Last updated: 14 January 2026
Privacy policy
This privacy policy describes how Stichting Kredanelio (“we”, “us”) processes personal data on the kredanelio.com domain. Our processing complies with the General Data Protection Regulation (GDPR) and the Dutch GDPR Implementation Act, as well as with the guidelines of the Dutch Data Protection Authority.
1. Controller
Stichting Kredanelio, established at Keizersgracht 271, 1016 ED Amsterdam, registered with the Dutch Chamber of Commerce under number 81429763, is the controller for the processing of personal data on this website. Questions may be addressed to redactie@kredanelio.com.
2. Which data we process
We only process the data that you actively provide via the newsletter subscription form: your name, your email address and an optional message. In addition, anonymised technical data — such as IP address and browser type — may be collected if you give consent for analytics cookies.
3. Purpose and legal basis
Your data are used to send our editorial newsletter, to reply to your question and to improve our articles. The legal basis is your explicit consent (Article 6(1)(a) GDPR). You may withdraw this consent at any time.
4. Retention
Subscription data are retained for as long as you are subscribed to the newsletter and for a maximum of 24 months thereafter for archival purposes. Anonymised statistics are not retained for longer than 26 months, in line with the default setting of the analytics platform we use.
5. Sharing with third parties
We do not sell personal data. We only share data with processors who technically support us (EU-based hosting, email delivery), on the basis of a data processing agreement. With advertising networks we only share aggregated, anonymised signals through Google Consent Mode v2, and only after you have given your consent.
6. Your rights
You have the right of access, rectification, erasure, restriction and portability of your data, and the right to object to processing. Requests can be addressed to redactie@kredanelio.com. We respond within four weeks. If you feel that we do not handle your data carefully, you may lodge a complaint with the Dutch Data Protection Authority.
7. Security
Our server is hosted in an ISO 27001 certified data centre in the Netherlands. Connections are made over TLS 1.3. Access to personal data is limited to two editorial members, governed by an internal authorisation matrix.
8. Changes
We reserve the right to amend this policy. Material changes will be announced at least thirty days in advance via a notice on the home page.