Privacy Policy

1. Who we are

elyXion B.V. trading as elyXion, is the controller for personal data described in this Privacy Policy unless we state otherwise. Our legal and contact details appear in the Legal Information page.

This Policy covers visitors, prospects, customer and supplier contacts, Portal users, event participants, job applicants, security researchers, and other business contacts. When we process personal data solely on a Customer’s documented instructions in managed or professional Services, the Customer is controller and our DPA applies.

2. Principles

We aim to process personal data lawfully, fairly, transparently, for specified purposes, and only to the extent necessary. We seek to keep data accurate, retain it no longer than needed, protect it appropriately, and demonstrate accountability.

3. Data we collect

Depending on the relationship, we may collect:

  • Identity and business contact data, such as name, organisation, role, email, phone number, and preferred language;
  • Commercial and contract data, such as proposals, orders, signatures, billing contacts, invoices, tax records, and communications;
  • Portal and account data, such as username, roles, tenant association, authentication events, IP address, device/browser information, and audit logs;
  • Service and support data, such as tickets, call notes, diagnostic data, system identifiers, configurations, files, and correspondence;
  • Website and cookie data, such as pages viewed, referral information, consent choices, and analytics identifiers;
  • Security data, such as alerts, logs, suspected abuse, vulnerability reports, and incident records;
  • Recruitment data, such as CV, employment history, qualifications, interview notes, right-to-work information, and references; and
  • Other data voluntarily provided or generated through the relationship.

We ask users not to include passwords, secret keys, unnecessary special-category data, or unrelated personal data in support requests.

4. Sources

We receive data directly from individuals; from their employer or Customer administrator; through our website and Portal; from Microsoft and other connected providers; from service and security tools; from public professional sources; and from advisers, suppliers, or referral partners where lawful.

5. Purposes and legal bases

Purpose Typical Legal Basis
Responding to enquiries and taking steps toward a contract Contract or pre-contractual steps; legitimate interests
Delivering, administering, securing, and supporting Services Contract; legitimate interests; legal obligation
Customer relationship, service review, and account management Contract; legitimate interests
Billing, tax, audit, and legal administration Contract; legal obligation; legitimate interests
Website operation and strictly necessary cookies Legitimate interests; provision of requested service
Optional analytics, personalisation, or marketing cookies Consent where required
Relevant B2B communications about our services Legitimate interests or consent, depending on channel and law
Security monitoring, abuse prevention, and incident response Legitimate interests; legal obligation
Recruitment Pre-contractual steps; legitimate interests; legal obligation
Legal claims, compliance, and corporate transactions Legal obligation; legitimate interests

Where we rely on legitimate interests, we consider necessity, proportionality, reasonable expectations, and individual rights. Individuals may object as described below. Consent may be withdrawn at any time without affecting earlier lawful processing.

6. Service Data and Processor Role

In many managed-service and implementation contexts, elyXion may have access to Customer Personal Data only to provide contracted Services. In that role, we act on the Customer’s instructions, apply the DPA, and direct data-subject requests to the Customer where appropriate.

elyXion may act as an independent controller for its own account administration, security logs, billing, legal compliance, professional records, and service relationship communications.

7. Sharing

We may share personal data with authorised elyXion personnel; hosting, identity, communications, support, analytics, security, professional-adviser, and payment providers; Microsoft and other providers chosen for the Services; competent authorities where legally required; and parties to a corporate transaction under appropriate confidentiality.

We do not sell personal data. A current list of material service subprocessors is published separately. Some providers are independent controllers for parts of their services.

8. International Transfers

We prefer European processing where practical, but global providers and support operations may involve access or transfer outside the European Economic Area. Where GDPR Chapter V applies, we use an adequacy decision, approved Standard Contractual Clauses, or another lawful mechanism and assess supplementary measures where required. See the Data Residency Statement.

9. Retention

We retain data only for business, contractual, security, or legal needs. Final periods must be validated before publication. Draft schedule:

Category Draft Retention
Enquiries not resulting in business 12 months
Customer contracts and core commercial records Contract term plus 7 years or statutory period
Invoices and tax administration At least the statutory Dutch retention period
Support tickets and service records Contract term plus 2–7 years, depending on need
Portal security and audit logs 90 days depending on log purpose and risk
Marketing preferences and suppression records Until withdrawal plus minimal suppression proof
Recruitment applications 4 weeks after process, or 1 year with valid consent
Vulnerability and incident records As needed for remediation, legal, security, and audit purposes

Backups may retain deleted data temporarily until rotation, with access restricted and deletion occurring through normal cycles.

10. Security

We use risk-appropriate technical and organisational measures such as identity controls, multi-factor authentication, least privilege, encryption in transit, logging, secure configuration, vulnerability management, backups, incident procedures, and personnel confidentiality. Measures vary by service and evolve. No method is completely secure.

11. Automated Decision-making and AI

We may use automation or AI to assist classification, search, summarisation, recommendations, fraud or security detection, and support. Unless separately disclosed, we do not make decisions producing legal or similarly significant effects about website visitors or customer contacts solely through automated processing. Material outputs are subject to appropriate human review. See the AI Usage Policy.

12. Individual Rights

Subject to legal conditions and exceptions, individuals may request access, correction, deletion, restriction, portability, or objection; withdraw consent; and request information about relevant automated decisions. Identity verification may be required. We normally respond within one month, subject to lawful extension.

Where elyXion is a processor, requests should be directed to the relevant Customer/controller. We will assist the Customer as required by the DPA.

13. Complaints

Contact legal@elyxion.eu first so we can address concerns. Individuals may also complain to the Autoriteit Persoonsgegevens, the Dutch supervisory authority, or another competent EEA authority.

14. Children

Our business Services are not directed to children. We do not knowingly solicit children’s personal data through the website. Customers must ensure any processing involving children is specifically assessed and lawfully configured.

15. Third-party Links

External sites and services have their own privacy practices. elyXion is not controller for independent third-party processing merely because we link to it.

16. Changes

We may update this Policy for legal, service, vendor, or operational changes. The current version and date will be published. Material changes may be highlighted or notified through appropriate channels.

17. Contact

Privacy contact: legal@elyxion.eu
Registered office: Brilliant Starstraat 61, 1611 DR Bovenkarspel, The Netherlands.
Data Protection Officer: Gert Labuschange
Owner: elyXion
Version: 1.0
Last updated: 11 Aug 2026
Status: Draft for legal and operational review