Hartwich Risk & Resilience
Reality CheckQuestionsOutputInsightsMethodContact
NL|EN
Discuss your question
Reality CheckQuestionsOutputInsightsMethodContact
NL|EN
Discuss your question
← Back to home
Last updated: 26 May 2026 · v1.0

Privacy Statement

This English version is provided for convenience. In case of inconsistency, the Dutch version prevails.

Company details

ItemInformation
Trade nameHartwich Risk & Resilience
Controller / contractorErik Hartwich, trading as Hartwich Risk & Resilience
AddressTacitusstraat 4, 6135 HR Sittard, Nederland
Chamber of Commerce number76948773
VAT identification numberNL003133490B55
Websitehartwichrisk.com
E-mailerik@hartwichrisk.com

1. Scope of this privacy statement

This privacy statement applies to the processing of personal data by Hartwich Risk & Resilience in connection with the website hartwichrisk.com, contact requests, business communication, quotations, agreements, service delivery, administration and relationship management.

HRR provides business-to-business advisory services. The website and services are not primarily aimed at children or consumers.

2. Personal data processed by HRR

HRR processes personal data only where necessary for business communication, service delivery and legal obligations. Depending on the situation, this may include:

  • name, business contact details, organisation, role and preferred form of address;
  • content of messages, contact forms, e-mails, meeting notes and business communication;
  • quotation, contract, assignment, project and invoice information;
  • payment and administrative data required for invoicing and accounting;
  • documents and information provided by a client for analysis or advisory work;
  • audio recordings, transcripts and summaries of meetings, but only where recording has been announced or agreed in advance;
  • technical website data such as IP address, browser data, device category, pages visited and cookie data through Google Analytics and necessary website functionality.

HRR does not request special categories of personal data. Clients are asked not to provide unnecessary personal or sensitive data unless this is necessary for the assignment and has been discussed in advance.

3. Sources of personal data

  • directly from you, for example by e-mail, contact form, meeting, quotation request or assignment;
  • from the organisation you work for or represent;
  • from documents, systems or information provided by a client for the performance of an assignment;
  • through the website and Google Analytics when you visit hartwichrisk.com;
  • through business interaction on platforms such as LinkedIn, Instagram or Google Business Profile, where you contact or respond through those platforms.

4. Purposes and legal bases

PurposeExamples of dataLegal basis
Contact and response to enquiriesName, e-mail, message contentLegitimate interest or pre-contractual steps
Quotations and commercial follow-upName, organisation, role, business contact details, quotation dataPre-contractual steps and legitimate interest
Performance of assignmentsClient data, project information, documents, communication, notes, transcriptsContract and legitimate interest
Invoicing and administrationInvoice data, payment data, correspondence, CoC/VAT dataLegal obligation and contract
Relationship managementBusiness contact details, previous communication, relevant client contextLegitimate interest
Website management and securityIP address, technical logs, browser and device dataLegitimate interest
Website analyticsAggregated and analytical website data through Google AnalyticsLegitimate interest for privacy-friendly analytics; consent where legally required
AI-assisted analysis and reportingSubmitted information, text, documents, transcripts, draftsContract and legitimate interest

5. AI, transcription and meeting recordings

HRR may use professional AI-assisted tools for analysis, structuring, transcription, summarisation, drafting, quality control and reporting. AI is used as support. Professional judgement and final responsibility remain with HRR.

Meetings are recorded or transcribed only where this has been announced or agreed in advance. Recordings and transcripts may be used for minutes, analysis and quality assurance of the services.

HRR does not use fully automated decision-making that produces legal effects concerning individuals or similarly significantly affects them.

6. Recipients of personal data

HRR does not sell personal data. HRR shares personal data only where necessary for business operations, service delivery or legal obligations. Recipients may include:

  • IT, hosting, website and cloud providers, including the website and CRM environment;
  • Microsoft 365 and other business office, storage and communication services;
  • Google Analytics for website analytics;
  • professional AI, transcription and analysis tools where necessary for the assignment;
  • bookkeeper, accountant, tax adviser, legal adviser or insurer;
  • public authorities or regulators where HRR is legally obliged to do so;
  • platforms such as LinkedIn, Instagram and Google for communications taking place through those platforms.

Where parties process personal data on behalf of HRR, HRR enters into appropriate arrangements where required, such as data processing agreements.

7. Transfers outside the EEA

HRR seeks to process personal data within the European Economic Area as much as possible. Some suppliers may process personal data outside the EEA. In that case, HRR relies on appropriate safeguards, such as an adequacy decision, EU Standard Contractual Clauses or other legally permitted safeguards.

8. Retention periods

CategoryRetention period
Contact requests and loose correspondenceUp to 24 months after the last substantive contact, unless earlier deletion is appropriate or a client relationship is established.
Quotations and commercial communicationUp to 3 years after the last contact, unless an agreement is entered into.
Client and project filesDuring the assignment and thereafter as reasonably necessary. Guideline: up to 5 years after completion, unless otherwise agreed.
Invoice and accounting data7 years due to Dutch tax retention obligations.
Meeting recordingsUp to 90 days, unless longer retention is necessary for the assignment or a dispute.
Transcripts and summariesDuring the assignment and up to 12 months after completion, unless part of the project file.
Website and analytics dataAs short as possible and, where configurable, up to 14 months for basic statistics.

9. Security

HRR takes appropriate technical and organisational measures to protect personal data against loss, misuse, unauthorised access, alteration and disclosure. Examples include access restriction, strong authentication where available, secure cloud environments, careful supplier selection and limiting data processing to what is necessary for the assignment.

10. Data subject rights

You have, where permitted by the GDPR, the right of access, rectification, erasure, restriction, portability and objection. You may also withdraw consent where processing is based on consent.

Requests can be sent to erik@hartwichrisk.com. HRR generally responds within one month. For complex or multiple requests, this period may be extended by up to two months. HRR may ask for additional information to verify your identity.

11. Complaints

If you have a complaint about the processing of personal data, please contact HRR first. You may also file a complaint with the Dutch Data Protection Authority.

12. Changes

HRR may amend this privacy statement when the services, tools, website or applicable rules change. The most recent version is available on hartwichrisk.com.

Back to home
Hartwich Risk & Resilience

Make digital dependency governable.

Website

Reality CheckQuestionsOutputInsightsMethodContact

Legal

Privacy StatementCookie StatementDisclaimerGeneral Terms

Follow Hartwich Risk & Resilience

LinkedInInstagram
CoC 76948773 · VAT NL003133490B55 · Sittard · hartwichrisk.com

We use analytics cookies (Google Analytics) to improve this website. Cookie statement