This policy outlines how Asset Family collects, uses, stores, shares, and protects personal data incompliance with applicable data protection laws and ISO/IEC 27001 requirements. The policy isintended to ensure the confidentiality, integrity, and availability of personal information.
This policy applies to:
Personal Data: Any information relating to an identified or identifiable natural person
Data Subject: An individual whose personal data is processed
Processing: Any operation performed on personal data (e.g., collection, storage, use)
Controller: The entity that determines the purposes and means of processing
Processor: The entity that processes data on behalf of the controller
Personal data is processed lawfully, fairly, and transparently. Legal bases may include:
We may collect and process the following categories of personal data:
Personal data is collected for specific, explicit, and legitimate purposes, including:
Personal data may be shared with:
International data transfers will follow applicable data protection laws (e.g., GDPR Article 44+) and be protected with appropriate safeguards such as Standard Contractual Clauses.
Personal data is retained only as long as necessary for the purposes outlined in this policy, or as required by legal obligations or contractual commitments. A data retention schedule is maintained and reviewed annually.
Data subjects have the right to:
Requests can be submitted to:
Jeroen van Proosdij
jeroen.van.proosdij@assetpeople.com
In accordance with ISO/IEC 27001 controls, Asset Family implements:
In the event of a data breach:
DPO / Information Security Officer: Oversight of data protection program
IT Department: Ensuring secure infrastructure and systems
Employees: Following policies, reporting incidents
This policy will be reviewed annually or after any significant changes in processing activities, regulatory requirements, or ISO/IEC 27001 updates.
Data Protection Officer (DPO)
Jeroen van Proosdij
jeroen.van.proosdij@assetpeople.com
+31655408560