Privacy & GDPR Policy
Last updated: 27 September 2026
Version: 3.0
Effective: 27 September 2026
Jurisdiction: Netherlands & EU/EEA
GDPR Compliant by Design
How to Read This Policy
The universal sections (1–5, 8–18) apply to everyone — visitors, registered users, and customers across all AdMun platforms.
Section 6 (Product-Specific Data) and Section 7 (Connected Platforms) apply only to the specific products or integrations you actually use. If you never use a given service, its data handling never applies to you.
Table of Contents
- Who We Are
- Our Products & Scope
- Information We Collect
- How & Why We Use It
- Marketing & Communications
- Product-Specific Data Handling
- Connected Platforms & Social Integrations
- Third-Party Data Sharing
- Sensitive & Special Category Data
- AI & Automated Processing
- Data Retention
- International Data Transfers
- Cookies & Tracking Technologies
- Your Rights & Data Requests
- Children's Privacy
- Security & Data Breaches
- Changes to This Policy
- Governing Law, Jurisdiction & Contact
1. Who We Are
AdMun (also operating as NetherlandsIT, AdMun EU, NLIT, NLEBIKE, Rational HRM) is a technology company registered in the Netherlands. We build a family of digital products across several industries, all governed by this single, unified privacy policy.
| Detail | Information |
|---|---|
| Legal Entity | Eenmanszaak (sole proprietorship) |
| KVK | 84121998 |
| VAT | NL003915624B42 |
| Address | Oudemansstraat 315, 2522SW 's-Gravenhage, The Netherlands |
| info@admun.eu • chishty@admun.eu | |
| Website | www.admun.eu |
Related Entities:
- Rational HRM B.V. (KVK 87654321) — Operator of Rational HRM platform (nlit.io)
- NLEBIKE — Trading name for e-commerce webshop (nlebike.com)
Controller vs Processor Roles
| Scenario | Role | Legal Basis |
|---|---|---|
| Data you provide directly to us (account, contact forms, purchases) | Data Controller | GDPR Art. 4(7) |
| Business customer uses Rational HRM to process their workers' data | Customer = Controller, AdMun = Data Processor | Art. 28 (DPA required) |
| E-commerce customer data (orders, shipping) | Data Controller | GDPR Art. 4(7) |
2. Our Products & Scope
This website is the central hub for the AdMun product family. One policy covers them all, but each product only collects what it needs.
Current Product Portfolio
| Product Line | Brand | Domain | Description |
|---|---|---|---|
| IT Services & Consulting | NetherlandsIT / AdMun | admun.eu | Custom software, cloud, DevOps, cybersecurity, AI automation |
| HRM SaaS Platform | Rational HRM | nlit.io | Dutch staffing agency HRM: ATS, compliance, payroll, AI matching |
| E-Commerce | NLEBIKE | nlebike.com | E-bikes, accessories, batteries, secure checkout |
Product Stages
| Stage | Description | Data Implications |
|---|---|---|
| Live | Generally available, production-ready | Standard data collection per this policy |
| Beta | User testing, not yet GA | Additional diagnostic data (legitimate interest: product improvement); you may object |
| Pre-Registration | Interest collection ahead of launch | Minimal data (email, company, use case); consent-based |
3. Information We Collect
We collect only what is relevant to the service you use. The categories below are the maximum range across all products; any single product uses a subset.
