Privacy Statement
Van Doorne is an independent full-service firm of lawyers, civil-law notaries and tax consultants with offices in Amsterdam and London. In this Privacy Statement we inform you about the way in which Van Doorne handles your personal data. This Privacy Statement applies to, amongst other things, the processing of the personal data of (the contact persons at) our clients, business relations and referrers, of persons who receive our communications and attend our events, and of visitors to our website www.vandoorne.com.
Van Doorne N.V. is the controller for the processing of your personal data. From time to time, we may amend this Privacy Statement, for instance where there are changes to the way in which we process your personal data or where this is necessary on the basis of applicable regulations. We shall inform you of material changes. This Privacy Statement was last updated in September 2026.
Index
- To whom does this Privacy Statement apply?
- What personal data does Van Doorne process concerning you?
- For what purposes do we process your personal data?
- What is the legal basis for the processing of your personal data?
- How did we obtain your personal data?
- How long do we keep your personal data?
- Who has access to your personal data?
- Transfer of personal data to countries outside the EEA
- How do we secure your personal data?
- Your Rights
- Third-party websites
- Our contact details
1. To whom does this Privacy Statement apply?
This Privacy Statement applies to everyone who visits this website and to persons whose personal data are processed by Van Doorne in the context of its provision of legal services.
Persons whose personal data are processed by Van Doorne in the context of its provision of legal services are:
- Contact persons at our clients;
- Contact persons at our potential clients;
- Contact persons at our business relations;
- Contact persons at our referrers;
- Recipients of our communications, such as our newsletters and invitations to events organised by or in cooperation with Van Doorne;
- Visitors to our website www.vandoorne.com; and
- Persons who otherwise contact us or whose personal data we otherwise process in the context of our services.
2. What personal data does Van Doorne process concerning you?
The personal data we process concerning you are:
- Personal data provided by you to us;
- Personal data that give insight into your use of our website or other electronic means of communication; and
- Personal data obtained from other sources.
- Personal data provided by you:
- contact details and other personal data that are necessary for the handling of your case by a lawyer, civil-law notary or tax consultant. These are details such as your name, address, telephone number and identification documents;
- contact details and other personal data filled in on contact forms or other web forms. The precise content of the data depends on the content of the contact forms and web forms;
- contact details provided during initial meetings, events, seminars, etc. These may include details such as those set out on business cards; and
- other personal data provided by you, such as personal data included in email correspondence addressed to one of our employees.
- Personal data that give insight into the use of our website or other electronic means of communication. These may include data such as:
- IP address (the unique identification number of your device when you connect to the internet), which we use to measure your interest in our website;
- your browsing behaviour on the website, such as data on your first visit, previous visit and current visit, the pages visited, and the way in which you navigate through the website and the type of device used; and
- the opening and reading of a newsletter or commercial email. This also includes click behaviour in the email or newsletter.
- Personal data obtained from other sources:
- personal data available on public professional social media platforms such as LinkedIn. These are names and contact details;
- personal data obtained from the Trade Register of the Chamber of Commerce and from the Land Registry Office (Kadaster). These include, for example, the Chamber of Commerce number and contact details; and
- personal data available on public professional websites, such as company websites.
3. For what purposes do we process your personal data?
We may use your personal data for the following purposes:
- To perform an agreement
- To invoice for the services provided
- To comply with our legal obligations
- To maintain contact
- To conduct evaluations
- For webinars and the communications related thereto
- To conduct analyses
- To conduct client satisfaction surveys
- To improve and secure our website
- To compile user statistics
- To monitor access to the office and safeguard security
- To conduct audits
- To perform an agreement in which you have engaged our lawyers, civil-law notaries or tax consultants to provide legal and tax-related services
If you engage a lawyer, civil-law notary or tax consultant to handle your case, your contact details will be requested in that context. Other personal data may also be necessary for the handling of the matter, depending on the nature of the case. Data of the parties involved may also be processed.
