Privacy & GDPR Policy

AVG-conform · Effective 27 Sep 2026 · Autoriteit Persoonsgegevens

Privacyverklaring conform de Algemene Verordening Gegevensbescherming (AVG/GDPR, EU 2016/679) en de Uitvoeringswet AVG (UAVG).

Privacy & GDPR Policy

Last updated: 27 September 2026
Version: 3.0
Effective: 27 September 2026
Jurisdiction: Netherlands & EU/EEA
GDPR Compliant by Design


How to Read This Policy

The universal sections (1–5, 8–18) apply to everyone — visitors, registered users, and customers across all AdMun platforms.
Section 6 (Product-Specific Data) and Section 7 (Connected Platforms) apply only to the specific products or integrations you actually use. If you never use a given service, its data handling never applies to you.


Table of Contents

  1. Who We Are
  2. Our Products & Scope
  3. Information We Collect
  4. How & Why We Use It
  5. Marketing & Communications
  6. Product-Specific Data Handling
  7. Connected Platforms & Social Integrations
  8. Third-Party Data Sharing
  9. Sensitive & Special Category Data
  10. AI & Automated Processing
  11. Data Retention
  12. International Data Transfers
  13. Cookies & Tracking Technologies
  14. Your Rights & Data Requests
  15. Children's Privacy
  16. Security & Data Breaches
  17. Changes to This Policy
  18. Governing Law, Jurisdiction & Contact

1. Who We Are

AdMun (also operating as NetherlandsIT, AdMun EU, NLIT, NLEBIKE, Rational HRM) is a technology company registered in the Netherlands. We build a family of digital products across several industries, all governed by this single, unified privacy policy.

Detail Information
Legal Entity Eenmanszaak (sole proprietorship)
KVK 84121998
VAT NL003915624B42
Address Oudemansstraat 315, 2522SW 's-Gravenhage, The Netherlands
Email info@admun.eu • chishty@admun.eu
Website www.admun.eu

Related Entities:
- Rational HRM B.V. (KVK 87654321) — Operator of Rational HRM platform (nlit.io)
- NLEBIKE — Trading name for e-commerce webshop (nlebike.com)

Controller vs Processor Roles

Scenario Role Legal Basis
Data you provide directly to us (account, contact forms, purchases) Data Controller GDPR Art. 4(7)
Business customer uses Rational HRM to process their workers' data Customer = Controller, AdMun = Data Processor Art. 28 (DPA required)
E-commerce customer data (orders, shipping) Data Controller GDPR Art. 4(7)

2. Our Products & Scope

This website is the central hub for the AdMun product family. One policy covers them all, but each product only collects what it needs.

Current Product Portfolio

Product Line Brand Domain Description
IT Services & Consulting NetherlandsIT / AdMun admun.eu Custom software, cloud, DevOps, cybersecurity, AI automation
HRM SaaS Platform Rational HRM nlit.io Dutch staffing agency HRM: ATS, compliance, payroll, AI matching
E-Commerce NLEBIKE nlebike.com E-bikes, accessories, batteries, secure checkout

Product Stages

Stage Description Data Implications
Live Generally available, production-ready Standard data collection per this policy
Beta User testing, not yet GA Additional diagnostic data (legitimate interest: product improvement); you may object
Pre-Registration Interest collection ahead of launch Minimal data (email, company, use case); consent-based

3. Information We Collect

We collect only what is relevant to the service you use. The categories below are the maximum range across all products; any single product uses a subset.

3.1 Information You Provide

Category Examples Applicable Products
Identity & contact Name, email, phone, job title All
Organisation details Company name, KVK number, business address IT Services, Rational HRM
Account credentials Username, securely hashed password All (registered users)
Preferences Communication, language, notification settings All
Content you submit Support requests, feedback, uploads, job postings, product reviews All
Contract/service data Service agreements, SLAs, DPAs IT Services, Rational HRM
E-commerce data Shipping/billing address, order history, payment method tokens NLEBIKE

3.2 Information Collected Automatically

Category Examples Legal Basis
Technical identifiers IP address, browser type, OS, device IDs Legitimate interest (security, fraud prevention)
Usage analytics Pages visited, time spent, click paths, searches Consent (analytics cookies)
Session data Referring URLs, session tokens, feature usage Contract (service delivery) / Consent
Cookies & tracking Pixels, local storage, fingerprinting (fraud only) See Cookie Policy

