Privacy Policy
Your privacy matters to us at SendNet. We respect your privacy in relation to all information we collect from you through our website.
1. Inleiding
Below we provide information about the collection of personal data when using
● our website index.html
● our social media profiles.
Personal data is any data that can be related to a specific natural person, such as their name or IP address.
1.1. Contactgegevens
The controller within the meaning of Art. 4(7) of the EU General Data Protection Regulation (GDPR) is SendNet Australia Pty Ltd, [Street address — to be completed], Eastern Creek NSW 2766, Australia, email: sales@send-net.com. We are legally represented by Oskar Ziegler and David Lagarde.
Our data protection officer is heyData GmbH, Kantstr. 99, 10627 Berlin, www.heydata.eu, e-mail: datenschutz@heydata.eu.
1.2. Scope of data processing, processing purposes and legal bases
Below we describe the scope of the data processing, the processing purposes and the legal bases. In principle, the following form the legal basis for data processing:
Art. 6(1)(a) GDPR serves as our legal basis for processing for which we obtain consent.
● Art. 6(1)(b) GDPR is the legal basis insofar as processing personal data is necessary for the performance of a contract, for example where a site visitor buys a product from us or we perform a service for them. This legal basis also applies to processing necessary for pre-contractual measures, such as enquiries about our products or services.
● Art. 6(1)(c) GDPR applies where we comply with a legal obligation by processing personal data, as may be the case under tax law, for example.
● Art. 6(1)(f) GDPR serves as the legal basis where we can rely on legitimate interests to process personal data, for example for cookies necessary for the technical operation of our website.
1.3. Data processing outside the EEA
Insofar as we transfer data to service providers or other third parties outside the EEA, the security of the data during transfer is safeguarded by adequacy decisions of the EU Commission, where these exist (e.g. for the United Kingdom, Canada and Israel) (Art. 45(3) GDPR).
Where no adequacy decision exists (e.g. for the US), the legal basis for the data transfer is usually — that is, unless we state otherwise — the Standard Contractual Clauses. These are a set of rules adopted by the EU Commission that form part of the contract with the third party concerned. Under Art. 46(2)(b) GDPR they safeguard the security of the data transfer. Many of the providers have given contractual guarantees going beyond the Standard Contractual Clauses to protect the data. These include, for example, guarantees relating to the encryption of data or to an obligation on the third party to notify data subjects if law enforcement agencies seek access to the data concerned.
1.4. Retention period
Unless expressly stated otherwise in this privacy policy, the data we store is deleted as soon as it is no longer needed for its intended purpose and no statutory retention obligations prevent deletion. Where data is not deleted because it is needed for other, legally permitted purposes, its processing is restricted — that is, the data is blocked and not processed for other purposes. This applies, for example, to data that must be retained for commercial or tax reasons.
1.5. Data subject rights
Data subjects have the following rights against us in relation to their personal data:
Right of access,
● Right to rectification or erasure,
● Right to restriction of processing,
● Right to object to processing,
● Right to data portability,
● Right to withdraw consent given at any time.
Data subjects also have the right to lodge a complaint with a data protection supervisory authority about the processing of their personal data.
1.6. Obligation to provide data
Within the business or other relationship, customers, prospective customers or third parties must provide us with personal data necessary for the establishment, performance and termination of a business or other relationship, or which we are legally required to collect. Without this data we will generally have to refuse to enter into the contract or provide a service, or will no longer be able to perform an existing contract or other relationship.
Mandatory data is marked as such.
1.7. No automated decision-making in individual cases
In principle we do not use fully automated decision-making within the meaning of Article 22 GDPR to establish and perform the business or other relationship. Should we use such procedures in individual cases, we will notify you separately where legally required.
1.8. Getting in touch
When you contact us, e.g. by email or phone, the data provided to us (e.g. names and email addresses) is stored by us so we can answer your questions. The legal basis for the processing is our legitimate interest (Art. 6(1)(f) GDPR) in answering enquiries addressed to us. We delete the data arising in this context once storage is no longer necessary, or restrict processing where statutory retention obligations apply.
1.9. Customer surveys
From time to time we run customer surveys to get to know our customers and their needs better. In each case we collect the data requested. Getting to know our customers and their needs better is our legitimate interest, so the legal basis for the associated data processing is Art. 6(1)(f) GDPR. We delete the data once the survey results have been evaluated.
