Legal

Privacy Policy

Find out which personal data suXus B.V. processes, for what purposes, how long we retain it and how you can exercise your privacy rights.

suXus B.V. processes personal data to respond to business enquiries, provide services and secure the website and our services. Below, we explain which data we use, why we use it, how long we retain it and how you can exercise your rights.

1 Who is responsible

suXus B.V. is the controller for the processing described in this policy, such as website visits, business enquiries and our own customer administration.

Address: Plein 13 B1, 2291 CA Wateringen, the Netherlands.

Dutch Chamber of Commerce number: 51005824. VAT number: NL823047052B01.

Email: [email protected]. Telephone: +31 70 750 6086.

Where we process personal data solely on behalf of a business customer, for example when managing or hosting its environment, that customer is generally the controller and we act as processor. The provisions of the data processing agreement apply. We coordinate requests concerning data in such a customer environment with that customer.

2 Which data we receive

Depending on your contact with suXus, we process your name, organisation, role, business contact details, correspondence, enquiry, customer or account details and information needed for quotations, performance of services, invoicing and payment.

Support may require technical data, usernames, system information, log files and information you share with us. During remote support, an authorised member of staff may see information on your screen or in your environment to the extent necessary for the agreed work.

Website visits and security checks involve the processing of technical data, such as IP address, time, requested page, browser and device information, connection characteristics, and error or security messages.

We receive this data from you, your organisation or an authorised contact, or through your use of our website and services. For a specific business enquiry, we may check additional business details in public business sources, such as the Dutch Business Register, to the extent necessary for that purpose.

Do not send passwords, recovery codes, identity documents or other confidential information or special categories of personal data through the general contact form. If sensitive information is necessary, first agree an appropriate secure channel with us.

We respond to enquiries and prepare quotations. If you are personally a party to the contract, for example as a sole trader, this processing may be necessary to take steps at your request before entering into a contract or to perform a contract. If you contact us on behalf of an organisation, we use your business contact details on the basis of our legitimate interest in communicating with that organisation and handling enquiries carefully.

For service delivery, account management and support, we use data to perform a contract with you, or on the basis of our legitimate interest in performing the contract with your organisation. We limit processing to what is necessary for that work.

For invoicing and financial administration, we process data to fulfil agreements and comply with statutory record-keeping and retention obligations. For contacts at organisations, we also process the necessary contact details on the basis of our legitimate interest in maintaining accurate business records.

For security, abuse prevention, troubleshooting and protection of our rights, we rely on legitimate interests. We weigh the necessity of the processing and its impact on your privacy and use no more data than is necessary for those purposes.

Where consent is required, we request it in advance. You may withdraw consent without affecting the lawfulness of processing carried out before its withdrawal. Consent to non-essential analytics or advertising is not a condition for using the contact form.

Providing data for an enquiry is not a statutory requirement. Without the necessary contact and enquiry details, we may be unable to handle your request. An order may require additional data that is necessary under the contract or by law. A telephone number is required when using the contact form.

4 Contact form

Through the contact form, we process your name, organisation, email address, telephone number, selected subject and message. We use this data to assess your enquiry and follow it up for business purposes.

Accepted enquiries are recorded in a lead register in Cloudflare D1. The content of the enquiry is encrypted at application level before storage. The lead register retains accepted enquiries for a maximum of 180 days. The system also processes the necessary technical characteristics to recognise duplicate submissions and manage processing.

For internal follow-up, suXus sends a notification in Microsoft 365 through Microsoft Graph. This contains the contact details and the content of the enquiry. The sender is [email protected]. The notification is sent to [email protected], an alias that delivers to the primary mailbox [email protected]. The email address you provide is used as the reply-to address.

There is no separate automatic deletion after thirty days for this notification email. Deletion from the lead register does not automatically delete the email. Emails are subject to the retention criteria for correspondence described below. Information necessary for an actual order, administration or a dispute may be retained for that separate purpose.

Cloudflare provides the secure form API, Turnstile spam protection and D1 storage. The D1 database is bound to EU jurisdiction. This does not mean that all HTTPS, network and Worker processing takes place exclusively within the European Union.

5 Website security, cookies and measurement

Our website uses Cloudflare to deliver and secure website traffic. Turnstile is loaded on the contact page to prevent automated abuse. Cloudflare processes information including IP addresses, browser and connection characteristics, and technical signals to distinguish human use from bots. Security controls may automatically block a submission. You can also contact us directly by email or telephone.

Cloudflare acts as processor when providing Turnstile. According to its privacy information, Cloudflare also acts as an independent controller for certain processing to improve its own bot detection. Further information is available in Cloudflare’s Turnstile Privacy Addendum.

The current website does not use Google Analytics, Google Ads remarketing or Microsoft Advertising tracking tags. We do not use advertising cookies to track you on other websites through this website.

Necessary cookies and browser storage are used for website operation, security and functional preferences, including your language and cookie choices. Your cookie choice is stored for up to six months. A visit or form submission does not constitute consent.

suXus uses Microsoft Clarity to analyse use of and interaction with the website. Microsoft is involved as an external service provider. This analytics processing takes place only after you have given consent. Clarity can record interactions with pages and present them in usage overviews. The implementation marks the entire contact form section and its input fields for masking, including names, organisations, email addresses, telephone numbers and messages. Campaign attribution is also processed only with analytics consent. Without this consent, Clarity is not loaded and its analytics cookies and browser storage are not actively used. Advertising tracking remains disabled.