3.3 Information from Third Parties

Source Data Type Purpose
KVK / Handelsregister Business verification, legal entity data KYC, compliance (Waadi), contract validity
Social login providers LinkedIn, Google, Microsoft — profile, email Authentication, profile pre-fill (Section 7)
Payroll/HR integrations NMBRS, AFAS, BrynQ, Salure — employee data Rational HRM service delivery (Processor role)
Payment processors Mollie, Stripe, PayPal — transaction data Order fulfillment, fraud prevention
Shipping carriers PostNL, DHL, DPD — tracking, delivery status NLEBIKE order fulfillment

Data Minimisation

We do not store sensitive identifiers (BSN, IBAN, ID document numbers) in plain text in general databases. Where a regulated product genuinely requires them (Rational HRM payroll), they are:
- Encrypted with AES-256 at rest
- Handled only by certified specialist processors
- Never used for marketing or AI training
- Subject to strict access controls (Section 9)


4. How & Why We Use Your Information

We process personal data on these legal bases under GDPR Art. 6:

Legal Basis GDPR Article Purposes
Contract 6(1)(b) Service delivery, account management, order fulfillment, subscription billing, SLA performance
Legal Obligation 6(1)(c) Tax/accounting records (7 years), payroll compliance, statutory reporting, consumer rights
Legitimate Interest 6(1)(f) Fraud prevention, platform security, uptime monitoring, product improvement, AI model training (anonymised), direct marketing to existing customers (soft opt-in)
Consent 6(1)(a) Marketing communications, non-essential cookies, connected platform integrations, beta program participation

Purpose Mapping by Product

Purpose IT Services Rational HRM NLEBIKE
Service delivery ✓ ✓ ✓
Account management ✓ ✓ ✓
Compliance (payroll, tax) ✓
Order fulfillment ✓
Fraud prevention ✓ ✓ ✓
AI model improvement (anonymised) ✓ ✓
Marketing (consent/soft opt-in) ✓ ✓ ✓

5. Marketing & Communications

With an appropriate legal basis (your explicit consent, or our legitimate interest where you are an existing customer — "soft opt-in" under Telecommunicatiewet Art. 11.7), we may use your name, email, phone, and general usage profile to send:

  • Service announcements & product updates
  • Newsletters & industry insights
  • Relevant offers & promotional content
  • Event invitations (webinars, demos)
  • Retargeted advertising (via marketing cookies — see Cookie Policy)

Your Control

Action Method
Unsubscribe from email Click "unsubscribe" in any marketing email
Object to direct marketing Email info@admun.eu with subject "Marketing Objection"
Manage cookie consent Cookie Preference Centre in footer
Withdraw consent (any time) Email info@admun.eu — no impact on service access

Opting out never affects your access to services.


6. Product-Specific Data Handling

The following applies only if and when you use the relevant product.

6.1 IT Services & Consulting (NetherlandsIT / AdMun Core)

Data Processed Purpose Retention Special Handling
Project requirements, specs, credentials Service delivery Project duration + 2 years Encrypted credential vault
Server/infrastructure access logs Security, debugging 12 months rolling Pseudonymised after 30 days
Code repositories, deployment logs DevOps, CI/CD Per client agreement Client-owned, we process only
Support tickets, communications Support SLA Account life + 1 year —

6.2 Rational HRM (nlit.io) — HR & Administration

Data Processed Purpose Retention Legal Basis
Worker records (name, BSN, IBAN, contract, hours, pay) Payroll, compliance, VBAR/DBA classification Statutory: 7 years (Dutch tax law) Legal obligation / Controller instruction
CAO scales, phase tracking (A/B/C) WAB compliance, ABU/NBBU certification Worker tenure + 5 years Legal obligation
IND visa status, Vreemdelingenwet data HSM thresholds, work permit tracking Visa validity + 2 years Legal obligation
UWV/Werk.nl reporting data Statutory reporting 7 years Legal obligation
eHerkenning / DigiD logs Authentication audit trail 3 years Security (legitimate interest)
AI-Vector matching data (skills, geo, reliability) Candidate ranking Anonymised after placement Legitimate interest / Consent
Timesheets, clock-in/out (geofence) Payroll accuracy, Working Hours Act 7 years Legal obligation
Veriff ID verification Identity proofing Verification session + 30 days (Veriff retains per their policy) Contract / Legal obligation

Critical: Rational HRM customers (staffing agencies/employers) are Controllers for worker data. AdMun/Rational HRM B.V. acts as Processor under a signed Data Processing Agreement (DPA). Workers' rights requests must be directed to the Controller (the agency/employer), who will instruct us as Processor.

