Privacy Statement.
ONE Risk Advisory B.V. processes personal data for advisory work, engagement delivery and relationship management. We do so as little as possible, only where necessary for the work you entrust to us, and always in accordance with the General Data Protection Regulation (GDPR). Below you can read which data we process, why, for how long and how you can exercise your rights.
We process as little personal data as possible and only for the purposes described in this statement. You remain in control of your own data at all times.
Controller
The controller for the processing of personal data via this website and our services is:
- Legal entity
- ONE Risk Advisory B.V.
- Visiting address
- Burgemeester Stramanweg 105, 1101 AA Amsterdam, the Netherlands
- Chamber of Commerce
- 54158303
- Phone
- +31 88 3303 100
We have not appointed a statutorily mandatory Data Protection Officer. Questions about privacy and data processing go to h.v.everdingen@oneriskadvisory.nl. You will receive a personal reply from Hans van Everdingen within five business days.
Which data do we process
We process only data that you actively provide to us yourself, or that is necessary for the performance of an agreement or for ordinary business contact. In practice this concerns the following categories:
- Contact data, name, job title, employer, email address, phone number, postal address where relevant.
- Correspondence, messages via the contact form, email and LinkedIn, plus notes we make before or after a conversation.
- Engagement data, documentation that you supply to us in the context of an advisory, audit or EQA engagement. This in principle does not include personal data of your employees; where this is unavoidable (for example interview notes), we make separate arrangements in a data-processing agreement.
- Invoicing data, data needed for quotations, invoices and payments.
- Application data, CV, motivation, contact data and interview notes if you apply for a position.
- Technical data, webserver log files (IP address, browser, page requested, timestamp) and cookie data (see cookie statement).
We do not process special categories or criminal-conviction personal data unless this is unavoidable for a specific engagement and prior written arrangements have been made.
Purposes and legal bases
We process personal data only for the following purposes, each time on the basis of one of the six legal bases set out in Article 6 GDPR:
| Purpose | Categories | GDPR legal basis |
|---|---|---|
| Responding to a contact form or email | Contact · correspondence | Consent (Art. 6(1)(a)) or legitimate interest (Art. 6(1)(f)) |
| Issuing a quotation and concluding an agreement | Contact · invoicing | Performance of contract (Art. 6(1)(b)) |
| Execution of advisory, audit or EQA engagement | Engagement · correspondence | Performance of contract (Art. 6(1)(b)) |
| Invoicing and bookkeeping | Invoicing | Legal obligation (Art. 6(1)(c)), fiscal retention duty |
| Sending substantive newsletters and invitations | Contact | Consent (Art. 6(1)(a)), opt-in, opt-out per message |
| Application procedure | Application | Pre-contractual measures (Art. 6(1)(b)) |
| Security and proper functioning of the website | Technical · cookies | Legitimate interest (Art. 6(1)(f)) |
| Analytical insight into website use (aggregated) | Technical | Consent (Art. 6(1)(a)) for non-essential cookies |
We do not use personal data for profiling, automated decision-making or resale to third parties.
Recipients and processors
We share personal data only with parties that carry out a specific task on our behalf as processor, and only on the basis of a data-processing agreement in accordance with Article 28 GDPR. The following categories are in principle relevant:
- Hosting party, for the website and mail servers. EU-based.
- Office automation, email, calendar, document storage (Microsoft 365). EU data centres.
- Bookkeeping, for the administrative processing of invoices and payments.
- Accountant and legal counsel, insofar as necessary in connection with an engagement or annual accounts.
- Newsletter platform, exclusively for subscribers who have explicitly given their consent.
A current overview of our sub-processors with country of establishment is available on request via h.v.everdingen@oneriskadvisory.nl. We do not share data with parties that use it for their own purposes.
Retention periods
We do not retain personal data for longer than is necessary for the purposes for which it was collected, or than is legally required. The guidelines we apply:
| Category | Retention period | Reason |
|---|---|---|
| Contact-form enquiries not leading to an engagement | 12 months | Possible follow-up, deleted thereafter |
| Correspondence around active engagements | Engagement term + 7 years | Fiscal retention duty · engagement file |
| Engagement files (substantive) | 7 years after completion | Statutory retention duty · professional standards |
| Invoices and payment information | 7 years | Fiscal retention duty (Art. 52 AWR, Dutch tax law) |
| Application data of non-hired candidates | 4 weeks · 1 year with consent | NVP application code (Dutch industry standard) |
| Newsletter subscription | Until unsubscription | Consent · opt-out per message |
| Server logs | 30 days | Security and debugging |
| Analytical cookies (aggregated) | 14 months | Per Google Analytics 4 default |
Security
We take appropriate technical and organisational measures to secure personal data:
- Encrypted connections (TLS 1.2 or higher) for all web and email traffic.
