Legal — updated 1 September 2026 — v1.0

Privacy statement

RABZI, based in the Netherlands and registered with the Dutch Chamber of Commerce under number [KVK-NUMBER], is responsible for the processing of personal data as described in this statement. We process as little data as possible and never sell data to third parties.

This is a courtesy translation. In the event of any discrepancy, the Dutch version prevails.

What data we process

Through the contact form we process your name, email address and optionally company name, phone number, project type, budget indication, timeline and the description you enter yourself. For an engagement we additionally process billing and contact details and the data needed to perform the work. Technically, when you visit the website we process your IP address (truncated), browser type and the pages you visit, in server logs that are deleted after 30 days.

Why we process data

To answer your request and prepare a proposal (pre-contractual phase), to perform an agreement, to comply with legal obligations such as tax retention, and on the basis of our legitimate interest in keeping the website secure and available. We do not use your data for unsolicited marketing unless you explicitly consent.

Cookies and measurement

This website sets no tracking or marketing cookies and uses no cookie banner because none is needed. We use one functional storage item in your browser (rabzi_theme) to remember your light or dark display preference; this falls under the exemption for strictly necessary storage. If we measure visitor statistics, we do so with a privacy-friendly method without cookies and without identifiable personal data. Fonts are preferably served from our own server.

Who we share data with

We only share personal data with parties needed for our services: our hosting provider (servers in the EU), our email provider and our accountant. We sign data processing agreements with processors. We do not transfer data outside the European Economic Area unless necessary and with appropriate safeguards. For projects in which we use AI services, we agree with the client in advance which data may be processed.

How long we keep data

Requests that do not lead to an engagement are kept for a maximum of 12 months. Data belonging to an engagement is kept for the duration of the agreement and 7 years afterwards insofar as tax retention requires. Server logs are kept for 30 days.

Security

We protect data with encrypted connections (TLS), two-factor authentication on all systems, need-based access control, encrypted backups and security updates. In the event of a data breach posing a risk to data subjects, we report it to the Dutch Data Protection Authority within 72 hours and inform those affected.

Your rights

You have the right to access, correct or delete your data, restrict processing, object and receive your data in a portable format. Send a request to the email address at the bottom of this page; we respond within one month. You can also file a complaint with the Dutch Data Protection Authority (Autoriteit Persoonsgegevens).

Changes and contact

We may update this statement; the date at the top indicates the latest change. Privacy questions go to [EMAIL ADDRESS]. RABZI, [ADDRESS], Chamber of Commerce [KVK-NUMBER], VAT ID [VAT-ID].