Haagsch Recherchebureau respects your privacy and attaches great importance to the protection of personal data. This privacy statement explains what data we process, for what purpose and on what legal basis. The statement applies to all services provided by Haagsch Recherchebureau.
1. Controller
Haagsch Recherchebureau, with its registered office at Alexanderveld 5, 2585 DB The Hague, registered with the Chamber of Commerce under number 74655736, is the controller within the meaning of Article 4 (7) GDPR.
We respect your privacy and handle your personal data carefully and confidentially. We comply with applicable privacy laws, including the General Data Protection Regulation. Our Data Protection Officer (DPO), with FG number FG0017215, supervises compliance with the GDPR and the AVG Implementation Act (UAVG). Do you have questions about this? Feel free to contact our Data Protection Officer (FG).
Contact details:
Haagsch Recherchebureau
Alexanderveld 5
2585 DB The Hague
070 20 42 7 42
fg@haagschrecherchebureau.nl
FG number: FG0017215
2. Personal Data
We process personal data that is necessary for carrying out our investigation, administrative and security purposes. This includes:
- name, address, date of birth and contact details;
- information about website usage and equipment;
- camera images when visiting office locations;
- other information that you actively provide, for example via email or telephone contact.
3. Purposes of processing
We process personal data for the following specific purposes:
- Carrying out private investigation assignments in accordance with the Private Security Organizations and Investigation Agencies Act (Wpbr), basis: legitimate interest, Art. 6 (1) (f) GDPR;
- Complying with legal obligations, such as the tax retention obligation — basis: Art. 6 (1) (c) GDPR;
- Executing agreements with clients — basis: Art. 6 (1) (b) GDPR;
- Ensuring the safety of our staff and clients via camera surveillance — basis: legitimate interest, Art. 6 (1) (f) GDPR;
- Sending newsletters (with your permission only) — basis: Art. 6 (1) (a) GDPR.
4. Legal basis for processing
Any processing of personal data takes place on one of the legal grounds in Article 6 GDPR. We only use the following principles:
- The person has given their explicit consent to the processing (Article 6 (1) (a) GDPR).
- Data processing is necessary to protect the legitimate interest of the controller or a third party to whom the data is provided, unless the interests or fundamental rights and freedoms of the person being investigated, in particular the right to privacy, prevail (Article 6 (1) (f) GDPR).
- Data processing is necessary to comply with a legal obligation to which the controller is subject (Article 6 (1) (c) GDPR).
- Data processing is necessary to protect the vital interests of the person being investigated or another natural person (Article 6 (1) (d) GDPR).
5. Retention periods
Personal data is not stored longer than necessary (Art. 5 (1) (e) GDPR):
- investigation files: maximum 5 years after completion;
- financial administration: 7 years (tax retention obligation);
- camera footage: maximum 4 weeks, unless incident investigation is required;
- other correspondence: maximum 1 year.
6. Sharing personal data
We only share personal data if this is necessary for the performance of our tasks or on the basis of a legal obligation (Art. 6 (1) (c) and (f) GDPR). Recipients can be:
- clients (where relevant);
- judicial authorities or supervisors;
- external experts or legal advisors under confidentiality.
A processing agreement is concluded with all processors in accordance with art. 28 GDPR.
7. Personal data security
We take appropriate technical and organizational measures to protect personal data against loss, misuse and unauthorized access (art. 32 GDPR). These include:
- Two-factor authentication (2FA): We use two-factor authentication to access our systems. This means that, in addition to a password, an additional verification step, such as a code on your mobile device, is also required to gain access.
- Single Sign-On (SSO): We use a Single Sign-On system, allowing employees to log in securely and efficiently with a single set of credentials for multiple applications, while their access is monitored and managed.
- Encryption (SSL): Sensitive information exchanged via our website is protected by Secure Sockets Layer (SSL) encryption. This ensures that data is transferred securely between your device and our servers.
- Data breach protocol: We have a strict data breach protocol that provides procedures for reporting, investigating and dealing with data breaches. If necessary, we will inform you and the Data Protection Authority in good time about a data breach, in accordance with legal requirements.
- Password protocol: We use a strict password protocol, where passwords must meet high security requirements, such as minimum length, complexity and regular renewal. Employees only have access to the systems and data that are necessary for their work.
- Access to data limited to authorized employees: Access to personal data is strictly limited to employees who are authorized to process that data. This is regulated through authorization management and the principle of minimal access, where employees only have access to the data they need for their specific tasks.
- Regular data protection checks: We carry out regular checks and audits to ensure that our data protection measures comply with the latest security standards and that there are no vulnerabilities in our systems. This helps us to continuously ensure the confidentiality, integrity and availability of your personal data.
Through these measures, we can guarantee the security of your personal data and ensure that it does not fall into the wrong hands or is processed unlawfully.
8. Rights
You have the rights as set out in chapter III GDPR (articles 15—22), including:
- Right to access, you can request a copy of the personal data we hold about you.
- Right to rectification, you can have incorrect or incomplete data corrected.
- Right to be forgotten, in certain cases, you can ask us to delete your personal data.
- Right to restrict processing, you can ask us to restrict the processing of your data in specific situations.
- Right to object, you can object to the processing of your data based on legitimate interests.
- Right to data portability, you can request that your data be received in a structured, commonly used and machine-readable format.
You can exercise your privacy rights through us AVG request form. To ensure that the request for inspection has been made by you, we ask you to perform an ID check.
If you are not satisfied with how your personal data is or has been processed by Haagsch Recherchebureau, you can make use of our legal obligations complaints procedure.
If your complaint has not been dealt with satisfactorily, you can contact the national supervisor, the Personal Data Authority.
We reserve the right to amend this privacy statement. You can always find the most current version on our website.