Legal

Privacy and cookies

This statement explains how personal data is processed when you visit dvold.com or contact us through the website.

Version
0.1, 1 August 2026
Status
In effect
Scope
Public website and contact form

01

Who is responsible?

Until a legal entity has been incorporated for DVOLD, Almansio Figueiredo Soares, trading under the name DVOLD, is the controller for the processing described in this statement.

You can reach the controller by email at info@dvold.com. Privacy questions and privacy requests reach us at that address as well.

Once a legal entity has been incorporated, this statement will be updated with the correct legal name, registration details and contact details.

02

Who and what does this statement cover?

This statement applies to:

  • visitors to dvold.com;
  • visitors to the protected preview where personal data is processed;
  • people who submit the contact form;
  • people who email DVOLD in connection with the website.

It does not automatically cover:

  • a future DVOLD application or wallet;
  • customer or partner portals;
  • pilots and implementations;
  • business agreements;
  • validation, ownership or asset data in a production environment.

Privacy information for those services will be established before they are used.

03

Which data do we process?

Website visits and server logs

The hosting environment may process technical log data, including:

  • IP address;
  • date and time;
  • requested page or file;
  • HTTP status;
  • referring page;
  • browser and device information;
  • technical error and security information.

This information is used to keep the website available, secure and technically functional. It is processed in the hosting environment rather than in the web page itself.

Which log fields bHosted.nl B.V. records, and for how long, is determined by the standard settings of that hosting environment.

Contact form

When you use the contact form, we process the details you enter yourself:

  • name;
  • organisation, when provided;
  • job title or role, when provided;
  • email address;
  • phone number, when provided;
  • request type;
  • message;
  • form language.

The form also carries two hidden technical fields that exist only for spam prevention: a field a visitor never fills in, and a timestamp of the moment the form was loaded in your browser. Neither field contains personal data and neither is included in the message that is sent.

The website has no contact database. The form handler does not store the content of your message on the web server: the content is sent only as email to the DVOLD mailbox, with your email address as the reply address. Any further retention then takes place in that mailbox.

If this changes technically at a later stage, this statement will be updated beforehand.

Spam prevention and rate limiting

To limit repeated misuse of the contact form, the server may use the IP address of a submission. The IP address itself is not retained: the server derives an encrypted value from it using a server secret and stores only that value, a counter and the start time of the window.

These temporary counter files are cleaned up automatically once they are no longer needed for the security function. When the server configuration holds no secret or storage location, this counting does not take place.

Direct communication

When you email us or when we follow up on a contact request, we may process the content of the correspondence, your contact details and relevant follow-up notes.

No sensitive data requested

Do not include health data, national identification numbers, copies of identity documents, payment data or other sensitive personal data in the free-text field unless DVOLD expressly requests it through a later secure process.

04

Why do we process this data?

Responding to contact requests

Purposes:

  • assess your question;
  • respond;
  • determine which team member should handle the request;
  • explore a possible application, collaboration or agreement.

Legal basis:

  • legitimate interests in responding to directed enquiries;
  • steps at your request before entering into a possible contract, where applicable.

Website security and technical administration

Purposes:

  • keep the website available;
  • detect misuse, spam and attacks;
  • resolve technical errors;
  • apply rate limiting.

Legal basis:

  • legitimate interests in maintaining a secure and functioning website.

Legal obligations and legal position

Data may sometimes be processed or retained to comply with legal obligations, handle disputes or establish, exercise or defend legal claims.

Newsletter or waitlist

The current website does not automatically use contact details for newsletters or marketing. The website contains no newsletter or waitlist sign-up.

If a newsletter or waitlist is introduced later, it will use separate, demonstrable consent and a clear unsubscribe option.

05

With whom do we share data?

We do not sell personal data or share it for advertising.

Data may be processed by parties required for the website and for communication.

Hosting

bHosted.nl B.V. hosts the website and may process technical server data as a processor.

Email

Contact forms and correspondence arrive in a business mailbox. The service that provides that mailbox processes the content of those messages as a processor.