- To conduct legal proceedings
- To invoice for services rendered
- To comply with our legal obligations
A civil-law notary is required under the Civil-Law Notaries Act (Wet op het notarisambt) to include certain personal data in a deed, such as the surname, first and middle names, date and place of birth, address, city of residence and civil status of the parties. Civil-law notaries are also required by law to provide certain personal data to the Chamber of Commerce and the Land Registry Office. Under the Legal Profession Regulations (Verordening op de advocatuur (Voda)) and the Civil-Law Notaries Act, we are required to verify the identity of our clients or their representatives. This is done on the basis of a valid identification document (a legalised copy in the case of remote identification). The document type and document number are stored to demonstrate that this obligation has been complied with. Under the Money Laundering and Terrorist Financing (Prevention) Act (Wwft), broader retention obligations apply. If the services fall under the Wwft, a copy of the identification document will therefore be retained. The photograph and citizen service number (BSN) are blacked out.
- To respond to your questions or messages that we receive from you via email correspondence, whether or not in the context of one of the purposes referred to above
In the event of the prolonged absence or departure of one of our employees, it may therefore be necessary for another employee to be granted temporary access to the messages you have sent us. Access to the mailbox and personal folders will only be granted to another colleague in exceptional circumstances, following a careful weighing of the interests involved and only on a need-to-know basis as referred to under 7. If an employee is absent for a prolonged period or has left the firm, you will receive an out-of-office message in response to your message stating this and offering you the option to indicate that you wish the message to be deleted. In addition to this temporary access, some employees whose position makes it necessary to have access to the mailboxes of other employees, such as secretaries, have ongoing access to that information.
- The State Taxes Act (Algemene wet inzake rijksbelastingen) requires us to process and retain certain personal data
- To maintain contact with you
We consider it important to approach you with information that is relevant to you. To make this possible, we combine and analyse the personal data available to us. On that basis, we determine which information and channels are relevant and which moments are most suitable for providing information or making contact. In our marketing activities, we do not process any special categories of personal data or any confidential information that is protected by the professional privilege of lawyers or civil-law notaries.
- For webinars and the communications related thereto
If you register for a webinar, we ask for your email address so that we can communicate with you about the webinar. You will receive a registration email at the email address you have provided. After the webinar you will also receive an email with the recording of the webinar. You will also receive this email if you have indicated that you cannot attend the webinar live. In addition, we ask you to enter your company name and job title. This is not mandatory. If you provide this information, we can tailor the content of the webinar to you more effectively. To attend a webinar, you register with your name and email address via the link we send you. We process your data relating to your participation in the webinar (such as registration details, time of registration, time of attendance and duration of your attendance). If you have given your consent, we will contact you afterwards to discuss the content of the webinars and to see whether we can be of further assistance to you. This contact may take place through various communication channels, including by telephone if you have provided your telephone number. The list of participants is shared internally with our Education department for the purpose of allocating professional development points. We also analyse this data for the ongoing improvement of our webinars. During the webinar, the participants cannot be heard or seen. Nor are the names of the participants visible to other participants. If you ask questions during the webinar, those questions, together with the name of the person asking them, are only visible to the host (Van Doorne) and not to other participants. We process this data in order to answer the questions during the webinar or, if necessary, afterwards.
- To conduct evaluations
If you have given your consent for this purpose, you will receive an email with a link to the evaluation (an online questionnaire). Participation is voluntary and can be anonymous. Prior to the evaluation, you will receive further information on the way in which we handle the information obtained.
- To conduct analyses
To conduct analyses we use:
- Interaction data:
- Personal data obtained from contact between Van Doorne and you. For example, about your use of our website or supporting applications. This also applies to offline interactions, such as how often there is contact between Van Doorne and you.
