Privacy policy

Privacy policy

Last updated: 23 July 2026.

Privacy policy

Privacy policy

Last updated: 23 July 2026.

Who we are

WinSphere is the trade name of WinSphere Dynamics, a sole proprietorship located at Krooneendstraat 19 in The Hague, registered with the Dutch Chamber of Commerce (KvK) under number 93325614. For privacy questions you can reach us at info@winsphere.ai.

What data we process

We process the data you provide yourself, such as your name, business email address, company name, website, sector and team size, plus the data needed to perform our service.

Data that does not come from you directly

For our business services and for approaching potential business contacts, we sometimes process data that we did not receive directly from you. This data comes from public or business sources, such as LinkedIn and Sales Navigator and business data sources like Apollo, and is used for cold email via Instantly and LinkedIn outreach via HeyReach. This concerns business contact details, such as name, job title, company name, sector and business email address. We process this data on the basis of our legitimate interest in business acquisition (Article 6(1)(f) GDPR) and inform you of this no later than at the moment of first contact, in accordance with Article 14 GDPR. You have the same rights as for data you provide yourself, including the right to object. No longer want to be approached by us, or want your data deleted? Send a message to info@winsphere.ai and we will process that request.

Purposes

We use your data to get in touch, draw up quotes and agreements, carry out the assignment and improve our services.

Legal grounds

We process data on the basis of the legal grounds in Article 6 GDPR: the performance of an agreement, compliance with a legal obligation, a legitimate interest such as our business operations, security and business acquisition, or your consent. In doing so, we adhere to the principles of Article 5 GDPR, including data minimisation and storage limitation.

Retention periods

We do not keep data longer than necessary. Specifically: invoices and tax records 7 years (statutory retention obligation), client and assignment data 5 years after the end of the assignment, contact form leads without an assignment 2 years, job application data 4 weeks after rejection (or 1 year with your consent). We retain aggregated, cookieless website statistics in accordance with the settings of our hosting platform Framer. Once Google Tag Manager and Cookiebot are active at launch, the retention periods we configure there apply to any Google Analytics data.

Sharing with third parties

We only share data with parties that help us deliver our services and only insofar as necessary. These parties process data as processors within the meaning of Article 28 GDPR and offer data processing terms as part of their services. For the website and our business operations we work with, among others: Framer (hosting and cookieless website statistics), n8n and HighLevel (processing and follow-up of form submissions), Notion (internal documentation and project administration), and Apollo, Instantly and HeyReach (enrichment and approaching of business contacts, see ‘Data that does not come from you directly’ above). At launch, Google Tag Manager and Cookiebot (consent management) will be added.

Transfer of data outside the EEA

Some of our suppliers are located in the United States or process data outside the European Economic Area. This applies, among others, to Framer (hosting), HighLevel (CRM and follow-up), Notion (internal documentation), Apollo (business data source for acquisition), Instantly (cold email) and HeyReach (LinkedIn outreach), and, at launch, Google (analytics). Our automation environment n8n runs on a server in Germany and therefore falls within the EEA. For transfers outside the EEA we ensure an adequate level of protection: an adequacy decision of the European Commission, including the EU-US Data Privacy Framework for US parties certified under it, or, where that does not apply, the European Commission's standard contractual clauses with additional measures. You can request a copy or summary of these safeguards via info@winsphere.ai.

Cookies and analytics

Our website runs on Framer and currently only uses Framer's built-in, cookieless website statistics (via events.framer.com); no tracking cookies are placed and data is processed in aggregated form. At launch we will activate Google Tag Manager and a consent banner via Cookiebot for any additional analytics; those additional analytics will only run after you have given consent via the banner.

Your rights

Under Articles 15 to 22 GDPR you have the right of access, rectification, erasure, restriction, objection and data portability. You also have the right to withdraw consent at any time, without affecting the lawfulness of the processing prior to withdrawal (Article 7(3) GDPR). To do so, send a message to info@winsphere.ai; we will respond within the statutory period of Article 12(3) GDPR.

Automated decision-making

We do not make decisions with legal effects or similarly significant effects that are based solely on automated processing or profiling of website visitors (Article 22 GDPR).

Security

We take appropriate technical and organisational measures to protect your data, in accordance with Article 32 GDPR. We report a data breach that poses a risk to you without undue delay and where possible within 72 hours to the Dutch Data Protection Authority (Autoriteit Persoonsgegevens, Article 33 GDPR) and, in the event of a high risk, also directly to you (Article 34 GDPR).

Contact and complaints

For questions you can contact info@winsphere.ai. Given the nature and scale of its processing, WinSphere is not required to appoint a data protection officer (Article 37 GDPR). You always have the right to file a complaint with the Dutch Data Protection Authority (Autoriteit Persoonsgegevens).

© 2026 WinSphere · winsphere.ai · KvK 93325614Den Haag, NL
WinSphere