Privacy notice
Clear, limited use of personal data.
This notice explains how DDQ B.V. handles personal data when someone visits ddq.nl, uses its public machine-readable interfaces or contacts DDQ. It does not replace the specific privacy and data-processing arrangements agreed for a customer project or operated service.
Controller: DDQ B.V., Kloosterweg 1, 6412 CN Heerlen, the Netherlands.
Privacy contact: [email protected] · +31 45 203 1008
Last updated: 2 September 2026.
Data handled on this public site
The public website has no advertising technology, behavioural analytics or public contact form. DDQ does not set tracking cookies on these pages. Like an ordinary web server, the infrastructure necessarily receives technical request data such as an IP address, date and time, requested path, response status, referrer when supplied, and browser or agent user-agent. DDQ uses that information to deliver requests, diagnose faults, protect the service, investigate abuse and understand aggregate operational load.
Requests to the public JSON API (/api/company.json and /status.json) are limited to 100 per client address per hour. A one-way representation of the client address and the current request count may be kept for the active rate-limit window. Ordinary security and server logs can be retained for longer when reasonably necessary to operate and protect the service, investigate an incident or meet a legal obligation. Access is restricted to people who need it for those purposes.
When you contact DDQ
If you email or telephone DDQ, we handle the contact details and content you provide, together with relevant follow-up correspondence. This may include your name, organisation, role, email address, telephone number and information about the proposed or existing work. We use it to answer the inquiry, evaluate fit, take requested steps before a contract, carry out a working relationship, keep appropriate business records and comply with applicable obligations. Please do not include patient information, passwords, private keys or other unnecessary sensitive data in an initial inquiry.
Purposes and legal bases
Depending on the context, DDQ processes these limited data because this is necessary to take steps at your request before entering into a contract, to perform a contract, to meet a legal obligation, or for legitimate interests in communicating with organisations and securely operating the website and business. Where a different basis is required, DDQ will explain it in the relevant context. DDQ does not sell personal data and does not use public-site request data for personalised advertising.
Sharing, infrastructure and transfers
DDQ operates this website on infrastructure under its control. Technical providers may still transmit or process limited data where this is necessary for internet connectivity, email delivery, security or professional services. Information may also be shared when required by law or needed to establish, exercise or defend legal claims. DDQ seeks appropriate contractual and technical safeguards when another party processes personal data on its behalf. Project-specific processors, locations and controls are addressed in the applicable project or service agreement.
Retention and security
Data is kept only for as long as reasonably needed for the purpose for which it was collected, ongoing correspondence or work, security and incident handling, applicable limitation periods, and statutory administration. Different records therefore have different retention periods. DDQ uses access controls, data minimisation, maintained systems and other proportionate organisational and technical measures. No internet service can promise absolute security; suspected vulnerabilities can be reported using the contact in security.txt.
Your rights
Under applicable data-protection law, you may have rights to access, correct or erase personal data, restrict or object to processing, and receive data in a portable form. Where processing depends on consent, you may withdraw that consent without affecting earlier processing. Rights can depend on the circumstances and may be limited by legal obligations or the rights of others. Send a request to [email protected]; DDQ may ask for information needed to verify identity before disclosing or changing data.
If a concern cannot be resolved directly, you may lodge a complaint with the Dutch supervisory authority, the Autoriteit Persoonsgegevens, or another competent data-protection authority. This notice may be updated when the site or applicable practices change; the date above identifies the current version.
Other sites and customer services
This site links to independent websites, research projects and DDQ-operated services. Their own notices apply when you follow those links or sign in to a service. For commissioned systems, DDQ may act as a processor while the customer remains controller; those roles, instructions, retention rules and safeguards are defined for that engagement rather than by this public-site notice.