Privacy statement Dataprovider
1. Privacy Statement
Dataprovider B.V. has its registered office at Van Elmptstraat 10, 9723 ZL in Groningen, the Netherlands. We are registered with the Chamber of Commerce under number 37142377 and active on the website www.dataprovider.com ("Dataprovider" or "we").
We need your personal data for the proper performance of our business activities and for providing services to our customers. It is important that you know what we do with your data, and how we protect your data from misuse by others. You can read all about that in this privacy statement. This privacy statement is valid from November 15, 2018.
Dataprovider, as the data controller, must comply with various regulations when processing your personal data. These regulations include:
- The EU General Data Protection Regulation
- The Dutch Telecommunications Act
2. How do we collect your data?
- Dataprovider requests data, including personal data from other sources. Our crawler only collects and processes data that are made publicly available on millions of webpages in different countries.
- We programmed our crawler in such a way that it observes the robot exclusion protocol. When such a robots.txt file on a website requests our web crawler to ignore specified files or directories when crawling a site, our web crawler will comply with the request.
- We do not access data that is protected by a log-in, security code, other technical measures, or that is otherwise secured.
- With the requested data, we index the web to create a database.
- We use third party sources to verify the data collected on the publicly available web, such as registration databases, trade registers and other publicly available websites.
- We use your publicly available data, so our customers could better tailor their services to you, and maybe offer you additional products. Our customers can create their own sets within our database of publicly available data. This dataset that is created by a customer, leads to a database which our customers can use to their advantage. This is what we call a record. Any decisions with legal consequences that are made by Dataprovider are never based solely on a record that is formed from data that have been processed automatically. The record is intended to help with decision-making, whereby the process always involves human beings.
3. Who is the data controller and who is the processor?
- Dataprovider is the data controller relating to indexing the web and processing of personal data in our database of your personal data and of our own customers personal data. Some of the personal data are processed by other companies. In those situations, we have concluded agreements regarding the processing of personal data by these companies.
- Dataprovider's customers are data controller relating to the processing of the personal data of their prospects, if they are the party that determines the purposes and means of the data processing.
- Dataprovider is the data processor when our customers ask us to process their data under their instructions.
This privacy statement explains how Dataprovider handles your personal data in its position as a data controller.
4. What do we use your data for?
We are an online service that crawls publicly available websites in many countries. We crawl and index the publicly available web and provide a platform to create data sets from the indexed and structured data that are useful for our customers. An example of a data set that can be created is: all websites in France that use WordPress and use Google Mail and changed their SSL certificate.
We crawl and index the publicly available web for the following purposes:
- Indexing and structuring the web to create a database for our customers. This purpose relates to our product "Public Data". The data involved consist of business information, website content, technical aspects, proprietary scorings such as Economic Footprint, Trust, Security and Heartbeat all related to the website and hosting properties.
- Indexing domain names to provide our customers with extensive information on the domain names provided by our customer. This purpose relates to our product KYC-Crawl, formerly named: Private Crawl. The data involved consist of business information, such as contact data, so our customers are able to reach out to the companies behind the domain names.
- Determining domain ownership information to our customers. This purpose relates to our product "Ownership". The data involved consist of the following: Whois name, Whois phone number, Whois address, Whois zip code, Whois city, Whois email address, Whois organisation, Company name, Phone number, Address, Zip code, City, Email address, Tax number, IBAN number, Business Registry number, Social media profiles, IP address, Analytics ID, Domain, Forwarding domains, Redirect hostname, DNS MX domain and DNS NS domain. In order to do this, customers are, for example, able to protect their intellectual property.
- Indexing and structuring the publicly available web to identify online brand abuses and bad actors for these activities for our customers. This purpose relates to our product "Brand Monitor". The data involved consist of the current and historical data of websites.
- Suggesting the perfect domain name for our customers. This purpose relates to our product "Domain Suggestions". The data involved consist of relevant domain names based on the website's content.
- Vacancies: a structured database with indexed vacancies.
- Places: a structured database with business contact information that is publicly available on the web.
