Skip to Content
 

Privacy Policy

PDCA4YOU B.V. 

Version: July 15th, 2026 | Effective as of: July 15th, 2026 


PDCA4YOU B.V. (hereinafter: “PDCA4YOU”, “we” or “us”) attaches great importance to the protection of your personal data. This Privacy Policy explains which personal data we collect, why we process it, how long we retain it and what rights you have. 


This Privacy Policy applies to all processing of personal data for which PDCA4YOU acts as controller within the meaning of the General Data Protection Regulation (GDPR) (EU) 2016/679. 


1. Identity and Contact Details of the Controller 

The controller responsible for the processing of your personal data is: 

 

PDCA4YOU B.V. 

Address: Stationsplein 45, 4th floor A4.004, 3013 AK Rotterdam, the Netherlands 

Chamber of Commerce number: 92907504 

Email address: pdca4you@safesecur.nl 

Telephone: +31613813880 

 

For any questions regarding the processing of your personal data, please contact us using the details above. 

 

Data Protection Officer (DPO): PDCA4YOU has not appointed a Data Protection Officer, as we are not required to do so under Article 37 GDPR. We do not carry out large-scale systematic monitoring of individuals, nor do we process special categories of personal data on a large scale. For privacy-related enquiries, please contact us at the email address stated above. 


2. What Personal Data Do We Process? 

We process the following categories of personal data: 

2.1  Account and identification data 
  • First and last name 

  • Email address (business) 

  • Telephone number (business) 

  • Company name and Chamber of Commerce number 

  • Job title 

  • Login credentials (username; passwords are stored in encrypted form and are not readable by us)  

2.2  Billing and payment data 
  • Name and address for invoicing purposes 

  • Bank account number (IBAN) 

  • Invoice history 

2.3  Usage data 
  • IP address and browser type 

  • Log data and session data 

  • Usage patterns and click behaviour within the Software and/or the Academy 

  • Time and duration of use 

2.4  Communication data 
  • Correspondence via email or support channels 

  • Content of support requests 

2.5  Marketing data (with consent only) 
  • Email address for newsletter communications 

  • Communication preferences 

 2.6  Academy and training data 
  • Progress data (completed modules, test results and scores) 

  • Certificate data (date of completion, certificate issued) 

  • Training history (courses followed and completion status) 

These data are generated through the use of the Academy and are used exclusively for the performance of the Agreement and, where applicable, for the issuance of Certificates. 

We do not process special categories of personal data as referred to in Article 9 GDPR (such as health data, national identification numbers, religious beliefs or biometric data). 


3. Purposes and Legal Bases for Processing 

We process personal data solely for the purposes listed below and on the basis of the stated legal ground under Article 6 GDPR. 

3.1  Performance of the agreement 

Legal basis: Performance of a contract (Art. 6(1)(b) GDPR) 

  • Creating and managing user accounts 

  • Granting access to the Software and/or the Academy 

  • Processing payments and issuing invoices 

  • Providing technical support 

  • Sending transactional emails (invoice confirmations, technical notifications, update and bug-fix notifications) 

3.2  Compliance with legal obligations 

Legal basis: Legal obligation (Art. 6(1)(c) GDPR) 

  • Retaining invoices and accounting records (statutory retention obligation: 7 years) 

  • Complying with obligations under applicable legislation 

3.3  Legitimate interests 

Legal basis: Legitimate interests (Art. 6(1)(f) GDPR) 

  • Securing our systems and detecting fraud or misuse 

  • Improving the Software on the basis of anonymised usage statistics 

  • Preparing internal reports and analyses 

  • Displaying the Client's name and logo on our website for reference purposes, where permitted under the applicable annex of our General Terms and Conditions. For individual consumers (Academy Individual), the use of name or logo for marketing purposes requires a separate explicit opt-in. For business clients (SaaS and Academy Education), an opt-out is available at any time by contacting us. 

3.4  Consent 

Legal basis: Consent (Art. 6(1)(a) GDPR) 

  • Sending commercial newsletters and marketing communications 

You may withdraw your consent at any time by unsubscribing via the unsubscribe link in our emails or by contacting us directly. Withdrawal of consent does not affect the lawfulness of processing carried out prior to the withdrawal. 

3.5  Obligation to provide data 

Certain personal data are necessary for the performance of the Agreement or to comply with a legal obligation. The table below indicates, per processing purpose, whether the provision of data is mandatory or voluntary, and what the consequences are if you choose not to provide the data. 

Account and identification data (name, email, company details): Mandatory for the performance of the Agreement. Without these data, we cannot create an account or grant access to the Software and/or the Academy. 

Billing and payment data (name, address, IBAN): Mandatory for the performance of the Agreement and compliance with our statutory accounting obligations. Without these data, we cannot issue invoices or process payments. 

Usage data and communication data: Collected automatically as part of the use of the Software and/or the Academy or generated through support interactions. Provision is inherent in the use of our services. 