3.1 Information You Provide
| Category | Examples | Applicable Products |
|---|---|---|
| Identity & contact | Name, email, phone, job title | All |
| Organisation details | Company name, KVK number, business address | IT Services, Rational HRM |
| Account credentials | Username, securely hashed password | All (registered users) |
| Preferences | Communication, language, notification settings | All |
| Content you submit | Support requests, feedback, uploads, job postings, product reviews | All |
| Contract/service data | Service agreements, SLAs, DPAs | IT Services, Rational HRM |
| E-commerce data | Shipping/billing address, order history, payment method tokens | NLEBIKE |
3.2 Information Collected Automatically
| Category | Examples | Legal Basis |
|---|---|---|
| Technical identifiers | IP address, browser type, OS, device IDs | Legitimate interest (security, fraud prevention) |
| Usage analytics | Pages visited, time spent, click paths, searches | Consent (analytics cookies) |
| Session data | Referring URLs, session tokens, feature usage | Contract (service delivery) / Consent |
| Cookies & tracking | Pixels, local storage, fingerprinting (fraud only) | See Cookie Policy |
3.3 Information from Third Parties
| Source | Data Type | Purpose |
|---|---|---|
| KVK / Handelsregister | Business verification, legal entity data | KYC, compliance (Waadi), contract validity |
| Social login providers | LinkedIn, Google, Microsoft — profile, email | Authentication, profile pre-fill (Section 7) |
| Payroll/HR integrations | NMBRS, AFAS, BrynQ, Salure — employee data | Rational HRM service delivery (Processor role) |
| Payment processors | Mollie, Stripe, PayPal — transaction data | Order fulfillment, fraud prevention |
| Shipping carriers | PostNL, DHL, DPD — tracking, delivery status | NLEBIKE order fulfillment |
Data Minimisation
We do not store sensitive identifiers (BSN, IBAN, ID document numbers) in plain text in general databases. Where a regulated product genuinely requires them (Rational HRM payroll), they are:
- Encrypted with AES-256 at rest
- Handled only by certified specialist processors
- Never used for marketing or AI training
- Subject to strict access controls (Section 9)
4. How & Why We Use Your Information
We process personal data on these legal bases under GDPR Art. 6:
| Legal Basis | GDPR Article | Purposes |
|---|---|---|
| Contract | 6(1)(b) | Service delivery, account management, order fulfillment, subscription billing, SLA performance |
| Legal Obligation | 6(1)(c) | Tax/accounting records (7 years), payroll compliance, statutory reporting, consumer rights |
| Legitimate Interest | 6(1)(f) | Fraud prevention, platform security, uptime monitoring, product improvement, AI model training (anonymised), direct marketing to existing customers (soft opt-in) |
| Consent | 6(1)(a) | Marketing communications, non-essential cookies, connected platform integrations, beta program participation |
Purpose Mapping by Product
| Purpose | IT Services | Rational HRM | NLEBIKE |
|---|---|---|---|
| Service delivery | ✓ | ✓ | ✓ |
| Account management | ✓ | ✓ | ✓ |
| Compliance (payroll, tax) | ✓ | ||
| Order fulfillment | ✓ | ||
| Fraud prevention | ✓ | ✓ | ✓ |
| AI model improvement (anonymised) | ✓ | ✓ | |
| Marketing (consent/soft opt-in) | ✓ | ✓ | ✓ |
5. Marketing & Communications
With an appropriate legal basis (your explicit consent, or our legitimate interest where you are an existing customer — "soft opt-in" under Telecommunicatiewet Art. 11.7), we may use your name, email, phone, and general usage profile to send:
- Service announcements & product updates
- Newsletters & industry insights
- Relevant offers & promotional content
- Event invitations (webinars, demos)
- Retargeted advertising (via marketing cookies — see Cookie Policy)
Your Control
| Action | Method |
|---|---|
| Unsubscribe from email | Click "unsubscribe" in any marketing email |
| Object to direct marketing | Email info@admun.eu with subject "Marketing Objection" |
| Manage cookie consent | Cookie Preference Centre in footer |
| Withdraw consent (any time) | Email info@admun.eu — no impact on service access |
Opting out never affects your access to services.
6. Product-Specific Data Handling
The following applies only if and when you use the relevant product.