6.3 NLEBIKE (nlebike.com) — E-Commerce

Data Processed Purpose Retention Legal Basis
Order data (name, email, phone, shipping/billing address) Order fulfillment, delivery, returns 7 years (tax law) Contract / Legal obligation
Payment data (tokenized, not full PAN) Payment processing, fraud check Per payment processor policy (typically 13 months) Contract / Legitimate interest
Account data (if registered) Order history, wishlist, faster checkout Account life + 1 year Contract
Product reviews, photos UGC display, trust signals Until removal request Consent
Wishlist, cart, viewed products Personalisation, abandoned cart email 90 days / until purchase Consent (cookies)
Warranty claims, RMA data 1-year manufacturer warranty Claim resolution + 2 years Legal obligation (consumer law)

Payments: We never store full card numbers. All payments processed by PCI-DSS Level 1 certified providers (Mollie, Stripe, PayPal, etc.). Crypto/USDC payments via Coinbase Commerce — no sensitive financial data stored.


7. Connected Platforms & Social Integrations

Some products let you connect a third-party account so we can perform actions you request (e.g., publish a job posting, sync contacts, import product catalog). Only platforms you connect apply.

Platform Purpose Data Accessed Retention Revocation
LinkedIn Job posting, recruiter profile, lead gen Profile, connections, company page (with permission) While connected + 30 days Disconnect in Settings → Integrations
Google / Microsoft SSO, Calendar, Contacts, Drive Email, name, calendar events (read/write per scope) While connected + 30 days Revoke in Google/MS account or our Settings
Meta (Facebook/Instagram) Ad audience sync, pixel events Ad account ID, pixel events (no private messages) While connected + 90 days Disconnect in Settings → Integrations
X (Twitter) Social posting, monitoring Profile, tweets (authored by you) While connected + 30 days Revoke in X settings
TikTok Content posting Profile, video uploads (initiated by you) While connected + 30 days Revoke in TikTok settings
Payroll APIs (NMBRS, AFAS, BrynQ, Salure) Payroll sync, worker data Employee records, contracts, payslips (per DPA) Per DPA / Controller instruction Disconnect in Rational HRM → Integrations
Shopify Apps (NLEBIKE) Storefront, reviews, email marketing Order data, customer data (per app scope) Per app privacy policy Uninstall app

Common to Every Integration

  • We request only the minimum scopes a feature needs
  • We act strictly on your instructions
  • We never sell connected-platform data
  • We keep it only as long as needed and within each platform's limits
  • You can disconnect at any time — we delete tokens and cached data within 30 days
  • Each platform's own privacy terms also apply to your account with them

8. Third-Party Data Sharing

We share data only where necessary, with providers bound by DPAs under Art. 28:

Category Providers (Examples) Purpose Safeguards
Cloud & hosting Google Cloud Platform, AWS, Azure (EU regions) Infrastructure, databases, AI compute EU hosting, SCCs, ISO 27001
Payment & finance Mollie, Stripe, PayPal, Coinbase Commerce Payment processing, invoicing, payouts PCI-DSS Level 1, SCCs
Payroll & statutory NMBRS, AFAS, BrynQ, Salure, Finqle Payroll execution, tax filings Certified processors, DPA
Analytics & monitoring Google Analytics, Sentry, Hotjar, Mixpanel (beta) Performance, error tracking, usage IP anonymisation, SCCs
Email & communications SendGrid, Mailchimp, Postmark Transactional & marketing email SCCs, EU data centers
Identity & verification Veriff, eHerkenning, DigiD KYC, identity proofing Certified, EU-based
Shipping & logistics PostNL, DHL, DPD, 17TRACK Order delivery, tracking Contractual necessity
Connected platforms LinkedIn, Google, Meta, X, TikTok Features you explicitly enable (Section 7) Platform ToS + our DPA

We Never

  • Sell your personal data
  • Share data with advertisers without your consent (marketing cookies)
  • Use sensitive data (health, BSN, IBAN) for analytics or AI training

Required Disclosures

We may disclose data to competent authorities where required by law or court order (KVK, Belastingdienst, Arbeidsinspectie, AP, ACM, police). Personal data may transfer to a successor entity in a merger/acquisition, subject to equivalent protection.