2. Nieuwsbrief
Interested parties have the option of subscribing to a free newsletter. We process the data provided during subscription solely to send the newsletter. Subscription takes place by selecting the relevant field on our website, ticking the relevant box on a paper document, or by another clear affirmative action, whereby interested parties declare their consent to the processing of their data, so the legal basis is Art. 6(1)(a) GDPR. Consent may be withdrawn at any time, e.g. by clicking the relevant link in the newsletter or by notifying the email address given above. Processing of the data up to the point of withdrawal remains lawful even in the event of withdrawal.
On the basis of recipients' consent (Art. 6(1)(a) GDPR), we also measure the open rate and click-through rate of our newsletters to understand what is relevant to our audience.
We send newsletters using the Mailchimp tool from provider Rocket Science Group LLC, 675 Ponce de Leon Ave NE, Suite 5000, Atlanta, GA 30308, USA (privacy policy: https://mailchimp.com/legal/privacy/). The provider processes content, usage, meta/communication data and contact details in the process in the US.
3. Data processing on our website
3.1. Informational use of our website
During informational use of the website — that is, where website visitors do not separately send us information — we collect the personal data the browser transmits to our server in order to safeguard the stability and security of our website. This is our legitimate interest, so the legal basis is Art. 6(1)(f) GDPR.
This data is:
● IP address
● Date and time of the request
● Time zone difference from Greenwich Mean Time (GMT)
● Content of the request (specific page)
● Access status/HTTP status code
● Amount of data transferred in each case
● Website the request originated from
● Browser
● Operating system and interface
● Language and version of the browser software.
This data is also stored in log files. It is deleted once it is no longer required, at the latest after 14 days.
3.2. Web hosting and making the website available
Our website is hosted by Webflow, Inc., 208 Utah, Suite 210, San Francisco, CA 94103, USA (privacy policy: https://webflow.com/legal/eu-privacy-policy). In doing so, the provider processes the personal data transmitted through the website, for example relating to content, usage, meta/communication data or contact details. Providing a website is our legitimate interest, so the legal basis for the data processing is Art. 6(1)(f) GDPR.
3.3. Contactformulier
When you contact us through the contact form on our website, we store the data requested there and the content of the message.
The legal basis for the processing is our legitimate interest in answering enquiries addressed to us. The legal basis for the processing is therefore Art. 6(1)(f) GDPR.
We delete the data arising in this context once storage is no longer necessary, or restrict processing where statutory retention obligations apply.
3.4. Vacante posities
We publish vacancies at our company on our website, on pages linked to the website, or on third-party websites.
The data provided as part of an application is processed in order to carry out the recruitment procedure. Insofar as this is necessary for our decision to enter into an employment relationship, the legal basis is Art. 88 GDPR in conjunction with Sec. 26(1) of the German Federal Data Protection Act (Bundesdatenschutzgesetz). We have marked or referenced the data needed to carry out the recruitment procedure accordingly. If applicants do not provide this data, we cannot process the application.
Further data is voluntary and not required for an application. Where applicants provide more information, the basis is their consent (Art. 6(1)(a) GDPR).
We ask applicants not to include information about political opinions, religious beliefs and similar sensitive data in their CV and cover letter. This data is not required for an application. If applicants nonetheless provide such information, we cannot prevent it being processed as part of processing the CV or cover letter. Its processing is therefore based on the applicants' consent (Art. 9(2)(a) GDPR).
Finally, we process applicants' data for further recruitment procedures where they have given us consent to do so. In this case the legal basis is Art. 6(1)(a) GDPR.
We pass applicants' data to the responsible staff in the HR department, to our recruitment data processors and to the staff otherwise involved in the recruitment procedure.
If we enter into an employment relationship with the applicant after the recruitment process, we only delete the data once that employment relationship has ended. In all other cases we delete the data no later than six months after rejecting an applicant.
Where applicants have given us permission to use their data for further recruitment processes as well, we will only delete their data one year after receiving the application.
3.5. Technically necessary cookies
Our website uses cookies. Cookies are small text files stored in the web browser on a website visitor's device. Cookies help make the offering more user-friendly, effective and secure. Insofar as these cookies are necessary for the operation of our website or its functions (hereinafter "Technically Necessary Cookies"), the legal basis for the associated data processing is Art. 6(1)(f) GDPR. We have a legitimate interest in providing customers and other website visitors with a functional website.
Specifically, we set technically necessary cookies for the following purposes:
● Cookies that remember search terms
3.6. Derden
3.6.1. Hotjar
We use Hotjar for analytics. The provider is Hotjar Ltd., Dragonara Business Centre, 5th Floor, Dragonara Road, Paceville St Julian's, STJ 3141, Malta. The provider processes usage data (e.g. web pages visited, interest in content, access times) and meta/communication data (e.g. device information, IP addresses) in the EU.