6.1 IT Services & Consulting (NetherlandsIT / AdMun Core)
| Data Processed | Purpose | Retention | Special Handling |
|---|---|---|---|
| Project requirements, specs, credentials | Service delivery | Project duration + 2 years | Encrypted credential vault |
| Server/infrastructure access logs | Security, debugging | 12 months rolling | Pseudonymised after 30 days |
| Code repositories, deployment logs | DevOps, CI/CD | Per client agreement | Client-owned, we process only |
| Support tickets, communications | Support SLA | Account life + 1 year | — |
6.2 Rational HRM (nlit.io) — HR & Administration
| Data Processed | Purpose | Retention | Legal Basis |
|---|---|---|---|
| Worker records (name, BSN, IBAN, contract, hours, pay) | Payroll, compliance, VBAR/DBA classification | Statutory: 7 years (Dutch tax law) | Legal obligation / Controller instruction |
| CAO scales, phase tracking (A/B/C) | WAB compliance, ABU/NBBU certification | Worker tenure + 5 years | Legal obligation |
| IND visa status, Vreemdelingenwet data | HSM thresholds, work permit tracking | Visa validity + 2 years | Legal obligation |
| UWV/Werk.nl reporting data | Statutory reporting | 7 years | Legal obligation |
| eHerkenning / DigiD logs | Authentication audit trail | 3 years | Security (legitimate interest) |
| AI-Vector matching data (skills, geo, reliability) | Candidate ranking | Anonymised after placement | Legitimate interest / Consent |
| Timesheets, clock-in/out (geofence) | Payroll accuracy, Working Hours Act | 7 years | Legal obligation |
| Veriff ID verification | Identity proofing | Verification session + 30 days (Veriff retains per their policy) | Contract / Legal obligation |
Critical: Rational HRM customers (staffing agencies/employers) are Controllers for worker data. AdMun/Rational HRM B.V. acts as Processor under a signed Data Processing Agreement (DPA). Workers' rights requests must be directed to the Controller (the agency/employer), who will instruct us as Processor.
6.3 NLEBIKE (nlebike.com) — E-Commerce
| Data Processed | Purpose | Retention | Legal Basis |
|---|---|---|---|
| Order data (name, email, phone, shipping/billing address) | Order fulfillment, delivery, returns | 7 years (tax law) | Contract / Legal obligation |
| Payment data (tokenized, not full PAN) | Payment processing, fraud check | Per payment processor policy (typically 13 months) | Contract / Legitimate interest |
| Account data (if registered) | Order history, wishlist, faster checkout | Account life + 1 year | Contract |
| Product reviews, photos | UGC display, trust signals | Until removal request | Consent |
| Wishlist, cart, viewed products | Personalisation, abandoned cart email | 90 days / until purchase | Consent (cookies) |
| Warranty claims, RMA data | 1-year manufacturer warranty | Claim resolution + 2 years | Legal obligation (consumer law) |
Payments: We never store full card numbers. All payments processed by PCI-DSS Level 1 certified providers (Mollie, Stripe, PayPal, etc.). Crypto/USDC payments via Coinbase Commerce — no sensitive financial data stored.
7. Connected Platforms & Social Integrations
Some products let you connect a third-party account so we can perform actions you request (e.g., publish a job posting, sync contacts, import product catalog). Only platforms you connect apply.
| Platform | Purpose | Data Accessed | Retention | Revocation |
|---|---|---|---|---|
| Job posting, recruiter profile, lead gen | Profile, connections, company page (with permission) | While connected + 30 days | Disconnect in Settings → Integrations | |
| Google / Microsoft | SSO, Calendar, Contacts, Drive | Email, name, calendar events (read/write per scope) | While connected + 30 days | Revoke in Google/MS account or our Settings |
| Meta (Facebook/Instagram) | Ad audience sync, pixel events | Ad account ID, pixel events (no private messages) | While connected + 90 days | Disconnect in Settings → Integrations |
| X (Twitter) | Social posting, monitoring | Profile, tweets (authored by you) | While connected + 30 days | Revoke in X settings |
| TikTok | Content posting | Profile, video uploads (initiated by you) | While connected + 30 days | Revoke in TikTok settings |
