
Privacy policy
Last updated: 19 August 2026
1. Introduction
DreCo Insights (“we,” “our,” or “us”) is committed to protecting your privacy and to the EU General Data Protection Regulation (GDPR). This policy explains how we collect, use, and protect your personal data when you visit our website or use our services.
2. Who we are
Data controller
DreCo Insights
Vossenkamp 152, 9675 KN Winschoten
KVK no. 92400205
The Netherlands
Contact
Email: [email protected]
Phone: +31 (0)6 580 16712
Website: drecoinsights.eu
DreCo Insights is the data controller for your personal data. We decide how and why your data is processed. To exercise your rights, contact us using the details above.
Data Protection Officer
We have not appointed a Data Protection Officer, as we are not required to under Article 37 GDPR. For data protection questions, contact [email protected].
3. How and why we process your personal data
| Purpose | Data processed | Legal basis | Retention |
|---|---|---|---|
| Client relationship management | Contact details, company info, project communications, financial records | Performance of a contract, Art. 6(1)(b) | Engagement plus 7 years |
| Business development | Business contact info, professional interests, industry sector | Legitimate interests, Art. 6(1)(f) | 2 years from last interaction |
| Marketing communications | Name, work email, company, engagement behaviour, opens and clicks. The list is held in ListMonk on our own server, and the mail is delivered by Mailjet | Consent, Art. 6(1)(a) | Until consent is withdrawn |
| Website analytics | Aggregated usage data, no cookies, no personal profiles, through Plausible | Legitimate interests, Art. 6(1)(f) | Aggregated only, no personal profile |
| Compliance and legal obligations | Client engagement data, contracts, financial transactions | Legal obligation, Art. 6(1)(c) | 7 years from engagement end |
4. Personal data we collect
Sources
- Directly from you: website forms, strategy call surveys, email, service delivery.
- Third parties: LinkedIn, professional events, public business directories, client referrals.
Categories
- Contact information: name, email, phone, company, job title.
- Professional information: company name, size, website, sector, decision role, strategic challenges.
- Technical data: IP address, browser type, device info, usage data. Our analytics holds none of this as a personal profile, see Section 10.
- Financial information: invoicing details, payment info, budget parameters, for clients.
- Project data: strategic plans, deliverables, technical specifications, for clients.
5. Who we share your data with
Most of our tools are European and self hosted on our own server in Germany. Your data sits under our control, on infrastructure inside the EU.
Infrastructure and European processors
| Provider | Purpose | Location | Safeguards |
|---|---|---|---|
| Hetzner Online GmbH | Hosting and infrastructure for our server and all self hosted tools | Germany, EU | DPA, EU hosted |
| Mailbox.org | Germany, EU | DPA, EU hosted | |
| Zeeg | Online booking and scheduling | Germany, EU, on the Open Telekom Cloud | DPA under Art. 28, data held only in Germany |
| Mailjet SAS, part of Sinch | Delivery of our marketing email. Our subscriber list is held in ListMonk on our own server. Mailjet transmits the messages, and therefore receives the recipient address, the message content, and the resulting delivery, bounce, open and click data | France, EU. Messages are processed in Google Cloud data centres in Frankfurt, Germany and Saint Ghislain, Belgium | DPA under Art. 28, the Sinch Data Processing Agreement, EU hosted. For the transmission itself, Sinch acts as an independent controller for network security and for spam and fraud prevention, under clause 3(a)(iv) of that agreement |
Self hosted on our own server, no third party receives the data
OnlyOffice for documents. OpenTalk for video calls. Hetzner Storageshare for file storage. OpenProject for project management. EspoCRM for the client database. Formbricks for website forms. n8n for automation. ListMonk for marketing email. Plausible for analytics. All run on our server in Germany.
One qualification. ListMonk holds our subscriber list on our own server, but it does not deliver the mail itself. Outbound marketing email is transmitted by Mailjet, listed as a processor above. Every other tool in this list operates without a third party seeing your data.
Declared exceptions, outside the EU
| Provider | Purpose | Location | Safeguards |
|---|---|---|---|
| Anthropic (Claude) | AI assistance for research and analysis | United States | Declared exception. We do not upload sensitive client personal data. Anthropic does not train on the work of paid users. Anthropic is certified under the EU-US Data Privacy Framework. Transfers are additionally covered by the 2021 EU Standard Contractual Clauses, with a transfer impact assessment on file. |
| Cloudflare | Network edge, traffic routing and protection against attack | United States | Transit only, no data stored. Certified under the EU US Data Privacy Framework since August 2024, and the DPA also incorporates the Standard Contractual Clauses. |
Specialist partners
We may share data with selected partners, for example prototyping labs, M&A advisors, lawyers, financial advisors, HR and recruitment agencies, only within an agreed collaboration and with your explicit consent for specific projects. All partners sign NDAs and DPAs.
Professional advisors
Limited disclosure to legal advisors, insurers, or tax accountants for compliance or advice.
