This Privacy Statement explains how Henses Holding B.V. handles personal data in connection with this website, in line with the GDPR/AVG. It reflects the site's current technical setup and data processing arrangements, and Henses Holding reviews it periodically to keep it accurate and legally current — particularly given the regulated sectors the group operates in.
Who is responsible for your data
Henses Holding B.V., Lange Voorhout 30–32, 2514 EE The Hague, the Netherlands.
Chamber of Commerce (KvK): 96277505
Contact for privacy questions: Info@hensesholding.com
This website's own data collection does not involve large-scale systematic monitoring of individuals or large-scale processing of special category data, so a Data Protection Officer is not required under Article 37 GDPR for the activity this statement covers. If any individual operating company's own work (for example, security operations) involves large-scale monitoring, that company should assess its own DPO obligation separately — this statement covers hensesholding.com only.
What this website collects
This site is built to collect only what is necessary:
- No cookies are set for tracking or advertising, and no analytics or ad-tracking pixels are embedded.
- Fonts are served from this server rather than a third party, so visiting the site alone does not send data to outside companies.
- The Contact page includes a form provided by HubSpot. If you submit it, the information you enter (such as name, email, company and message) is sent to and stored by HubSpot on Henses Holding's behalf, in HubSpot's EU (eu1) data region.
Your web host, Hostinger, also records standard server access logs — typically IP address, timestamp, requested page and browser identification — for security, troubleshooting and abuse-prevention purposes. This is standard hosting-infrastructure logging rather than something Henses Holding separately collects or reviews; Hostinger's own retention period for these logs is set out in Hostinger's privacy policy.
If you contact us
Whether you use the contact form, write to the published email address, or call the published number, we process the details you choose to share in order to answer you and, where relevant, to explore a possible business relationship. The legal basis is our legitimate interest in responding to enquiries, and where a contract follows, the performance of that contract.
Retention period: enquiry correspondence and related CRM records are kept for as long as needed to handle the enquiry and, where it does not lead to an ongoing business relationship, for no longer than 24 months from the date of last contact. Where a business relationship does develop, records are kept for the duration of that relationship plus any period required by Dutch tax or corporate record-keeping law.
Who else sees it
Personal data may be shared with service providers acting on our instructions, and with operating companies within the group where necessary to answer you. Known processors currently include:
- HubSpot — contact form submissions and related CRM records (EU data region).
- Hostinger — website hosting and server access logs.
- Microsoft 365 / Outlook — email correspondence with Henses Holding. Microsoft is a global processor; data residency depends on the Microsoft 365 tenant's configured region, which Henses Holding should confirm in its Microsoft 365 admin settings and set to an EU region if not already, so the applicable transfer mechanism can be stated precisely.
No other processors are currently used by this website. This list should be updated whenever a new tool or service provider is added.
Your rights
Under the GDPR you may request access to your personal data, correction, erasure, restriction of processing, or portability, and you may object to processing based on legitimate interests. Write to the contact address above and we will respond within one month.
You also have the right to lodge a complaint with the Dutch supervisory authority, the Autoriteit Persoonsgegevens.
Security
We take appropriate technical and organisational measures to protect personal data against loss and unauthorised access. On this website, that includes enforced HTTPS encryption for all traffic, security headers that restrict which external resources the site can load and how it can be embedded elsewhere (Content-Security-Policy, X-Frame-Options, Referrer-Policy), and access to the hosting account and HubSpot account restricted to authorised personnel. This describes the website's technical measures; broader organisational security practices across Henses Holding are managed separately.
Changes
This statement may be updated from time to time. The version in force is the one published on this page.
Last updated: 19 August 2026