9. Sensitive & Special Category Data

Strict Handling Protocols

Data Type Classification Handling
Health data (Wegiz/healthcare products) Special category Art. 9 Encrypted, isolated DB, strict RBAC, never marketing/AI
BSN (Burgerservicenummer) Sensitive identifier Encrypted at rest (AES-256), tokenized in logs, payroll-only access
IBAN / payment details Sensitive financial Tokenized by payment processor, never in our DB
ID documents (passport, driver's license) Special category / sensitive Veriff processes; we receive only verification result
Biometric data (geofence clock-in) Special category potential Minimal collection, encrypted, worker consent, auto-delete 30d

Technical Measures (Art. 32)

  • Encryption: AES-256 at rest, TLS 1.3 in transit
  • Access Control: Role-based (RBAC), principle of least privilege, MFA for admin
  • Audit Logging: Immutable logs for all sensitive data access
  • Data Minimisation: Automated purging per retention schedules
  • Penetration Testing: Annual third-party pen tests, quarterly vulnerability scans

10. AI & Automated Processing

AI Features Across Products

Product AI Feature Data Used for Training
Rational HRM AI-Vector matching, Screener Agent, Fraud flags, Compliance Agent Anonymised/aggregated only — no personal data
NLEBIKE Product recommendations, search ranking Anonymised behavioural only — no PII
AdMun Core Code generation, security scanning, compliance Q&A No customer data — trained on public/open-source

Your Rights Regarding Automated Decisions

Where an automated decision would have a significant legal effect (e.g., VBAR classification affecting employment status), you have the right not to be subject to it on a solely automated basis (Art. 22) and may request human review.

  • Rational HRM: Workers can request human review of AI classification → routed to two-key approval (audit-logged)
  • NLEBIKE: No automated decisions with legal effect
  • AdMun Core: AI output is advisory only (see Terms §10)

AI Training Principles

  1. Anonymisation first: We use anonymised or aggregated data wherever possible
  2. Special category exclusion: Health, BSN, IBAN, biometrics excluded from model training
  3. Purpose limitation: Training only for improving our own services
  4. No third-party training: We do not provide data to external model providers (OpenAI, Anthropic, etc.) for their training

11. Data Retention

We keep personal data only as long as needed, then delete or anonymise it.

Data Category Retention Period Trigger for Deletion
Account data (profile, credentials) Life of account + 1 year Account closure
Financial / payroll / tax records 7 years (Dutch Wet op de inkomstenbelasting) Statutory expiry
Order / e-commerce records 7 years (tax) / 2 years (consumer warranty) Statutory expiry
Connected-platform tokens & data While integration active + 30 days Revocation / disconnect
Marketing data (consent-based) Until withdrawal or 24 months inactivity Opt-out / inactivity
Analytics / telemetry (anonymised) 26 months (GA4 default) Auto-anonymisation at 14 months
Support tickets & communications Account life + 1 year Account closure
Beta / pre-registration data Product GA launch + 6 months or withdrawal GA transition / opt-out
Security / fraud logs 12 months rolling Time-based purge
AI training derivatives (anonymised) Model version lifecycle Model deprecation

Legal holds override: If data is subject to litigation, regulatory investigation, or audit, retention extends until the hold is lifted.


12. International Data Transfers

Primary Principle

We primarily process and host data within the EU/EEA (Google Cloud EU-West, AWS EU-Central, Azure NL).

Transfers Outside EEA

Where a service or connected platform involves transfer outside the EEA (e.g., US-based social providers, Shopify CDN, certain AI APIs), we rely on appropriate safeguards under GDPR Chapter V:

Transfer Mechanism Applied To
Adequacy Decision Canada, Japan, UK, Switzerland, Israel, Argentina, Uruguay, New Zealand, South Korea
Standard Contractual Clauses (SCCs) US providers (Google, Microsoft, Meta, LinkedIn, Shopify, Stripe, SendGrid, Sentry, Veriff, Mixpanel)
Binding Corporate Rules Where available (e.g., Microsoft, Google enterprise)
Derogations (Art. 49) Rare — explicit consent, contract performance, vital interests

US Transfers Post-Schrems II

For US providers, we:
- Use SCCs (2021 version) + Supplementary Measures (encryption in transit/at rest, access controls, transparency reports)
- Monitor US surveillance law developments (EO 14086, EU-US Data Privacy Framework)
- Prefer EU-hosted alternatives where functionally equivalent


13. Cookies & Tracking Technologies

We use cookies governed by Telecommunicatiewet Art. 11.7a and GDPR Art. 5.

Summary by Category

Category Consent Required? Purpose Examples
Strictly Necessary No (exempt) Authentication, sessions, security, cart, consent record Session ID, CSRF token, cookie consent flag
Analytics & Performance Yes Usage measurement, UX improvement, error tracking Google Analytics, Hotjar, Sentry
Marketing & Advertising Yes Retargeting, personalisation, conversion tracking Google Ads, LinkedIn Insight Tag, Meta Pixel
Functional & Preference Yes Language, theme, saved filters, acknowledged modals Locale, dark mode, dismissed banners

Manage preferences: Cookie Preference Centre in footer. Withdrawing consent doesn't affect prior lawful processing.

