1. Who is responsible for your data
Waterblom Beheer B.V., trading as Waterbloom, based at Nieuwe Rijn 8A, 2312 JB Leiden, the Netherlands (KVK 28106188, VAT NL814689693B02), is the data controller for the personal data processed via waterbloom.nl, en.waterbloom.nl, the customer portal and the hosted service.
Questions about this statement or about your data can be sent to sales@waterbloom.nl.
2. Who this statement applies to
This statement applies to everyone whose personal data Waterbloom processes: website visitors, customers who purchase a hosting or domain package, users of the customer portal, and people who get in touch through support.
3. What data we collect and why
| Category | What data | What for | Legal basis |
|---|---|---|---|
| Order and customer data (hosting/domain) | Name, email address, phone number, address, (if applicable) company name and VAT number | Processing the order, delivering the service, registering the domain, invoicing | Performance of a contract |
| Payment data | Payment status and reference via Stripe; Waterbloom itself never sees full card or bank details | Processing and handling payment | Performance of a contract |
| Customer portal login | Email address, IP address and timestamp of login attempts (magic link, no passwords) | Secure sign-in to the customer portal, detecting abuse | Legitimate interest (security) |
| Support (tickets) | Name, email address, customer number, messages and any attachments | Handling support and service requests | Performance of a contract |
| Website visits (waterbloom.nl) | IP address, page visited, timestamp, browser/operating system — from server logs, no cookies | Understanding website traffic and recognising automated/bot traffic | Legitimate interest |
| AI processing | Where a request or text contains personal data and is processed via Claude (Anthropic), e.g. for internal automation | Supporting service delivery and internal operations | Legitimate interest / performance of a contract |
4. How we obtain this data
You provide almost all of this data yourself: when ordering a package or domain, when logging in to the customer portal, or when sending a support request. Website visit data arises automatically because every web server logs which pages are requested — this happens without cookies or client-side tracking, purely based on server logs.
5. Who we share data with
We only share data with parties that help us deliver the service, never for those parties' own marketing purposes. These are the parties currently processing data on Waterbloom's behalf:
| Party | Role | For |
|---|---|---|
| Stripe | Processor | Processing payments |
| TransIP | Processor / registrar | Registering and managing domain names |
| Microsoft (Microsoft 365 / Graph) | Processor | Sending email from the customer portal |
| Anthropic (Claude) | Processor | AI-assisted features and internal automation |
| ipinfo.io | Processor | Recognising automated/bot traffic based on IP address |
| OVH | Processor (hosting) | Hosting the website, the customer portal and the service (VPS in the EU) |
Some of these parties may process data outside the EU/EEA. Where that happens, we ensure an appropriate legal safeguard is in place, such as the EU Standard Contractual Clauses.
6. How long we retain data
| Data | Retention period |
|---|---|
| Customer and order data, invoices | For as long as you are a customer, plus 7 years after the end of the financial year (statutory tax record-keeping obligation) |
| Support tickets | 2 years after the ticket is resolved |
| Login attempts / IP-to-customer matching | 90 days, then automatically deleted |
| Website visit logs (server logs) | A few weeks |
| IP origin cache (bot detection) | 30 days |
7. How we secure data
Access to servers and systems is restricted to authorised administration, changes to the website and systems are tested and backed up beforehand, and the customer portal uses login links (magic links) instead of passwords. For the rest, we refer to the security measures of the parties listed in article 5, who are responsible for their own service.
8. Your rights
Under the GDPR you have the following rights regarding your personal data:
- Access — you can request which data we hold about you.
- Rectification — you can have inaccurate data corrected.
- Erasure — you can request that your data be deleted, unless we are legally required to keep it.
- Restriction and objection — you can have processing restricted or object to it.
- Data portability — you can request your data in a portable format.
You can exercise these rights by emailing sales@waterbloom.nl. If you disagree with how we handle your data, you can file a complaint with the Dutch data protection authority, the Autoriteit Persoonsgegevens.
9. Cookies
The website waterbloom.nl does not place cookies and does not use client-side tracking scripts. Website visits are measured exclusively server-side via log files, as described in article 3. The customer portal uses a functional session cookie to keep you signed in after you log in — this is necessary for the service to work and does not require consent.
10. Changes
We may update this privacy statement, for example if we start using a new supplier or if regulations change. The date at the top of this statement shows when it was last updated.