Privacy Policy
D&V Global B.V.
Last updated: 16 August 2026 | Version 2.1
1. Who We Are
This Privacy Policy describes how D&V Global B.V., registered in the Netherlands (Chamber of Commerce no. 69819718, VAT no. NL858025309B01), with registered office at Microfoonstraat 10, 1322 BN Almere, the Netherlands, also trading as GETSERVERS.NL and SERVERSMART.NL (“D&V Global”, “we”, “us”), processes personal data as a controller in accordance with the General Data Protection Regulation (GDPR).
Privacy contact: office@dv-global.nl | Phone: +31 368 45 16 55
2. Scope: Controller vs. Processor
This Policy covers the personal data we process for our own purposes: data of website visitors, prospects, customers and their contact persons, suppliers, and persons who contact us.
Where we host or otherwise process data on behalf of our customers (content of hosted systems, “Customer Data”), we act as a processor. That processing is governed by our Data Processing Agreement, and the customer concerned — or its own client — is the controller, as applicable. If you have questions about data processed in a system hosted by one of our customers, please contact that customer.
3. What Data We Process, Why, and on What Legal Basis
| Category | Examples | Purpose | Legal basis (Art. 6 GDPR) |
|---|---|---|---|
| Lead and contact data | Name, business email, phone, company, job title, message content from the quote/contact form | Responding to inquiries, preparing proposals | Steps at the data subject’s request prior to entering into a contract (Art. 6(1)(b)); legitimate interest (follow-up on business inquiries) |
| Onboarding and compliance data | Identity and business information, company-register data, beneficial owners where applicable, results of sanctions and creditworthiness checks. Sources: the customer, public registers, and compliance service providers | Onboarding, fraud prevention, sanctions and risk compliance | Legal obligation where applicable; legitimate interests (fraud prevention and compliance risk management) |
| Account and contract data | Name, contact details, company details, KvK/VAT numbers, accepted document versions and timestamps, recorded consents | Concluding and performing the agreement, managing accounts, evidencing acceptance of terms and consumer consents | Contract performance; legal obligation; legitimate interest (record-keeping) |
| Billing and payment data | Invoice details, bank details, payment status, transaction references | Invoicing, payment processing, debt collection | Contract performance; legal obligation (tax law) |
| Technical and security data | IP addresses, access logs, portal login records, network metadata | Service delivery, security monitoring, abuse prevention, incident response | Legitimate interest (network and information security); contract performance |
| Support and abuse communications | Support tickets, emails, abuse reports and related evidence | Providing support, handling abuse and illegal-content notices (including under the Digital Services Act) | Contract performance; legal obligation; legitimate interest (handling reports) |
| Website data | Cookie and analytics data | Website operation and improvement | Consent (non-functional cookies); legitimate interest (functional cookies) — see our Cookie Policy |
| Marketing data | Email address, communication preferences | Sending commercial communications about our services | Consent; legitimate interest (existing-customer communications about similar services, with opt-out) |
We do not use personal data for automated decision-making producing legal or similarly significant effects: material decisions such as suspension or termination of services, refusal on compliance grounds, or fraud blocking beyond temporary containment measures are subject to human review. We do not sell personal data.
4. Recipients
We share personal data only as necessary with: data center and network providers involved in service delivery; payment service providers processing your payments; IT, software, and security vendors supporting our operations; accountants, auditors, and legal advisors; and competent authorities where disclosure is required by law or a binding order. Service providers acting as our processors are bound by data processing agreements.
5. International Transfers
We process controller data primarily within the European Economic Area. Where our vendors or other recipients process controller data outside the EEA, we ensure appropriate safeguards within the meaning of Chapter V GDPR — an adequacy decision of the European Commission or the European Commission’s Standard Contractual Clauses. A copy of the relevant safeguards can be requested via office@dv-global.nl.
6. Retention
We retain personal data no longer than necessary: contract and billing records — 7 years after the end of the financial year concerned (Dutch fiscal retention law); records relating to transactions reported under the Union OSS scheme — 10 years, where applicable; account data and recorded acceptances/consents — for the duration of the agreement plus the applicable limitation period; support tickets — up to 2 years after closure; abuse and illegal-content case files — up to 2 years after closure of the case, or longer where required for legal proceedings; technical and security logs — typically 6 to 12 months; lead data without a subsequent agreement — up to 18 months after last contact; marketing consents — until withdrawn.
7. Security
We protect personal data with technical and organizational measures appropriate to the risk, including access control and least-privilege access, encryption of data in transit for management connections, network security and monitoring, logging of administrative actions, physical security at data center level, staff confidentiality obligations, and secure media sanitization in accordance with our Data Destruction Policy.
8. Your Rights
Under the GDPR you have the right to access, rectification, erasure, restriction of processing, data portability, and to object to processing based on legitimate interests. Where processing is based on consent, you may withdraw consent at any time without affecting the lawfulness of prior processing. You can object to direct marketing at any time, including via the unsubscribe link in each message.
To exercise your rights, contact office@dv-global.nl. We respond within one month (extendable by two months for complex requests, in which case we inform you). We may ask for information to verify your identity.
You also have the right to lodge a complaint with the Dutch supervisory authority: Autoriteit Persoonsgegevens (autoriteitpersoonsgegevens.nl), or with the supervisory authority of your place of residence.
9. Cookies
Our use of cookies and similar technologies is described in our Cookie Policy (EU). You can adjust your preferences at any time via the cookie consent banner.
10. Changes to This Policy
We may update this Policy from time to time. The current version, with its date, is always published on this page. Material changes affecting customers will be announced by email or through the customer portal.
11. Contact
D&V Global B.V.
Microfoonstraat 10, 1322 BN Almere, the Netherlands
KvK: 69819718 | VAT: NL858025309B01
Email: office@dv-global.nl | Phone: +31 368 45 16 55