Privacy Policy

Last updated: 22 May 2026

This Privacy Policy explains how Arpacore B.V. ("Arpacore", "we", "us", or "our") collects, uses, and protects personal data when you visit arpacore.com (the "Website") or get in touch with us. We are committed to handling your personal data in accordance with the EU General Data Protection Regulation (GDPR) and the Dutch implementing legislation (Uitvoeringswet AVG).

1. Who we are

Arpacore B.V. is a software development agency registered in the Netherlands (KVK: 62627058), with its operating office at Coolsingel 65, 3012 AC Rotterdam, Netherlands (VAT: NL854893180B02). We are the data controller responsible for the personal data processed through this Website.

For any question about this policy or about how we handle your data, you can contact us at privacy@arpacore.com.

2. What data we collect

We only collect personal data that you provide to us or that is strictly necessary to operate the Website:

  • Contact form data. When you submit our contact form, we collect your name, company name, phone number, email address, and the content of your message.
  • Usage and analytics data. If you consent to analytics cookies, we collect aggregated information about how you use the Website, such as pages visited, approximate location, device and browser type. See our Cookie Policy for details.
  • Technical data. Our hosting infrastructure may automatically log limited technical data (such as IP address and request timestamps) for security and operational purposes.

We do not knowingly collect special categories of personal data, and we do not collect data from children.

3. Why we use your data and the legal basis

We process your personal data for the following purposes:

  • To respond to your enquiries and provide the information or services you request. Legal basis: your consent and our legitimate interest in answering you (Art. 6(1)(a) and 6(1)(f) GDPR).
  • To improve the Website through analytics, where you have given consent. Legal basis: consent (Art. 6(1)(a) GDPR).
  • To keep the Website secure and operational. Legal basis: our legitimate interest in protecting our systems (Art. 6(1)(f) GDPR).
  • To comply with legal obligations where applicable. Legal basis: legal obligation (Art. 6(1)(c) GDPR).

We do not use your contact details for marketing purposes, and we do not sell your personal data.

4. Who we share your data with

We share personal data only with trusted service providers who process it on our behalf, under appropriate data-processing agreements:

  • Hosting and infrastructure providers that host the Website and process contact-form submissions.
  • Google LLC for website analytics, only where you have accepted analytics cookies.

We do not share your personal data with third parties for their own marketing purposes.

5. International transfers

Some of our service providers (including our hosting provider and Google) may process data on servers located outside the European Economic Area, such as in the United States. Where this happens, the transfer is protected by appropriate safeguards under the GDPR, such as the European Commission's Standard Contractual Clauses or an adequacy decision.

6. How long we keep your data

We keep personal data only for as long as necessary for the purposes described in this policy. Contact enquiries are retained for as long as needed to handle your request and for a reasonable period afterwards for record-keeping, after which they are deleted or anonymised. Analytics data is retained according to the retention settings of our analytics provider.

7. Your rights

Under the GDPR, you have the right to:

  • access the personal data we hold about you;
  • rectify inaccurate or incomplete data;
  • request erasure of your data ("right to be forgotten");
  • restrict or object to our processing;
  • data portability;
  • withdraw your consent at any time, without affecting the lawfulness of processing before withdrawal.

To exercise any of these rights, contact us at privacy@arpacore.com. You also have the right to lodge a complaint with the Dutch Data Protection Authority (Autoriteit Persoonsgegevens, autoriteitpersoonsgegevens.nl).

8. How we protect your data

We apply appropriate technical and organisational measures to protect your personal data against unauthorised access, loss, or misuse, including encrypted connections (HTTPS), access controls, and security headers. No method of transmission over the internet is fully secure, but we work to protect your data using industry-standard practices.

9. Cookies

This Website uses cookies and similar technologies. Analytics cookies are only activated with your consent. For full details, please read our Cookie Policy.

10. Changes to this policy

We may update this Privacy Policy from time to time to reflect changes in our practices or for legal reasons. The latest version will always be published on this page, with the "Last updated" date revised accordingly.