- Behavioural data:
- Personal data that Van Doorne processes about your behaviour, such as your preferences, opinions, wishes and needs. We may derive these data, for example, from your browsing behaviour on our website, from your reading of our newsletters or from the fact that you have requested information. Also from inbound telephone conversations and email contact with our employees. Information obtained via a tracking cookie is only collected and used with your consent, which you may withdraw at any time.
- To conduct client satisfaction surveys
We sometimes ask clients to cooperate in a client satisfaction survey. This is done by means of an online questionnaire. Participation is voluntary.
- For security purposes, your data may be used as follows:
- IP addresses are stored
- Use is analysed in the event of suspicious activity
- Data is temporarily processed in security software
- To compile user statistics
The user statistics of the website enable us to obtain a picture of, among other things, the number of visitors, the duration of visits, which parts of the website are viewed and click behaviour. These are generic reports, without any information about individual persons. We use the information obtained to improve the website.
- To monitor access to the office and safeguard security
When you visit our office, we note your name upon arrival. Camera footage is also recorded outside the office, at the entrances and exits of the office, in the car park and at the reception desk. We do this in order to know who is in the building in the event of an emergency and to ensure that unauthorised persons do not gain access to the office. Camera footage is in principle destroyed after four weeks.
- To conduct audits
4. What is the legal basis for the processing of your personal data?
We only process your personal data where this is permitted on the basis of one of the legal bases set out in the General Data Protection Regulation (GDPR). We rely on the following legal bases:
- Consent
- The processing is necessary for the conclusion of an agreement or in the run-up to the conclusion of an agreement
- Legal obligation
- Legitimate interest
- Consent
- We ask for your consent to participate in a client satisfaction survey.
- We ask for your consent for direct marketing purposes, which will be further specified when you give your consent.
- We ask for your consent for the use of cookies on our website.
- If we have asked for your consent to process your personal data and you have given that consent, you also always have the right to withdraw such consent. You can do so by contacting us at: privacy@vandoorne.com.
- The processing is necessary for the conclusion of an agreement or in the run-up to the conclusion of an agreement
- If you engage us to provide legal or tax-related services, we process personal data if and to the extent that this is necessary for the performance of the engagement.
- Legal obligation
- A civil-law notary is required under the Civil-Law Notaries Act to include certain personal data in a deed, such as the surname, first and middle names, date and place of birth, address, city of residence and civil status of the parties.
- Civil-law notaries are also required by law to provide certain personal data to the Chamber of Commerce and the Land Registry Office.
- The Money Laundering and Terrorist Financing (Prevention) Act (Wwft) requires lawyers, civil-law notaries and tax consultants to obtain and record certain information. This includes, among other things, a copy of an identification document (passport) with the citizen service number (BSN) and the photograph blacked out.
- Legitimate interest
- We may also process personal data where we have a legitimate interest and doing so does not disproportionately infringe your privacy. For instance, we use your contact details to invite you to seminars and events.
- We also have a legitimate interest where we use your personal data to contact you after you have contacted us on your own initiative.
- We do not always need consent to contact you. Where we obtain your email address as a result of providing services, we may offer you similar services via direct marketing. In that case, we have a legitimate interest in offering you those services.
5. How did we obtain your personal data?
We obtain some information automatically when you visit our website. We collect this information via cookies, for example. We obtain other information when you actively provide it to us. This is the case, for example, if you are or become a client of ours, or when you sign up for newsletters or events. In addition, we obtain information from third parties, such as personal data obtained from the Trade Register of the Chamber of Commerce and the Land Registry Office, or personal data available on public professional websites. We also obtain information from professional social media, such as LinkedIn.
6. How long do we keep your personal data?
We do not keep your personal data any longer than is necessary for the purposes for which they are processed, unless we are required to keep your personal data for longer in connection with legal obligations. More specifically, the following retention periods apply.
- We will delete your personal data if you have withdrawn your consent or if you have opted out.
- We keep your personal data in our contact database for up to two years from the end of the business relationship. After this period we delete your personal data.
- The personal data processed for the purpose of verifying the identity of a client or its representative are kept for five years from the end of the business relationship.
