Privacy Policy

Privacy Policy

Envision Connect BV
Campus Seven Cities, Lange Kleiweg 62 B, Rijswijk, The Netherlands
KvK: 42063966 · VAT: NL869541894B01
Website: envision-connect.com

Last updated: 22 June 2026


1. Who We Are (Data Controller)

Envision Connect BV is the data controller responsible for processing your personal data through our website and B2B e-commerce operations.

  • Controller: Envision Connect BV
  • Address: Campus Seven Cities, Lange Kleiweg 62 B, Rijswijk, The Netherlands
  • Privacy contact: sales@envision-connect.com
  • Phone: +3197006548145

We have appointed a Data Protection Officer (DPO), K. Raja. DPO contact: sales@envision-connect.com.

2. Scope

This Privacy Policy explains how we collect, use, and protect personal data in accordance with the EU General Data Protection Regulation (GDPR / Regulation (EU) 2016/679) and the Dutch GDPR Implementation Act (UAVG). As a B2B business, most data we process relates to representatives, contacts, and employees of our business customers and suppliers.

3. Personal Data We Collect

Category Examples
Identity & contact data Name, job title, company name, business email, business phone
Account data Username, password (hashed), order history, preferences
Order & transaction data Billing/shipping addresses, products ordered, VAT identification number, invoices, payment status
Financial data Bank/IBAN details for transfers, credit-assessment data (for net-terms accounts)
Technical data IP address, device/browser type, log data, cookie identifiers
Usage data Pages viewed, interactions, referral source
Communications Emails, support tickets, quote requests, RMA correspondence

We do not intentionally collect special categories of personal data.

4. Lawful Bases for Processing

Purpose Lawful basis (Art. 6 GDPR)
Processing and fulfilling orders, RMA, and quotes Performance of a contract (Art. 6(1)(b))
Invoicing, tax, accounting, VAT/VIES validation Legal obligation (Art. 6(1)(c))
Account management and customer support Contract / legitimate interests (Art. 6(1)(b)/(f))
Fraud prevention, credit assessment, network security Legitimate interests (Art. 6(1)(f))
Direct marketing to business contacts Legitimate interests or consent (Art. 6(1)(f)/(a))
Analytics and marketing cookies Consent (Art. 6(1)(a))

Where we rely on legitimate interests, we balance those interests against your rights and freedoms.

5. How We Use Your Data

We use personal data to: create and manage accounts; process quotes, orders, payments, deliveries, and returns; validate VAT identification numbers via VIES; meet tax, accounting, and other legal obligations; provide support; prevent fraud and secure our systems; send service communications; and, where permitted, send relevant B2B marketing.

6. Cookies and Tracking

We use cookies and similar technologies as described in our Cookie Policy. Non-essential cookies (analytics, marketing) are set only with your consent (default-decline).

7. Recipients and Processors

We share personal data with third parties only as necessary. Categories include:

  • Hosting / website infrastructure: GoDaddy
  • Payment service providers / banks: PayPal, Stripe, and ING Bank
  • Tax authorities, auditors, and advisers where legally required.

We conclude data-processing agreements (DPAs) with processors as required by Article 28 GDPR.

8. International Transfers

Where data is transferred outside the European Economic Area (EEA), we rely on appropriate safeguards such as European Commission adequacy decisions or Standard Contractual Clauses (SCCs). We do not transfer your personal data outside the European Economic Area (EEA).

9. Retention

We retain personal data only as long as necessary for the purposes described or as required by law:

  • Invoicing, tax, and accounting records: 7 years (Dutch fiscal retention obligation, Art. 52 AWR).
  • Order and RMA records: the duration of the business relationship plus the statutory limitation period of 7 years.
  • Account data: for the life of the account plus 2 years of inactivity.
  • Marketing data: until consent is withdrawn or the contact objects.
  • Server/technical logs: 12 months.

10. Your Rights

Subject to conditions in the GDPR, you have the right to:
Access your personal data;
Rectify inaccurate data;
Erasure (“right to be forgotten”);
Restrict processing;
Data portability;
Object to processing based on legitimate interests, including direct marketing;
Withdraw consent at any time (without affecting prior lawful processing).

To exercise your rights, contact sales@envision-connect.com. We respond within one month. We may verify your identity first.

11. Complaints

If you have concerns, please contact us first. You also have the right to lodge a complaint with the Dutch Data Protection Authority:

Autoriteit Persoonsgegevens (AP) — Postbus 93374, 2509 AJ Den Haag — autoriteitpersoonsgegevens.nl

12. Security

We implement appropriate technical and organisational measures to protect personal data, including encryption in transit (TLS), access controls, and regular review. No system is fully secure; we cannot guarantee absolute security.

13. Changes

We may update this Privacy Policy. The current version is always available on envision-connect.com with the “last updated” date.


Envision Connect BV · KvK 42063966 · VAT NL869541894B01

Envision Connect — Light Theme Footer