LEGAL INFORMATION
Privacy notice
This notice explains which personal data we use, why we need it and your rights. It covers this Celsius BI website and our business contact.
1. Who is responsible?
Celsius BI · Floris Moest · Van Dijklaan 5, 5581 WG Waalre, the Netherlands · Chamber of Commerce 91526116 · info@celsiusbi.com
Celsius BI is the controller for personal data processed for its own website, communications and business administration. For privacy questions or requests about your data, email info@celsiusbi.com.
2. Data, purposes and legal bases
Contact and introductions: when you email us or book a meeting, we process your name, business contact details and information you choose to share. We use these to respond and discuss a possible engagement. The legal basis is our legitimate interest in business communications; where you request steps towards a contract with you, pre-contractual steps may also apply.
Engagements and administration: we process contact, engagement and billing data to perform contracts, manage business relationships and meet statutory recordkeeping duties. For business contact persons, relationship management is based on our legitimate interest in managing the business relationship.
Website and security: when pages are requested, the hosting environment receives technical information such as your IP address, requested page and browser information. This is needed to deliver the website and investigate misuse, based on the legitimate interest in operating a functioning, secure website.
You do not need to provide personal data to read website content, apart from technically necessary data exchanges. Without necessary contact or engagement details, we may be unable to handle your request or engagement. Do not send sensitive personal data or identity documents unless necessary.
3. Cookies and Google Analytics
Google Analytics is not yet enabled in this published version. The website code does not load a Google Analytics tag or set analytics or advertising cookies. This version does not use other visitor analytics or advertising tracking in the website code.
Technically necessary processing by the hosting environment is separate from visitor analytics. This notice therefore does not promise that browsing is fully anonymous.
If we activate Google Analytics later, we will update this notice with the actual settings, data, retention periods and any international transfers. Where consent is required, Analytics will load only after consent, which can also be withdrawn.
4. Email, Calendly and recipients
This website contains an email link and a link to Calendly for booking a meeting. Calendly is not embedded in the page: you visit that external service only when you open the link. Data entered there is processed under the applicable arrangements and Calendly privacy information.
Where necessary, personal data may be accessible to hosting, security, email, scheduling and administration providers, and persons involved in delivering an engagement. Access is limited to what is needed. Where a supplier processes data on our behalf, appropriate processing agreements are required. We do not sell your personal data.
We provide data to competent authorities where legally required, or where necessary and lawful to establish, exercise or defend legal rights.
5. Retention periods
We do not retain personal data longer than needed for its purpose. For a standalone enquiry that does not lead to an engagement, we delete correspondence no later than one year after the last substantive contact, unless a specific legal need requires longer retention.
Engagement data is retained for as long as needed for delivery, maintenance and handling potential disputes. Data forming part of tax records is subject to the statutory retention period, generally seven years. Technical data is retained as needed for delivery, security and investigating specific incidents, not indefinitely for general visitor profiling.
6. Processing outside the EEA
Suppliers may process data outside the European Economic Area. Access by separate service providers in Bangalore may also constitute an international transfer. Such a transfer requires a valid GDPR transfer mechanism, such as an applicable adequacy decision or standard contractual clauses with supplementary measures where needed.
For engagements, we agree in advance who will have access and which safeguards are needed. A general reference to a cloud provider does not replace that assessment. You may request information about safeguards used for your data and, where applicable, a copy by emailing info@celsiusbi.com.
7. Security and client-controlled data
We take appropriate technical and organisational measures suited to the data and risks. Access must be limited to authorised persons. No digital service can guarantee absolute security; statutory security and notification duties remain applicable.
When we process data on behalf of a client, that client determines the purpose and separate processing arrangements apply. Requests concerning that data should initially be directed to that organisation. We assist the client where required by the agreement and the GDPR.
8. Your rights and complaints
Depending on the processing, you have rights of access, correction, deletion, restriction and portability. You may object to processing based on legitimate interests. You may withdraw consent; this does not retrospectively make earlier lawful processing unlawful.
Email your request to info@celsiusbi.com. Where needed, we verify your identity appropriately and generally respond within one month. If the GDPR permits an extension, we will inform you within that first month. You may also complain directly to the Dutch Data Protection Authority.
We do not use this website to make solely automated decisions producing legal or similarly significant effects for visitors. If our processing changes, we update this notice.
