things.
If you are not happy with how we handle your data or your request, tell us first. Email privacy@opencommerce.agency and we will look into it.
You also have the right to complain to the Dutch Data Protection Authority:
Autoriteit Persoonsgegevens Postbus 93374 2509 AJ Den Haag autoriteitpersoonsgegevens.nl
We update this policy when our processing changes. The current version always can be found via our website, linkedin in the footer.. The date at the top tells you when it last changed. If a change materially affects you, we will let you know rather than relying on you to notice.