| Payroll APIs (NMBRS, AFAS, BrynQ, Salure) | Payroll sync, worker data | Employee records, contracts, payslips (per DPA) | Per DPA / Controller instruction | Disconnect in Rational HRM → Integrations |
| Shopify Apps (NLEBIKE) | Storefront, reviews, email marketing | Order data, customer data (per app scope) | Per app privacy policy | Uninstall app |
Common to Every Integration
- We request only the minimum scopes a feature needs
- We act strictly on your instructions
- We never sell connected-platform data
- We keep it only as long as needed and within each platform's limits
- You can disconnect at any time — we delete tokens and cached data within 30 days
- Each platform's own privacy terms also apply to your account with them
8. Third-Party Data Sharing
We share data only where necessary, with providers bound by DPAs under Art. 28:
| Category | Providers (Examples) | Purpose | Safeguards |
|---|---|---|---|
| Cloud & hosting | Google Cloud Platform, AWS, Azure (EU regions) | Infrastructure, databases, AI compute | EU hosting, SCCs, ISO 27001 |
| Payment & finance | Mollie, Stripe, PayPal, Coinbase Commerce | Payment processing, invoicing, payouts | PCI-DSS Level 1, SCCs |
| Payroll & statutory | NMBRS, AFAS, BrynQ, Salure, Finqle | Payroll execution, tax filings | Certified processors, DPA |
| Analytics & monitoring | Google Analytics, Sentry, Hotjar, Mixpanel (beta) | Performance, error tracking, usage | IP anonymisation, SCCs |
| Email & communications | SendGrid, Mailchimp, Postmark | Transactional & marketing email | SCCs, EU data centers |
| Identity & verification | Veriff, eHerkenning, DigiD | KYC, identity proofing | Certified, EU-based |
| Shipping & logistics | PostNL, DHL, DPD, 17TRACK | Order delivery, tracking | Contractual necessity |
| Connected platforms | LinkedIn, Google, Meta, X, TikTok | Features you explicitly enable (Section 7) | Platform ToS + our DPA |
We Never
- Sell your personal data
- Share data with advertisers without your consent (marketing cookies)
- Use sensitive data (health, BSN, IBAN) for analytics or AI training
Required Disclosures
We may disclose data to competent authorities where required by law or court order (KVK, Belastingdienst, Arbeidsinspectie, AP, ACM, police). Personal data may transfer to a successor entity in a merger/acquisition, subject to equivalent protection.
9. Sensitive & Special Category Data
Strict Handling Protocols
| Data Type | Classification | Handling |
|---|---|---|
| Health data (Wegiz/healthcare products) | Special category Art. 9 | Encrypted, isolated DB, strict RBAC, never marketing/AI |
| BSN (Burgerservicenummer) | Sensitive identifier | Encrypted at rest (AES-256), tokenized in logs, payroll-only access |
| IBAN / payment details | Sensitive financial | Tokenized by payment processor, never in our DB |
| ID documents (passport, driver's license) | Special category / sensitive | Veriff processes; we receive only verification result |
| Biometric data (geofence clock-in) | Special category potential | Minimal collection, encrypted, worker consent, auto-delete 30d |
Technical Measures (Art. 32)
- Encryption: AES-256 at rest, TLS 1.3 in transit
- Access Control: Role-based (RBAC), principle of least privilege, MFA for admin
- Audit Logging: Immutable logs for all sensitive data access
- Data Minimisation: Automated purging per retention schedules
- Penetration Testing: Annual third-party pen tests, quarterly vulnerability scans
10. AI & Automated Processing
AI Features Across Products
| Product | AI Feature | Data Used for Training |
|---|---|---|
| Rational HRM | AI-Vector matching, Screener Agent, Fraud flags, Compliance Agent | Anonymised/aggregated only — no personal data |
| NLEBIKE | Product recommendations, search ranking | Anonymised behavioural only — no PII |
| AdMun Core | Code generation, security scanning, compliance Q&A | No customer data — trained on public/open-source |
Your Rights Regarding Automated Decisions
Where an automated decision would have a significant legal effect (e.g., VBAR classification affecting employment status), you have the right not to be subject to it on a solely automated basis (Art. 22) and may request human review.