Technical support

A developer or administrator may receive limited access when required for maintenance, security or troubleshooting. That access is restricted, documented and contractually arranged where required.

Legal recipients

Data may be disclosed where legally required or necessary to protect rights and safety.

06

Transfers outside the European Economic Area

DVOLD aims to process website and contact data within the European Economic Area.

The website as built makes no requests to other domains itself. For hosting, email and support services, processing within the European Economic Area is chosen wherever that is possible.

Where a transfer occurs, a valid GDPR transfer mechanism will be used and this statement will be updated.

07

How long do we retain data?

Contact requests and correspondence

Up to 24 months after the last substantive contact, unless:

  • a longer period is required for an agreement;
  • a legal retention obligation applies;
  • data is needed for a legal claim;
  • earlier deletion is appropriate and feasible.

This period is an agreement about how the mailbox is managed. Clearing it is carried out by DVOLD and does not happen automatically through the website.

Server logs

No longer than technically necessary for availability, security and troubleshooting, following the period the hosting environment applies for this.

Spam and rate-limit data

No longer than needed for the security function. The temporary counter files hold no full IP address, only an encrypted derived value, a counter and a timestamp, and they are cleaned up automatically.

Privacy requests

For as long as required to handle the request and to demonstrate that it was met.

08

Cookies, localStorage and similar technologies

Baseline

The baseline for dvold.com is:

  • no marketing cookies;
  • no tracking cookies;
  • no advertising networks;
  • no social tracking plugins;
  • no analytics requiring consent;
  • locally hosted fonts;
  • minimal external network requests.

What the current website does

A technical review of the website as built established that:

  • the website sets no cookies of its own;
  • the website uses no localStorage, sessionStorage or comparable browser storage;
  • no analytics, tracking or advertising code is present;
  • the fonts are loaded from dvold.com and not from an external font service;
  • no external scripts, embeds, video or map services, chat tools or CAPTCHA are present;
  • the pages make no requests to other domains when they load.

Because the website uses no cookies or similar technologies requiring consent, no consent banner is shown. This finding applies to the website as currently built and is reviewed again at every subsequent change.

Necessary technologies

Strictly necessary cookies or temporary browser storage may be used without prior consent where necessary for a function explicitly requested by the visitor, such as security or temporary retention of form input. The current website does not use that option.

Consent

If the website later uses cookies or similar technologies requiring consent, they will be placed only after a free and specific choice. Refusing must be as easy as accepting and the choice must be changeable later.

09

Automated decision-making

No automated decision-making or profiling with legal or similarly significant effects takes place through the website or the contact form.

Spam filters and rate limiting may technically block a request. This is a security measure, not an assessment of the individual.

A submission stopped by the spam protection is not forwarded. If that happens, please contact us directly at info@dvold.com.

10

How do we protect data?

We use appropriate technical and organisational measures where applicable, including:

  • HTTPS;
  • restricted access;
  • server-side validation;
  • spam prevention and rate limiting;
  • secrets outside the public webroot;
  • no form content in URLs or public logs;
  • software and configuration maintenance;
  • backup and recovery measures;
  • processor arrangements;
  • periodic security review.

The contact form is always validated on the server as well, even when the browser has already checked the input. Form content is not placed in the URL and is not written to error logs.

No security measure can remove all risk.

11

Which rights do you have?

Depending on the circumstances, you may request:

  • access;
  • rectification;
  • erasure;
  • restriction;
  • objection;
  • portability;
  • withdrawal of consent where processing is based on consent.

Send your request to info@dvold.com.

We may ask for additional information to verify your identity. We generally respond within one month. For a complex request the statutory period may be extended, and you will be informed if that happens.

You may lodge a complaint with the Dutch Data Protection Authority.

12

Children

The public website and the contact form are not specifically directed at children under 16.

Do not submit a child's data without the involvement of a parent or legal guardian where consent would be the applicable basis.

14

Changes

We may update this statement when the website, technology, organisation or law changes.

The current version and date are shown at the top of this page. A suitable additional notice will be used for material changes where required.

15

Contact

Send privacy questions or requests, and general questions about the website, to info@dvold.com.