Privacy

CleverFranke B.V.

Version: 1.1 · Effective date: 30 May 2026 · Last reviewed: 28 May 2026

Clever°Franke B.V. (“C°F”, “we”, “us”) is a data design & technology studio, based in the Netherlands. We are part of the Amsterdam Data Collective (ADC) Group. We respect your privacy and handle personal data in line with the EU General Data Protection Regulation (GDPR), the Dutch GDPR Implementation Act (UAVG), and the Dutch Telecommunications Act.

This policy explains what personal data we collect, why, on what legal basis, how long we keep it, and what rights you have. It applies to our website, our services, and our day-to-day interactions with clients, prospects, and visitors.

1.Whoweare

Controller: CleverFranke B.V.

Contact for privacy matters: gdpr@adc-consulting.com

Data Protection Officer: C°F has not appointed a DPO as it is not required under Art. 37 GDPR. For privacy questions contact the address above.

For some processing activities C°F acts as a processor on behalf of a client (the controller). In those cases the client's privacy notice applies and our processing is governed by a Data Processing Agreement.

2.Scopeofthispolicy

This policy covers personal data we process as a controller, including:

  • visitors to our website cleverfranke.com and any subdomains;
  • prospective clients, clients, and their representatives;
  • recipients of our newsletter or marketing communications;
  • candidates applying for a role at C°F;
  • suppliers and business contacts.

Where C°F processes personal data on behalf of a client (e.g., when building or hosting a data visualisation that contains personal data), we act as a processor. The terms of that processing are set out in the contract and Data Processing Agreement with the client.

3.Whatweprocess,why,andonwhatbasis

The table below summarizes our main processing activities. Where placeholders appear in brackets, the value is to be confirmed and finalised before this policy is published.

Legal bases (Art. 6 GDPR): consent; performance of a contract; compliance with a legal obligation; legitimate interest. We balance our legitimate interests against your rights and freedoms; you can object at any time (see Section 8).

We do not knowingly process special categories of personal data (Art. 9) or children's data through our website.

4.Datacollectiononcleverfranke.com

On the website cleverfranke.com:

  • All visitor data is anonymized; you cannot be identified by the stored data
  • We use Google Analytics to monitor traffic
  • Google is the sole facilitator of data collection on our site.
  • We have a written agreement with Google, in which they agree not to use any of the data collected.
  • We have disabled data sharing through Google Analytics.
  • We do not use and/or share data between Google services.
  • The last three digits of visitors’ IP addresses are masked.
  • Our webfonts are self-hosted, they neither collect nor store any information about website visitors.

5.Whowesharepersonaldatawith

We share personal data only with parties that need it to deliver a service to us, or where we are legally required to do so. We have written agreements with all processors, including the data processing terms required by Art. 28 GDPR.

We do not sell personal data. We do not share personal data with third parties for their own marketing purposes without your consent.

6.Internationaltransfers

Where personal data is transferred outside the European Economic Area (EEA), we rely on one of the safeguards permitted by Chapter V GDPR:

  • an adequacy decision by the European Commission;
  • Standard Contractual Clauses (SCCs) supplemented by a transfer impact assessment where needed;
  • for transfers to the United States, certification under the EU-US Data Privacy Framework where the recipient is certified.

A copy of the safeguards in place can be requested from the contact in Section 1.

7.Howlongwekeeppersonaldata

Retention periods are set per processing activity (see Section 3). General principles:

  • we keep personal data only as long as necessary for the purpose for which it was collected;
  • statutory retention periods (e.g., 7 years for fiscal records under Dutch law) override shorter periods;
  • when a retention period ends, data is deleted or irreversibly anonymized.

8.Yourrights

Under the GDPR you have the following rights:

How to exercise your rights: send a request to the contact in Section 1. We respond within one month (extendable by two months for complex requests, Art. 12(3) GDPR). We may need to verify your identity before acting on the request.

9.Security

C°F is part of the ADC Group, which operates an ISO 27001-aligned Information Security Management System. We apply organisational and technical measures appropriate to the risk, including access control, encryption in transit, logging, regular backups, secure development practices, and staff training. Despite these measures, no system can be guaranteed to be fully secure; we ask you not to send sensitive personal data through unencrypted channels.

The ISO 27001 certification of ADC is being applied to C°F effective December 2026.

In the event of a personal data breach involving a risk to data subjects, we notify the Dutch DPA within 72 hours and affected individuals where required, in line with Articles 33 and 34 GDPR.

10.Automateddecision-makingandprofiling

C°F does not use automated decision-making producing legal or similarly significant effects on individuals (Art. 22 GDPR). Where we use analytics or aggregated profiling for service improvement, this does not produce decisions about individuals.

11.Changestothispolicy

We may update this policy to reflect changes in our processing or in the law. The version and effective date at the top of this document indicate the current version. Material changes will be communicated through our website and, where appropriate, by direct notice.

12.Questionsandcomplaints

Please contact us first if you have questions or concerns. If we cannot resolve your concern, you have the right to lodge a complaint with the Dutch Data Protection Authority:

  • Autoriteit Persoonsgegevens, Postbus 93374, 2509 AJ Den Haag
  • https://autoriteitpersoonsgegevens.nl · +31 (0)88 1805 250

If you reside in another EEA country, you may also contact your local supervisory authority.