- Rational HRM: Workers can request human review of AI classification → routed to two-key approval (audit-logged)
- NLEBIKE: No automated decisions with legal effect
- AdMun Core: AI output is advisory only (see Terms §10)
AI Training Principles
- Anonymisation first: We use anonymised or aggregated data wherever possible
- Special category exclusion: Health, BSN, IBAN, biometrics excluded from model training
- Purpose limitation: Training only for improving our own services
- No third-party training: We do not provide data to external model providers (OpenAI, Anthropic, etc.) for their training
11. Data Retention
We keep personal data only as long as needed, then delete or anonymise it.
| Data Category | Retention Period | Trigger for Deletion |
|---|---|---|
| Account data (profile, credentials) | Life of account + 1 year | Account closure |
| Financial / payroll / tax records | 7 years (Dutch Wet op de inkomstenbelasting) | Statutory expiry |
| Order / e-commerce records | 7 years (tax) / 2 years (consumer warranty) | Statutory expiry |
| Connected-platform tokens & data | While integration active + 30 days | Revocation / disconnect |
| Marketing data (consent-based) | Until withdrawal or 24 months inactivity | Opt-out / inactivity |
| Analytics / telemetry (anonymised) | 26 months (GA4 default) | Auto-anonymisation at 14 months |
| Support tickets & communications | Account life + 1 year | Account closure |
| Beta / pre-registration data | Product GA launch + 6 months or withdrawal | GA transition / opt-out |
| Security / fraud logs | 12 months rolling | Time-based purge |
| AI training derivatives (anonymised) | Model version lifecycle | Model deprecation |
Legal holds override: If data is subject to litigation, regulatory investigation, or audit, retention extends until the hold is lifted.
12. International Data Transfers
Primary Principle
We primarily process and host data within the EU/EEA (Google Cloud EU-West, AWS EU-Central, Azure NL).
Transfers Outside EEA
Where a service or connected platform involves transfer outside the EEA (e.g., US-based social providers, Shopify CDN, certain AI APIs), we rely on appropriate safeguards under GDPR Chapter V:
| Transfer Mechanism | Applied To |
|---|---|
| Adequacy Decision | Canada, Japan, UK, Switzerland, Israel, Argentina, Uruguay, New Zealand, South Korea |
| Standard Contractual Clauses (SCCs) | US providers (Google, Microsoft, Meta, LinkedIn, Shopify, Stripe, SendGrid, Sentry, Veriff, Mixpanel) |
| Binding Corporate Rules | Where available (e.g., Microsoft, Google enterprise) |
| Derogations (Art. 49) | Rare — explicit consent, contract performance, vital interests |
US Transfers Post-Schrems II
For US providers, we:
- Use SCCs (2021 version) + Supplementary Measures (encryption in transit/at rest, access controls, transparency reports)
- Monitor US surveillance law developments (EO 14086, EU-US Data Privacy Framework)
- Prefer EU-hosted alternatives where functionally equivalent
13. Cookies & Tracking Technologies
We use cookies governed by Telecommunicatiewet Art. 11.7a and GDPR Art. 5.
Summary by Category
| Category | Consent Required? | Purpose | Examples |
|---|---|---|---|
| Strictly Necessary | No (exempt) | Authentication, sessions, security, cart, consent record | Session ID, CSRF token, cookie consent flag |
| Analytics & Performance | Yes | Usage measurement, UX improvement, error tracking | Google Analytics, Hotjar, Sentry |
| Marketing & Advertising | Yes | Retargeting, personalisation, conversion tracking | Google Ads, LinkedIn Insight Tag, Meta Pixel |
| Functional & Preference | Yes | Language, theme, saved filters, acknowledged modals | Locale, dark mode, dismissed banners |
Manage preferences: Cookie Preference Centre in footer. Withdrawing consent doesn't affect prior lawful processing.
Full details: See our dedicated Cookie Policy.
14. Your Rights & Data Requests
Under GDPR Chapter III you have the rights to:
| Right | Article | How to Exercise |
|---|---|---|
| Access & Portability | Art. 15, 20 | Request data export |
| Rectification | Art. 16 | Request correction |
| Erasure ("Right to be Forgotten") | Art. 17 | Request deletion — subject to legal retention (tax, payroll) |
| Restriction | Art. 18 | Email info@admun.eu |
| Objection (incl. direct marketing) | Art. 21 | Email info@admun.eu or unsubscribe link |
| Human Review (automated decisions) | Art. 22 | Email info@admun.eu — "Art. 22 Review Request" |
Required Information for Requests
Include in your email:
- Full name
- Email on your account
- Phone (optional)
- Product(s) your request relates to (Rational HRM / NLEBIKE / AdMun Core)
- Details of the request
Response Timeline
- Acknowledgement: Within 1 business day
- Substantive response: Within 30 calendar days (extendable by 2 months for complex requests — we'll notify you)
Identity Verification
To protect your privacy, we may verify your identity before fulfilling requests (e.g., request copy of ID, confirm recent activity).