The legal basis for the processing is Art. 6(1)(a) GDPR. The processing is based on consent. Data subjects may withdraw their consent at any time by contacting us, for example using the contact details in our privacy policy. Withdrawal does not affect the lawfulness of processing carried out before withdrawal.
We delete the data once the purpose for which it was collected no longer applies. Further information is available in the provider's privacy policy at https://www.hotjar.com/legal/po
licies/privacy/.
3.6.2. LinkedIn Inzicht Tag
We use the LinkedIn Insight Tag for conversion tracking. The provider is LinkedIn Ireland Unlimited Company, Wilton Place, Dublin 2, Ireland. The provider processes usage data (e.g. web pages visited, interest in content, access times) and meta/communication data (e.g. device information, IP addresses) in the EU.
The legal basis for the processing is Art. 6(1)(a) GDPR. The processing is based on consent. Data subjects may withdraw their consent at any time by contacting us, for example using the contact details in our privacy policy. Withdrawal does not affect the lawfulness of processing carried out before withdrawal.
The data is deleted once the purpose for which it was collected no longer applies and there is no obligation to retain it. Further information is available in the provider's privacy policy at https://www.linkedin.com/legal/priva
cy-policy?.
3.6.3. HubSpot
We use HubSpot for customer relationship management. The provider is HubSpot, Inc., 25 1st Street, Cambridge, MA 02141, USA. The provider processes usage data (e.g. web pages visited, interest in content, access times), content data (e.g. entries in online forms) and meta/communication data (e.g. device information, IP addresses) in the EU.
The legal basis for the processing is Art. 6(1)(f) GDPR. We have a legitimate interest in managing data simply and cost-effectively.
The data is deleted once the purpose for which it was collected no longer applies and there is no obligation to retain it. Further information is available in the provider's privacy policy at https://legal.hubspot.com/de/privacy-policy.
3.6.4. Matomo
We use Matomo for analytics. The provider is InnoCraft Ltd., 150 Willis St, 6011 Wellington, New Zealand. The provider processes usage data (e.g. web pages visited, interest in content, access times) and meta/communication data (e.g. device information, IP addresses) in the EU.
The legal basis for the processing is Art. 6(1)(f) GDPR. We have a legitimate interest in getting to know our customers and users and their needs better.
The data is deleted once the purpose for which it was collected no longer applies. Further information is available in the provider's privacy policy at https://matomo.org/privacy-policy/.
3.6.5. Axeptio
We use Axeptio to manage consent. The provider is Axeptio, 5 rue du Général Campredon, 34000 Montpellier, France. The provider processes meta/communication data (e.g. device information, IP addresses) in the EU.
The legal basis for the processing is Art. 6(1)(c) GDPR, as the processing is necessary for compliance with a legal obligation to which we are subject.
Further information is available in the provider's privacy policy at https://developers.axeptio.eu/faq/gdpr-and-eprivacy.
3.6.6. Google lettertypen
We use Google Webfonts for typefaces on the website. The provider is Google Ireland Limited, Gordon House, Barrow Street, Dublin 4, Ireland. The provider processes meta/communication data (e.g. device information, IP addresses) in the US.
The legal basis for the processing is Art. 6(1)(a) GDPR. The processing is based on consent. Data subjects may withdraw their consent at any time by contacting us, for example using the contact details in our privacy policy. Withdrawal does not affect the lawfulness of processing carried out before withdrawal.
The legal basis for the transfer to a country outside the EEA is consent.
Further information is available in the provider's privacy policy at https://policies.google.com/privacy?hl=en-US.
3.6.7. Calendly
We use Calendly to schedule appointments. The provider is Calendly LLC, BB&T Tower, 271 17th St NW, Atlanta, GA 30363, USA. The provider processes usage data (e.g. web pages visited, interest in content, access times), contact details (e.g. email addresses, phone numbers) and master data (e.g. names, addresses) in the US.
The legal basis for the processing is Art. 6(1)(a) GDPR. The processing is based on consent. Data subjects may withdraw their consent at any time by contacting us, for example using the contact details in our privacy policy. Withdrawal does not affect the lawfulness of processing carried out before withdrawal.
