Privacy Statement

The Privacy Boutique is a specialised consultancy firm in the fields of Data Privacy, Artificial Intelligence (AI), and Digital Ethics. We support organisations through, among other services, the provision of interim Privacy Officers and Data Protection Officers (DPOs), the performance of GDPR and AI maturity assessments, the delivery of tailored advisory services, and our Privacy Concierge service.

In this Privacy Statement, we explain how The Privacy Boutique collects, uses, shares, and otherwise processes personal data in connection with the services we provide. We also inform you of your rights regarding the processing of your personal data.

For the services and activities described in this Privacy Statement, The Privacy Boutique acts as the data controller within the meaning of the General Data Protection Regulation (GDPR). The Privacy Boutique is established in Oostzaan, the Netherlands, and can be visited at Tuinstraat 133, Amsterdam, the Netherlands. We can be contacted by email at info@theprivacyboutique.com or by telephone at +31 6 [telephone number]. The Privacy Boutique is registered with the Dutch Chamber of Commerce (Kamer van Koophandel) under registration number [number].

Personal Data, Purposes of Processing, Legal Bases, and Recipients

The categories of personal data processed by The Privacy Boutique depend on the nature of the services we provide to you. In any event, we process contact details, such as your name, email address, and telephone number. We process this information to communicate with you, provide our services, and fulfil our contractual obligations.

In addition, we process the information you provide to us in connection with an advisory assignment, or other services. This information is processed in light of the performance of the contract between you and The Privacy Boutique and, where applicable, on the basis of our legitimate interests in providing our services in a careful, effective, and professional manner.

For invoicing and financial administration purposes, we also process relevant financial information, including bank account details. This processing is necessary for the performance of the contract and to comply with our legal obligations relating to accounting, administration, and taxation.

Where necessary to comply with our administrative and tax obligations, personal data may be shared with our accountant. Such data is processed solely for the purposes of maintaining our financial records and complying with applicable legal obligations, including tax reporting requirements.

The Privacy Boutique does not use cookies on its website. Consequently, we do not collect personal data through cookies, process IP addresses for tracking purposes, or monitor visitors' use of our website.

The Privacy Boutique has deliberately chosen a European, digitally sovereign service provider. Personal data processed in connection with our website and email services is stored and processed exclusively in data centres located in Switzerland and/or the European Economic Area (EEA). We endeavour not to transfer or otherwise process personal data outside the EEA or countries that have been recognised by the European Commission as providing an adequate level of data protection, unless appropriate safeguards have been implemented in accordance with the GDPR.

Automated Decision-Making and Profiling

The Privacy Boutique does not use automated decision-making and does not engage in profiling when processing personal data. Personal data is not used to make automated decisions, perform automated analyses, or create profiles relating to individuals' personal preferences, behaviour, reliability, performance, or other characteristics.

Any decisions relating to our services are always made with meaningful human involvement and assessment.

Data Subject Rights

Pursuant to Articles 15 to 22 of the General Data Protection Regulation (GDPR), you have a number of rights in relation to your personal data. These include the right of access, rectification, erasure, restriction of processing, data portability, and the right to object to the processing of your personal data.

If you wish to exercise any of these rights, you may contact us at info@theprivacyboutique.com. If you believe that The Privacy Boutique is processing your personal data in breach of the GDPR, you have the right to lodge a complaint with the competent supervisory authority. For more information, please refer to the website of the Dutch Data Protection Authority (Autoriteit Persoonsgegevens).

Retention Periods

We retain your personal data only for as long as necessary to comply with applicable legal and regulatory requirements, to provide our website and services, to conduct our business operations, or to fulfil the purposes for which the personal data was collected.

Security Measures

The Privacy Boutique implements appropriate technical and organisational measures to protect your personal data against loss, misuse, unauthorised access, unauthorised disclosure, and unlawful alteration.

To ensure the security of data transmitted via our website, The Privacy Boutique uses encryption.

In addition, we contractually require third parties that process personal data on our behalf to implement appropriate technical and organisational security measures and to maintain privacy and security standards that are at least equivalent to those applied by The Privacy Boutique.

Changes

We reserve the right to amend this Privacy Statement at any time. Any changes will be published on this page. We encourage you to review this Privacy Statement periodically to stay informed of any updates.

This Privacy Statement is effective as of August 2026.

Search