Privacy policy
Last updated: 18 September 2026
Certavo respects your privacy and processes personal data in accordance with the General Data Protection Regulation (GDPR). This policy explains which data we process, why, and what rights you have.
1. Data controller
The controller within the meaning of Article 4(7) GDPR is Raghoe Consulting (trading as Certavo), Chamber of Commerce (KvK) no. 83159290, correspondence address c/o IPCO Law B.V., Fascinatio Boulevard 216-220, 3065 WB Rotterdam, the Netherlands. Contact: info@certavo.nl.
2. Data protection officer
Certavo is not legally required to appoint a data protection officer (Article 37 GDPR) and has not done so. For privacy questions, please use the email address above.
3. Which data we process
We only process the data you provide to us yourself, such as your name, email address, company name and the content of your message when you contact us. Visiting this website does not collect any tracking or profiling data.
4. Purposes and legal bases
| Purpose | Data | Legal basis (GDPR) |
|---|---|---|
| Responding to your request/contact | Name, email, message | Art. 6(1)(b) (pre-contractual) / (f) (legitimate interest) |
| Performing an engagement | Contact and project data | Art. 6(1)(b) (contract) |
| Complying with legal obligations | Administration/invoicing | Art. 6(1)(c) (legal obligation) |
5. Automated decision-making
Certavo does not make decisions with legal effects based solely on automated processing or profiling within the meaning of Article 22 GDPR.
6. Our role as processor
When we configure AI agents on behalf of a client that process personal data from that client's systems, we act as a processor within the meaning of Article 28 GDPR. In that case the client is the controller and we record the arrangements in a data processing agreement. Processing takes place within the client's own Microsoft environment (tenant).
7. Security
We take appropriate technical and organisational measures to protect personal data against loss or unlawful processing, in accordance with Article 32 GDPR.
8. Data breaches
In the event of a data breach we act in accordance with Articles 33 and 34 GDPR and, where required, report it within 72 hours to the Dutch Data Protection Authority and, if necessary, to the data subjects.
9. Retention periods
We do not retain personal data longer than necessary for the stated purposes or than legally required (such as the tax retention obligation for administration).
10. Transfers outside the EEA
Our principle is processing within the European Economic Area. If any transfer outside the EEA does take place, it occurs only with appropriate safeguards in accordance with Articles 45 and 46 and Chapter V GDPR.
11. External services
This website uses no external services that collect personal data. Fonts are loaded locally (no Google Fonts), so no data is sent to third parties when you visit.
12. Your rights
Under Articles 15 to 21 GDPR you have the right to access, rectification, erasure, restriction, portability and objection. Where processing is based on consent, you may withdraw it at any time (Article 7(3) GDPR). We respond to your request within one month at the latest (Article 12(3) GDPR). Send your request to info@certavo.nl.
13. Complaint to the supervisory authority
If you disagree with how we handle your data, you have the right to lodge a complaint with the Dutch Data Protection Authority (Autoriteit Persoonsgegevens) (Article 77 GDPR).
Terms & conditions · Cookie policy · Company details · Nederlands