Privacy statement
Last updated: 24 August 2026 · Version 1.0
This statement explains which personal data Valmoors Digital processes, why we do so and what rights you have. It covers this website as well as the AI WhatsApp agent we run for our clients.
In short
This website sets no cookies, uses no analytics or tracking software and contains no contact forms. So we do not know who you are if you only browse these pages. Only when you send us a message on WhatsApp do we process personal data about you.
Contents
- Who is responsible
- Our two roles: controller and processor
- Data via this website
- Data via the WhatsApp agent
- Data of clients and prospects
- Purposes and legal bases
- AI and automated processing
- Sharing with third parties
- Transfers outside the EEA
- Retention periods
- Security
- Your rights
- Lodging a complaint
- Changes
- Contact
1. Who is responsible
Valmoors Digital is the controller for the processing of personal data described in this statement.
| Organisation | Valmoors Digital |
|---|---|
| Address | Irenestraat 7, 7075 BA Etten |
| Chamber of Commerce number | [not yet known - add once registered] |
| privacy@valmoorsdigital.com | |
| +31 6 12984290 | |
| Website | www.valmoorsdigital.com |
We have not appointed a data protection officer (DPO); this is not required for an organisation of our size and nature. You can raise privacy questions through the contact details above.
2. Our two roles: controller and processor
This distinction determines who you should address a request to.
- Controller. For our own website, our own client contacts and the messages you send directly to Valmoors Digital, we determine the purposes and means ourselves. In that case you can come to us directly.
- Processor. Where the AI agent runs for a client — a restaurant, hair salon, dental practice or beauty salon — that business is the controller for the conversations with its own guests. We process those data solely on that business's instructions, under a data processing agreement. If you are a guest, customer or patient of such a business and wish to exercise your rights, please contact that business directly. We support them in handling it.
3. Data via this website
This website is deliberately kept simple. We process as little data here as possible.
What we do not do
- No cookies for analytics, advertising or profiling.
- No Google Analytics, Meta pixel or comparable tracking software.
- No contact or sign-up forms on this site.
- No selling or renting of data to third parties. Ever.
What is processed
| Data | Why | By whom |
|---|---|---|
| IP address, timestamp, page requested, browser type (server logs) | Necessary to serve the website, and for security and troubleshooting | Our hosting provider Hostinger (Hostinger International Ltd.) |
| Theme preference (light/dark) in local storage | Remembers your display preference in your own browser. This is not a cookie and is never sent to us. | Stays on your device |
Fonts are served from our own server. The Poppins and Inter typefaces load from valmoorsdigital.com and are not fetched from Google. Your IP address therefore does not go to an external party for this.
4. Data via the WhatsApp agent
When you click a WhatsApp button, WhatsApp opens with a pre-filled message. At that point the terms and privacy policy of WhatsApp Ireland Ltd. (Meta) also apply. We have no influence over what Meta itself does with your data.
As soon as you send us a message, we process:
- Your phone number and your WhatsApp profile name.
- The content of your messages, including any photos or documents you send.
- Conversation metadata: timestamps, whether a message has been read, and the status of the conversation.
- A conversation record on our server. The agent stores the conversation and its session data as a file on the server it runs on, so that it knows the context of earlier messages.
- Data you provide yourself for a booking or appointment: name, date and time, and depending on the business also the number of people, the treatment or service you want, dietary requirements or allergies, and any other remarks.
Special categories of personal data. Some of the data you pass on may say something about your health: an allergy or dietary requirement at a restaurant, a skin condition at a salon, or the mere fact that you have an appointment at a dental practice. We process such data solely to carry out your appointment properly and for no other purpose. Please do not share more medical information over WhatsApp than is needed to make the appointment; clinical questions belong with the practice itself.
If you book an appointment through the agent, we put it in our calendar in Google Calendar. That entry contains your name and the subject of the appointment.
5. Data of clients and prospects
If you contact us as a business owner, we process your name, company name, contact details and the content of our correspondence. If you become a client, invoicing and payment data are added, which we keep for seven years under tax law retention obligations.
6. Purposes and legal bases
We only process personal data on a legal basis under Article 6 GDPR.
| Purpose | Legal basis |
|---|---|
| Answering your message and handling your enquiry | Performance of a contract, or steps at your request before entering into one (Art. 6(1)(b)) |
| Recording and confirming a booking | Performance of a contract (Art. 6(1)(b)) |
| Processing allergy and dietary information | Explicit consent, given by providing it yourself (Art. 9(2)(a)) |
| Security, abuse prevention and server logs | Legitimate interest: a secure and functioning service (Art. 6(1)(f)) |
| Improving the agent using real conversations | Legitimate interest: quality of service (Art. 6(1)(f)) |
| Invoicing and administration | Legal obligation (Art. 6(1)(c)) |
| Commercial follow-up with past clients | Legitimate interest, always with the option to opt out (Art. 6(1)(f)) |
7. AI and automated processing
Your messages are read and answered by an AI agent. We think you should know that, so we are open about it.
