Privacy
Version: July 2026
1. Who we are and to whom this privacy statement applies
New Aspect B.V. attaches great importance to the protection of personal data. We process personal data carefully, transparently and in accordance with the General Data Protection Regulation (GDPR) and other applicable laws and regulations.
This privacy statement applies, among other things, to personal data that we process relating to:
- customers and dealers;
- suppliers;
- business contacts;
- prospective customers;
- users of our webshop and customer portal;
- visitors to our website;
- persons who contact us by email, telephone or through a form.
The controller is:
New Aspect B.V.
Generatorstraat 60
7556 RC Hengelo
The Netherlands
Telephone: 085 – 065 68 88
Email: [email protected]
Chamber of Commerce number: 08134992
VAT number: NL814424910B01
Questions about this privacy statement or the processing of personal data may be sent to [email protected].
2. What personal data do we process?
Depending on your relationship with New Aspect, we may process the following categories of personal data:
- name, company name and position;
- address and contact details;
- telephone number and email address;
- Chamber of Commerce number and VAT number;
- customer or dealer number;
- account, user and login details;
- purchase, order and invoice details;
- delivery addresses and shipping and tracking details;
- payment status, bank and transaction details;
- data concerning returns, repairs and warranty claims;
- correspondence and contact history;
- information that you provide through a form, by email or by telephone;
- newsletter preferences and subscription or unsubscribe details;
- IP address, browser data, device data, session data and technical or security log data;
- other personal data necessary for our services or business operations.
We do not process data that is not necessary or relevant for the purpose for which it is collected. Our services are not directed at persons under the age of 16.
Sources of personal data
In most cases, we receive personal data directly from you. In some cases, we receive business contact details through:
- your employer or a colleague;
- a customer, supplier or other business relationship;
- public trade registers, such as the Trade Register of the Netherlands Chamber of Commerce;
- publicly accessible business websites;
- logistics, administrative or payment service providers;
- credit or business information service providers, insofar as we use their services.
Where we do not receive data directly from you, we process it only if a valid legal basis exists.
Mandatory data
Data that we identify as mandatory in a form or ordering process is required, for example, to:
- create an account;
- prepare a quotation;
- process an order;
- deliver products;
- process a payment or invoice;
- handle a warranty claim or return request;
- comply with a legal obligation.
If you do not provide this data, we may be unable to provide the relevant service, or may be unable to provide it in full.
3. Why and on what legal basis do we process personal data?
We process personal data only for clearly defined purposes and where a legal basis exists.
Accounts and business relationships
We process personal data for the following purposes:
- creating and managing customer and dealer accounts;
- registering contact persons;
- maintaining business relationships;
- managing access rights to our webshop or customer portal.
The legal basis is performance of a contract where you are the contracting party. Where you act on behalf of an organisation, we generally base the processing on our legitimate interest in performing and maintaining the business relationship.
Quotations, orders and deliveries
We process personal data for the following purposes:
- preparing and following up quotations;
- processing orders;
- delivering and tracking products;
- processing payments;
- sending order confirmations and invoices;
- handling return, repair and warranty requests;
- providing customer service.
The legal basis is performance of a contract or taking steps prior to entering into a contract. For contact persons of business customers, the legal basis may also be our legitimate interest in performing the contract with their organisation.
Contact and communication
When you contact us, we process your personal data in order to:
- answer your question;
- handle a contact request;
- provide information;
- resolve a complaint or problem;
- manage our correspondence and business relationship.
Our legitimate interest in this context is to respond to business enquiries, provide good service and maintain business relationships.
Administration and legal obligations
We process personal data for the following purposes:
- our financial administration;
- invoicing;
- tax audits;
- product and warranty registration;
- complying with statutory record-keeping and retention obligations;
- responding to lawful requests from supervisory authorities or government bodies.
The legal basis is compliance with a legal obligation.
Security and prevention of misuse
We may process personal and technical data in order to:
- secure our website, webshop and systems;
- prevent unauthorised access;
- investigate fraud, misuse and cyber incidents;
- manage backups and log files;
- ensure the proper technical operation of our services.
Our legitimate interest is to protect our systems, employees, customers and business information and to prevent fraud and misuse.
Creditworthiness and payment risk
When an application is made for a business account, credit limit or payment on account, we may, where necessary, consult public trade data or information from a credit or business information service.
We do this to assess payment risks, prevent fraud and make responsible business decisions. The legal basis is our legitimate interest in limiting financial risks.
Any credit assessment will not, without human intervention, result in a decision that produces legal effects concerning you or similarly significantly affects you.
Balancing of interests
Where we rely on a legitimate interest, we assess in advance whether that interest outweighs your privacy interests, rights and freedoms. We do not process more data than is necessary for the relevant purpose.
4. Newsletters and commercial communications
We send commercial emails where:
- you have given your prior consent; or
- the statutory existing-customer exception applies.
