Privacy Policy – marXact B.V.

Last updated: 30 September 2026 (version 2.1)

Einführung

marXact takes your privacy seriously and handles your personal data with care. This Privacy Policy explains what personal data we process, why we process it, how long we keep it, and what rights you have under the EU General Data Protection Regulation (GDPR). We recommend you read this policy in full. If you have questions, contact us at privacy@marxact.com.

Wer ist marXact?

marXact B.V. (“marXact”, “we”, “us”) is the controller for the personal data we process about you. Where we process personal data contained in customer projects in the UNI-Cloud on behalf of a customer, we act as a processor under our agreement with that customer. The customer acts as the controller and is responsible for informing the individuals concerned about how and why their personal data is processed, including the use of UNI-Cloud to store and process that data.

Our primary customers are businesses (B2B), including sole traders (ZZP) and self-employed professionals. If you are a natural person acting on behalf of a business, this policy applies to you with respect to the personal data we process about you in that capacity.

What personal data we process

Depending on how you interact with us, we may process the following categories of personal data:

Account, customer, and order data: name, business name, business address, shipping address, billing address, email address, telephone number, role/job title, Chamber of Commerce number, VAT number, bank account number (IBAN/BIC), payment information, login credentials.

Service and product usage data: account activity, device identifiers, software version, operating system, IP address, support ticket history, measurement data and locations associated with your account (UNI-Cloud), service performance logs.

Communication and support data: name, email address, phone number, content of messages, calls, complaints, and support requests.

Marketing data: name, email address, telephone number, company, role, communication preferences, click and open behaviour in marketing emails, website browsing behaviour (where consented).

Job application data: name, contact details, CV, cover letter, references, assessment results, application correspondence.

Website visitor data: IP address, browser type, operating system, pages visited, referrer URL, approximate location, interactions with forms or chat.

We do not knowingly collect data from children under 16. We do not process special categories of data (such as health, racial or ethnic origin, religious beliefs).

Why we process your data, and on what legal basis

PurposeLegal basis (Art. 6 GDPR)
Concluding and performing your contract with us (orders, deliveries, subscriptions, support, accounts, UNI-Cloud service)Performance of contract (Art. 6(1)(b))
Invoicing, accounting, and tax administrationLegal obligation (Art. 6(1)(c)) – Dutch fiscal law (AWR Art. 52)
Customer relationship management (CRM), maintaining customer records, handling complaintsLegitimate interest (Art. 6(1)(f)) – to operate and improve our services
Direct marketing to existing customers about similar products/servicesLegitimate interest (Art. 6(1)(f)) – opt-out available in every email
Direct marketing to prospects (newsletters, campaigns)Consent (Art. 6(1)(a)) – opt-in via subscription form
Website analytics (functional and security)Legitimate interest (Art. 6(1)(f))
Website analytics and marketing cookies/pixelsConsent (Art. 6(1)(a)) via cookie banner
Recruitment and hiringPre-contractual measures (Art. 6(1)(b)) and consent (Art. 6(1)(a)) for retention beyond 4 weeks
Network and information security, fraud preventionLegitimate interest (Art. 6(1)(f))
Compliance with legal requests, defending legal claimsLegal obligation (Art. 6(1)(c)) and legitimate interest (Art. 6(1)(f))

For each “legitimate interest” basis, we have weighed our interest against your rights and freedoms. You have the right to object to processing based on legitimate interest (see “Your rights” below).

How long we keep your data

We do not keep your data longer than necessary. Specific retention periods:

