Privacy Policy
What we collect when you use this site or get in touch, why we have it, how long we keep it, and what you can ask us to do about it.
Who we are
Nimbble is a web design and development studio based in Amsterdam. When you use this website or get in touch with us, Nimbble is the controller of your personal data under the General Data Protection Regulation (GDPR) and the Dutch implementation act, the Uitvoeringswet AVG.
You can reach us at hello@nimbble.nl, or by post at Reguliersdwarsstraat 108, Amsterdam, The Netherlands. We are registered with the Dutch Chamber of Commerce under KvK number 65883829 and our VAT number is NL001118917B69.
We have not appointed a Data Protection Officer. We are a small studio, we do not process personal data on a large scale, and none of the criteria in Article 37 of the GDPR apply to us. Questions about your data come straight to us.
What we collect
We collect very little, and only what a conversation actually needs.
When you fill in our contact form, we receive your name, your email address, and (if you choose to give them) your company name and website. We also receive whatever you write in the message field. Please do not send us sensitive personal data through this form; it is not the right place for it.
When you email us directly, we receive your email address and the contents of your message, along with anything your email client includes in the headers.
When you visit the website, our hosting provider processes technical data such as your IP address, browser type, device type and the pages you request. This happens automatically for every website you visit and is necessary to deliver the page to you and to keep the service secure.
We do not buy personal data from third parties, we do not build profiles, and we make no automated decisions about you.
Why we use it, and on what basis
The GDPR requires us to have a lawful basis for everything we do with your data. Ours are these.
To answer you. If you contact us about a possible project, we use your details to reply, ask follow-up questions and prepare a proposal. The basis is Article 6(1)(b): steps taken at your request before entering into a contract.
To deliver work we have agreed. If you become a client, we use your contact details to run the project. The basis is Article 6(1)(b): performance of a contract.
To keep the website working and secure. Server logs and functional cookies exist so pages load correctly and abuse can be identified. The basis is Article 6(1)(f): our legitimate interest in operating a functioning, secure website. We have weighed this against your interests and consider the impact minimal, since the data is technical and short-lived.
To meet our legal obligations. Invoices and related records are kept because Dutch tax law requires it. The basis is Article 6(1)(c).
We do not send marketing email. If that ever changes, we will ask for your consent first, and every message will carry a working unsubscribe link.
Cookies
This website uses functional cookies set by our hosting platform. They are strictly necessary to deliver and secure the site, and under Dutch law and the ePrivacy Directive strictly necessary cookies do not require your consent.
With your permission we use Google Analytics 4 to understand how the site is used: which pages are visited and for how long, which website or search brought you here, and your device type, browser and approximate location. It only loads after you choose Accept all or switch on Analytics in Cookie settings. If you don't, nothing is sent to Google. Google Analytics sets two cookies for this, _ga and _ga_L457WY3GY1. The data is kept for 30 days and then deleted. The legal basis is your consent under Article 6(1)(a) GDPR, and you can withdraw it at any time through Cookie settings in the footer of every page. Google Ireland Limited processes this data on our behalf; some of it may be transferred to the United States under the EU-US Data Privacy Framework. Your cookie choice itself is stored in a small functional cookie, so we don't have to ask again on every page.
You can block or delete cookies through your browser settings at any time. Blocking strictly necessary cookies may stop parts of the site from working.
Who else sees it
We do not sell your personal data, and we do not share it for anyone else's marketing.
A small number of service providers process data on our behalf, under written processor agreements as required by Article 28 of the GDPR:
- Webflow: hosts this website and stores contact form submissions.
- Our email provider: receives and stores the messages you send us.
- Our accountant and administrative software: for invoicing and bookkeeping, where a client relationship exists.
We may also disclose data where the law requires it, for example in response to a valid order from a competent authority.
Where your data is stored
Our hosting provider is based in the United States and may process data outside the European Economic Area. Where that happens, the transfer is covered by the European Commission's Standard Contractual Clauses and, where applicable, the EU–US Data Privacy Framework. You can ask us for details of the safeguards that apply.
How long we keep it
We do not keep things indefinitely.
Enquiries that do not lead to a project are deleted within twelve months. Project correspondence is kept for the duration of the work and for two years afterwards, so we can support what we built. Invoices and the administrative records attached to them are kept for seven years, because Dutch tax law obliges us to. Server logs are retained by our hosting provider for a short period as part of normal operations.
Your rights
Under the GDPR you have the right to ask us for a copy of the personal data we hold about you, to have inaccurate data corrected, to have data erased, to have our processing restricted, to receive your data in a portable format, and to object to processing we carry out on the basis of legitimate interests. Where we rely on your consent, you can withdraw it at any time, and doing so does not affect anything we did before you withdrew it.
Email hello@nimbble.nl and we will respond within one month, as the GDPR requires. There is no charge. We may ask you to confirm your identity first, so that we do not hand your data to someone else.
Security
The site is served over HTTPS. Access to form submissions and email is protected by strong, unique credentials and two-factor authentication. We keep the number of people who can reach your data as small as it can reasonably be. Given the size of the studio, that is very small.
No system is perfectly secure. If a breach ever occurred that posed a risk to your rights, we would report it to the Autoriteit Persoonsgegevens within 72 hours and tell you directly where the law requires it.
Links to other websites
This site links to work we have built for clients, and to our LinkedIn page. Once you follow a link you are on someone else's website, governed by their privacy policy, not ours. We would encourage you to read it.
Changes to this policy
If we change how we handle personal data, we will update this page. Where a change is significant, we will say so rather than letting it pass quietly.
Questions and complaints
If something here is unclear, or you think we have handled your data badly, please email hello@nimbble.nl first. We would rather hear it from you and fix it.
You also have the right to lodge a complaint with the Dutch data protection authority, the Autoriteit Persoonsgegevens, at autoriteitpersoonsgegevens.nl. If you live or work in another EU member state, you can complain to your local supervisory authority instead.