- Multi-factor authentication (MFA) on all accounts with access to personal data.
- Encrypted storage on workstations (BitLocker / FileVault) and in cloud storage.
- Data-minimisation principle: engagement files do not contain personal data of the client’s employees unless strictly necessary.
- Periodic awareness training for all partners and staff.
- Strict access control on a ‘need-to-know’ basis.
- Independent annual penetration test of the website infrastructure.
Data breaches
If, despite these measures, a possible data breach occurs, we apply the following procedure:
- Establish the facts and scope within 24 hours.
- Assessment of risk for data subjects.
- For a notifiable breach: report to the Dutch Data Protection Authority within 72 hours.
- Where there is a high risk to data subjects: direct notification to the persons affected.
- Internal evaluation and adjustment of measures to prevent recurrence.
Do you suspect a data breach or an unsafe processing activity? Send a message directly to h.v.everdingen@oneriskadvisory.nl.
Transfers outside the EEA
We aim to process personal data exclusively within the European Economic Area. Where this is not practicable, for example when using US-based SaaS suppliers, we base the transfer on one of the statutory exceptions:
- An adequacy decision of the European Commission (for example the EU-US Data Privacy Framework).
- Standard Contractual Clauses (SCCs) of the European Commission, supplemented by additional measures where necessary.
Your rights
Under the GDPR you have the following rights with regard to your personal data:
- Right of access, you can request which personal data we process about you.
- Right to rectification, you can have inaccurate or incomplete data corrected.
- Right to erasure, you can request deletion, subject to statutory retention duties.
- Right to restriction, you can have processing restricted, for example during a pending objection.
- Right to data portability, you can request data you provided to us in machine-readable form.
- Right to object, against processing on the basis of legitimate interest.
- Right to withdraw consent, insofar as processing is based on consent, without affecting the lawfulness of earlier processing.
A request can be submitted via h.v.everdingen@oneriskadvisory.nl citing “GDPR request”. We will respond within four weeks of receipt. For verification we may ask for additional identification.
Complaints
Do you have a complaint about how we handle your personal data? We would be glad to discuss it with you directly first. You also have the right at any time to lodge a complaint with the supervisory authority:
- Supervisor
- Autoriteit Persoonsgegevens (Dutch Data Protection Authority)
- Postal address
- Postbus 93374, 2509 AJ Den Haag, the Netherlands
Cookies
We use cookies and similar techniques on this website in three categories. For non-essential categories we ask for your consent first via the cookie banner. You can change your choice at any time via Cookie settings in the footer.
| Category | Purpose | Retention | Legal basis |
|---|---|---|---|
| Necessary | Session ID, language preference, storage of your cookie choice, basic security | Session up to 12 months | Legitimate interest (Art. 6(1)(f) GDPR) |
| Analytics | Aggregated statistics on page views and visit duration. No personal profiles, no cross-site tracking | 14 months | Consent (Art. 6(1)(a) GDPR) |
| Marketing | Currently unused. We do not run advertising or behavioural tracking | n/a | Consent (Art. 6(1)(a) GDPR), if ever introduced |
Your cookie choice is stored locally on your device under the key one_cookie_consent_v1 in localStorage. This storage is anonymous and is not sent to our servers. You can clear it via your browser or via the “Cookie settings” link in the footer.
Changes
We may amend this privacy statement when legislation, case law or our services give cause to do so. Substantive changes will be announced at least two weeks before they take effect via a notice on this page. The date of the last change is shown in the summary below.
A question about your data ?
Send us a message. You will receive a personal reply from Hans van Everdingen within five business days, no ticket number, no automated follow-up.
Direct contact
- Contact person
- Hans van Everdingen
- General
- +31 88 3303 100
- Address
- Burg. Stramanweg 105
1101 AA Amsterdam - Response time
- 5 business days