1. Who we are
elyXion B.V. trading as elyXion, is the controller for personal data described in this Privacy Policy unless we state otherwise. Our legal and contact details appear in the Legal Information page.
This Policy covers visitors, prospects, customer and supplier contacts, Portal users, event participants, job applicants, security researchers, and other business contacts. When we process personal data solely on a Customer’s documented instructions in managed or professional Services, the Customer is controller and our DPA applies.
2. Principles
We aim to process personal data lawfully, fairly, transparently, for specified purposes, and only to the extent necessary. We seek to keep data accurate, retain it no longer than needed, protect it appropriately, and demonstrate accountability.
3. Data we collect
Depending on the relationship, we may collect:
- Identity and business contact data, such as name, organisation, role, email, phone number, and preferred language;
- Commercial and contract data, such as proposals, orders, signatures, billing contacts, invoices, tax records, and communications;
- Portal and account data, such as username, roles, tenant association, authentication events, IP address, device/browser information, and audit logs;
- Service and support data, such as tickets, call notes, diagnostic data, system identifiers, configurations, files, and correspondence;
- Website and cookie data, such as pages viewed, referral information, consent choices, and analytics identifiers;
- Security data, such as alerts, logs, suspected abuse, vulnerability reports, and incident records;
- Recruitment data, such as CV, employment history, qualifications, interview notes, right-to-work information, and references; and
- Other data voluntarily provided or generated through the relationship.
We ask users not to include passwords, secret keys, unnecessary special-category data, or unrelated personal data in support requests.
4. Sources
We receive data directly from individuals; from their employer or Customer administrator; through our website and Portal; from Microsoft and other connected providers; from service and security tools; from public professional sources; and from advisers, suppliers, or referral partners where lawful.
5. Purposes and legal bases
| Purpose | Typical Legal Basis |
| Responding to enquiries and taking steps toward a contract | Contract or pre-contractual steps; legitimate interests |
| Delivering, administering, securing, and supporting Services | Contract; legitimate interests; legal obligation |
| Customer relationship, service review, and account management | Contract; legitimate interests |
| Billing, tax, audit, and legal administration | Contract; legal obligation; legitimate interests |
| Website operation and strictly necessary cookies | Legitimate interests; provision of requested service |
| Optional analytics, personalisation, or marketing cookies | Consent where required |
| Relevant B2B communications about our services | Legitimate interests or consent, depending on channel and law |
| Security monitoring, abuse prevention, and incident response | Legitimate interests; legal obligation |
| Recruitment | Pre-contractual steps; legitimate interests; legal obligation |
| Legal claims, compliance, and corporate transactions | Legal obligation; legitimate interests |
Where we rely on legitimate interests, we consider necessity, proportionality, reasonable expectations, and individual rights. Individuals may object as described below. Consent may be withdrawn at any time without affecting earlier lawful processing.
6. Service Data and Processor Role
In many managed-service and implementation contexts, elyXion may have access to Customer Personal Data only to provide contracted Services. In that role, we act on the Customer’s instructions, apply the DPA, and direct data-subject requests to the Customer where appropriate.
elyXion may act as an independent controller for its own account administration, security logs, billing, legal compliance, professional records, and service relationship communications.
7. Sharing
We may share personal data with authorised elyXion personnel; hosting, identity, communications, support, analytics, security, professional-adviser, and payment providers; Microsoft and other providers chosen for the Services; competent authorities where legally required; and parties to a corporate transaction under appropriate confidentiality.
We do not sell personal data. A current list of material service subprocessors is published separately. Some providers are independent controllers for parts of their services.
8. International Transfers
We prefer European processing where practical, but global providers and support operations may involve access or transfer outside the European Economic Area. Where GDPR Chapter V applies, we use an adequacy decision, approved Standard Contractual Clauses, or another lawful mechanism and assess supplementary measures where required. See the Data Residency Statement.
9. Retention
We retain data only for business, contractual, security, or legal needs. Final periods must be validated before publication. Draft schedule:
| Category | Draft Retention |
| Enquiries not resulting in business | 12 months |
| Customer contracts and core commercial records | Contract term plus 7 years or statutory period |
| Invoices and tax administration | At least the statutory Dutch retention period |
| Support tickets and service records | Contract term plus 2–7 years, depending on need |
| Portal security and audit logs | 90 days depending on log purpose and risk |
| Marketing preferences and suppression records | Until withdrawal plus minimal suppression proof |
| Recruitment applications | 4 weeks after process, or 1 year with valid consent |
| Vulnerability and incident records | As needed for remediation, legal, security, and audit purposes |
Backups may retain deleted data temporarily until rotation, with access restricted and deletion occurring through normal cycles.
10. Security
We use risk-appropriate technical and organisational measures such as identity controls, multi-factor authentication, least privilege, encryption in transit, logging, secure configuration, vulnerability management, backups, incident procedures, and personnel confidentiality. Measures vary by service and evolve. No method is completely secure.
11. Automated Decision-making and AI
We may use automation or AI to assist classification, search, summarisation, recommendations, fraud or security detection, and support. Unless separately disclosed, we do not make decisions producing legal or similarly significant effects about website visitors or customer contacts solely through automated processing. Material outputs are subject to appropriate human review. See the AI Usage Policy.
12. Individual Rights
Subject to legal conditions and exceptions, individuals may request access, correction, deletion, restriction, portability, or objection; withdraw consent; and request information about relevant automated decisions. Identity verification may be required. We normally respond within one month, subject to lawful extension.
Where elyXion is a processor, requests should be directed to the relevant Customer/controller. We will assist the Customer as required by the DPA.
13. Complaints
Contact legal@elyxion.eu first so we can address concerns. Individuals may also complain to the Autoriteit Persoonsgegevens, the Dutch supervisory authority, or another competent EEA authority.
14. Children
Our business Services are not directed to children. We do not knowingly solicit children’s personal data through the website. Customers must ensure any processing involving children is specifically assessed and lawfully configured.
15. Third-party Links
External sites and services have their own privacy practices. elyXion is not controller for independent third-party processing merely because we link to it.
16. Changes
We may update this Policy for legal, service, vendor, or operational changes. The current version and date will be published. Material changes may be highlighted or notified through appropriate channels.
17. Contact
| Privacy contact: | legal@elyxion.eu |
| Registered office: | Brilliant Starstraat 61, 1611 DR Bovenkarspel, The Netherlands. |
| Data Protection Officer: | Gert Labuschange |
| Owner: | elyXion |
| Version: | 1.0 |
| Last updated: | 11 Aug 2026 |
| Status: | Draft for legal and operational review |
