CleverFranke B.V.
Version: 1.1 · Effective date: 30 May 2026 · Last reviewed: 28 May 2026
Clever°Franke B.V. (“C°F”, “we”, “us”) is a data design & technology studio, based in the Netherlands. We are part of the Amsterdam Data Collective (ADC) Group. We respect your privacy and handle personal data in line with the EU General Data Protection Regulation (GDPR), the Dutch GDPR Implementation Act (UAVG), and the Dutch Telecommunications Act.
This policy explains what personal data we collect, why, on what legal basis, how long we keep it, and what rights you have. It applies to our website, our services, and our day-to-day interactions with clients, prospects, and visitors.
Controller: CleverFranke B.V.
Contact for privacy matters: gdpr@adc-consulting.com
Data Protection Officer: C°F has not appointed a DPO as it is not required under Art. 37 GDPR. For privacy questions contact the address above.
For some processing activities C°F acts as a processor on behalf of a client (the controller). In those cases the client's privacy notice applies and our processing is governed by a Data Processing Agreement.
This policy covers personal data we process as a controller, including:
Where C°F processes personal data on behalf of a client (e.g., when building or hosting a data visualisation that contains personal data), we act as a processor. The terms of that processing are set out in the contract and Data Processing Agreement with the client.
The table below summarizes our main processing activities. Where placeholders appear in brackets, the value is to be confirmed and finalised before this policy is published.
Legal bases (Art. 6 GDPR): consent; performance of a contract; compliance with a legal obligation; legitimate interest. We balance our legitimate interests against your rights and freedoms; you can object at any time (see Section 8).
We do not knowingly process special categories of personal data (Art. 9) or children's data through our website.
On the website cleverfranke.com:
We share personal data only with parties that need it to deliver a service to us, or where we are legally required to do so. We have written agreements with all processors, including the data processing terms required by Art. 28 GDPR.
We do not sell personal data. We do not share personal data with third parties for their own marketing purposes without your consent.
Where personal data is transferred outside the European Economic Area (EEA), we rely on one of the safeguards permitted by Chapter V GDPR:
A copy of the safeguards in place can be requested from the contact in Section 1.
Retention periods are set per processing activity (see Section 3). General principles:
Under the GDPR you have the following rights:
How to exercise your rights: send a request to the contact in Section 1. We respond within one month (extendable by two months for complex requests, Art. 12(3) GDPR). We may need to verify your identity before acting on the request.
C°F is part of the ADC Group, which operates an ISO 27001-aligned Information Security Management System. We apply organisational and technical measures appropriate to the risk, including access control, encryption in transit, logging, regular backups, secure development practices, and staff training. Despite these measures, no system can be guaranteed to be fully secure; we ask you not to send sensitive personal data through unencrypted channels.
The ISO 27001 certification of ADC is being applied to C°F effective December 2026.
In the event of a personal data breach involving a risk to data subjects, we notify the Dutch DPA within 72 hours and affected individuals where required, in line with Articles 33 and 34 GDPR.
C°F does not use automated decision-making producing legal or similarly significant effects on individuals (Art. 22 GDPR). Where we use analytics or aggregated profiling for service improvement, this does not produce decisions about individuals.
We may update this policy to reflect changes in our processing or in the law. The version and effective date at the top of this document indicate the current version. Material changes will be communicated through our website and, where appropriate, by direct notice.
Please contact us first if you have questions or concerns. If we cannot resolve your concern, you have the right to lodge a complaint with the Dutch Data Protection Authority:
If you reside in another EEA country, you may also contact your local supervisory authority.