The legal basis for the transfer to a country outside the EEA is the Standard Contractual Clauses. The security of data transferred to the third country (i.e. a country outside the EEA) is safeguarded by standard data protection clauses (Art. 46(2)(c) GDPR) adopted by the EU Commission in accordance with the examination procedure under Art. 93(2) GDPR, which we have agreed with the provider.
We delete the data once the purpose for which it was collected no longer applies. Further information is available in the provider's privacy policy at https://calendly.com/pages/privacy.
3.6.8. Google Tag Manager
We use Google Tag Manager for analytics and advertising. The provider is Google Ireland Limited, Gordon House, Barrow Street, Dublin 4, Ireland. The provider processes usage data (e.g. web pages visited, interest in content, access times) in the US.
The legal basis for the processing is Art. 6(1)(a) GDPR. The processing is based on consent. Data subjects may withdraw their consent at any time by contacting us, for example using the contact details in our privacy policy. Withdrawal does not affect the lawfulness of processing carried out before withdrawal.
The legal basis for the transfer to a country outside the EEA is the Standard Contractual Clauses. The security of data transferred to the third country (i.e. a country outside the EEA) is safeguarded by standard data protection clauses (Art. 46(2)(c) GDPR) adopted by the EU Commission in accordance with the examination procedure under Art. 93(2) GDPR, which we have agreed with the provider.
We delete the data once the purpose for which it was collected no longer applies. Further information is available in the provider's privacy policy at https://policies.google.com/privacy?hl=en-US.
3.6.9. Zapier
We use Zapier to automate between applications. The provider is Zapier, Inc., 548 Market St. #62411, San Francisco, CA 94104-5401, USA. The provider processes usage data (e.g. web pages visited, interest in content, access times) and meta/communication data (e.g. device information, IP addresses) in the US.
The legal basis for the processing is Art. 6(1)(f) GDPR. We have a legitimate interest in easily connecting the applications in our business to optimise how we work.
The legal basis for the transfer to a country outside the EEA is the Standard Contractual Clauses. The security of data transferred to the third country (i.e. a country outside the EEA) is safeguarded by standard data protection clauses (Art. 46(2)(c) GDPR) adopted by the EU Commission in accordance with the examination procedure under Art. 93(2) GDPR, which we have agreed with the provider.
We delete the data once the purpose for which it was collected no longer applies. Further information is available in the provider's privacy policy at https://zapier.com/privacy.
3.6.10. Facebook-pixel
We use the Facebook Pixel for analytics. The provider is Facebook Ireland Ltd., 4 Grand Canal Square, Grand Canal Harbour, Dublin 2, Ireland. The provider processes usage data (e.g. web pages visited, interest in content, access times) in the US.
The legal basis for the processing is Art. 6(1)(a) GDPR. The processing is based on consent. Data subjects may withdraw their consent at any time by contacting us, for example using the contact details in our privacy policy. Withdrawal does not affect the lawfulness of processing carried out before withdrawal.
The legal basis for the transfer to a country outside the EEA is the Standard Contractual Clauses. The security of data transferred to the third country (i.e. a country outside the EEA) is safeguarded by standard data protection clauses (Art. 46(2)(c) GDPR) adopted by the EU Commission in accordance with the examination procedure under Art. 93(2) GDPR, which we have agreed with the provider.
The data is deleted once the purpose for which it was collected no longer applies and there is no obligation to retain it. Further information is available in the provider's privacy policy at https://www.facebook.com/policy.php.
3.6.11. Google conversietag
We use the Google Conversion Tag for conversion tracking. The provider is Google Ireland Limited, Gordon House, Barrow Street, Dublin 4, Ireland. The provider processes usage data (e.g. web pages visited, interest in content, access times) in the US.
The legal basis for the processing is Art. 6(1)(a) GDPR. The processing is based on consent. Data subjects may withdraw their consent at any time by contacting us, for example using the contact details in our privacy policy. Withdrawal does not affect the lawfulness of processing carried out before withdrawal.
The legal basis for the transfer to a country outside the EEA is the Standard Contractual Clauses. The security of data transferred to the third country (i.e. a country outside the EEA) is safeguarded by standard data protection clauses (Art. 46(2)(c) GDPR) adopted by the EU Commission in accordance with the examination procedure under Art. 93(2) GDPR, which we have agreed with the provider.
The data is deleted once the purpose for which it was collected no longer applies and there is no obligation to retain it. Further information is available in the provider's privacy policy at https://policies.google.com/privacy?hl=en https://support.google.com/tagmana
ger/answer/9323295?hl=nl&ref_topic=3441532.