- IP 2 Company a structured database with IP addresses in combination with business information that is publicly available on the web.
A data set will consist at least 200 variables. If you have made your business email address publicly available on the web, only two (2) of these variables will include your personal data: 1) your business email address (for example, chris@chrissmith.com) and 2) your name but only if your business name includes your name (www.chrissmith.com). When you register for our trail period, we use the data you give us, such as your name and email address for lead generation, marketing automation and to approach you with relevant offers.
5. What personal data do we process and why?
We need your personal data for the proper performance of our business activities and for providing services to our customers. We crawl and index the publicly available web to provide our customers with a search engine where they can create data sets that are useful for them. These data sets will include personal data, but only under the circumstances as described above. For example, we provide data to Statistics Netherlands (CBS), a national administrative body, for a report on Measuring the internet economy in the Netherlands. Show CBS Report
6. Who has access to your data?
Your personal data will be processed by our internal staff who are specifically trained and authorised to process it.
We only transfer your personal data to other companies, if your data are part of the data sets created by our customers. Our customers are responsible for the lawful use and processing of personal data in any further use made of these personal data in the data sets.
We may also transfer your personal data to the police and judicial and administrative authorities, in accordance with the law, for the detection and prosecution of crimes, the prevention and protection from threats to public security, to allow us to ascertain, exercise or defend a right in court, as well as for other reasons related to the protection of the rights and freedoms of others.
7. On what legal basis do we use your data?
We process your personal data pursuant to the following legal bases:
- The EU General Data Protection Regulation allows us to process personal data under the so called "legitimated interest". This means that we may use your personal data because this is necessary for the proper performance of our business activities and for providing services to our customers. We process your personal data in a reasonable way, while your privacy rights as an individual are respected because we are transparent about the processing that we do in this Privacy Statement and in product descriptions on our web site, because we have technical and organisational security measures in place to protect your data, because the personal data that we process does not include sensitive data and, are business related. Also because we only obtain the data from publicly available sources. In addition, based on the subsidiarity principle that applies under the EU General Data Protection Regulation, there is no reasonable alternative way that is more privacy friendly.
Also, you have the option to use robot.txt on your web site to indicate that you do not want your data to be indexed from the publicly available web. In that case, we cannot process your personal data.
- Dataprovider must comply with legal requirements based on the law. These may be related to taxes, sanction legislation, debt, attachments, the prevention of money laundering, financing of terrorism and fraud.
- In the event you have given us your consent for receiving newsletters. Providing your consent for these activities is optional. You are free to give your consent or not. But without your consent, it will not be possible to receive information about our services.
8. What are your rights?
Rights with respect to the processing of personal data
You have the right to view and change the personal data that we have collected from you. You have the right to object to the processing of your personal data. In certain cases, you can also ask us to limit the processing of your personal data, erase your data, transfer your data to another data controller or have it deleted. If you wish to do any of these, please send a request to our Privacy Officer: privacy.officer@dataprovider.com and indicate that it concerns a personal data request.
Please enclose a copy of your identity document so that we can be sure that you are the person submitting the request. Make sure that you black out your passport photograph and citizen service number. This is to protect your privacy. Also provide your private address. You will receive an overview of your data or a response to your request within one month of your request.
Do Not Sell My Personal Information - California
If you are a California resident, you have the right to tell us to not sell your personal information. If you wish to do this, please send a request to our Privacy Officer: privacy.officer@dataprovider.com and indicate that it concerns a Do Not Sell My Personal Information – California request. Requests must be made by or on behalf of a current resident of California. Please state the following and we will make sure we do not sell your personal information:
- your first and last name
- your address in California, including the ZIP code and the city
- your email
Consent
If you have given your consent for us to process your personal data, you can withdraw this consent at any time by clicking the "unsubscribe" link at the bottom of each email or by sending a letter to our Privacy Officer at the address below under contact details.
