GDPR Policy

This policy incorporates the requirements of the EU General Data Protection Regulation (GDPR), the Dutch GDPR Implementation Act (Uitvoeringswet AVG or UAVG), and the Dutch Telecommunications Act (Telecommunicatiewet) regarding cookies and online tracking.

Privacy Policy — 

Vadavas® Concept Store Utrecht, The Netherlands


Last Updated: July 29, 2026]

At Vadavas® Concept Store(accessible via https://vadavas.nl/ ), protecting the privacy and personal data of our visitors and customers is a core priority. This Privacy Policy explains what personal data we collect, why we collect it, how long we store it, and what rights you have under the General Data Protection Regulation (GDPR / AVG) and relevant Dutch privacy laws.

1. Identity of the Data Controller

For the purposes of applicable data protection laws, the data controller responsible for processing your personal data is:

  • Legal Entity / Company Name: Vadavas® Concept Store Utrecht, The Netherlands
    Trade Name:  Vadavas®

  • Address: Donkere Gaard 1, 3511 KV Utrecht, Netherlands

  • Phone: +31613777639

  • Email: info@vadavas.nl

2. Personal Data We Collect & How We Collect It

We collect and process personal data when you visit our webshop, create an account, place an order, contact our customer service, or subscribe to our newsletter.

A. Data Collected During Order Placement & Execution

  • Full name

  • Billing address and shipping address

  • Email address and phone number

  • Payment details (processed securely via our payment provider; we do not store full credit card details)

  • Order details and purchase history

B. Data Collected During Account Creation

  • Account credentials (email, hashed password)

  • Account preferences and saved shipping addresses

C. Data Collected During Customer Support Interactions

  • Correspondence history (email, live chat logs, contact form submissions)

  • Any additional information provided in support requests

D. Data Collected Automatically (Technical & Device Data)

  • IP address

  • Browser type, device type, and operating system

  • Browsing behavior on our website (pages viewed, referral sources, timestamps)

  • Cookie identifiers (see Section 7)

3. Purposes and Legal Bases for Data Processing

Under the GDPR / AVG, we must have a valid legal basis to process your personal data. We rely on the following legal grounds:

Purpose

Personal Data Used

Legal Basis (GDPR Art. 6)

Order Processing & Delivery

Name, address, email, phone number, payment details

Performance of a Contract (Art. 6(1)(b))

Customer Service & Support

Name, order number, contact logs

Performance of a Contract / Legitimate Interest (Art. 6(1)(b)/(f))

Financial Accounting & Invoicing

Order records, invoices, customer address

Legal Obligation (Art. 6(1)(c) - Dutch Tax Law)

Direct Marketing (Email Newsletters)

Email address, product preferences

Consent (Art. 6(1)(a)) or Legitimate Interest for existing customers (Opt-out)

Fraud Prevention & Website Security

IP address, device details, log data

Legitimate Interest (Art. 6(1)(f))

Analytics & Site Optimization

Anonymized or pseudonymous browsing data

Consent (for tracking cookies) / Legitimate Interest (for privacy-friendly analytics)

4. How Long We Retain Your Data

We store your personal data no longer than necessary for the purposes for which it was collected, or to comply with statutory retention obligations:

  • Order & Transaction Data: Retained for 7 years to comply with the Dutch State Taxes Act (Algemene wet inzake rijksbelastingen).

  • Customer Accounts: Retained until you request account deletion or after 2 years of continuous account inactivity.

  • Customer Service Inquiries: Retained for 2 years following resolution to handle follow-up questions or disputes.

  • Newsletter Subscriptions: Retained until you unsubscribe or withdraw your consent.

  • Cookies: Retention periods vary depending on the specific cookie (ranging from session duration up to 2 years max).

5. Sharing Data with Third Parties (Processors & Sub-Processors)

We share personal data with third-party service providers (processors) only to the extent necessary to deliver our services, run our store, or comply with legal mandates. All processors are bound by Data Processing Agreements (DPAs) in compliance with GDPR Article 28.