3.6.12. Typeform
We use Typeform for quizzes and forms. The provider is Typeform S.L., 163 Carrer de Bac de Roda, Barcelona, Spain. The provider processes content data (e.g. entries in online forms) and meta/communication data (e.g. device information, IP addresses) in the US.
The legal basis for the processing is Art. 6(1)(f) GDPR. We have a legitimate interest in requesting information from customers and others in a simple and appealing way.
The legal basis for the transfer to a country outside the EEA is the Standard Contractual Clauses. The security of data transferred to the third country (i.e. a country outside the EEA) is safeguarded by standard data protection clauses (Art. 46(2)(c) GDPR) adopted by the EU Commission in accordance with the examination procedure under Art. 93(2) GDPR, which we have agreed with the provider.
The data is deleted once the purpose for which it was collected no longer applies and there is no obligation to retain it. Further information is available in the provider's privacy policy at https://admin.typeform.com/to/dwk6
gt.
3.6.13. Google Analytics
We use Google Analytics for analytics. The provider is Google Ireland Limited, Gordon House, Barrow Street, Dublin 4, Dublin, D04E5W5, Ireland. The provider processes usage data (e.g. web pages visited, interest in content, access times) and meta/communication data (e.g. device information, IP addresses) in the US.
The legal basis for the processing is Art. 6(1)(a) GDPR. The processing is based on consent. Data subjects may withdraw their consent at any time by contacting us, for example using the contact details in our privacy policy. Withdrawal does not affect the lawfulness of processing carried out before withdrawal.
The legal basis for the transfer to a country outside the EEA is the Standard Contractual Clauses. The security of data transferred to the third country (i.e. a country outside the EEA) is safeguarded by standard data protection clauses (Art. 46(2)(c) GDPR) adopted by the EU Commission in accordance with the examination procedure under Art. 93(2) GDPR, which we have agreed with the provider.
The data is deleted once the purpose for which it was collected no longer applies and there is no obligation to retain it. Further information is available in the provider's privacy policy at https://policies.google.com/privacy?hl=en-US.
4. Data processing on social media platforms
We are present on social media networks in order to present our company and services there. The operators of these networks regularly process their users' data for advertising purposes. Among other things, they create user profiles based on online behaviour, which are used, for example, to show advertising matching users' interests on the networks' pages and elsewhere on the internet. To this end, the network operators store information about user behaviour in cookies on users' computers. It also cannot be ruled out that the operators combine this information with other data. Users can find more information and instructions on how to object to processing by the site operators in the data protection statements of the respective operators listed below. It is also possible that the operators or their servers are located in non-EU countries, so that they process data there. This may pose risks for users, for example because enforcing their rights is more difficult or because government authorities can access the data.
If users of these networks contact us through our profiles, we process the data provided to us in order to answer their questions. This is our legitimate interest, so the legal basis is Art. 6(1)(f) GDPR.
4.1. Facebook
We maintain a profile on Facebook. The operator is Facebook Ireland Ltd, 4 Grand Canal Square, Grand Canal Harbour, Dublin 2, Ireland. The privacy policy is available here: https://www.facebook.com/policy.php. One way to object to the data processing is through the advertising settings: https://www.facebook.com/settings?tab=ads.
We are jointly responsible for processing the data of visitors to our profile on the basis of an agreement within the meaning of Art. 26 GDPR with Facebook. Facebook explains exactly which data is processed at https://www.facebook.com/legal/ter
ms/informatie_over_pagina_inzichten
_data. Data subjects may exercise their rights against both us and Facebook. Under our agreement with Facebook, however, we are obliged to forward requests to Facebook. Data subjects will therefore get an answer faster if they contact Facebook directly.
4.2. Instagram
We maintain a profile on Instagram. The operator is Facebook Ireland Ltd, 4 Grand Canal Square, Grand Canal Harbour, Dublin 2, Ireland. The privacy policy is available here: https://help.instagram.com/51952212
5107875.
4.3. LinkedIn
We maintain a profile on LinkedIn. The operator is LinkedIn Ireland Unlimited Company, Wilton Place, Dublin 2, Ireland. The privacy policy is available here: https://https://www.linkedin.com/leg
al/privacy-policy?_l=de_DE. One way to object to the data processing is through the advertising settings: https://www.linkedin.com/psettings/
guest-controls/retargeting-opt-out.
5. Changes to this privacy policy
We reserve the right to amend this privacy policy with effect for the future. A current version is always available here.
6. Questions and comments
If you have questions or comments about this privacy policy, please feel free to contact us using the details above.