Right to make a complaint
You can make a complaint about the processing of your personal data. If Dataprovider does not meet your request for access, correction, objection, restriction, deletion or transfer of your personal data, you can submit a complaint with the Data Protection Authority in your country. If you are not happy with how the complaint is resolved, you can lodge an appeal with the courts.
9. Security of your personal data
Dataprovider takes the protection of your data very seriously. We take measures to prevent misuse, loss, unauthorised access, unwanted disclosure and unauthorised changes to your data. The measures we take meet the general data security requirements. We have made agreements about this with the processors and regularly evaluate the measures taken and, if necessary, we will adjust them.
10. What are your risks?
We do not have control over your personal data after we have provided our customers with data sets, which may include your personal data. This could imply that these customers may send you unsolicited, usually commercial, messages. If you are not interested in these messages, you can always file a complaint about the processing of your personal data with the company that send you the unsolicited emails or offer. If they do not meet your request for access, correction, objection, restriction, deletion or transfer of your personal data, you can file a complaint with the Data Protection Authority in your country.
11. Data Retention
For many types of data, the minimum retention periods are the statutory time periods. If there is no statutory period, Dataprovider stores the data insofar as necessary to provide its services.
12. Processing outside the European Economic Area
For technical and operational reasons, it may be necessary to transfer your personal data to countries outside the European Economic Area. We will ensure proper data protection. We use European model contracts (Standard Contractual Clauses) for processing outside the European Economic Area. For transfer to USA, as valid transfer mechanism, we may also use the EU-US Data Privacy Framework, but only if the US company participates in and has certified its compliance with the EU-U.S. Data Privacy Framework. Such US company is then committed to subjecting all personal data received from European Union (EU) member countries in reliance to the Data Privacy Framework applicable principles. To learn more about the Data Privacy Framework, visit the U.S. Department of Commerce’s EU-US Data Privacy Framework participant list at: https://www.dataprivacyframework.gov/s/participant-search. A company that is certified under the EU-US Data Privacy Framework is responsible for the processing of personal data it receives under the EU-US Data Privacy Framework, and for subsequent transfers to a third party acting as an agent on its behalf. A company that is certified under the EU-US Data Privacy Framework complies with the EU-US Data Privacy Framework principles for all onward transfers of personal data from the EU, including the onward transfer liability provisions. With respect to personal data received or transferred pursuant to the EU-US Data Privacy Framework, a company that is certified under the EU-US Data Privacy Framework is subject to the regulatory enforcement powers of the US Federal Trade Commission. In certain situations, a company that is certified under the EU-US Data Privacy Framework may be required to disclose personal data in response to lawful requests by public authorities, including to meet national security or law enforcement requirements. If you have an unresolved privacy or data use concern, please contact us so we will able to help you. Under certain conditions, you may be entitled to use the independent and impartial redress mechanism, which includes a US Data Protection Review Court to investigate and resolve complaints regarding access to your data by US national security authorities when other dispute resolution procedures have been exhausted.
13. Questions and contact
If you have any questions about the way we handle your personal data, please contact the Privacy Officer of Dataprovider. Send your email to privacy.officer@dataprovider.com or send a letter to:
Privacy Officer DataproviderVan Elmptstraat 10
9723 ZL Groningen
The Netherlands
14. We use cookies on our websites
Cookies are small text files that are automatically placed on your computer, tablet or mobile phone when you visit our website. There are several different types of cookies. We always place necessary cookies. These ensure the proper functioning of our website. For any other cookies (such as tracking cookies), we will inform you first on how to disable these. If you continue to surf our website, these cookies will be placed. The data we collect via these cookies are used to send you offers and show you suitable adverts. You can read more about this in our cookie policy, which you can find later in this document.
15. External links
This website may contain links to other websites. We are not responsible for the privacy policies or the content of these other websites. You can read these in the privacy statements on these websites.
16. Updates to our privacy statement
Dataprovider has the right to change this privacy. This may happen, for example, in the case of new developments, business activities, online services, or if there are changes in the law or case law. We therefore advise you to check this privacy statement on a regular basis. This privacy statement was last amended on November 20, 2023.