Privacy at Fookus
Clear information about what happens to your data
This statement applies to fookus.nl, ordinary enquiries, the intelligent business audit and the personal follow-up connected to them.
Last updated: 12 August 2026
Who is responsible?
Fookus is responsible for processing your personal data. Fookus is registered with the Dutch Chamber of Commerce under number 83692517 and is established at Strodorpsweg 9, 6861 EN Oosterbeek, the Netherlands. Email [email protected] for privacy questions or requests.
Which data do we use?
- Contact and business details you provide, such as your name, business email, company, role, website and LinkedIn profile.
- Your enquiry, audit answers, consent choices and technical delivery status.
- Relevant public professional information found only on the website and LinkedIn profile you provide.
- Limited security data, such as a one-way hash of the IP address, timestamps and technical error or abuse statuses.
- For ordinary website visits outside the enquiry and audit pages: only a cookieless, temporary measurement of clicks on contact options. It does not create a persistent visitor profile.
Why and on what legal basis?
- To assess and answer your enquiry, or create and deliver the audit you requested. This is necessary to perform your request or take steps before a possible agreement.
- To protect the website, forms and AI costs against abuse and recover failed delivery. This is Fookus's legitimate interest in providing a secure and reliable service.
- To discuss your enquiry or audit personally. This is part of the requested service; the analysis does not automatically trigger a proposal or another external action.
- To email practical insights and offers only when you opt in separately and confirm by email. You can withdraw this consent at any time.
- To comply with a legal obligation or handle a legal dispute when actually necessary.
What does the intelligent audit do?
The audit combines your answers with relevant information from the two public pages you provide. AI helps organise facts, formulate improvements and critically check the report. Fookus does not perform an open-ended person search and does not use the audit for a solely automated decision with legal or similarly significant effects. Fook personally reviews commercial follow-up.
When public professional data is used, it comes from the business website and LinkedIn profile you provide. It concerns business context, role, offer and publicly visible working methods needed for the requested audit.
Who helps process the data?
Fookus uses specialised suppliers under appropriate terms and shares only what is necessary for their task:
- Supabase for the central database and private report storage.
- Vercel for website hosting and reliable process execution.
- OpenAI, through the restricted Eve agent, for bounded analysis.
- Apify for retrieving relevant information from the public pages you provide.
- Resend for transactional email and, after separate confirmation, marketing email.
- Cloudflare for bot protection, security and traffic limits.
- Google Workspace for business email and calendar handling.
- Cal.com for booking a call when you choose to do so.
- PostHog EU for cookieless contact-action measurement outside the enquiry and audit pages.
Transfers outside the European Economic Area
Some suppliers may process data internationally. When personal data is transferred outside the European Economic Area, Fookus uses a valid transfer mechanism, such as an adequacy decision or European Commission standard contractual clauses, with additional safeguards where necessary. You can request information or a copy of the relevant safeguards through [email protected].
How long do we retain data?
- An incomplete audit is reviewed for deletion after 7 days.
- A failed or rejected audit is reviewed for deletion after 90 days so delivery and abuse checks remain recoverable.
- A completed audit and its related enquiry are retained for no more than 24 months after the last substantive interaction, unless earlier deletion is possible and requested.
- We retain marketing consent and opt-out evidence for as long as needed to demonstrably respect your choice.
- A statutory retention duty or specific legal dispute may require longer retention. We then retain only what is needed for that purpose.
What are your rights?
You may request access, correction, deletion, restriction, portability or object to processing. You can withdraw marketing consent through the unsubscribe link or by email. Send your request to [email protected]. We may first reasonably verify that the request is yours and normally respond within one month.
If you are not satisfied, you may lodge a complaint with the Dutch Data Protection Authority, the Autoriteit Persoonsgegevens. You also retain the right to seek a judicial remedy.
Do you have to provide the data?
For an ordinary enquiry, your email and substantive question are required; other fields are optional. For the audit, the fields and answers marked as required are needed to safeguard identity, context and report quality. Without them, we cannot provide that service. Marketing is always optional.
Changes
If the processing changes materially, we update this statement and its version. Where a change requires new consent, we ask for it before the new processing starts.
Privacy question or request?
[email protected]