Dirivian B.V. — Legal

Privacy Policy

Effective date: 1 September 2026

At Dirivian B.V. we place great importance on protecting your personal data. We process personal data in accordance with the General Data Protection Regulation (GDPR) and other applicable privacy legislation. This policy explains what data we collect, why, how long we retain it and what rights you have.

1Data Controller

Dirivian B.V. is the data controller for the processing of personal data as described in this policy.

2Contact Details

For questions about your personal data or this privacy policy, please contact us via:

3What Personal Data We Collect

We only collect personal data that is necessary for the purposes described below, including but not limited to:

  • Identity and contact data (such as name, email address, phone number)
  • Technical data (such as IP address, browser type, operating system)
  • Usage data (such as pages visited, time on site, click behaviour)
  • Transaction data when you make purchases (such as payment details and invoice data)

4Purposes and Legal Bases

We process personal data for clearly defined purposes and on the basis of a legal ground, for example:

  • Performance of a contract (e.g. service delivery, orders)
  • Legal obligations (e.g. statutory retention requirements)
  • Legitimate interest (e.g. improving the website, analytical purposes, fraud prevention)
  • Consent (e.g. marketing communications, where you have given explicit consent)

5Cookies and Tracking

We use cookies and similar technologies for functional and analytical purposes and, where relevant, for marketing. You can disable cookies via your browser settings; please note that some features may no longer work correctly. Where required, we request your consent via a cookie banner.

6Retention Periods

We do not retain personal data longer than necessary for the purpose for which it was collected, unless legislation requires longer periods. General guidelines:

  • Transaction and invoice data: up to 7 years (statutory retention requirement)
  • Log files and analytics: generally up to 12 months
  • Contact and service requests: as long as needed for handling and complaints

7Third-Party Processors

We may share personal data with processors who perform services on our behalf, such as hosting providers, payment processors and email services. We enter into data processing agreements and take appropriate measures to protect your data.

8International Transfers

When using international service providers, data may be transferred outside the EU/EEA. In that case we apply appropriate safeguards, such as standard contractual clauses or other legal safeguards.

9Security Measures

We take appropriate technical and organisational measures to protect personal data and Google user data against unauthorised access, disclosure, alteration, loss, or destruction.

We protect sensitive data using appropriate security measures, including encryption during transmission and encryption at rest, access controls, authentication and authorisation mechanisms, secure storage, and regular monitoring and security reviews.

Access to personal data and Google user data is limited to authorised personnel and service providers who need such access to provide and maintain our services. We do not sell Google user data or use it for advertising purposes.

OAuth access tokens and other authentication credentials are stored securely and are protected against unauthorised access. When access to a user's Google account is no longer required, we revoke the applicable access and delete the associated credentials in accordance with our retention and deletion practices.

We regularly review and update our technical and organisational security measures to protect the confidentiality, integrity, and availability of user data.

10AI Processing and Google User Data

Our assistant uses AI to hold conversations, summarise messages and draft replies. We do not develop, host or train any AI or ML model of our own, and we do not fine-tune any model on your data. We use hosted third-party AI services only, called server-to-server from our own environment:

  • Google LLC — Gemini API, for the assistant's speech and text processing
  • OpenAI, L.L.C. — API platform, for drafting suggested replies in our email channel

We hold a paid API account with both providers. Under the terms of both providers, inputs to and outputs from paid APIs are not used to train or improve their models.

Google user data is never used for AI training. Information we receive through Google APIs, including Google Calendar data, is not used to develop, improve or train any AI or ML model, whether generalised or personalised. We do not sell this data and we do not use it for advertising.

When the assistant needs to know whether a time slot is available, it receives only the derived availability for the requested window: the start and end times of busy blocks. The content of calendar entries — titles, descriptions, locations and attendees — never leaves our environment and is never presented to an AI model.

Our use and transfer of information received from Google APIs adheres to the Google API Services User Data Policy, including the Limited Use requirements: "VoiceHelden's use and transfer to any other app of information received from Google APIs will adhere to the Google API Services User Data Policy, including the Limited Use requirements."

11Rights of Data Subjects

You have rights regarding your personal data, including the right of access, rectification, erasure, restriction of processing, objection and data portability. You may also withdraw your consent where processing is based on consent. For mobile messages you can opt out by replying "STOP". To exercise your rights, contact us via the details above.

12Automated Decision-Making

We do not carry out automated decision-making that produces legal effects or similarly significantly affects you. If we do make automated decisions, we will inform you clearly and, where required, provide appropriate safeguards.

13Complaint to the Supervisory Authority

If you believe we are not handling your personal data correctly, you have the right to lodge a complaint with the Dutch Data Protection Authority: www.autoriteitpersoonsgegevens.nl.

Changes to this policy: We may update this privacy policy. We will publish significant changes on this page with an updated effective date. We recommend checking this policy periodically.