You can refuse analytics without affecting the contact form. You can change or withdraw your consent at any time through Cookie preferences in the website footer. When consent is withdrawn, the website communicates the updated choice, stops Clarity through the available interface and removes the analytics Clarity cookies managed by the implementation for the website domain.

6 Who we share data with

We share data only where necessary for the purposes described, a legal obligation or the protection of legitimate interests. We use Cloudflare and Microsoft for the website form as described above.

The hosting, cloud, software and support suppliers involved in your order may also process data to perform that order. The parties involved depend on the service you purchase; not every supplier receives data from every website visitor. For administration or a dispute, necessary data may be shared with our administrative service providers, accountant, legal adviser, debt collection provider or a competent authority, to the extent that they are involved in the matter concerned.

We make agreements with parties that process personal data on our behalf on matters including purpose limitation, confidentiality, security and deletion. Some recipients, such as competent authorities and certain professional advisers, determine their own statutory processing purposes. We do not sell your personal data.

A link to the client portal, webmail or a download does not automatically disclose the content of your enquiry to that destination. Additional processing and privacy arrangements may apply when you visit or use another service.

7 Processing outside the EEA

Our suppliers may process data outside the European Economic Area or allow access from outside it, for example from the United States. An EU storage location alone does not rule out such access or processing.

Transfers outside the EEA must be covered by a valid protection mechanism. This may be an applicable adequacy decision or the European Commission’s standard contractual clauses, supplemented by additional measures where necessary. Cloudflare’s and Microsoft’s contractual arrangements contain provisions on international transfers. The precise arrangement depends on the processing and recipient concerned.

You may contact [email protected] to request information about the safeguards applicable to your data and how to obtain a copy. Confidential information and other individuals’ personal data may be redacted.

8 How long we retain data

We retain personal data for the purpose for which it is needed and delete or anonymise it once that purpose and any lawful need for retention no longer apply. The following periods or criteria apply to each category.

Accepted enquiries in the production lead register: a maximum of 180 days from receipt. A separate customer file or necessary correspondence is subject to the criteria below and is not automatically covered by the same deletion process.

Notification emails and other enquiry correspondence: for as long as the enquiry is being handled and the correspondence remains necessary afterwards for specific business follow-up, recording agreements made or handling a dispute. Once that need ceases, the data is deleted. The mere possibility of future contact does not justify indefinite retention. There is no separate automatic thirty-day retention period for form notifications.

Customer, contract and support data: for the duration of the relevant customer relationship and afterwards to the extent necessary to deal with outstanding work, obligations, complaints or claims. The type of agreement, the need for evidence and the applicable statutory periods are decisive. This does not mean that the entire support file must be retained for as long as the financial records.

Basic tax records: generally seven years under the statutory record-keeping obligation. Where a longer statutory period applies to particular data, we follow that period. The statutory period starts when the data is no longer current for administrative purposes.

Technical and security logs: for the period necessary for troubleshooting, security, and identifying or handling incidents. The duration depends on the type of log, the incident lifecycle and the settings of the service concerned. Relevant incident data may be retained separately for longer where a specific investigation, recovery activity or legal claim makes this necessary. Form application logs do not contain complete form messages or unnecessary contact details.

Technical recovery copies: data may remain in restricted-access copies until the applicable, limited recovery cycle expires. These copies are not used as an active contact database. Where data is restored, applicable deletions must be reapplied. A recovery copy is not a basis for indefinite retention.

9 Security

We take technical and organisational measures appropriate to the nature of the data and the risks, such as secure connections, restricted access, careful account management and measures to prevent abuse. Enquiry content in the lead register is additionally encrypted at application level.

Security does not provide an absolute guarantee against every incident. If you suspect abuse or a vulnerability, contact us and share only the information needed to investigate the issue safely.

10 Your privacy rights

You may ask which personal data we process about you, obtain access to or a copy of it, and have inaccurate data corrected. Subject to the statutory conditions, you may have data erased, restrict processing, or receive data in a commonly used electronic format and have it transferred.

You may object to processing based on a legitimate interest on grounds relating to your particular situation. You may always object to direct marketing. Where processing is based on consent, you may withdraw that consent through [email protected] and, where applicable, through the consent settings provided.

Send your request to [email protected] or contact us by telephone. We generally respond within one month. For a complex request or multiple requests, the GDPR allows the period to be extended by up to two months; we will inform you within the first month and explain the reason.

We may request additional information where necessary to verify your identity. Do not send a complete copy of your identity document unless asked. Requests are generally handled free of charge. A right may be restricted, for example by a statutory retention obligation or the rights of others; we will explain any restriction.

When handling business enquiries, we do not make decisions based solely on automated processing that have legal effects or similarly significant effects on you. The form’s automated security check is intended to prevent abuse.

11 Complaints and changes

If you have questions or disagree with our processing, you can contact us at [email protected]. You also have the right to lodge a complaint with the Dutch Data Protection Authority (Autoriteit Persoonsgegevens). You do not have to complete our complaints procedure first.

We update this policy when changes to our processing or the applicable rules make this necessary. The current English version is available at https://www.suxus.com/en/privacy-policy/. Where necessary, we will provide additional information to those affected by a material change. New wording does not constitute consent to a new purpose for which your consent is required.

Version 2026.01

1 October 2026