Certavo ← Back to home
← Home

Privacy policy

Last updated: 18 September 2026

Certavo respects your privacy and processes personal data in accordance with the General Data Protection Regulation (GDPR). This policy explains which data we process, why, and what rights you have.

1. Data controller

The controller within the meaning of Article 4(7) GDPR is Raghoe Consulting (trading as Certavo), Chamber of Commerce (KvK) no. 83159290, correspondence address c/o IPCO Law B.V., Fascinatio Boulevard 216-220, 3065 WB Rotterdam, the Netherlands. Contact: info@certavo.nl.

2. Data protection officer

Certavo is not legally required to appoint a data protection officer (Article 37 GDPR) and has not done so. For privacy questions, please use the email address above.

3. Which data we process

We only process the data you provide to us yourself, such as your name, email address, company name and the content of your message when you contact us. Visiting this website does not collect any tracking or profiling data.

4. Purposes and legal bases

PurposeDataLegal basis (GDPR)
Responding to your request/contactName, email, messageArt. 6(1)(b) (pre-contractual) / (f) (legitimate interest)
Performing an engagementContact and project dataArt. 6(1)(b) (contract)
Complying with legal obligationsAdministration/invoicingArt. 6(1)(c) (legal obligation)

5. Automated decision-making

Certavo does not make decisions with legal effects based solely on automated processing or profiling within the meaning of Article 22 GDPR.

6. Our role as processor

When we configure AI agents on behalf of a client that process personal data from that client's systems, we act as a processor within the meaning of Article 28 GDPR. In that case the client is the controller and we record the arrangements in a data processing agreement. Processing takes place within the client's own Microsoft environment (tenant).

7. Security

We take appropriate technical and organisational measures to protect personal data against loss or unlawful processing, in accordance with Article 32 GDPR.

8. Data breaches

In the event of a data breach we act in accordance with Articles 33 and 34 GDPR and, where required, report it within 72 hours to the Dutch Data Protection Authority and, if necessary, to the data subjects.

9. Retention periods

We do not retain personal data longer than necessary for the stated purposes or than legally required (such as the tax retention obligation for administration).

10. Transfers outside the EEA

Our principle is processing within the European Economic Area. If any transfer outside the EEA does take place, it occurs only with appropriate safeguards in accordance with Articles 45 and 46 and Chapter V GDPR.

11. External services

This website uses no external services that collect personal data. Fonts are loaded locally (no Google Fonts), so no data is sent to third parties when you visit.

12. Your rights

Under Articles 15 to 21 GDPR you have the right to access, rectification, erasure, restriction, portability and objection. Where processing is based on consent, you may withdraw it at any time (Article 7(3) GDPR). We respond to your request within one month at the latest (Article 12(3) GDPR). Send your request to info@certavo.nl.

13. Complaint to the supervisory authority

If you disagree with how we handle your data, you have the right to lodge a complaint with the Dutch Data Protection Authority (Autoriteit Persoonsgegevens) (Article 77 GDPR).

Terms & conditions · Cookie policy · Company details · Nederlands

© 2026 CertavoCoC 83159290