Privacy policy
Last updated: 10 October 2026
This policy explains how Goudbound handles personal data: on this website, in our client portal, and when we run cold email campaigns for our clients. We keep it short and in plain language.
What data we process, and why
When you contact us through the website: your name, company, phone number, email address and preferred language. We use this to answer your request and, if you like, to prepare a proposal. Legal basis: taking steps at your request before a possible agreement, and our legitimate interest in responding to enquiries.
When you are a client: the names and email addresses of the people who log in to the client portal, plus the campaign results we show there. We use this to deliver our service. Legal basis: performance of our agreement.
When we email you on behalf of a client: we use business contact details (name, job title, company, business email address and publicly available company information) from public sources and B2B data providers, plus your reply if you send one. We only contact business decision-makers with an offer that is relevant to their role. Legal basis: legitimate interest in business-to-business outreach. You can object at any time, and every email offers a simple way to opt out.
Technical data: our hosting providers briefly log technical data such as IP addresses to keep the services secure and working. Legal basis: legitimate interest in security.
Our role in client campaigns
For campaigns we run for a client, that client decides who is contacted and why; we process the data on their behalf under a data processing agreement. You can ask questions or exercise your rights with us or with that client — we will make sure your request is handled.
How long we keep data
- Website enquiries: up to 12 months if no agreement follows.
- Client and portal data: for the duration of the agreement; financial records for 7 years, as Dutch tax law requires.
- Campaign contacts: for the duration of the campaign and at most 12 months afterwards. If you opt out, we keep only your email address on a do-not-contact list, so we never email you again.
Who we share data with
We never sell personal data. We use these service providers, each bound by a data processing agreement:
| Provider | Purpose | Where |
|---|---|---|
| Supabase | Database and logins for the client portal | EU (Frankfurt) |
| Vercel | Hosting of this website and the portal | EU / US |
| Brevo | Sending account emails (invites, password resets) | EU |
| Web3Forms | Delivering website contact form messages to us | US |
| Reachkit | Sending and tracking campaign emails | Per Reachkit's processing terms |
| Anthropic | Writing the analysis in clients' campaign reports, from aggregated numbers only (no personal data) | US |
Where data is processed outside the EU, it is protected by the EU Standard Contractual Clauses or the EU–US Data Privacy Framework.
Cookies
We only use cookies that are strictly necessary (to keep you logged in to the client portal and to remember your language), plus analytics cookies only if you give permission. Our cookie policy lists every cookie and explains how to change your choice.
Your rights
You can ask us to access, correct or delete your data, to restrict its use, or to receive it in a portable format. You can object to our processing at any time — an objection to direct marketing is always honoured. Email us at info@goudbound.nl and we will respond within one month.
If you are not satisfied with how we handle your data, you can file a complaint with the Dutch Data Protection Authority, the Autoriteit Persoonsgegevens.
Security
All connections are encrypted (HTTPS). Access to the client portal is protected by personal logins, and each client can only see their own data. Credentials for connected tools are stored encrypted. Only people who need access for their work have it.
Changes
We may update this policy when our services or the law change. The date at the top shows the latest version.