- The retention period for client files depends on various factors, including the type of matter. As a general rule, we keep client files for a period of five or twenty years after the file has been closed. This depends on the limitation period applicable to the file in question. Certain documents in files, such as notarial deeds and the related preparatory acts, are kept in accordance with the legal retention periods. These periods are 20 or 30 years, or even indefinitely (for instance where a deed is executed and registered).
- If you have registered for a webinar, your registration details will be deleted from our CRM system after we have sent you the recording of the webinar. An exception applies if you have given your consent for further use of your data and you are interested in a further webinar. In that case, the retention periods for those specific processing activities apply. The data relating to the webinar that has been filled in or registered by our supplier (WebinarGeek) is kept for one year. This enables us to analyse the webinars and to continue to improve them.
- Webinar evaluations are kept for six months, for the reason mentioned above. If you have provided your telephone number and/or email address for the purpose of the evaluation, this data will be deleted as soon as we have contacted you.
- Camera footage is kept for no longer than four weeks, unless there is an incident in connection with which the footage needs to be kept for longer.
- Visitor registration details are deleted no later than seven weeks after the date on which the right of access lapses or after the date of the visit.
7. Who has access to your personal data?
Your personal data are only accessible on a “need-to-know” basis to persons authorised for that purpose at Van Doorne. Outside the situations mentioned in this Privacy Statement, we will not disclose your personal data unless we consider this necessary in order to comply with our legal obligations, or to protect our rights or the rights of others.
It is sometimes necessary to share your personal data with third parties. Depending on the circumstances of the case, this may be necessary in the handling of your file. There are also legal obligations that require personal data to be passed on to third parties. We may engage service providers (processors) for the processing of your personal data, which process personal data exclusively on our instructions. We conclude a processing agreement with these processors that meets the requirements imposed by the General Data Protection Regulation (GDPR).
Personal data are provided to third parties in, among other things, the following cases:
When handling a file, it may be necessary to share your personal data with third parties. For example, when litigating against another party, when concluding an agreement or in the case of a notarial deed involving several parties.
Furthermore, Van Doorne is required under the Wwft to report unusual transactions to the FIU-Netherlands (Dutch Financial Intelligence Unit). Van Doorne is not permitted to inform its clients about (an intention to make) such a report.
In addition, as a result of Council Directive (EU) 2018/822 of 25 May 2018, Van Doorne is, in certain circumstances, also required to provide information on reportable cross-border arrangements to the tax authorities.
Civil-law notaries are required by law to provide certain personal data to the Chamber of Commerce and the Land Registry Office.
If a court order requires us to provide personal data to third parties, we shall have to comply with such order.
Your personal data are not shared with third parties for commercial purposes. There is one exception. We sometimes organise a joint activity, such as an event or seminar, with another organisation. In that case, only the necessary contact details are exchanged.
Personal data may furthermore be provided to third parties in the event of a reorganisation or merger of our business, or the sale of (part of) our business.
For example, we work with service providers that offer SaaS (software as a service) solutions or provide hosting services. There are also ICT service providers that support us in keeping our systems secure and stable. We also use third-party services for the sending of newsletters and commercial emails.
8. Transfer of personal data to countries outside the EEA
The files handled by our lawyers and civil-law notaries are stored within the European Economic Area (EEA). The personal data contained therein are not transferred to countries outside the EEA, unless this is necessary for the establishment, exercise or defence of a legal claim, or where this is necessary in order for support to be provided by the cloud service provider (access).
When we process your personal data, your personal data may be shared with third parties. These parties may be located outside the European Economic Area (EEA). Where applicable, we have taken appropriate security measures to share the personal data. This is the case, for example, with our email marketing provider (newsletters, forms on the website). We also take into account the additional requirements imposed by the GDPR on transfers outside the EEA.
We may transfer this data where this is necessary for the performance of the agreement for the provision of legal or tax-related services, or where this is necessary in the context of a legal claim for which we are providing you with legal support.
