Skip to content

DRAFT — legally to be reviewed

Last updated: 4 August 2026

Privacy statement

This statement describes which personal data we process when you visit our website, fill in a form or place an order — what for, on which legal basis and for how long. We process nothing beyond what is set out below.

Who is responsible

The controller is the business whose details appear at the bottom of this page under Company details, including its Chamber of Commerce number, address and the e-mail address you can reach us on. Questions about this statement or about your data go to that address.

What we process when you order

When you place an order in the webshop we process:

  • your name and e-mail address — to confirm the order and to be able to contact you;
  • your telephone number, if you provide it (optional) — only if something is wrong with the delivery;
  • your delivery address (street, house number, postcode, town) — to deliver. If you choose pickup, we do not ask for an address;
  • what you ordered: items, size, quantity and the amounts paid;
  • the order number and payment status, and the payment reference we receive back from our payment provider.

Once the order is being handled, that order record grows with what happens to it. Added to it are:

  • the dispatch details — carrier, track-and-trace code and the date of dispatch;
  • cancellations and returns — which items, which quantities, when they were notified, the return number and any reason you give yourself;
  • refunds — the amount, the payment provider's reference and its status;
  • the invoice and any credit notes — as a fixed snapshot of what is printed on them, so that an invoice cannot quietly change later;
  • an action log: which of us took which step, and when (for example marked as shipped or return booked in). It holds no payment data and no free text about you;
  • internal notes we make on an order. They are not visible in your portal; you can request them, like the rest of your data.

Legal basis: performance of the purchase agreement; for the invoicing data also our statutory record-keeping obligation.

Where this lives: orders are stored in our own database on our own server (a separate database used only by the webshop). They are not held by an external webshop service and are not used for profiling, advertising or sale to third parties.

Payment data: the payment itself takes place at Mollie B.V.. You enter your iDEAL, card or Apple Pay details in Mollie's environment. We neither see nor store those details; we only receive whether the payment succeeded, by which method and under which reference. The same goes for a refund: it runs through Mollie, back to the payment method you used, without us seeing your account or card number.

Retention: an order with an invoice is part of our accounts. We keep those for about seven years — the Dutch fiscal retention obligation. That covers the order record, the invoice, any credit note and the action log belonging to it. Data that is not part of those accounts is deleted sooner. [TO CONFIRM] — record which fields are cleaned up once the guarantee and returns periods have passed.

The customer portal and the sign-in links

At My orders you can view your own orders, invoices and credit notes. That needs no account and no password, so there is no profile of you that we maintain.

There are two ways in:

  • The link in your order confirmation. It opens exactly that one order. The link is signed; we store nothing extra for it.
  • A sign-in link by e-mail. Enter your e-mail address and we send you a one-time link that opens all of your orders. Of that link we store not the link itself but only an encrypted fingerprint of it, together with your e-mail address, when it was created and when it expires. The link is valid for 15 minutes and works once; the row is swept afterwards. So someone who read our database could not extract a working sign-in link from it.

If somebody asks for a sign-in link for an address we do not know, they see exactly the same screen as for an address we do know — and no e-mail goes out. That is deliberate: the screen must not reveal who is a customer of ours. To limit abuse there is a maximum number of requests per e-mail address and per IP address.

After signing in your browser holds a session cookie that lasts two hours and contains nothing but your e-mail address in signed form. Signing out clears it immediately. This cookie is strictly necessary for the service you asked for yourself.

What we process when you fill in a form

The contact, sign-up and request forms on this site send us:

  • your name and e-mail address;
  • your telephone number, if you provide it (optional);
  • the subject and your message;
  • for a sign-up or request: the event or service it concerns and the number of people, where you fill that in.

Your message is delivered by e-mail to the mailbox belonging to the subject you chose; we keep it in that mailbox and not in a separate customer system. We use your address only to reply — never for newsletters or marketing you did not ask for.

Legal basis: your request for contact (performance of the agreement or legitimate interest).

Retention: correspondence is kept for as long as it takes to handle your question and for a maximum of 24 months thereafter. [TO CONFIRM] — confirm or adjust this period.

Spam protection on forms

To prevent abuse of the forms we use Cloudflare Turnstile and a temporary per-IP count. Your IP address is checked in the process; it is not linked to your message and not stored permanently. Turnstile sets no advertising cookies and does not track you across websites.

Cookies and browser storage

We use no tracking or advertising cookies and no third-party tracking technology. That is why there is no cookie banner: there is nothing to refuse.

What is stored in your browser:

  • your cart — the items you added, held in your own browser's local storage (localStorage). That information stays on your device and is only sent to us at the moment you check out. You can empty the cart or clear your browser storage;
  • a customer-portal session cookie — only after you have clicked a sign-in link yourself, valid for two hours, and containing nothing but your e-mail address in signed form. Signing out clears it;
  • an admin login cookie — only for staff signing in at /admin, strictly necessary for that session.

If we ever measure visitor numbers we will do so without cookies and without personal data; if that changes, it will be stated here before it takes effect.

Who we share data with

Only with parties needed to deliver what you ask for:

  • Mollie B.V. — the payment;
  • the carrier — your name and delivery address, in order to deliver;
  • Microsoft (Microsoft 365) — the mail environment our confirmation and contact mail is sent and kept in;
  • our hosting provider — the server the website and database run on.

We do not sell your data and do not use it for advertising.

Your rights

You have the right of access, rectification, erasure, restriction and data portability, and you may object to processing. Send a message to the e-mail address at the bottom of this page; we reply within a month.

What "erasure" can and cannot mean

For a paid order we cannot erase everything, and we are not allowed to. The invoice, the order record it rests on, any credit note and the action log that goes with them are accounting records: we have to keep them for about seven years. An erasure request therefore does not remove them while that period runs. That is not unwillingness but a legal obligation that outweighs the right to erasure.

What we do do on request:

  • rectify anything factually wrong (a misspelled name, an out-of-date address);
  • erase what is not part of the accounts — internal notes on an order, your correspondence in our mailbox, and any outstanding sign-in links;
  • restrict: we then use your data only to meet the retention obligation and for nothing else;
  • erase once the period ends: as soon as the seven years are up, the order leaves our accounts.

For an order that was never paid it is different: there is no invoice, so we can erase it on request.

On any request we always tell you concretely what was erased and what we had to keep, with the reason.

If you disagree with how we handle your data you may lodge a complaint with the Dutch data protection authority, the Autoriteit Persoonsgegevens (autoriteitpersoonsgegevens.nl).

Security

The site runs exclusively over a secure connection (HTTPS). The order database is not reachable from the internet. Access to the admin requires a password and a second factor (authenticator app).

Company details

  • Uithoorn, Netherlands
  • 085 060 1407
  • info@vieta.work

Vieta Services | NL 24 BUNQ 2144 8802 20 | BTW: NL004617084B50 | KvK: 88511693 | Tel: 085 060 1407 | Info@vieta.work