KategorieRetention
Order, invoice, and tax records7 years after the end of the financial year (Dutch fiscal retention obligation, AWR Art. 52)
Contract and customer relationship recordsDuration of the contract + 5 years (Dutch civil law claim period, BW Art. 3:307)
CRM records of inactive customers7 years after last commercial contact, then deleted or anonymised
CRM records of inactive prospects (no commercial relationship)24 months after last contact, then deleted
Support tickets and complaint records5 years after closure of the ticket
UNI-Cloud account and measurement dataDuration of the subscription + 90 days after termination, then deleted (subject to user export)
Marketing email subscribersUntil unsubscribe, then removed within 30 days. Suppression list kept for compliance.
Marketing campaign engagement data24 months from last engagement
Website analytics (aggregated/anonymised)26 months
Website cookie data (consented marketing/tracking)Maximum 12 months, or until consent is withdrawn
Job applications – rejected candidates4 weeks after rejection (Dutch Sollicitatiecode), or up to 1 year with the candidate’s explicit consent
Job applications – hired candidatesMoved to employee file (separate retention applies)
Employee personnel recordsDuration of employment + 7 years (fiscal records) or + 5 years (other records)
Live chat transcripts6 months, or longer if linked to an open support case
Server and security logs12 months

Some retention periods are dictated by law and cannot be shortened. Where the law allows, we delete or anonymise sooner if the data is no longer needed.

Who receives your data

We share personal data with the following categories of recipients:

Within marXact: only employees who need access for their role (sales, support, finance, development, operations, management).

Service providers acting as data processors on our behalf: these are third parties who process your data only on our instructions, under signed Data Processing Agreements (DPAs) that meet GDPR requirements. We use processors for:

  • Cloud infrastructure and hosting (UNI-Cloud, website, internal systems)
  • CRM and sales (Pipedrive)
  • Email marketing (Outfunnel)
  • Customer support (HelpScout)
  • Webshop and payments (WooCommerce, Stripe, PayPal)
  • Accounting and finance (Yuki, O’Cliance)
  • HR administration and payroll (HoorayHR, O’Cliance)
  • Communication and collaboration (Microsoft 365, Slack, Atlassian/Jira and Confluence, Calendly)
  • Workflow automation (n8n)
  • Design tools (Canva, Figma)
  • AI tools used internally (see “AI-assisted processing” below)

A current list of our sub-processors is available on request via privacy@marxact.com.

Other recipients: shipping and logistics providers (for delivery of hardware), payment service providers (for payment processing), professional advisors (accountants, lawyers, auditors), regulatory and tax authorities where legally required, and prospective acquirers in the event of a corporate transaction (with appropriate confidentiality protections).

We do not sell your personal data to any third party.

International data transfers

Some of our service providers process data outside the European Economic Area (EEA). Where this is the case, we rely on appropriate safeguards under GDPR Chapter V:

  • EU-US Data Privacy Framework for certified US providers (where applicable)
  • Standard Contractual Clauses (SCCs) approved by the European Commission, supplemented by additional technical and organisational measures where needed
  • UK International Data Transfer Addendum (IDTA) where data flows touch the UK

Specific countries where our processors operate include the United States (Anthropic, Salesforce/Slack), Australia (Atlassian, Canva), and within the EU/EEA (n8n – Germany; Pipedrive – Estonia; O’Cliance – Netherlands). Data we store in Atlassian Jira and Confluence is stored in the EU (Germany), and our Slack data is stored in the EU (Frankfurt, Germany). The providers themselves are based outside the EEA.

You can request a copy of the relevant transfer safeguards at privacy@marxact.com.

AI-assisted processing

marXact uses approved AI tools internally to support tasks such as drafting communications, analysing business data, summarising information, and automating workflows. When your personal data is part of the context for such a task (for example, your name and email address when we draft a reply to you), that data may be processed by the following AI providers:

ProviderToolStandort
AnthropicClaude (Chat, Cowork, Code)USA
AtlassianRovo (AI in Jira and Confluence)Data stored in the EU (Germany); AI processing by Atlassian’s model providers
n8n GmbHn8n AI Agent nodesGermany (EU)
PipedrivePipedrive AIEstonia (EU)

All of these providers act as data processors on our behalf under Data Processing Agreements. None of them use your personal data for AI model training under our business terms. marXact applies a strict data minimisation rule: we only share the personal data necessary for the specific task. Bulk customer databases are never uploaded to AI tools. Project data that customers store in UNI-Cloud is only processed with AI tools after names, user identifiers, photos of people and address or owner details have been removed; object coordinates and technical measurement data may be used to resolve support or development questions.