9. How do we secure your personal data?
We do our utmost to take appropriate technical and organisational security measures to protect against the loss, misuse and alteration of the personal data for which we are responsible.
We have an information security policy. This policy sets out how we process and protect information, including personal data. In this policy we have laid down guidelines on data protection, we have specified which measures (must) be taken to safeguard security and we have laid down how incidents are to be dealt with.
Some examples of these are:
- Availability and continuity
- Device management and security
- Physical security
- Authorisations
- Encryption
- Monitoring of our systems
- Periodic penetration testing
- Threat protection
- Privacy-by-design and privacy-by-default
- Data Protection Impact Assessment
- Training and awareness
- Data breaches
To secure your personal data, we have taken, among other things, the following technical and organisational measures:
- Availability and continuity: We take appropriate technical and organisational measures to safeguard the availability and continuity of our critical systems and services.
- Device management and security: Access to our systems is based on device-compliance and risk-driven access controls. Devices managed by Van Doorne are centrally managed and equipped with security measures such as encryption, patch management and endpoint protection. Access from unmanaged or private devices is only possible subject to additional security conditions, such as limited functionality, prevention of local storage of data, and strong authentication via conditional access measures.
- Physical security: Our building is secured by physical access control and camera surveillance. Access to the building is limited to authorised persons.
- Authorisations: Access to our systems is granted on the basis of roles and functions, whereby users are only granted access to the information and systems that are necessary for their work.
- Encryption: Data is encrypted by default when stored and transmitted, so that confidential information is adequately protected both on devices and during exchange.
- Monitoring of our systems: Our systems are continuously monitored for security incidents and anomalous behaviour, with an external security service providing 24/7 monitoring, detection and response.
- Periodic penetration testing: On a regular basis, our IT environments are tested for internal and external vulnerabilities by an independent external party.
- Threat protection: We take technical measures to prevent and to detect in a timely manner security threats, unauthorised access and misuse of data.
- Privacy-by-design and privacy-by-default: New systems are tested in advance for compliance with the privacy principles, so that data protection is safeguarded from the design stage onwards.
- Data Protection Impact Assessment (DPIA): For new systems we carry out a data protection impact assessment in advance, where legally required.
- Training and awareness: Our employees receive continuous training on information security and data protection.
- Data breaches: For the detection, handling and reporting of a data breach, we have set up a Data Breach Team and implemented a protocol.
10. Your Rights
Under the privacy regulations you have various privacy rights.
You may request:
- Access to the personal data we process concerning you.
- That your personal data be amended or supplemented, where you consider that the personal data we process concerning you are incomplete or inaccurate.
- That certain personal data relating to you be erased.
- That your data be transferred to another party.
You may also object to the processing of your personal data. As already indicated, you have the right to withdraw your consent at any time where we process your personal data on the basis of your consent.
For more information about the rights you can exercise on the basis of the privacy regulations, we also refer you to the website of the Dutch Data Protection Authority (Autoriteit Persoonsgegevens). For an overview of your rights under the privacy regulations, please see this webpage.
11. Third-party websites
Our website contains hyperlinks to websites of other parties and social media buttons. We are not responsible for the content of those websites or the services of the social media platforms concerned. Nor is Van Doorne responsible for the privacy policy and the use of cookies on those websites and social media platforms.
12. Our contact details
If you have a general question or complaint about the processing of personal data, or if you wish to exercise one of your rights, please contact our privacy officer at privacy@vandoorne.com.
Van Doorne also has a Data Protection Officer (DPO). The DPO supervises the application of and compliance with the GDPR within Van Doorne. If you are dissatisfied with the way in which we handled your question or complaint, you can contact the DPO at fg@vandoorne.com.
You also always have the right to lodge a complaint with the Dutch Data Protection Authority.
Van Doorne N.V.
Amstelveenseweg 638
1081 JJ Amsterdam
020-6789123