/Privacy
Privacy
Last Updated: April 30, 2026
This Privacy Policy describes how Made Relevant B.V., a private limited company incorporated under Dutch law (KvK: 96097132), with its registered office at Gijsbrecht van Amstelstraat 213, 1214 BA Hilversum, the Netherlands (“Made Relevant,” “we,” “us”) processes personal data in connection with our website and AI services.
We act as a data controller for personal data we process in managing our own business (website visitors, prospective and current clients, suppliers). We act as a data processor when processing personal data on behalf of clients as part of a project engagement - in that context, the client’s own privacy policy and our Data Processing Agreement (DPA) govern that processing.
1. Information We Collect
Information you provide directly Name, email address, job title, company name, phone number, billing and payment details, and any information shared in the course of an engagement - including project briefs, datasets, credentials for system access, or other materials submitted for AI or automation development.
Website usage data Pages visited, actions taken, IP address, device and browser information, session duration, and referring URLs. This data is collected via cookies and analytics tools (see Section 8).
Communications Emails, meeting notes, and records of correspondence with prospective and current clients, partners, and suppliers.
Client-provided data As part of a project engagement, clients may share personal data (such as employee records, customer data, or operational datasets) for the purpose of building, testing, or operating AI or automation systems. This data is processed solely within the agreed scope and governed by a DPA.
2. How We Use Personal Data
We process personal data for the following purposes:
| Purpose | Legal basis |
|---|---|
| Delivering agreed services and project engagements | Contract necessity (Art. 6(1)(b) GDPR) |
| Managing client relationships and communications | Legitimate interests (Art. 6(1)(f) GDPR) |
| Invoicing and financial administration | Legal obligation (Art. 6(1)(c) GDPR) |
| Improving our website and service quality | Legitimate interests (Art. 6(1)(f) GDPR) |
| Security monitoring and fraud prevention | Legitimate interests (Art. 6(1)(f) GDPR) |
| Compliance with legal and regulatory obligations | Legal obligation (Art. 6(1)(c) GDPR) |
| Marketing communications (newsletter, updates) | Consent (Art. 6(1)(a) GDPR) - opt-in only |
We do not sell personal data. We do not use client project data to train general-purpose models or share it with other clients.
3. AI and Automation Processing
Where we build or operate AI systems or RPA workflows on behalf of clients, the following applies:
- Personal data processed through these systems is used exclusively within the agreed project scope
- We do not use client data to improve our own models or systems without explicit written consent
- Where AI systems involve automated decision-making with significant effects on individuals, we document this and support clients in meeting their obligations under Articles 13–15 and 22 of the GDPR and, where applicable, the EU AI Act
- Processing is governed by a signed DPA prior to any personal data being shared with us Clients requiring a DPA, sub-processor list, or technical and organizational measures (TOM) documentation should contact hello@maderelevant.com.
4. Sharing Personal Data
We share personal data only where necessary and with appropriate safeguards:
Service providers and sub-processors - We use third-party providers for hosting, cloud infrastructure, project management, communication, payments, and analytics. All sub-processors are bound by data processing agreements and may not process data for their own purposes.
Professional advisors - Legal, financial, and compliance advisors, under confidentiality obligations.
Clients - In the context of project deliverables, where relevant to scope.
Legal requirements - Where required to comply with a court order, legal obligation, or to protect our rights. We will notify you in advance where permitted by law.
We do not sell, rent, or trade personal data to third parties.
5. International Transfers
Made Relevant B.V. is based in the Netherlands. Some of our sub-processors operate infrastructure outside the EEA. Where personal data is transferred outside the EEA, we rely on:
- Standard Contractual Clauses (SCCs) approved by the European Commission
- Adequacy decisions where applicable A list of sub-processors and applicable transfer mechanisms is available upon request.
6. Data Retention
We retain personal data for as long as necessary for the purposes described in this policy:
| Category | Retention period |
|---|---|
| Client and project records | 7 years from project completion (tax and legal obligations) |
| Financial and billing records | 7 years (Dutch fiscal retention requirement) |
| Website analytics data | 13 months (rolling) |
| Marketing consent records | Until consent is withdrawn, plus 1 year |
| Client project data (as processor) | As specified in the DPA; typically deleted or returned within 30 days of project completion |
We delete or anonymize data when the applicable retention period expires, unless a longer period is required by law or active legal proceedings.
7. Security
We apply technical and organizational measures proportionate to the risk, including:
- Access controls and role-based permissions
- Encrypted data transmission (TLS/HTTPS)
- Secure development practices
- Incident response procedures
- Confidentiality obligations for all personnel with access to personal data We operate security controls aligned with ISO 27001 principles. We do not currently hold ISO 27001 certification; clients with specific certification requirements should raise these prior to engagement.
In the event of a personal data breach that poses a risk to individuals, we will notify the Dutch Data Protection Authority (Autoriteit Persoonsgegevens) within 72 hours and affected data subjects without undue delay, in accordance with Articles 33–34 GDPR.
8. Cookies and Tracking
Our website uses cookies and similar technologies for functionality, analytics, and performance measurement. We obtain consent for non-essential cookies via a cookie banner upon first visit.
You can manage cookie preferences at any time through your browser settings or our cookie preference center. Refusing non-essential cookies does not affect your ability to use our website.
9. Your Rights
Under the GDPR, you have the right to:
- Access - request a copy of the personal data we hold about you
- Rectification - request correction of inaccurate or incomplete data
- Erasure - request deletion of your data where we no longer have a lawful basis to retain it
- Restriction - request that we restrict processing in certain circumstances
- Portability - receive your data in a structured, machine-readable format
- Object - object to processing based on legitimate interests or for direct marketing purposes
- Withdraw consent - where processing is based on consent, withdraw it at any time without affecting the lawfulness of prior processing To exercise any of these rights, contact us at hello@maderelevant.com. We will respond within 30 days (extendable by a further 60 days for complex requests, with notice).
If you believe we have not handled your personal data correctly, you have the right to lodge a complaint with the Dutch Data Protection Authority: autoriteitpersoonsgegevens.nl.
10. Children
Our services are directed at businesses and professionals. We do not knowingly collect personal data from individuals under the age of 16. If we become aware that we have collected such data without appropriate consent, we will delete it promptly.
11. Company Information and Data Controller
Made Relevant B.V. Gijsbrecht van Amstelstraat 213, 1214 BA Hilversum, the Netherlands KvK: 96097132
For all privacy-related inquiries, data subject requests, or to request our DPA and compliance documentation: hello@maderelevant.com
We do not currently operate at a scale requiring a formally designated Data Protection Officer (DPO), but our founding team handles all privacy matters directly and is reachable at the address above.
12. Updates
We may update this policy to reflect changes in our practices or applicable law. The “Last Updated” date at the top reflects the most recent revision. For material changes, we will provide notice to active clients by email. Continued use of our website or services after the effective date constitutes acceptance of the revised policy.