Privacy Statement

Kurumi Innovations, sole proprietorship
Papenstraat 73, 2611 JB Delft, the Netherlands
Chamber of Commerce (KvK) number: 74562568 | VAT identification number: NL002499550B72
Contact form
Version 1.2, in force from 3 August 2026

This is a translation of the Dutch text for convenience. In the event of any discrepancy, the Dutch version prevails.

1. About this statement

Kurumi Innovations respects your privacy and processes personal data in accordance with the General Data Protection Regulation (GDPR). This statement describes which personal data we process when you visit our website kurumi.nl, use our contact form or contact us in any other way, and what rights you have.

Where we process personal data as a processor on behalf of a client, for example during a data or AI project, the arrangements in the data processing agreement with that client apply rather than this statement. In that case the client is the controller.

2. Controller

The controller is Kurumi Innovations, Papenstraat 73, 2611 JB Delft, registered with the Dutch Chamber of Commerce under number 74562568. For any privacy question please use our contact form. We are not required to appoint a data protection officer and have not done so.

3. What we process and why

3.1 Contact form

When you complete the contact form we process your email address, the content of your message and the time it was sent. We use this solely to answer your question and handle the related correspondence. Legal basis: performance of, or steps preparatory to, a contract (article 6(1)(b) GDPR) where your message concerns one, and otherwise our legitimate interest in being able to respond to messages (article 6(1)(f) GDPR). Your message is stored in our database and also forwarded to us by email. You receive a confirmation by email.

3.2 Email and other contact

If you contact us directly by email we process your name, email address, any company details and the content of the correspondence, for the same purposes and on the same legal bases as above.

3.3 Client administration

If you are a client or represent one, we process contact details, job title, company details, Chamber of Commerce and VAT numbers, and invoicing and payment data. Legal basis: performance of the contract (article 6(1)(b) GDPR) and compliance with our statutory bookkeeping and retention obligations (article 6(1)(c) GDPR).

3.4 Server logs

Our web server automatically records technical data on each visit: IP address, timestamp, the page requested, the HTTP status code and details of your browser and operating system. We use this to keep the website available and secure and to detect abuse and attacks. Legal basis: our legitimate interest in the security and availability of our systems (article 6(1)(f) GDPR).

3.5 Spam protection

The contact form is protected against automated submissions by a hidden field, a check on the time between opening and sending the form, and a limit on the number of submissions per internet connection. These checks run entirely on our own server; no data is sent to an external service. For the limit we temporarily hold a hashed representation of your IP address, for at most one hour. Legal basis: our legitimate interest in protecting the form against abuse (article 6(1)(f) GDPR).

3.6 Visitor statistics

We keep statistics on how our website is used, so that we know which pages are read and whether the contact form works. We do this entirely ourselves, on our own server in Germany. No external service is involved: visiting the site sends nothing to Google, Meta or any other party.

We set no cookies for this and store nothing on your device. To recognise a returning visitor within the same day we compute a hash of your IP address and your browser details together with a secret value that is replaced every night. Your IP address itself and the full browser details are not stored, and because the secret value changes daily a visit today cannot be linked to a visit yesterday. We therefore cannot see who you are, nor follow you across days.

For each pageview we record: the page requested, the language, the time, the HTTP status code, the render time, the site you came from and any campaign parameters in the link, the type of device, the browser and operating system family, the country, the screen dimensions, how far down the page you read, how long the page was visible, clicks on external links, email addresses and telephone numbers, errors in the page's scripts, and whether the contact form was started, sent or blocked as spam. We build no profiles, take no automated decisions and share this data with no one.

Legal basis: our legitimate interest in understanding and improving our website (article 6(1)(f) GDPR). We have weighed that interest against your privacy and kept the measurement as limited as we could: no cookies, no IP addresses in our database, no third parties, and an identifier that expires every night. You may object under article 21 GDPR through our contact form.

If your browser sends the Do Not Track or Global Privacy Control signal we measure nothing at all: your visit is not counted and the measurement script is not even added to the page. Almost every browser lets you switch this on.

3.7 No tracking or external services

We use no third-party analytics, build no profiles and share no data with advertisers. The website loads no scripts, fonts, maps or other components from external servers. Everything is served from kurumi.nl itself, so visiting the site does not disclose your IP address to any other party. The map on the home and contact pages is an ordinary image. The site does carry ordinary links to other websites, such as OpenStreetMap and LinkedIn; a connection to those is made only if you click one yourself, and from that point their own privacy statement applies.

4. Retention periods

We do not keep personal data longer than necessary for the purposes for which we process it:

DataRetention period
Contact form messages24 months after the last contact
Email correspondence24 months, unless part of a client file
Client files7 years after the end of the assignment
Invoices and accounting records7 years (Dutch tax retention obligation, article 52 AWR)
Server logs12 months at most
Visitor statistics, per pageview6 months
Daily totals of the visitor statistics (not traceable to individuals)indefinitely
Daily secret used to recognise visitors2 days

5. Who receives your data

We do not sell your data and do not share it with third parties for commercial purposes. We do engage the following parties, with whom we have concluded a data processing agreement where required:

6. Transfers outside the European Economic Area

We do not transfer personal data outside the European Economic Area. Our website, database and email are hosted on servers in Germany.

7. Cookies and similar techniques

A cookie is a small text file stored on your device when you visit the website. We set only the two cookies below, both from kurumi.nl itself. There are no third-party cookies on our website.

CookieSet byPurposeCategoryRetention
csrftokenkurumi.nlProtects forms against abuse (CSRF)Necessary1 year
sessionidkurumi.nlSession management in the admin areaNecessary2 weeks

Both cookies are strictly necessary to deliver and secure the website. We may place them without your consent under article 11.7a(3) of the Dutch Telecommunications Act. That is why you will not see a cookie banner on our website: there is nothing to choose, because we use no cookies for statistics, advertising or tracking.

If you would rather not have them, you can delete or block them in your browser settings. The contact form may then stop working.

8. Your rights

Under the GDPR you have the following rights:

Submit your request through our contact form; we reply to the email address you give there. We respond within one month. To avoid disclosing data to the wrong person we may ask for additional information to establish your identity, requesting no more than is necessary.

9. Lodging a complaint

If you are unhappy with how we handle your data, please contact us first. You also always have the right to lodge a complaint with the Dutch Data Protection Authority (Autoriteit Persoonsgegevens), Postbus 93374, 2509 AJ The Hague, autoriteitpersoonsgegevens.nl.

10. Security

We take appropriate technical and organisational measures to protect your data. Traffic to our website is encrypted over HTTPS, access to the database and the admin area is limited to authorised persons, and we keep our systems up to date and take regular backups. No measure offers complete certainty. If you suspect a security problem, please report it through our contact form.

11. No automated decision-making

We do not take decisions about visitors to this website based on automated processing that produce legal effects or otherwise significantly affect them.

12. Changes

We may amend this privacy statement when our practices or the law give cause to. The current version is always on this page, with its version number and effective date at the top.