1. Who is responsible for your data
SQLServerSpecialist.nl is a brand of Databaseonline B.V., Kade 28, 4703 GG Roosendaal, the Netherlands, registered with the Chamber of Commerce under number 30171190. Databaseonline B.V. is the controller for the personal data described in this policy, unless section 8 says otherwise. You can reach us at danny.riebeek@databaseonline.nl or through the contact page.
Databaseonline B.V. also operates DatabaseOnline, SQLTreeo, SSMSFolders, SSMS Addon, 24x7DBA and Office365 Mail Solutions. Those websites and products have their own privacy statements. This policy covers www.sqlserverspecialist.nl and the consultancy services delivered under the SQLServerSpecialist.nl name.
2. Which data we collect
When you contact us
If you use the contact form, the time-slot request form or e-mail us, we receive the details you provide: your name, company, work e-mail address, telephone number if you give it, the subject you select, proposed times and the content of your message. Both forms open your own e-mail program; nothing is stored on this website when you send them.
When you book a call
The booking page on this website embeds Microsoft Bookings, part of the Microsoft 365 service we use for e-mail and calendars. When you book, Microsoft collects the details you enter (name, e-mail address, telephone number if you give it, notes) and creates an appointment in our calendar and a confirmation and Teams meeting invitation for you. Microsoft processes this data on our behalf under the Microsoft Products and Services Data Protection Addendum. The booking page sets the cookies Microsoft needs to complete a booking; it is loaded only when you open the booking page.
When you visit the website
Our hosting provider, Microsoft Azure Static Web Apps, records technical data for every request in a server log: the IP address of your device, date and time, the page requested, the referring page, browser type and operating system. We use this data to keep the website available and secure. This website itself sets no cookies and uses no analytics or advertising trackers.
When we work for you
When you become a customer we process the business contact details of the people we work with: names, roles, e-mail addresses, telephone numbers, escalation details and the content of our communication, reports and tickets. For invoicing we process company details, VAT number and payment references.
Data inside your databases
During consultancy work we have access to your database environments and may incidentally see personal data stored in your systems, for example while analysing a query or a restore. In that situation we act as a processor on your behalf; see section 8. We do not copy business data out of your systems unless the engagement explicitly requires it and you have agreed to it in writing.
3. Why we use your data and on which legal basis
| Purpose | Data | Legal basis (GDPR article 6) |
|---|---|---|
| Answering your enquiry, planning a call and preparing a quote | Contact details, proposed times, message | Steps prior to entering into a contract (6.1 b) and our legitimate interest in responding to business enquiries (6.1 f) |
| Holding a booked call | Booking details, calendar entry, Teams meeting | Steps prior to entering into a contract (6.1 b) |
| Delivering consultancy services | Business contact details, communication, reports | Performance of a contract (6.1 b) |
| Invoicing and bookkeeping | Company and payment details | Legal obligation (6.1 c), Dutch tax law |
| Keeping the website and our systems secure | Server logs, access logs | Legitimate interest (6.1 f) |
| Keeping in touch with existing customers about our services | Business e-mail address | Legitimate interest (6.1 f); you can object at any time |
We do not use your data for automated decision-making or profiling, and we do not sell personal data.
4. How long we keep your data
- Enquiries and call bookings that do not lead to an engagement: 12 months after our last contact, then deleted.
- Customer contact details and project communication: for the duration of the engagement and 2 years afterwards, so that we can answer questions about work delivered.
- Contracts, invoices and payment records: 7 years, as required by Dutch tax law.
- Website server logs: 30 days.
5. Who receives your data
We share personal data only with parties that help us run our business, under a contract that obliges them to protect it:
- Microsoft, for hosting this website (Azure Static Web Apps), for e-mail, calendar, Microsoft Bookings, document storage and Microsoft Teams (Microsoft 365), and for Microsoft Azure where a customer environment runs there.
- Our accountant and, where legally required, the tax authorities.
We do not share your data with other parties unless the law requires it or you ask us to, for example when we work together with your other suppliers.
6. Data outside the European Economic Area
We store and process data within the European Economic Area wherever we can. This website is served from Microsoft Azure in Europe, including its typefaces, so loading a page sends no request to Google or any other third party. Microsoft 365 data, including bookings, is stored in EU data centres, and Microsoft applies the European Commission's standard contractual clauses for any support access from outside the EEA.
7. How we protect your data
All connections to this website and to our systems are encrypted with TLS. Access to customer environments uses named accounts, least-privilege rights and multi-factor authentication, and is withdrawn when an engagement ends. We are bound by confidentiality in every engagement.
8. When we process data on your behalf
When we work inside your database environments, you remain the controller of the personal data in those systems and Databaseonline B.V. acts as your processor. We sign a data processing agreement (in Dutch: verwerkersovereenkomst) that sets out the instructions, security measures, sub-processors, breach notification and deletion at the end of the engagement. Ask for our standard agreement or send us yours.
9. Your rights
Under the GDPR you have the right to:
- access the personal data we hold about you and receive a copy;
- have inaccurate data corrected and incomplete data completed;
- have your data erased when we no longer need it or you withdraw consent;
- restrict how we use your data while a question about it is resolved;
- receive the data you gave us in a portable format;
- object to processing based on our legitimate interest, including any marketing contact.
Send your request to danny.riebeek@databaseonline.nl. We answer within one month. We may ask you to confirm your identity before we act on a request. If you are not satisfied with our response, you can lodge a complaint with the Dutch Data Protection Authority, the Autoriteit Persoonsgegevens, at autoriteitpersoonsgegevens.nl.
10. Cookies
This website sets no cookies of its own and uses no analytics or advertising cookies. The booking page embeds Microsoft Bookings, which sets the functional cookies Microsoft needs to show the agenda and complete a booking. They are set only when you open the booking page. You can read about them in Microsoft's privacy statement.
11. Children
This website and our services are aimed at businesses. We do not knowingly collect data from anyone under 16.
12. Changes to this policy
We update this policy when our services or the law change. The version number and effective date at the top tell you which version applies. Substantial changes that affect existing customers are announced by e-mail.
13. Contact
Databaseonline B.V., trading as SQLServerSpecialist.nl
Kade 28
4703 GG Roosendaal
The Netherlands
KvK 30171190 · VAT NL820774704B01
danny.riebeek@databaseonline.nl