Privacy notice
How Zitha & Houwen handles personal data when you visit this website or contact us about Convenor.
1. Who is responsible
Convenor is a product of Zitha & Houwen, a general partnership (vennootschap onder firma, VOF) under Dutch law, established in Delft, the Netherlands (see company details). For the personal data described in this notice we are the controller under the General Data Protection Regulation (GDPR).
For anything about your data, write to legal@convenor.eu. We are not required to appoint a data protection officer and have not done so; this address reaches the people who handle data protection.
2. What we collect, why, and on what basis
When you use the contact form
Your name, organisation, work email, where your project is, and your message if you write one. We use them to answer you and, if you ask, to arrange a call or a demo.
Legal basis: steps you ask us to take before a possible contract (GDPR Art. 6(1)(b)), and our legitimate interest in answering people who contact us (Art. 6(1)(f)). Giving these details is up to you, but without your name and email we cannot reply.
When you open the sample project
Before you open the sample project, we ask for your first and last name, work email, organisation and role. We email you one link to open it, because you ask us to; the link works for 24 hours. When you open it, your details go to our team mailbox, so we can follow up about Convenor. Legal basis: our legitimate interest in following up with people who look at our product (Art. 6(1)(f)). Giving these details is up to you, but without them the sample project does not open.
Your browser then keeps a signed copy of these details for 90 days (local storage), so you can come back without filling in the form. It stays on your device: "Not you? Use different details" on that page, or clearing this site's data, removes it. When you come back, we may tell our team, at most once a day.
When you email us
Your email address, your name if you give it, and what you write. We use them to answer you, on the same legal basis as the form.
To stop misuse of the form
The form counts messages per connection (your IP address) and per email address, so that nobody can flood it. These counts are kept only in the working memory of the form's server and are gone within 24 hours, often sooner. Legal basis: our legitimate interest in keeping the form usable and secure (Art. 6(1)(f)).
When you visit a page
To deliver a page, our hosting provider has to process your IP address, the page you ask for, the time, and your browser type. It uses them to serve the site and to protect it against attacks. We keep no visitor logs ourselves and do not use this data to identify you. Legal basis: our legitimate interest in a working, secure website (Art. 6(1)(f)).
Your light or dark choice
If you use the theme switch, your choice is kept in your own browser (local storage). It never leaves your device.
What we do not do
This website sets no cookies, so there is nothing to accept or refuse. We do not measure visits. We do not sell personal data, use it for advertising, build profiles, or take decisions about you by automated means.
3. Who processes it for us
Only the small team behind Convenor reads your messages. To run the website and our mailboxes we use these providers, who handle data on our behalf under a data processing agreement:
- Cloudflare (Cloudflare, Inc.) runs the bot check (Turnstile) on the sample project form. To tell people from automated programs it sees your IP address and technical details of your browser, sets no cookies, and does not use them for advertising. Cloudflare is certified under the EU-US Data Privacy Framework.
- Microsoft Azure (Microsoft Ireland Operations Ltd.) hosts this website, runs the form, and delivers its message to our mailbox (Azure Communication Services, which handles the message as it passes and keeps no copy of it), in the EU.
- Microsoft 365 (Microsoft Ireland Operations Ltd.) holds our mailboxes, in the EU. Your messages arrive there.
4. Outside the European Union
Your data is stored in the EU. Microsoft is part of a United States group, so in rare cases, for example for support or maintenance, staff outside the EU may be able to see it. Safeguards cover this: the European Commission's adequacy decision for the EU-US Data Privacy Framework, in which Microsoft takes part, and the standard contractual clauses in Microsoft's data processing terms. Write to us if you would like a copy.
5. How long we keep it
- The form: the website stores nothing, and neither does the email service. Your message goes straight to our mailbox.
- Your messages and our replies: 12 months after our last contact. If the conversation leads to a contract, we keep what the contract and the law require, for example 7 years for the records Dutch tax law requires.
- The misuse counts: at most 24 hours.
- The sample project form: the website stores nothing; your details reach our mailbox and are kept like other messages. The copy in your browser: 90 days, or until you remove it.
6. Your rights
You can ask us for a copy of your personal data, and to correct it, delete it, restrict its use, or hand it over in a portable format. You can object at any time to our use of it based on our legitimate interest. Write to legal@convenor.eu. We answer within one month. If we first need to check that the request is really yours, we tell you.
If you think we handle your data wrongly, please tell us, so we can put it right. You also have the right to complain to a data protection authority: in the Netherlands the Autoriteit Persoonsgegevens, or the authority in the EU country where you live or work.
7. Changes
When we change how we handle data, we update this notice and the date at the top. If a change matters for you and we have your email address, we tell you.
8. Questions
Write to legal@convenor.eu. For anything else: info@convenor.eu.