We do not use AI to make automated decisions that produce legal or similarly significant effects on you. AI output that is sent to you (for example, a support response) is reviewed by a marXact employee before it is sent.

This processing is based on our legitimate interest in operating our business efficiently. You have the right to object to this processing – see “Your rights” below.

Cookies and similar technologies

Our website uses cookies and similar technologies. We distinguish between:

  • Strictly necessary cookies (functional, security, load balancing) – placed without consent, as they are essential for the website to function
  • Analytics cookies – placed only with your consent via the cookie banner
  • Marketing and tracking cookies (including retargeting and social media pixels) – placed only with your consent

You can manage your cookie preferences at any time via the cookie banner. Withdrawing consent does not affect previous lawful processing. Strictly necessary cookies cannot be refused, but they do not track you across websites.

A list of the cookies we set, with their purpose and duration, is shown in the cookie banner and is available on request via privacy@marxact.com.

Your rights

Under GDPR, you have the following rights:

  • Right of access (Art. 15): obtain a copy of the personal data we hold about you.
  • Right to rectification (Art. 16): have inaccurate or incomplete data corrected.
  • Right to erasure / “right to be forgotten” (Art. 17): have your data deleted in defined circumstances.
  • Right to restriction of processing (Art. 18): have processing limited in defined circumstances.
  • Right to data portability (Art. 20): receive your data in a structured, commonly used, machine-readable format and transmit it to another controller.
  • Right to object (Art. 21): object to processing based on legitimate interest, including direct marketing (we will always honour an objection to direct marketing).
  • Right not to be subject to a decision based solely on automated processing (Art. 22): see “Automated decision-making” below.
  • Right to withdraw consent (Art. 7): where processing is based on consent, you can withdraw it at any time.

How to exercise your rights: send a request to privacy@marxact.com. We may ask you to verify your identity to make sure we do not disclose data to the wrong person. We will respond within one (1) month of receiving your request. If your request is complex or we receive many requests, we may extend this by a further two months and will inform you in that case.

If we reject your request, we will explain why and inform you of your right to lodge a complaint with a supervisory authority.

Automated decision-making

marXact does not make decisions about you that are based solely on automated processing and that produce legal effects on you or similarly significantly affect you. Where automation supports our work (for example, AI-assisted drafting, lead scoring, or fraud screening), the final decision is always taken by a person at marXact.

Security

We apply appropriate technical and organisational measures to protect your personal data against unauthorised access, loss, alteration, or disclosure. Measures include encryption in transit (TLS) and at rest, role-based access controls, multi-factor authentication, secure development practices, vendor due diligence, and incident response procedures. We require our processors to apply equivalent standards.

If a data breach occurs that is likely to result in a risk to your rights and freedoms, we will notify the Dutch Data Protection Authority (Autoriteit Persoonsgegevens) within 72 hours, and we will inform you directly where the breach is likely to result in a high risk to you.

How we obtain your data

We obtain your personal data:

  • Directly from you – when you contact us, place an order, request a demo, sign up for a newsletter, apply for a job, or use our products.
  • From your employer or a colleague – when they provide your business contact details to set up an account or arrange a service.
  • From third-party sources where you have made data publicly available – for example, business contact information from LinkedIn or company websites used for B2B sales outreach (under our legitimate interest).
  • From our partners – referrals, integrators, and resellers who pass on your details to provide a quote or service.

Changes to this Privacy Policy

We may update this Privacy Policy. The date at the top of this page indicates when the policy was last updated. Material changes will be communicated through our website and, where appropriate, by email to active customers. Previous versions are available on request.

Complaints

If you have a complaint about how we process your personal data, please first contact us at privacy@marxact.com so we can try to resolve it. You always have the right to lodge a complaint with the Dutch Data Protection Authority:

Autoriteit Persoonsgegevens
Postbus 93374, 2509 AJ Den Haag
Phone: +31 88 1805 250
Website: https://autoriteitpersoonsgegevens.nl

You can also contact the supervisory authority in the EU country where you live or work.


This Privacy Policy is governed by Dutch law. The English version is the leading version; translations are for convenience only.