Key categories of recipients include:

  • E-commerce Platform Providers: [e.g., Shopify, WooCommerce, Magento]

  • Payment Service Providers (PSPs): [e.g., Mollie, Adyen, Stripe, Klarna] to securely handle payments via iDEAL, credit card, or pay-later methods.

  • Fulfillment & Logistics: [e.g., PostNL, DHL Express, DPD, PostNL Pakketten] to ship and deliver your packages.

  • Marketing & Email Software: [e.g., Klaviyo, Mailchimp] (only if you opted in).

  • Analytics Providers: [e.g., Google Analytics 4 (configured privacy-friendly with IP masking), Matomo].

  • Hosting & IT Infrastructure: Cloud servers located within the European Economic Area (EEA).

We never sell your personal data to third parties.

6. International Data Transfers

Whenever possible, we store and process data within the European Economic Area (EEA). If personal data is transferred to a country outside the EEA (e.g., cloud software hosted in the United States), we ensure appropriate safeguards are implemented in accordance with Chapter V of the GDPR, such as:

  • Standard Contractual Clauses (SCCs) approved by the European Commission.

  • EU-U.S. Data Privacy Framework certification (for US-based providers).

7. Cookies and Tracking Technologies

Our website uses functional, analytical, and marketing cookies in accordance with the Dutch Telecommunications Act (Telecommunicatiewet).

  • Essential / Functional Cookies: Required for the technical operation of our shop (e.g., remembering shopping cart items, session logins). Do not require prior consent.

  • Analytical Cookies: Used to evaluate website usage. If configured with minimal privacy impact (e.g., anonymized IP addresses), consent is not required. Otherwise, we obtain your prior consent.

  • Marketing / Tracking Cookies: Used to track visitors across websites to deliver targeted advertising. Require explicit, active consent via our cookie banner before loading.

You can update or withdraw your cookie preferences at any time by clicking the "Cookie Settings" link in our website footer.

8. Your Privacy Rights Under the GDPR / AVG

As a data subject, you have the following rights under European and Dutch data protection laws:

  1. Right of Access (Art. 15): You can request a copy of the personal data we hold about you.

  2. Right to Rectification (Art. 16): You can ask us to correct inaccurate or incomplete data.

  3. Right to Erasure / "Right to be Forgotten" (Art. 17): You can request the deletion of your data, provided legal retention duties do not apply.

  4. Right to Restriction of Processing (Art. 18): You can request that we pause processing your data under certain conditions.

  5. Right to Data Portability (Art. 20): You can receive your data in a structured, commonly used machine-readable format.

  6. Right to Object (Art. 21): You have the right to object to processing based on legitimate interests or direct marketing at any time.

  7. Right to Withdraw Consent (Art. 7(3)): If processing is based on consent, you may withdraw it at any time without affecting prior processing.

How to Exercise Your Rights

To submit a request, contact us at [privacy@yourdomain.nl]. To protect your privacy, we may ask you to verify your identity before fulfilling your request. We will respond to your request within 30 days.

9. Protection of Minors

Under Article 5 of the Dutch GDPR Implementation Act (UAVG), individuals under 16 years of age must have consent from a parent or legal guardian to share personal data online. Our website does not intentionally target or collect personal data from minors under 16 without parental consent. If you believe a minor has provided us with personal data without consent, please contact us immediately.

10. Data Security

We implement technical and organizational measures to safeguard your personal data against loss, misuse, unauthorized access, disclosure, or alteration. These include:

  • SSL/TLS encryption across the entire webshop (https://)

  • Secure access controls and two-factor authentication (2FA) for admin panels

  • Regular security updates and monitoring

11. Lodging a Complaint with the Supervisory Authority

If you believe we are processing your personal data unlawfully or not handling your requests properly, please contact us first so we can resolve the issue.

You also have the legal right to file a complaint directly with the Dutch Data Protection Authority (Autoriteit Persoonsgegevens):

12. Changes to This Privacy Policy

We reserve the right to update this Privacy Policy to reflect changes in our legal obligations or operational practices. Any updates will be posted on this page with an updated revision date.