We take the handling of data and your personal information seriously. That is why we handle it with care.
Last updated: July 9, 2026
At Pegamento B.V., we believe it is important to handle personal data with care. We process personal data only when necessary, do so securely, and are transparent about how we use that data.
In this privacy statement, we explain what personal data we process, why we do so, the legal basis for our processing, how long we retain the data, and what rights you have.
Pegamento B.V. is responsible for the processing of personal data as described in this privacy statement.
Pegamento B.V.
Arnhemse Bovenweg 160
3708 AH Zeist
Netherlands
Phone: +31 (0) 88 0067180
Email: [email protected] / CISO: [email protected]
Chamber of Commerce number: 32106184
VAT number: NL814286495B01
When we refer to “Pegamento,” “we,” “us,” or “our” in this privacy statement, we mean Pegamento B.V.
This privacy statement applies to everyone whose personal data Pegamento processes in the course of our business operations. This includes:
When Pegamento processes personal data on behalf of clients within client environments—for example, during the implementation, management, or support of customer contact, automation, or communication solutions—we do so in most cases as a processor on behalf of that client. In such situations, the client is the data controller, and the terms of the data processing agreement with that client apply.
Depending on your relationship with Pegamento, we may process the following personal data:
Contact and Identification Information
Website and Device Information
Contact and Application Information
Customer, contract, and billing information
Marketing and Event Information
Job Application Information
When you apply for a job at Pegamento, we may process the following information, among other things:
AppTime Data
For AppTime by Pegamento, depending on how the app is used, we may process the following data, among other things:
We do not request sensitive personal data, such as information about health, religion, political views, or criminal records, unless it is strictly necessary and permitted by law. We therefore ask that you not provide us with such information unsolicited via forms, email, or other communication channels.
We process personal data for the following purposes.
Contact and Communication
We use personal data to:
Legal basis: performance of a contract, steps taken prior to entering into a contract, legitimate interest, or consent.
Performance of Contracts
We process personal data in order to:
Legal basis: performance of a contract, legal obligation, and legitimate interest.
Sales, Customer Relationship Management, and Business Marketing
We process business contact information in order to:
We focus on business contacts. If you no longer wish to receive commercial communications, you can always unsubscribe or object.
Legal basis: legitimate interest or consent.
Newsletters and Email Marketing
When you subscribe to our newsletter or explicitly consent to receive marketing communications, we use your information to send you relevant updates, invitations, articles, or information about our services.
Every commercial email includes a way for you to unsubscribe.
Legal basis: consent or legitimate interest in existing business relationships.
Website Analysis and Improvement
We analyze the use of our website in order to:
To the extent possible, we use anonymized or aggregated data for this purpose.
Legal basis: legitimate interest or consent, depending on the type of cookie or analytics technique.
Events, Webinars, Training Courses, and the Academy
When you register for an event, webinar, training session, or Academy program, we process personal data in order to:
Legal basis: performance of a contract, legitimate interest, or consent.
Support and Services
When you contact support or when we provide support, we process personal data in order to:
Legal basis: performance of a contract and legitimate interest.
Job Applications
We process job application data in order to:
Legal basis: preparation for an employment contract, legitimate interest, and, where necessary, consent.
Security and Fraud Prevention
We process personal data in order to:
Legal basis: legitimate interest and legal obligation.
Legal obligations
We process personal data when necessary to comply with legal obligations, such as those related to record-keeping, tax laws, information security, or cooperation with competent authorities.
Legal basis: legal obligation.
For certain types of processing, we rely on our legitimate interest. We do so only after we have determined that our interest is proportionate to your privacy interests.
Our legitimate interests may include, among other things:
You may always object to processing based on legitimate interests. We will carefully review your objection.
Our websites use cookies and similar technologies. Cookies are small text files that are stored on your device when you visit our website.
We use cookies for various purposes. A complete overview of all the cookies we use is displayed when you first visit our website.
Functional cookies
These cookies are necessary for the website to function properly. Examples include cookies required for security, language preferences, form functionality, or remembering cookie preferences.
Consent is not required for functional cookies.
Analytical cookies
We use analytical cookies to track how visitors use our website. We use this information to improve our website.
If analytical cookies are configured to respect your privacy and have little or no impact on your privacy, we may place them without your consent. If analytical cookies have a greater impact on your privacy, we will ask for your consent in advance.
Marketing and Tracking Cookies
We use marketing and tracking cookies only if you give your consent. These cookies may be used to:
You can withdraw or change your consent at any time through the cookie settings on our website.
Google Analytics
We may use Google Analytics to gain insight into how our website is used. We configure Google Analytics to be as privacy-friendly as possible. This means, among other things, that wherever possible, we:
When Google or other providers process data outside the European Economic Area, we ensure that appropriate safeguards are in place.
AppTime is a division of Pegamento B.V. In addition to the general provisions in this privacy statement, the following additional provisions also apply to AppTime.
Access to device functions
AppTime only requests access to device features when it is necessary for the app to function or when you grant permission.
