# Privacy Policy

Source: https://contracko.com/legal/privacy-policy

# Privacy Policy

Version 3.0. Last updated: 26 July 2026.

This Privacy Policy explains how Velocity Ventures B.V., trading as Contracko ("Contracko", "we", "us"), processes personal data when you visit contracko.com, use the Contracko contract-management platform, or engage with our sales and marketing. We are the controller for the processing described here.

Where we act as a processor. When our customers upload contracts and other content to the platform, we process the personal data in that content on our customer's behalf and instructions. For that processing the customer is the controller, and it is governed by our Data Processing Agreement (DPA), not this policy. This policy covers the personal data for which we decide the purpose and means (visitors, prospects, account holders, and our own contacts).

## 1. Who we are

- Controller: Velocity Ventures B.V., trading as Contracko, Van Imhoffplein 19, 2595 SK Den Haag, Netherlands. KvK 87321432.
- Privacy contact: [security@contracko.com](mailto:security@contracko.com).

## 2. What personal data we collect, and where it comes from

Data you provide:

- Account and profile data: name, email, password or authentication data, job title, organisation, contact preferences.
- Sign-in with Google or Microsoft: if you register or log in using Google or Microsoft (OAuth), we receive your name, email address, and a profile identifier from that provider.
- Billing data: billing contact and address. Card details are entered directly with our payment processor and are not stored by us.
- Communications: messages you send us (support, sales, email).

Data we collect automatically when you use the site or app:

- Usage and device data: IP address, approximate location inferred from IP, browser and device type, operating system, referring URLs, pages viewed, and actions taken, collected through cookies and similar technologies and our analytics (see Section 9).

Data we obtain from third parties (business prospects):

- For business-to-business outreach we collect business-contact data (name, job title, organisation, business email, LinkedIn profile) from public sources and enrichment providers. This concerns you in your professional capacity.

We do not intentionally collect special-category (sensitive) personal data, and the platform is not directed at children.

Providing your account and billing details is necessary to create your account and provide the platform, and we are required to collect certain billing information to meet tax and accounting obligations; without this data we cannot provide the platform to you. Any other information you provide (for example optional profile fields or marketing consent) is voluntary, and there is no consequence if you choose not to provide it.

## 3. Why we process it, and our lawful basis

| Purpose | Lawful basis (GDPR Art. 6) |
| --- | --- |
| Provide, operate and secure the platform; manage your account and authentication | Performance of a contract (Art. 6(1)(b)); legitimate interests in securing our services (Art. 6(1)(f)) |
| Billing and payments | Performance of a contract (Art. 6(1)(b)); legal obligation for tax and accounting records (Art. 6(1)(c)) |
| Product and website analytics, service improvement, fraud and abuse prevention | Consent (Art. 6(1)(a)) for analytics that use cookies or similar storage (Section 9); legitimate interests (Art. 6(1)(f)) in improving and securing our services and preventing fraud and abuse |
| Business-to-business sales outreach to prospects | Legitimate interests (Art. 6(1)(f)); we honour objections and opt-outs |
| Marketing and lifecycle email | Consent (Art. 6(1)(a)) where required, or legitimate interests for existing-customer messaging; opt out any time |
| Comply with legal obligations and defend legal claims | Legal obligation (Art. 6(1)(c)); legitimate interests (Art. 6(1)(f)) |

Where we rely on legitimate interests, we have weighed them against your rights; you may object at any time (see Section 8).

## 4. Who we share it with

We share personal data only as needed, and only with processors that act on our instructions under a data processing agreement. The categories of recipients are:

- Hosting, storage and infrastructure and our application database.
- Payment processing.
- Product and website analytics.
- Email delivery (transactional, inbound, and lifecycle) and our support chat.
- Sales and marketing tools (such as CRM and outreach tools) that process business-contact data of prospects.
- AI providers that assist with our sales and marketing communications, customer support, and prospect research, and with analysing product and website usage, and that may process the personal data involved in those activities.

A current list of the processors that handle personal data, with their locations, is available on request. The sub-processors that handle customer content are listed separately in the sub-processor list referenced in our DPA.

We do not sell personal data, and we do not use it to train AI models. We may also disclose personal data where required by law, to defend legal claims, or in connection with a merger, acquisition, or sale of assets (subject to this policy).

## 5. International transfers

Our hosting and primary storage are in the EU. Some processors are established outside the EEA, mainly in the United States. For those transfers we rely on an adequacy decision or the EU-US Data Privacy Framework where the recipient is certified, and otherwise on the EU Standard Contractual Clauses with supplementary measures. Details are available on request.

## 6. How long we keep it

We keep personal data only as long as necessary for the purposes described in this policy, unless a longer period is required by law. In particular, billing and tax records are retained for the statutory period (7 years under Dutch law). When personal data is no longer needed, we delete or anonymise it; residual copies in backups are purged on the normal backup cycle.

## 7. How we keep it safe

We apply appropriate technical and organisational measures, including encryption in transit and at rest, per-tenant isolation, access controls with multi-factor authentication, and ongoing security testing. Our Technical and Organisational Measures are available on request.

## 8. Your rights

Under the GDPR you have the right to access, rectification, erasure, restriction, data portability, and objection, and the right not to be subject to solely automated decisions with legal or similarly significant effects. Where we rely on consent, you may withdraw it at any time (without affecting prior processing). You can opt out of marketing via the unsubscribe link in any email.

To exercise your rights, contact [security@contracko.com](mailto:security@contracko.com). We respond within the statutory time limits. We may need to verify your identity before acting on a request; please do not send a copy of your identity document unless we ask, and if you do, redact your photo and citizen-service number (BSN).

Automated decision-making. We do not make decisions that produce legal or similarly significant effects concerning you based solely on automated processing. The AI features in the platform assist our customers and are subject to human oversight; where they process personal data in customer content, that is governed by the DPA, not this policy.

Supervisory authority. If you believe we process your personal data unlawfully, you have the right to lodge a complaint with the Dutch supervisory authority, the Autoriteit Persoonsgegevens (autoriteitpersoonsgegevens.nl), or with the authority in your EU country of residence.

## 9. Cookies and similar technologies

We use a small number of cookies. A consent banner appears on your first visit; analytics cookies are set only after you opt in, in line with the Dutch Telecommunicatiewet and the ePrivacy rules, and you can change your choice at any time via "Cookie preferences" in the site footer. We use no advertising or cross-site marketing cookies.

For what we store, why, and how to manage your choices, see our [Cookie Statement](https://contracko.com/legal/cookie-statement).

## 10. Changes to this policy

We may update this policy from time to time. We will change the "Last updated" date above and, for material changes, provide a more prominent notice.

## 11. Contact

Velocity Ventures B.V. (Contracko), Van Imhoffplein 19, 2595 SK Den Haag, Netherlands. Privacy contact: [security@contracko.com](mailto:security@contracko.com).

Language. This policy may be provided in other languages for convenience. In the event of any conflict or inconsistency between the English version and a translation, the English version prevails.
