Home › Privacy statement
Privacy statement
Van Croonenburg IT-Consultancy B.V. processes personal data in two ways: from visitors to this website, and from client employees while administering their ITSM environment. This page sets out exactly what that involves.
Last updated 9 September 2026.
Controller
Van Croonenburg IT-Consultancy B.V., trading as VCITC, established in Apeldoorn, Netherlands, Chamber of Commerce 99307596. For questions about this statement or your data: info@vcitc.nl or +31 85 203 3506.
This website
This site loads almost nothing from third parties: no content delivery network, no external fonts and no embedded video. The one exception is Google Analytics, which we load only after you have given permission. See Cookies and statistics below.
The web server does keep standard access logs containing IP address, requested path, timestamp and browser type. These are needed for security and troubleshooting, are not linked to individuals, and are deleted after 30 days. Legal basis: legitimate interest (Article 6(1)(f) GDPR).
Cookies and statistics
On your first visit we ask whether we may measure how the site is used, using Google Analytics 4. If you decline, nothing happens: no Google script is loaded, no cookies are placed and no data reaches Google. The site works exactly the same.
If you agree, Google places the cookies _ga and _ga_<id>. They expire after
two years and serve to recognise a returning browser, so that we can see how many distinct visitors there are
and which pages they read. We look at pages read, country, device and whether someone reaches the contact
form. We do not link this to names, we use no advertising features and we share nothing with advertisers.
According to Google, IP addresses are not stored in Analytics 4: they are used to determine the country and
then discarded.
Your choice is kept in your own browser rather than in a cookie. We ask again after a year. To change it in the meantime, click Cookie preferences at the bottom of any page.
Legal basis: consent (Article 6(1)(a) GDPR and Article 11.7a of the Dutch Telecommunications Act). You may withdraw that consent at any time; it does not affect measurements taken before then.
The contact form
If you use the form, we process your name, organisation, email address, optional telephone number and the content of your message. We use that solely to respond to your enquiry. Legal basis: performance of a contract or steps prior to it (Article 6(1)(b) GDPR).
If you request the whitepaper, we send you one email containing the download link so you can find the document again later. That does not put you on a mailing list; we do not send a newsletter.
If the contact does not lead to an engagement, we delete the enquiry after 12 months. If it does, the retention periods below apply.
The form contains a hidden field that only automated systems fill in, and a simple limit on the number of submissions per hour per IP address. Both exist purely to stop spam; no profile is built.
Client data
For administration purposes we process contact details of client employees: name, role, business email address and telephone number. Legal basis: performance of the contract. Retention: for the duration of the engagement and seven years thereafter, insofar as it forms part of records subject to statutory tax retention requirements.
Data in your ITSM environment
Administering a TOPdesk environment inevitably brings us into contact with personal data: names of reporters and agents, email addresses, telephone numbers, and sometimes attachments to tickets. For that data we are a processor and the client is the controller.
Every management contract therefore includes a data processing agreement. Our standard version is published on this site so you can assess it in advance. It covers instruction-bound processing, security measures, breach notification, the handling of sub-processors and what happens to data on termination.
We do not export data from your environment into systems of our own unless a specific assignment requires it and it has been agreed in advance. We work inside your environment.
Sharing with third parties
We do not sell data and do not share it with third parties, except with the parties we engage for our own operations: the host of this website, our email provider and our accountant. A processing agreement is in place with each of them. Processing takes place within the European Economic Area.
If you consent to statistics, Google joins that list. For Google, the data processing terms that form part of the Analytics terms apply. Google may transfer data to the United States on the basis of the EU-US Data Privacy Framework.
Security
This website is only reachable over HTTPS. Access to client environments runs through personal, named accounts with two-factor authentication, never through shared administrator accounts — so your own logging always shows who did what. Equipment is encrypted and set to lock automatically.
Your rights
You have the right to access, rectification, erasure, restriction and portability of your data, and you may object to processing based on legitimate interest. Send a request to info@vcitc.nl; we respond within four weeks.
If your request concerns data in a client's ITSM environment, we are the processor and the request must go to that organisation. We will refer you and assist them in handling it.
If we cannot resolve matters together, you may lodge a complaint with the Dutch Data Protection Authority (Autoriteit Persoonsgegevens).
Changes
If this statement changes, we update the date at the top. For substantial changes affecting current clients, we notify them directly.