Marketing data (email address for newsletter): Voluntary. Providing this data is not a condition for using the Software or the Academy or entering into the Agreement. You may withdraw your consent at any time without consequence for the Agreement. 


4. Recipients of Personal Data 

We share your personal data with third parties only to the extent necessary for the performance of the agreement or where required by law. We enter into data processing agreements with all parties that process personal data on our behalf. 

To provide our service, PDCA4YOU engages the following sub-processors:

  • Microsoft Corporation (Hosting and infrastructure)
  • Bubble Group, Inc. (Application platform)
  • Supabase, Inc. (Database and authentication)
  • Stripe, Inc. (Payment processing)
  • Odoo S.A. (Customer management and invoicing)
  • Make (Celonis, Inc.) (Workflow automation and integration)

This list may be updated from time to time as PDCA4YOU engages new sub-processors or ceases to work with existing ones. We recommend checking this page periodically for the most current overview. If you have questions regarding a specific sub-processor, please contact us at pdca4you@safesecur.nl

We do not share your personal data with other third parties, unless required to do so by law or unless you have given your prior consent. 

Please note that PDCA4YOU acts in two distinct roles depending on the product used. For the SaaS-solution and Academy Education, PDCA4YOU acts as a data processor on behalf of the Client, who is the data controller. In these cases, a separate data processing agreement governs the processing of personal data. This Privacy Policy applies exclusively to the processing of personal data for which PDCA4YOU acts as data controller, primarily in connection with the Academy Individual and general account and billing data. 

 

5. Retention Periods 

We do not retain your personal data for longer than is necessary for the purpose for which it was collected, or for as long as required by law. 

 

6. Security of Personal Data 

We take appropriate technical and organisational measures to protect your personal data against loss, destruction, falsification, unauthorised access or unauthorised disclosure. These measures include, among others: 

  • Encrypted storage and transmission of data (TLS/SSL) 

  • Access controls based on the need-to-know principle 

  • Strong password requirements and, where possible, two-factor authentication 

  • Regular backups 

  • Monitoring of unauthorised access attempts 

In the event of a personal data breach that is likely to result in a high risk to your rights and freedoms, we will notify you without undue delay, in accordance with the requirements of the GDPR. 

 

7. Your Rights as a Data Subject 

Under the GDPR, you have the following rights in relation to your personal data: 

Right of access (Art. 15 GDPR): You have the right to request access to the personal data we process about you. 

Right to rectification (Art. 16 GDPR): You have the right to have inaccurate or incomplete personal data corrected. 

Right to erasure (Art. 17 GDPR): You have the right to request that we delete your personal data, unless we have a legitimate reason to retain it (such as a statutory retention obligation). 

Right to restriction of processing (Art. 18 GDPR): You have the right to request that the processing of your data be restricted in certain circumstances. 

Right to data portability (Art. 20 GDPR): You have the right to receive the personal data you have provided to us in a structured, commonly used and machine-readable format. 

Right to object (Art. 21 GDPR): You have the right to object to the processing of your personal data on the basis of our legitimate interests or for direct marketing purposes. 

Right to withdraw consent: Where processing is based on your consent, you have the right to withdraw that consent at any time. 

You may exercise your rights by submitting a request to pdca4you@safesecur.nl. We will respond to your request within four (4) weeks. We may ask you to verify your identity before processing your request. 

 

8. Right to File a Complaint 

If you believe that we are not processing your personal data in accordance with the GDPR, you have the right to file a complaint with the supervisory authority in your country of residence. In the Netherlands, this is:  

Autoriteit Persoonsgegevens (Dutch Data Protection Authority) 

Website: www.autoriteitpersoonsgegevens.nl 

Telephone: +31 88 180 52 50  

You may also file a complaint with the supervisory authority in the EU member state in which you reside, work or where the alleged infringement took place. 

 

9. Cookies and Similar Technologies 

Our Software, Academy and website use cookies and similar technologies. A cookie is a small text file stored on your device when you first visit our website or use our services.  

We use the following categories of cookies: 

  • Functional cookies: Strictly necessary for the functioning of the Software and the Academy (e.g. session management, login status). No consent is required for these cookies. 

  • Analytics: We use Plausible Analytics to measure website and platform usage. Plausible is a privacy-friendly, cookieless analytics tool, it does not place any cookies on your device and does not collect personal data or track individual users. 

We do not use marketing cookies or advertising cookies. 

You may adjust your cookie preferences at any time through your browser settings 

 

10. Automated Decision-Making and Profiling 

We do not engage in fully automated decision-making that produces legal effects concerning you or similarly significantly affects you, as referred to in Article 22 GDPR. 


11. Changes to This Privacy Policy 

We reserve the right to amend this Privacy Policy. Any changes will be published on our website and, where you are an active user, we will notify you by email of any material changes. The date at the top of this document indicates when the Policy was last updated.  

We recommend that you review this Privacy Policy periodically to stay informed of any changes. 

 

Date: 15th of July 2026