Supervisory Authority
You may also lodge a complaint with the Autoriteit Persoonsgegevens (Dutch DPA): autoriteitpersoonsgegevens.nl/klacht-indienen or your local EU DPA.
15. Children's Privacy
Our products are intended for business users and adults (18+). We do not knowingly collect personal data from children under 16 without appropriate parental/guardian consent as required by GDPR Art. 8.
- NLEBIKE: Age-gated at checkout (18+ for e-bike purchases)
- Rational HRM: Workers must be of legal working age per Dutch law
- AdMun Core: B2B services only
If you believe a child has provided us data, contact us and we will delete it.
16. Security & Data Breaches
Our Measures (Art. 32)
| Measure | Implementation |
|---|---|
| Architecture | Zero-Trust, micro-segmentation, private networks |
| Encryption | AES-256 at rest, TLS 1.3 in transit, encrypted backups |
| Access Control | RBAC, MFA mandatory for admin, just-in-time access |
| Monitoring | 24/7 SIEM, anomaly detection, automated alerts |
| Testing | Annual pen test (3rd party), quarterly vuln scans, bug bounty |
| Certifications | ISO 27001 (GCP/AWS/Azure), SOC 2 Type II (processors), PCI-DSS (payment) |
| Staff Training | Annual security & privacy training, phishing simulations |
Breach Notification (Art. 33, 34)
| Event | Timeline | To Whom |
|---|---|---|
| Personal data breach (likely risk to rights) | 72 hours of awareness | Autoriteit Persoonsgegevens |
| High risk to individuals | Without undue delay | Affected data subjects (direct email) |
| Processor breach (Rational HRM) | Without undue delay | Controller (customer/agency) — we assist their Art. 33/34 obligations |
No system is perfectly secure. While we work hard to protect your data, we cannot guarantee absolute security against every threat.
17. Changes to This Policy
We may update this policy as our products and legal obligations evolve.
| Change Type | Notification |
|---|---|
| Material changes (new purposes, new sharing, reduced rights) | Prominent notice on website + email to registered users (where practical) |
| Minor changes (clarifications, contact updates) | Updated "Effective Date" at top of policy |
| New product launch | Policy updated at launch; in-product notice for affected users |
Version history available on request. The "Effective Date" at the top shows the latest revision.
18. Governing Law, Jurisdiction & Contact
Legal Framework
This policy is governed by Dutch and EU law, including:
- GDPR 2016/679
- Telecommunicatiewet (ePrivacy implementation)
- Burgerlijk Wetboek Boek 6 (consumer rights)
- EU Directive 2011/83/EU (consumer rights)
Disputes
Disputes fall under the courts of 's-Gravenhage (The Hague), The Netherlands.
EU ODR Platform: ec.europa.eu/consumers/odr
Contact Us
| Channel | Details |
|---|---|
| Data Protection / Privacy | info@admun.eu • chishty@admun.eu |
| Data Subject Requests | Use mailto links in Section 14 |
| Postal Address | Oudemansstraat 315, 2522SW 's-Gravenhage, The Netherlands |
| KVK | 84121998 (Eenmanszaak) |
| Supervisory Authority | Autoriteit Persoonsgegevens |
| EU ODR | ec.europa.eu/consumers/odr |
Related Legal Documents
Terms & Conditions | Cookie Policy | Terms of Service | Disclaimer | Legal Imprint
© 2026 AdMun / NetherlandsIT — KVK 84121998 — VAT NL003915624B42 — registered in The Netherlands.
Privacy & GDPR Policy v3.0 — Effective 27 September 2026