GDPR Compliance

Fully
GDPR-compliant

Privacy and data protection are not optional, but a requirement. We ensure that your website and data fully comply with the General Data Protection Regulation.

Privacy by Design

All websites we build are designed from the ground up with privacy in mind. We only collect data that is strictly necessary.

EU Hosting

All our servers are located in Europe (Germany and Finland). Your data never leaves the European Union, guaranteeing full GDPR compliance.

Encryption

All data transfer is secured with SSL/TLS encryption. Data at rest is stored encrypted on our servers.

Transparency

We are fully transparent about what data we collect and why. No hidden tracking or unexpected data collection.

Data Processing Agreement

For all our clients, we draw up a data processing agreement that meets all GDPR requirements.

Data subject rights

We facilitate all data subject rights: access, correction, deletion, objection and data portability.

Quality & trust

Serious about security and compliance

Anyone handing us their platform, customer data and brand wants to know how we keep our own house in order. That's why we're a member of the industry association and why we're working towards recognised standards: instead of leaning on fine-sounding words.

Membership

NLdigital

Industry association for the Dutch digital sector

TovoT is a member of NLdigital, the collective of more than 600 IT organisations in the Netherlands. In practice that means we work with the NLdigital Terms and Conditions and its accompanying data processing agreement: the sector standard for IT engagements, drawn up in consultation with client organisations. No home-made small print, but terms the whole industry knows and recognises.

NLdigital

Certification roadmap

We're structuring our processes around the two standards that carry the most international weight when it comes to information security.

ISO 27001

Information security

In preparation

The international standard for an information security management system: documented policy, structural risk assessment, clear ownership and demonstrable, continuous improvement across everything we build and operate.

SOC 2 Type II

Independent audit

In preparation

An external auditor tests not just whether the controls look right on paper, but whether they actually hold up over an extended period: across security, availability and confidentiality. The standard international clients and partners ask for.

To be transparent: these programmes are in progress: the certificates have not been issued yet. We mention them because we're already working towards them and shaping our processes accordingly, not because we can hand them over today. As soon as an audit is completed, it will be listed here with its date.

What's already in place

Certification formalises what we already do. This is the foundation we're building on.

GDPR by default

Consent Mode v2 and cookie consent are properly configured from the start, data processing agreement included. Privacy is part of the build, not an afterthought.

Hosting inside the EU

Our servers and backups live in European data centres. Customer data doesn't leave the EU without an explicit agreement covering it.

Monitoring & backups

Uptime monitoring, automated backups and a public status page for the environments we manage. We spot outages ourselves: not when the client calls.

Maintenance on a fixed rhythm

Updates, patches and dependencies run on a fixed cycle instead of ad hoc. Deferred maintenance is the most underestimated security hole there is.

What is the GDPR?

The General Data Protection Regulation (GDPR), also known as AVG in Dutch, is the European privacy legislation that has been in effect since May 25, 2018. This law regulates how organizations may collect, process and store personal data. For websites, this includes obligations regarding cookies, contact forms and analytics.

Our approach

For every project we ensure:

  • Cookie consent banner: Cookiebot integration for correct consent collection
  • Privacy-friendly analytics: GA4 with anonymized IP addresses or alternatives like Plausible
  • Secured forms: Contact forms with minimal data collection and encryption
  • SSL certificates: HTTPS on all pages for secure data transfer
  • Privacy statement: Custom privacy policy for your website

Server-side tracking

As a partner of Taggrs, we offer server-side tracking solutions. This means tracking data runs through your own server instead of directly to Google or Meta. This provides better data quality, works without third-party cookies, and is more privacy-friendly because you have full control over what data is shared.

Data Processing Agreement

When we act as a processor for your personal data (for example with hosting or maintenance), we draw up a data processing agreement. This document regulates the responsibilities, security measures and rights in accordance with the GDPR. Feel free to ask us for an example.

Questions?

Do you have questions about GDPR compliance or want to know how we can make your website compliant? Contact us via . [email protected]