- You are initially talking to software. The agent identifies itself as such and you can always ask for a human.
- There is human oversight. The business owner and we can read along and step in or take over the conversation at any moment.
- No decisions with legal effect, and no advice. The agent makes appointments and answers practical questions. It gives no medical, cosmetic or other professional advice and refers such questions to the practice or salon concerned. No automated decisions are taken that produce legal effects concerning you or similarly significantly affect you, within the meaning of Article 22 GDPR. No profiling takes place.
- Message content goes to an AI provider to generate a reply. We choose providers that do not use business customers' data to train their models. For this we use Claude by Anthropic (Anthropic PBC). Anthropic does not use business API customers' data to train its models.
Healthcare providers. Where we work for a dental practice or another healthcare provider, stricter requirements apply. In those cases the data processing agreement sets out additional arrangements on access, retention and security, and we never process record or treatment information from the patient system — only what is needed to schedule or confirm an appointment. [have your lawyer check this point against the Dutch Wgbo and NEN 7510, among others]
8. Sharing with third parties
We do not sell your data. We do engage service providers that process on our behalf. With each of them we conclude a data processing agreement.
| Category | Purpose | Party |
|---|---|---|
| Messaging platform | Delivering and receiving WhatsApp messages | WhatsApp Ireland Ltd. (Meta) |
| AI language model | Generating replies | Anthropic PBC (Claude), United States |
| Website hosting | Serving this website | Hostinger International Ltd., Lithuania |
| Hosting of the agent | Running the WhatsApp agent | Railway Corp., United States |
| Calendar | Recording booked appointments | Google Ireland Ltd. (Google Calendar) |
| Our client | Carrying out your booking or appointment | The restaurant, salon or practice you are contacting |
| Bookkeeping | Invoicing and tax obligations | [not yet selected - add once known] |
In addition, we disclose data where we are legally required to, for example at the demand of a competent authority.
9. Transfers outside the EEA
Some providers are established outside the European Economic Area or process data there, notably in the United States. In that case we ensure a valid basis for transfer: an adequacy decision of the European Commission (such as the EU-US Data Privacy Framework) or the Commission's standard contractual clauses (SCCs), supplemented by appropriate additional measures.
10. Retention periods
We do not keep data longer than is necessary for the purpose for which we received it.
| Data | Period |
|---|---|
| WhatsApp conversations with no follow-up | 12 months after the last message |
| Booking and appointment data | 12 months after the date of the appointment |
| Health-related remarks (allergy, diet, skin) | Deleted immediately after the appointment, unless you are a regular client and prefer otherwise |
| Client records and invoices | 7 years (statutory tax retention) |
| Website server logs | Kept by Hostinger, only for as long as needed for security and error analysis. |
| Correspondence with prospects | 24 months after the last contact |
Where we run the agent for a client, the periods agreed with that client in the data processing agreement apply.
11. Security
We take appropriate technical and organisational measures, including:
- encrypted connections (TLS) for the website and all integrations;
- access to conversations only for those who need it for their work;
- two-factor authentication on the accounts that grant access to systems;
- periodic review of providers and their data processing agreements.
Do you suspect a vulnerability or a data breach? Let us know at privacy@valmoorsdigital.com. We respond as quickly as possible and, where required, report a breach to the Dutch Data Protection Authority within 72 hours.
12. Your rights
Under the GDPR you have the following rights:
- Access to the data we process about you.
- Rectification of inaccurate or incomplete data.
- Erasure of your data, insofar as we are not legally required to keep it.
- Restriction of processing.
- Objection to processing based on legitimate interest.
- Data portability: receiving your data in a commonly used file format.
- Withdrawing consent, without affecting processing carried out beforehand.
Send a request to privacy@valmoorsdigital.com. We respond within one month. To prevent us handing data to the wrong person, we may ask you for additional identification. If your request concerns a conversation with a business for which we run the agent, please contact that business (see point 2).
13. Lodging a complaint
If we cannot resolve matters together, you have the right to lodge a complaint with the supervisory authority. In the Netherlands this is the Autoriteit Persoonsgegevens, autoriteitpersoonsgegevens.nl. If you live in another EU country, you can turn to the supervisory authority in your own country.
14. Changes
We may amend this statement when our services or the rules give cause to. The current version is always on this page, with the date of the last change at the top. For substantial changes we actively inform existing clients.
15. Contact
Questions about this statement or about your data? Send a message to privacy@valmoorsdigital.com or message us on +31 6 12984290.