Privacy policy – Nexpace Netherlands B.V.

This privacy policy (“Privacy policy”) applies to the processing of personal data by Nexpace Netherlands B.V., with its registered office at Beeachavenue 98, 1119 PT Schiphol Rijk, registered with the Chamber of Commerce under number 97148237 (“Nexpace”, “we”, “us”). Nexpace provides flexible office and workplace solutions that are offered via its website www.nexpace.nl (“Website”), and in doing so processes personal data of visitors, (potential) customers and other parties involved in accordance with the applicable privacy and data protection legislation, including the General Data Protection Regulation (GDPR).

 

1. Data controller

The data controller within the meaning of the GDPR is:

Nexpace Netherlands B.V.

Beeeachavenue 98, 1119 PT Schiphol Rijk

E-mail: success@nexpace.nl

Tel.: +31 85 238 28 00
If applicable, a Data Protection Officer may be appointed; their contact details are available on request via the above email address.

 

2. Purposes and legal bases for data processing

We process personal data for the following purposes:

  • Offering, managing and carrying out services and products via our Website and on-site.
  • Maintaining (customer) relationships and correspondence.
  • Handling (quotation) requests, reservations and payments.
  • Complying with legal obligations.
  • Security and fraud prevention.
  • Analysis and improvement of our Website and services.

The processing of personal data takes place on the basis of one or more legal bases under the GDPR, including:

  • Necessity for the performance of an agreement between the data subject and Nexpace.
  • Consent of the data subject, insofar as required by law.
  • Compliance with a legal obligation.
  • Legitimate interests of Nexpace, unless the interests or fundamental rights and freedoms of the data subject override.

 

3. Categories of personal data

We may process the following categories of personal data:

  • Identification and contact details (such as name, address, email address and telephone number)
  • Account details (such as username, password, preferences)
  • Transaction and payment details
  • Usage and interaction data (such as IP address, browser and website data
  • Communication and correspondence details.

 

4. Recipients and transfers to third parties

Personal data may be shared with:

  • Service providers and processors that perform services on our behalf (such as IT providers, payment processors)
  • Government bodies or law enforcement authorities when this is legally required or necessary to protect our rights.

If personal data is transferred to countries outside the European Economic Area (EEA), we ensure appropriate safeguards as required by the GDPR.

 

5. Retention periods

Personal data will not be kept for longer than is necessary for the purposes for which it was collected or as required by law. Criteria for determining retention periods include, among other things, the nature of the data, the purposes of the processing and legal obligations.

 

6. Rights of data subjects

Under the GDPR, data subjects have the following rights, insofar as applicable:

  • Right of access to the personal data we process;
  • Right to rectification of incorrect or incomplete data;
  • Right to restriction of processing;
  • Right to erasure (“right to be forgotten”) under certain conditions;
  • Right to object to processing;
  • Right to data portability;
  • Right to withdraw consent, insofar as it has been given.

Requests relating to the exercise of these rights may be submitted in writing or by email to success@nexpace.nl.

 

7. Cookies and similar technologies

On our Website, cookies and similar technologies are used to ensure functionality, remember preferences and carry out statistical analyses. On the first visit, a cookie notice is displayed allowing the data subject to give consent for the placement of non-essential cookies. Refusing cookies may affect the functionality of the Website.

 

8. Security measures

We take appropriate technical and organisational measures to protect personal data against loss, unauthorised access or other unlawful processing, in accordance with the requirements of Article 32 of the GDPR.

 

9. Complaint to a supervisory authority

If a data subject believes that the processing of personal data is contrary to the GDPR, they may lodge a complaint with the national supervisory authority, the Dutch Data Protection Authority (Autoriteit Persoonsgegevens) in the Netherlands.

 

10. Changes to this policy

We reserve the right to modify this Privacy policy. Changes will be published on the Website with the date of entry into force.