Privacy Policy of Rivermark Digital B.V.
This Privacy Policy explains how Rivermark Digital B.V. (“we”, “us”, “our”), acting as data controller, collects, uses, shares, stores, and protects personal data in connection with our omnichannel-marketing services, website, communications, and related business activities.
1. Introduction and company information
Rivermark Digital B.V. is established in the Netherlands and operates in the field of omnichannel marketing. This Privacy Policy applies to personal data processed by us when you visit our website, contact us, use our services, subscribe to our communications, interact with our campaigns, or otherwise engage with us.
- Company name: Rivermark Digital B.V.
- Address: Keurenplein 41, 1069 CD Amsterdam, Netherlands
- Email: [email protected]
- Phone: +31 20 794 83 61
We process personal data in a careful and lawful manner, taking into account applicable privacy laws and principles such as transparency, purpose limitation, data minimization, accuracy, storage limitation, integrity, and confidentiality.
2. Data collection and processing
Depending on your relationship with us, we may collect and process the following categories of personal data:
- Identity data: name, job title, company name, and related identification details.
- Contact data: email address, phone number, postal address, and communication preferences.
- Communication data: messages, inquiries, requests, correspondence history, and call notes.
- Technical data: IP address, browser type, device information, operating system, log data, and cookie-related information.
- Usage data: pages visited, interactions with our website or emails, campaign engagement, click behavior, and response patterns.
- Marketing data: preferences, consent status, segmentation attributes, and campaign performance data.
- Contract and business data: service details, billing information, project records, and commercial correspondence.
- Any other information you choose to provide: for example through forms, surveys, meetings, or support requests.
We may collect personal data directly from you, from your organization, from publicly available sources, from our business partners, and through technical means such as cookies and similar technologies where permitted by law.
3. Purpose of data processing
We process personal data for the following purposes:
- to provide and manage our omnichannel-marketing services;
- to respond to questions, inquiries, and requests;
- to enter into, perform, and administer contracts;
- to maintain client and supplier relationships;
- to personalize and improve our website, services, and communications;
- to send newsletters, offers, or marketing materials where permitted;
- to analyze campaign performance and service effectiveness;
- to comply with legal obligations and regulatory requirements;
- to protect our rights, property, security, and operations;
- to detect, prevent, and investigate fraud, misuse, or unauthorized access;
- to manage internal administration, reporting, and record-keeping.
4. Legal basis for processing
We only process personal data when we have a valid legal basis. Depending on the context, our processing may be based on:
- Consent: where you have given clear consent, for example for certain marketing communications or optional cookies;
- Performance of a contract: where processing is necessary to provide requested services or take steps at your request before entering into a contract;
- Legal obligation: where processing is necessary to comply with applicable laws, tax rules, or regulatory duties;
- Legitimate interests: where processing is necessary for our legitimate business interests, such as business development, security, service improvement, and marketing analytics, provided these interests do not override your rights and freedoms.
Where required by law, we will obtain your consent before processing personal data. You may withdraw consent at any time, as described below.
5. Data sharing and third parties
We may share personal data with third parties only where necessary and appropriate for the purposes described in this Privacy Policy. These third parties may include:
- Service providers: hosting providers, IT support, cloud services, CRM systems, analytics providers, email delivery services, and other technology vendors;
- Business partners: agencies, suppliers, subcontractors, and channel partners involved in delivering our services;
- Professional advisers: lawyers, accountants, auditors, consultants, and insurers;
- Authorities and public bodies: where required by law, court order, or lawful request;
- Prospective transaction parties: in connection with a merger, acquisition, restructuring, or sale of assets, subject to appropriate confidentiality safeguards.
We require third parties to handle personal data appropriately and, where applicable, in accordance with contractual safeguards and confidentiality obligations.
6. Data transfer to third countries
In some cases, personal data may be transferred to or accessed from countries outside the European Economic Area (“EEA”). Where this occurs, we will take steps to ensure that such transfers are carried out lawfully and with an adequate level of protection.
Appropriate safeguards may include, as applicable:
- an adequacy decision by the relevant authority;
- standard contractual clauses or equivalent transfer mechanisms;
- additional technical, organizational, and contractual safeguards;
- your explicit consent where legally permitted and necessary.
7. Storage duration
We keep personal data only for as long as necessary to fulfill the purposes for which it was collected, unless a longer retention period is required or permitted by law.
Retention periods may depend on factors such as:
- the nature of the relationship with you;
- contractual and legal obligations;
- tax, accounting, and regulatory requirements;
- the need to resolve disputes or enforce agreements;
- the duration of any applicable consent.
When personal data is no longer needed, we will delete, anonymize, or securely archive it in accordance with applicable requirements.
8. User rights
Subject to applicable law, you may have the following rights regarding your personal data:
- Access: to request confirmation of whether we process your personal data and obtain a copy;
- Rectification: to request correction of inaccurate or incomplete data;
- Erasure: to request deletion of your personal data in certain circumstances;
- Restriction: to request limitation of processing in certain situations;
- Data portability: to request transfer of data you provided to us in a structured, commonly used, machine-readable format, where applicable;
- Objection: to object to processing based on legitimate interests, and to direct marketing at any time.
To exercise your rights, please contact us using the details below. We may need to verify your identity before responding. We will respond within the time limits required by applicable law.
9. Withdrawal of consent
If we process your personal data based on consent, you may withdraw that consent at any time. Withdrawal does not affect the lawfulness of processing carried out before withdrawal.
You can withdraw consent by following the instructions provided in our communications, adjusting your preferences, or contacting us directly at [email protected].
10. Right to complain
If you believe that our processing of your personal data is not compliant with applicable law, you have the right to lodge a complaint with the competent supervisory authority. In the Netherlands, this is the Dutch Data Protection Authority (Autoriteit Persoonsgegevens).
We encourage you to contact us first so that we can try to resolve your concern directly and promptly.
11. Data security
We implement appropriate technical and organizational measures to protect personal data against unauthorized access, loss, alteration, disclosure, or destruction. These measures may include:
- access controls and role-based permissions;
- password protection and authentication measures;
- secure data storage and transmission practices;
- monitoring and logging of relevant systems;
- staff confidentiality obligations and training;
- vendor due diligence and contractual safeguards;
- regular review of security practices and incident response procedures.
Although we take reasonable steps to protect personal data, no method of transmission or storage is completely secure. We therefore cannot guarantee absolute security.
12. Contact information
If you have any questions, requests, or concerns regarding this Privacy Policy or the processing of your personal data by Rivermark Digital B.V., please contact us:
- Rivermark Digital B.V.
- Keurenplein 41, 1069 CD Amsterdam, Netherlands
- Email: [email protected]
- Phone: +31 20 794 83 61
13. Changes to privacy policy
We may update this Privacy Policy from time to time to reflect changes in our practices, services, legal requirements, or operational needs. Any updated version will be made available on our website with a revised effective date where appropriate.
We encourage you to review this Privacy Policy periodically to stay informed about how Rivermark Digital B.V. processes personal data.
Effective date: 17 July 2026