Privacy Policy

Nalta, located at Jool-hulstraat 4 in Almere, is responsible for the processing of personal data as set out in this privacy statement.
What is personal data?

Personal data is information that tells us something about you or that we can link to you.

You share personal data with us when you are a customer or when you are in contact with us. This includes your name, phone number, or email address, but also your computer's IP address or an invoice. It concerns all data that we can associate with you. A standalone customer number is not personal data, but it becomes so as soon as you know who that customer number belongs to.

If you are a freelancer or have a sole proprietorship, general partnership (vof), or professional partnership (maatschap), you are considered an individual, and the data also includes information that directly or indirectly tells us something about you.

What do we use personal data for?

Providing IT products and services is only possible and permitted if we know you well. That is why we ask for and process your personal data. With your personal data, we can:

Executing our agreements with you as a customer
  • Getting in touch with you.
  • Determining whether you are eligible to become a customer.
  • Assessing whether we can provide you with suitable products and services.
  • Processing your requests for, or changes to, a quote, order, or invoice.
  • Handling our financial administration and invoicing.
  • Accurately recording your data in our systems and updating it whenever there are changes.
  • Managing your products and services with us.
Mitigating risks

We are jointly responsible for your data, our data, and the data of all our customers. That is why we also use your personal data to mitigate risks.

You will notice this, for example, when:

  • Ensuring robust information security. This includes usernames, passwords, tokens, and security questions.
Complying with the law
  • We provide your personal data to organizations that are legally entitled to request certain information from us. This includes judicial authorities, intelligence services, and regulatory bodies.
Carrying out marketing activities

We like to keep you informed. For example, through emails, newsletters, campaigns on our website, or apps tailored specifically to you. Or through personalized advertisements on third-party apps and sites and on social media. These activities often require the use of personal data.

We can do this:

  • We look at which products you are already using and which ones you are not.
  • We collect and analyze your preferences and search queries when you visit our web pages or apps and open emails, such as the Nalta newsletter. For example, if you visit a page about Dell Boomi, you might be interested in application integration.
  • We may use your pseudonymized personal data to show you interesting and relevant information on social media.
  • Would you prefer not to receive personalized offers or newsletters? No problem; you can unsubscribe from any of the channels we use to communicate with you via the nalta.com website.
Improve and innovate

We also use personal data to make doing business with Nalta more personal. We do this by combining and analyzing the data. These analyses lead to new ideas and better solutions—areas where we strive to be leaders, because that is how we help you move forward. This allows us to:

  • Resolving the root causes of complaints, improving pages and forms on nalta.com, and accelerating ordering and delivery processes.
  • Further improving security.
  • Measuring how customers use our services and the results of our campaigns. And, if necessary, making improvements.
  • Developing new services.
  • When analyzing data, we remove any personal information we do not need. We may also aggregate data at a certain level of abstraction, pseudonymize it, or anonymize it.
  • We also categorize customers with similar characteristics or behaviors into groups (profiles) so we can better address their needs.
  • We determine which service best suits a specific group of customers. Small businesses have different needs than large, international companies, and we tailor our offerings accordingly.
‍
What we mean by processing

Processing is a legal term (GDPR). It is a very broad concept that covers everything you can do with personal data, from collection to destruction. The GDPR defines processing as: 'the collection, recording, organization, structuring, storage, adaptation or alteration, retrieval, consultation, use, disclosure by transmission, dissemination or otherwise making available, alignment or combination, restriction, erasure or destruction of data.'

Whose personal data do we hold?

We can be quite brief about that: from everyone who has had, or currently has, direct or indirect contact with us.

What personal data do we collect?

Below you can see which personal data we collect and therefore may also use.

  • Information about who you are
  • Your transactions and payments
  • Your contact history
  • Data required for information security, such as usernames, IP addresses, and passwords
  • Your use of our websites and apps
  • Your reactions to and about nalta.com on social media

We keep this data for as long as necessary for the purpose for which we use your data, and for as long as the law requires us to keep it. The exact duration varies, ranging from a few months to many years. We delete rejected job applications after 3 months, and we delete your payment details 7 years after an invoice has been paid.

How long do we keep personal data?

Nalta does not store your personal data longer than is strictly necessary to achieve the purposes for which your data is collected. We apply the following retention periods for the following (categories of) personal data:

1. For business contact details for the use of our services

We retain the data as long as the service agreement for the delivery of services to your employer continues or as long as you are employed by us. Your data will be erased no later than three months after either of these periods ends.