Full details: See our dedicated Cookie Policy.


14. Your Rights & Data Requests

Under GDPR Chapter III you have the rights to:

Right Article How to Exercise
Access & Portability Art. 15, 20 Request data export
Rectification Art. 16 Request correction
Erasure ("Right to be Forgotten") Art. 17 Request deletion — subject to legal retention (tax, payroll)
Restriction Art. 18 Email info@admun.eu
Objection (incl. direct marketing) Art. 21 Email info@admun.eu or unsubscribe link
Human Review (automated decisions) Art. 22 Email info@admun.eu — "Art. 22 Review Request"

Required Information for Requests

Include in your email:
- Full name
- Email on your account
- Phone (optional)
- Product(s) your request relates to (Rational HRM / NLEBIKE / AdMun Core)
- Details of the request

Response Timeline

  • Acknowledgement: Within 1 business day
  • Substantive response: Within 30 calendar days (extendable by 2 months for complex requests — we'll notify you)

Identity Verification

To protect your privacy, we may verify your identity before fulfilling requests (e.g., request copy of ID, confirm recent activity).

Supervisory Authority

You may also lodge a complaint with the Autoriteit Persoonsgegevens (Dutch DPA): autoriteitpersoonsgegevens.nl/klacht-indienen or your local EU DPA.


15. Children's Privacy

Our products are intended for business users and adults (18+). We do not knowingly collect personal data from children under 16 without appropriate parental/guardian consent as required by GDPR Art. 8.

  • NLEBIKE: Age-gated at checkout (18+ for e-bike purchases)
  • Rational HRM: Workers must be of legal working age per Dutch law
  • AdMun Core: B2B services only

If you believe a child has provided us data, contact us and we will delete it.


16. Security & Data Breaches

Our Measures (Art. 32)

Measure Implementation
Architecture Zero-Trust, micro-segmentation, private networks
Encryption AES-256 at rest, TLS 1.3 in transit, encrypted backups
Access Control RBAC, MFA mandatory for admin, just-in-time access
Monitoring 24/7 SIEM, anomaly detection, automated alerts
Testing Annual pen test (3rd party), quarterly vuln scans, bug bounty
Certifications ISO 27001 (GCP/AWS/Azure), SOC 2 Type II (processors), PCI-DSS (payment)
Staff Training Annual security & privacy training, phishing simulations

Breach Notification (Art. 33, 34)

Event Timeline To Whom
Personal data breach (likely risk to rights) 72 hours of awareness Autoriteit Persoonsgegevens
High risk to individuals Without undue delay Affected data subjects (direct email)
Processor breach (Rational HRM) Without undue delay Controller (customer/agency) — we assist their Art. 33/34 obligations

No system is perfectly secure. While we work hard to protect your data, we cannot guarantee absolute security against every threat.


17. Changes to This Policy

We may update this policy as our products and legal obligations evolve.

Change Type Notification
Material changes (new purposes, new sharing, reduced rights) Prominent notice on website + email to registered users (where practical)
Minor changes (clarifications, contact updates) Updated "Effective Date" at top of policy
New product launch Policy updated at launch; in-product notice for affected users

Version history available on request. The "Effective Date" at the top shows the latest revision.


18. Governing Law, Jurisdiction & Contact

This policy is governed by Dutch and EU law, including:
- GDPR 2016/679
- Telecommunicatiewet (ePrivacy implementation)
- Burgerlijk Wetboek Boek 6 (consumer rights)
- EU Directive 2011/83/EU (consumer rights)

Disputes

Disputes fall under the courts of 's-Gravenhage (The Hague), The Netherlands.
EU ODR Platform: ec.europa.eu/consumers/odr

Contact Us

Channel Details
Data Protection / Privacy info@admun.eu • chishty@admun.eu
Data Subject Requests Use mailto links in Section 14
Postal Address Oudemansstraat 315, 2522SW 's-Gravenhage, The Netherlands
KVK 84121998 (Eenmanszaak)
Supervisory Authority Autoriteit Persoonsgegevens
EU ODR ec.europa.eu/consumers/odr

Terms & Conditions | Cookie Policy | Terms of Service | Disclaimer | Legal Imprint


© 2026 AdMun / NetherlandsIT — KVK 84121998 — VAT NL003915624B42 — registered in The Netherlands.
Privacy & GDPR Policy v3.0 — Effective 27 September 2026