Privacy policy
TH WORKS
Last updated: 26 August 2026
This document sets out which personal data TH WORKS processes when you visit this website or get in touch, why, how long we keep it, and what rights you have. It describes this website as it actually works — not boilerplate about trackers that are not here.
1. Who is responsible
TH WORKS is the data controller for the processing described in this document.
- Company name: [to be supplied]
- Legal form: [to be supplied]
- Registered address: [to be supplied]
- Chamber of Commerce number: [to be supplied]
- VAT number: [to be supplied]
- General contact: hello@thworks.nl
- Privacy requests: hello@thworks.nl
Where a marker appears above instead of a detail, that detail has not been finalised yet. It will be filled in once registration is complete; we would rather leave a gap here than state something that later turns out to be wrong.
2. What personal data we process
Through the form on the project page we process only what you enter there yourself:
- your name
- your email address
- your company name, if you fill it in — that field is optional
- the content of your message
- the language of the page you sent the form from (nl or en)
If you would rather email us directly, we process whatever you put in that email. What goes in it is up to you; please do not send us data your question does not need.
In addition, the party hosting this website processes the technical data needed to serve a page: your IP address and ordinary server logs, such as the address requested, the time, the status code and the browser type. That is inherent to requesting a web page and happens on every website. The hosting party is [to be supplied].
We do not buy data, we do not enrich it from other sources, and we do not build profiles.
3. Why we process it
We use your data for these purposes and no others:
- to reply to your enquiry or your email
- to contact you about a possible project
- to prepare and carry out a quote or an agreement
- to meet administrative and legal obligations once you become a client
- to serve and secure the website technically
4. The legal basis
The GDPR requires a legal basis for every processing operation. For us there are four.
- Replying to your enquiry and preparing a quote: taking steps at your request before entering into a contract (Article 6(1)(b) GDPR).
- Carrying out work once you are a client: performance of the contract (Article 6(1)(b) GDPR).
- Keeping your email if you write to us directly, and serving and securing the website: our legitimate interest in being reachable and keeping the site working (Article 6(1)(f) GDPR).
- Keeping invoices and accounts: compliance with a legal obligation (Article 6(1)(c) GDPR).
We never ask you to consent to cookies, for the simple reason that we do not set any.
5. Cookies, analytics and trackers
This website sets no cookies. Not functional, not analytical, not advertising — and therefore no cookie banner either.
There is no Google Analytics or any other statistics package. There are no advertising or tracking pixels, no social media buttons or widgets, and no embedded third-party content — such as videos or maps — that could observe you.
Fonts are served from this website itself rather than fetched from an external font service. Opening a page therefore tells nobody else that you were here.
Storage in your own browser stays empty too: nothing is written to localStorage or sessionStorage.
This was verified on the website itself rather than assumed. Across a full page visit, zero cookies are set, browser storage stays empty, and every request goes to this website — without a single connection to an outside party.
6. Who we share data with
We do not sell your data, and we do not share it for advertising or marketing.
There are, however, parties that necessarily process data because they provide a service this website or our work depends on. We put a data processing agreement in place with such parties.
- Hosting: [to be supplied] — processes your IP address and server logs in order to serve pages.
- Email: [to be supplied] — processes the messages you send us and we send you.
- Accounts: our bookkeeper or accountant may see data that forms part of our administration, such as invoices. The Dutch tax authority may also request access where it is entitled to.
No external form service is in use. A submitted form is handled by the website itself on the hosting party's server; it does not pass through a form platform, and there is no separate database in which enquiries are stored.
7. Transfers outside the EEA
In principle we process personal data within the European Economic Area.
Whether that holds in full depends on the hosting and email providers: some store data in the EU but have components or support outside it. The current position is: [to be supplied]
Where a transfer outside the EEA does take place, it happens only on the basis of an adequacy decision of the European Commission or the European Commission's standard contractual clauses (SCCs).
8. How long we keep data
We do not keep data longer than necessary, and not everything for the same length of time.
- Enquiries and contact requests that do not lead to work: no longer than two years after the last contact.
- Correspondence around a project: until the project is finished, and after that for as long as needed to answer questions about it — as a rule no more than two years.
- Data forming part of our administration, such as invoices and order confirmations: seven years, because Dutch tax law requires it.
- Server logs at the hosting party: according to that party's retention period, typically weeks to months.
The seven-year period therefore applies to the administration, not to all correspondence. An email exchange that leads nowhere is not kept for seven years.
9. Security
We take appropriate technical and organisational measures to protect personal data against loss, misuse and unlawful processing.
These include encrypted connections to the website and to our email, access limited to those who need it for the work, and the principle of collecting as little as possible: data we do not hold cannot leak.
We deliberately do not describe our measures here in detail — doing so would not serve security.
10. Your rights
Under the GDPR you have the following rights.
- Access: to ask which personal data we process about you.
- Rectification: to have incorrect or incomplete data corrected.
- Erasure: to have your data deleted, insofar as we are not legally required to keep it.
- Restriction: to have processing paused, for example while we handle a rectification request.
- Objection: to object to processing based on our legitimate interest.
- Portability: to receive the data you supplied yourself in a common file format. This right applies to data we process on the basis of consent or a contract.
Send a request to hello@thworks.nl. We reply within one month as a rule. If a request is complex we may extend that by two months — we will tell you within the first month if we do.
We may ask you to make it plausible that you are who you say you are, so that we do not hand data to the wrong person.
If you disagree with how we handle your data, you can lodge a complaint with the Autoriteit Persoonsgegevens, the Dutch supervisory authority, at autoriteitpersoonsgegevens.nl.
11. Automated decision-making
TH WORKS does not take decisions based on automated processing that produce legal effects concerning you or similarly significantly affect you. No profiling takes place.
The form only checks whether the fields you filled in are complete and valid. That is a technical check on the form, not an assessment of you.
12. Changes
We update this privacy policy when the website or the way we work changes. The date at the top of this document says when that last happened.
There is no mailing list to notify you, because we do not have one. When in doubt, check this page.