1. Who we are
For the purposes of the EU General Data Protection Regulation ("GDPR"), the data controller for personal data collected through this website is:
- Name: Neil Clulow
- Trading as: Jeeves Software Development
- Address: Buitenom 26, 2821 BN Stolwijk, South Holland, Netherlands
- Contact: [email protected]
2. What data we collect
We only collect personal data that you actively send us, and basic technical data needed to operate the site.
Contact form submissions
When you submit the contact form on this site, we collect:
- Your name — so we know how to address you in our reply.
- Your email address — so we can respond to your enquiry.
- Subject and message — so we understand what you're asking.
Server access logs
Our hosting provider keeps short-term access logs containing your IP address, the page you requested, your browser user-agent string and the timestamp. These are used solely for security, abuse prevention, and debugging.
What we do not collect
At the time of writing, this website does not use third-party analytics, advertising trackers, or marketing pixels, and does not set any cookies. The Inter and Syne fonts used on this site are hosted directly from our own server — no requests are made to Google Fonts or any other third-party CDN. If we add any tracking, analytics, or cookies in future, this policy will be updated and your consent will be sought where the law requires it.
3. Why we process this data (legal basis)
- Contact form data — processed on the basis of our legitimate interest (Article 6(1)(f) GDPR) in responding to enquiries about our services, and your prior expectation of receiving a reply.
- Server logs — processed on the basis of our legitimate interest (Article 6(1)(f) GDPR) in keeping the site secure and available.
4. Who we share data with
We only share your data with the processors needed to operate the site and respond to you:
- Microsoft Corporation — the contact form sends an email via our Microsoft 365 mailbox. Microsoft acts as a sub-processor for the storage and delivery of that email. Microsoft's privacy terms apply to that processing.
- Our hosting provider — handles the technical delivery of the website. Server access logs are retained by them according to their own retention policy.
We do not sell, rent, or share your personal data with third parties for marketing or any purpose other than what is described above.
5. How long we keep your data
- Contact form messages — retained for as long as is reasonably necessary to respond to your enquiry and any subsequent correspondence. Where we enter into an engagement with you, related correspondence is kept for the duration of that engagement and any period required by law (for example, tax or accounting obligations). Other contact records are typically removed once they are no longer needed, generally no later than 24 months after our last contact.
- Server access logs — retained by our hosting provider in line with their own retention policy. We do not actively use these logs ourselves except where needed to investigate a security or abuse incident.
6. International transfers
Some of our processors (notably Microsoft) may transfer data outside the European Economic Area. Where this happens, the transfer is covered by the European Commission's Standard Contractual Clauses or an equivalent legal mechanism approved under Chapter V GDPR.
7. Your rights
Under the GDPR you have the right to:
- Access the personal data we hold about you (Art. 15)
- Rectify data that is inaccurate or incomplete (Art. 16)
- Erase your data ("right to be forgotten") (Art. 17)
- Restrict our processing of your data (Art. 18)
- Receive your data in a portable format (Art. 20)
- Object to processing based on legitimate interests (Art. 21)
- Not be subject to automated decision-making (Art. 22) — we don't do any.
To exercise any of these rights, email [email protected]. We aim to respond within 1 to 3 working days, and in any case no later than the one-month maximum required by Article 12 GDPR.
8. Right to lodge a complaint
If you believe our processing of your personal data violates the GDPR, you have the right to lodge a complaint with a supervisory authority. Our lead supervisory authority is the Autoriteit Persoonsgegevens (Dutch Data Protection Authority), reachable at autoriteitpersoonsgegevens.nl. You may also lodge a complaint with the data protection authority of the EU member state where you live, work, or believe the infringement occurred. A list of all EU supervisory authorities is available at edpb.europa.eu/about-edpb/about-edpb/members.
9. Security
We take reasonable technical and organisational measures to protect personal data against accidental or unlawful destruction, loss, alteration, unauthorised disclosure, or access, in line with Article 32 GDPR. These currently include serving the website exclusively over HTTPS, rate-limiting form submissions to prevent abuse, and delivering contact-form messages directly to a protected mailbox rather than storing them in a database. No system can be guaranteed to be completely secure; we encourage you to share only the information you consider reasonable in any unsolicited message.
10. Changes to this policy
We may update this policy from time to time to reflect changes in the services we use, the data we collect, or applicable law. The "Last updated" date at the top of this page reflects the most recent revision. Continued use of the website after a revision constitutes acceptance of the updated policy where the law permits this. We encourage you to review this page periodically.
11. Good faith and precedence of law
This Privacy Policy is provided in good faith and describes our personal data processing practices as of the "Last updated" date above. It does not constitute legal advice and is not intended to limit or override any rights you have under applicable law. Where any term of this policy conflicts with the GDPR, the Dutch Uitvoeringswet AVG (UAVG), or any other mandatory legal provision, the law prevails and your rights under that law are unaffected.