Legal authorities
We may disclose data when legally required, for example to tax authorities or law enforcement.
What we never do
- Sell your data to third parties.
- Share your data with marketing companies or data brokers.
- Use your data for undeclared purposes.
6. International data transfers
Your data is stored and processed in the EU. Two services sit outside the EU and never store your data in a way we do not control.
- Anthropic (Claude), United States. AI processing. We do not upload sensitive client personal data. Safeguard: certification under the EU-US Data Privacy Framework, with the 2021 EU Standard Contractual Clauses and a transfer impact assessment as an additional layer.
- Cloudflare, United States. Network edge and protection. Traffic passes through, nothing is stored. Safeguard: certification under the EU US Data Privacy Framework, and the Standard Contractual Clauses in the DPA.
Your rights: request a copy of the safeguards, or object to a transfer.
We are EU first by design, and we are removing the few remaining non EU services from our path over time.
7. How long we keep your data
| Category | Retention |
|---|---|
| Website visitors, non clients | Aggregated analytics only, no personal profile |
| Business contacts, prospects | 2 years from last interaction |
| Active clients | Engagement plus 7 years |
| Marketing consent | Until withdrawal, deletion within 30 days |
| Email delivery data held by our relay | Delivery, bounce, open and click statistics are kept by Mailjet for 90 days on our current plan. Recipient addresses remain as contacts in that account until we delete them |
Client data is kept for 7 years after an engagement for legal, tax, and professional indemnity reasons.
8. How we protect your data
Technical measures
Encryption in transit and at rest, TLS and AES 256. Access controls. Regular backups. Security monitoring. 2FA where available.
Organisational measures
Confidentiality agreements, staff training, an incident response plan.
Breach notification
We notify the authority within 72 hours, and affected individuals without undue delay, where a breach poses a high risk.
9. Your rights under GDPR
| Right | What it means |
|---|---|
| Access, Art. 15 | Request a copy of your data. |
| Rectification, Art. 16 | Correct inaccurate or incomplete data. |
| Erasure, Art. 17 | Request deletion, subject to legal obligations. |
| Restriction, Art. 18 | Limit processing in specific cases. |
| Portability, Art. 20 | Receive your data in a machine readable format. |
| Object, Art. 21 | Object to marketing or legitimate interest processing. |
| Withdraw consent, Art. 7 | Withdraw consent for marketing, with no effect on past processing. |
| Complain, Art. 77 | Lodge a complaint with your supervisory authority, the Autoriteit Persoonsgegevens in the Netherlands. |
To exercise your rights, email [email protected] with your full name, contact details, and a description of your request. We respond within one month, extendable by two months for complex requests.
10. Cookies
We use privacy first, cookieless analytics through Plausible. Plausible sets no cookies and builds no personal profile. Because of this, the site does not need a tracking consent banner.
The only cookie that may be set is a strictly necessary security cookie from Cloudflare, used to protect the site from automated attacks. It carries no marketing function and needs no consent.
| Type | Purpose | Legal basis | Duration |
|---|---|---|---|
| Strictly necessary | Site function and security, including the Cloudflare security cookie | Legitimate interests | Session or up to 1 year |
You can manage cookies in your browser settings in Chrome, Firefox, Safari, or Edge. We respect Do Not Track browser settings.
11. Changes to this policy
We may update this policy to reflect changes in practice or law. Material changes will be notified by email, for clients and subscribers, or on our website.
12. Contact us
Email: [email protected]
Phone: +31 (0)6 580 16712
Post: DreCo Insights, Vossenkamp 152, 9675 KN Winschoten, The Netherlands
We aim to respond within 5 working days.
Version history
2.4, 19 August 2026: The Mailjet safeguards note extended. Under clause 3(a)(iv) of the Sinch Data Processing Agreement, Sinch acts as an independent controller for the transmission itself, for network security and for spam and fraud prevention. Recorded so that the processor table does not overstate our control over that leg.
2.3, 19 August 2026: Marketing email relay changed from Brevo to Mailjet. Section 3 marketing row, the Section 5 European processors table and the self hosted paragraph updated. A retention row for delivery data held by the relay added to Section 7.
2.2, 17 August 2026: Brevo added as a processor for marketing email delivery. Section 3 marketing row, Section 5 EU processors table and self hosted paragraph corrected to disclose the SMTP relay.
2.1, 3 July 2026: Anthropic entry updated. Certification under the EU-US Data Privacy Framework confirmed against the official participant list, the pending status marker removed. Standard Contractual Clauses and the transfer impact assessment kept as an additional layer.
2.0, 19 June 2026: Stack corrected to the live setup. Microsoft 365, Salesflow CRM, Google Analytics and Mistral AI removed. Mailbox.org, OnlyOffice, EspoCRM, ListMonk, the other self hosted EU tools, Zeeg, Plausible, and the declared exceptions Anthropic and Cloudflare added. Transfers and cookies updated.
1.0, 22 October 2025: Initial publication.