However, if you are the authorized signatory for the delivery of services on behalf of your employer, we are legally required to retain your business contact details for 7 years after the contract ends. After that, the data will be erased.

Data on our websites, such as IP addresses, cookies, reports of browsing activity on our website, and information about your web browser and computer, are always deleted no later than three months after your last visit to our website.

2. Personal data we process on behalf of clients

Nalta receives instructions from our clients regarding the retention period for the data we process on their behalf. Sometimes this involves data covered by the Medical Treatment Contracts Act (WGBO), for which a retention period of 15 years may apply.

Who do we share personal data with?

Nalta does not sell your data to third parties and, as a rule, does not share it with others. We only do so if there is a legal obligation. The police, judicial authorities, regulators, and the Tax and Customs Administration may request data from us by law. Furthermore, a court may compel us to provide data.

Sometimes we are required to share your data with another party or organization based on an agreement or regulation. There are strict rules for sharing personal data, which we naturally adhere to. We enter into data processing agreements with companies that process your data on our behalf to ensure the same level of security and confidentiality for your information. Below, you can see who we may share personal data with:

Service providers working for nalta.com
  • We are assisted in our work by other business service providers. In such cases, we only share the personal data necessary for a specific assignment.
  • We make clear agreements with these service providers regarding what they are permitted to do with your personal data. We record these agreements in contracts (data processing agreements).

The companies and individuals who assist us do this, for example:

  • They design, maintain, and improve some of our IT systems, internet tools, and applications;
  • They organize events, send emails and mail, and create videos and brochures;
  • They help us place advertisements on apps, websites, and social media outside of nalta.com.
Cookies, or similar technologies, that we use

Nalta uses only technical and functional cookies that do not infringe on your privacy. A cookie is a small text file that is stored on your computer, tablet, or smartphone when you first visit this website. The cookies we use are necessary for the technical operation of the website and your ease of use. They ensure that the website works properly and remember, for example, your preferences. They also allow us to optimize our website. You can opt out of cookies by setting your internet browser so that it no longer stores cookies. In addition, you can also delete all information previously stored via your browser settings.

Accessing, correcting, or deleting data

You have the legal right to access, correct, or delete your personal data. Additionally, you have the right to withdraw your consent for data processing or object to the processing of your personal data by Nalta. Finally, you have the right to data portability. This means that you can submit a request to us to send the personal data we hold about you in a computer file to you or another organization mentioned by you.

You can send a request for access, correction, deletion, or data portability of your personal data, or a request to withdraw your consent or object to the processing of your personal data, to privacy@nalta.com.

To ensure that the request for access has been made by you, we ask that you include a copy of your ID with your request. In this copy, please black out your passport photo, the MRZ (machine-readable zone, the strip of numbers at the bottom of the passport), the passport number, and the Citizen Service Number (BSN). This is to protect your privacy. We will respond to your request as soon as possible, but no later than within four weeks.

For requests regarding access, correction, deletion, or data portability of personal data that we process on behalf of our clients, you must direct your request to one of these clients.

Nalta would also like to point out that you have the option to file a complaint with the national supervisory authority, the Dutch Data Protection Authority (Autoriteit Persoonsgegevens). You can do so via the following link: https://autoriteitpersgegevens.nl/nl/contact-met-de-autoriteit-persoonsgegevens/tip-ons

How we handle your personal data

Nalta takes the protection of your data seriously and takes appropriate measures to prevent misuse, loss, unauthorized access, unwanted disclosure, and unauthorized modification. If you believe that your data is not properly secured or there are indications of misuse, please contact our helpdesk or email us at privacy@nalta.com.

Nalta has implemented the following measures to secure your personal data:

  • Security software, such as a firewall;
  • Software to detect intrusion attempts;
  • Anti-malware protection;
  • Digital Certificates (compliant with X.509) for the identification of users and systems;
  • TLS (formerly SSL) for secure data transport over an internet connection. You can recognize this by the 'https' in the address bar and the padlock icon;
  • DKIM, SPF, and DMARC are three internet standards we use to prevent you from receiving emails in our name that contain viruses, are spam, or are intended to obtain personal (login) credentials;
  • Encryption of data that we store in our marketing, CRM, and helpdesk systems.

‍

Questions about privacy?

For questions, comments, or complaints regarding privacy and data protection, please contact us at privacy@nalta.com or by calling +31 88 88 22 201.

Contact details:

www.nalta.com
Jool-hulstraat 4
1327 HA Almere
+31 88 88 22 201