AppTime may request access to:
You can manage app permissions through your device’s settings.
Not for advertising purposes
AppTime does not contain any ads and does not use personal data for advertising purposes.
However, service providers may be engaged to support the technical operation of AppTime, for example for hosting, security, app distribution, push notifications, or technical support. We enter into appropriate agreements with parties that process personal data on our behalf.
We share personal data only when it is necessary for the purposes described in this privacy statement, when you have given your consent, or when we are legally required to do so.
We may share personal data with the following categories of recipients:
We enter into a data processing agreement with parties that process personal data on our behalf. In this agreement, we set forth provisions regarding security, confidentiality, retention periods, and the use of personal data. If you would like to know which parties we have entered into agreements with, please contact our CISO.
We do not sell personal data to third parties.
We strive to process personal data within the European Union or the European Economic Area as much as possible.
Some suppliers or sub-processors may process personal data in countries outside the EU/EEA. When this occurs, we ensure that it takes place only on the basis of a valid data transfer mechanism, such as:
We do not retain personal data for longer than is necessary for the purpose for which we collected it, unless we are legally required to retain the data for a longer period.
We generally adhere to the following retention periods:
Category | Retention Period |
Contact requests without a subsequent agreement | No later than 1 year after the last contact |
Business CRM and Prospect Data | No later than 2 years after the last relevant contact, unless there is an active relationship or an objection is raised earlier |
Customer and Contract Information | During the term of the agreement and thereafter for as long as necessary for administrative purposes, to provide evidence, or to comply with legal obligations |
Financial and Tax Accounting | 7 years, in accordance with the statutory retention requirement |
Support and Service Requests | For as long as necessary for processing, contractual obligations, quality improvement, and evidence retention |
Newsletter Information | Until you opt out or withdraw your consent |
Event, Webinar, and Training Information | No later than 2 years after participation, unless longer retention is necessary for certification, record-keeping, or follow-up |
Job Application Information | Up to 4 weeks after the procedure is completed, or up to 1 year with your consent; you may withdraw your consent at any time |
Analytical data | Up to 26 months, unless shorter terms have been set |
Cookie Preferences | For as long as necessary to remember your preferences and in accordance with the settings of the cookie tool used |
Technical Log Files | For as long as necessary for security, error analysis, and abuse prevention |
When data is no longer needed, we delete or anonymize it.
We take appropriate technical and organizational measures to protect personal data against loss, misuse, unauthorized access, disclosure, and unauthorized alteration.
These measures include, among other things:
Pegamento is ISO 27001 and ISO 9001 certified. These certifications underscore our commitment to information security, quality, and a process-oriented approach.
Despite all security measures, a security incident may occur. In the event of a data breach, we carefully assess the potential consequences. If required by law, we report the data breach to the Dutch Data Protection Authority and/or to the individuals concerned.
We maintain an internal record of security incidents and data breaches.
Pegamento does not make decisions regarding individuals that are based solely on automated processing and that have legal effects or similarly significantly affect a person.
We can use automation to make processes more efficient, for example, for spam detection, security, website analysis, CRM follow-up, or categorizing requests. Human review remains an option when necessary.
Under the GDPR, you have various rights. You have the right to:
Would you like to exercise your rights? Please send a request to our CISO, [email protected], with the subject line “privacy request.”
To prevent abuse, we may ask for additional information to verify your identity. We generally respond to your request within one month. If a request is complex or if we receive multiple requests, we may extend this period by up to two months. In that case, we will notify you.
Withdrawing your consent does not affect any processing that was already lawfully carried out before you withdrew your consent.
When we send you marketing communications, you can always unsubscribe by clicking the unsubscribe link in the email or by contacting us.
If you object to direct marketing, we will stop using your personal data for that purpose.
If you feel that we are not handling your personal data with due care, please let us know. You can contact us via the following page: https://pegamento.nl/klacht/
You also have the right to file a complaint with the Dutch Data Protection Authority.
Our websites may contain links to third-party websites or platforms, such as LinkedIn, YouTube, Spotify, or other external services. When you click on these links, the privacy policy of that third party applies.
Pegamento is not responsible for how external websites or platforms handle personal data. We recommend that you review these parties’ privacy policies.
Our websites and services are not specifically aimed at children under the age of 16. We process personal data of minors only when necessary and when there is a valid legal basis for doing so, such as consent from a parent or legal guardian when required.
If you suspect that we are processing a minor’s personal data without valid consent, please contact us at [email protected]. We will then assess the situation and delete the data if necessary.
We may update this privacy statement if our services, laws, or data processing practices change. The most current version is always available on our website.
In the event of significant changes, we may actively notify you, for example, through our website or by email.
Do you have any questions about this privacy statement or about how Pegamento handles personal data? Please contact us:
Pegamento B.V.
Arnhemse Bovenweg 160
3708 AH Zeist
Phone: +31 (0) 88 0067180
Email: [email protected] / CISO: [email protected]
Chamber of Commerce: 32106184
Deepen your knowledge with Pegamento’s white papers.