Where we rely on the existing-customer exception, we will inform you only about our own products or services that are similar to products or services you previously purchased from us.
You may unsubscribe at any time, free of charge:
- using the unsubscribe link in every commercial email; or
- by contacting us at [email protected].
Withdrawal of consent does not affect the lawfulness of processing carried out before consent was withdrawn.
After you unsubscribe, we may retain your email address in limited form on a suppression list. We do this solely to ensure that you do not receive commercial emails again.
5. With whom do we share personal data?
New Aspect never sells or rents personal data to third parties.
We share personal data only where this is necessary for our services, business operations or legal obligations.
Depending on the circumstances, personal data may be shared with:
- IT, (Google) cloud, security and hosting service providers;
- providers of email, document and communication systems;
- financial and administrative service providers;
- accountants and professional advisers;
- banks and payment service providers;
- newsletter and marketing service providers;
- project management and collaboration platforms;
- credit information, credit insurance or debt collection service providers, insofar as their services are used;
- carriers, fulfilment partners and other logistics service providers;
- government bodies, supervisory authorities or law-enforcement agencies where we are legally required to disclose data;
- parties involved in a possible reorganisation, merger, acquisition or transfer of business activities, insofar as legally permitted.
Service providers that we use include:
- Microsoft 365 for email, communications and documents;
- Exact Online for financial administration;
- Mailchimp for newsletters;
- Wrike for project management;
- PostNL, GLS, Eurosped and DHL for the delivery and processing of shipments.
Depending on their services, these parties process personal data on behalf of New Aspect as processors or for their own purposes as independent controllers.
Where required by the GDPR, we enter into a data processing agreement with parties that process personal data on our behalf. We do not provide more personal data than is necessary for the relevant service. This list may change when we engage new service providers.
6. Processing outside the European Economic Area
Some service providers or their subprocessors may process personal data outside the European Economic Area (EEA).
Where personal data is processed outside the EEA, we ensure that a valid transfer mechanism is in place. Depending on the country and service provider, we use:
- an adequacy decision of the European Commission;
- Standard Contractual Clauses approved by the European Commission;
- additional technical, contractual or organisational safeguards;
- another legally permitted transfer mechanism.
An adequacy decision is used only where it actually applies to the country concerned and, where relevant, to the organisation concerned.
You may request further information at [email protected] about the safeguards we use for international data transfers. To the extent legally possible, you may also request a copy of the relevant safeguards.
Where personal data is processed by organisations in the United States that are certified under the EU-US Data Privacy Framework, that certification may serve as an appropriate transfer mechanism.
7. How long do we retain personal data?
We do not retain personal data for longer than is necessary for the purpose for which it was collected. We also take account of statutory retention obligations, warranty periods, possible disputes and applicable limitation periods.
In principle, we apply the following retention periods:
| Data | Retention period |
| Contact requests | Up to 12 months after full resolution |
| Quotation requests | Up to 2 years after the last substantive contact |
Customer and dealer accounts | For as long as the account is active and up to 2 years after termination of the business relationship, unless the data is required for longer for administration, claims or legal obligations |
| Purchase, order and invoice details | In principle, 7 years after the end of the financial year to which the records relate |
| Data subject to a special EU VAT scheme |
Up to 10 years where required by applicable tax legislation |
| Payment and transaction details | For as long as necessary for the payment and thereafter in accordance with tax and administrative retention obligations |
| Warranty, repair and return data | For the duration of handling and the warranty period and thereafter for as long as necessary in connection with applicable statutory limitation or liability periods |
| Newsletter data | Until you unsubscribe or withdraw your consent |
| Suppression list for commercial email | For as long as necessary to honour your unsubscribe request or objection |
| Technical and security data | No longer than necessary for security, troubleshooting and investigation of incidents |
When data is no longer required, we delete or anonymise it. Data may be retained for longer where this is necessary due to a legal obligation, ongoing dispute, fraud investigation or security incident.
8. Cookies and security
Our website and webshop use functional cookies that are necessary for their proper and secure operation.
These cookies may be used for:
- securely logging in to an account;
- remembering a session;
- the operation of the webshop and shopping cart;
- securing forms;
- preventing misuse;
- ensuring the technical operation of the website.
No prior consent is required for strictly necessary functional cookies.
New Aspect does not use tracking or advertising cookies without first requesting the required consent. If our use of cookies or similar technologies changes, we will amend this privacy statement and request consent where legally required.
Security
We take appropriate technical and organisational measures to protect personal data against loss, misuse, unauthorised access, alteration, disclosure and other unlawful processing.
Our security measures are tailored to the nature of the data, the processing and the associated risks. Only employees and service providers who require personal data for their work are granted access to it.
No system can guarantee complete security. If a personal data breach occurs, we investigate and handle it in accordance with applicable legal obligations.
If a personal data breach is likely to result in a high risk to data subjects, we notify both the Dutch Data Protection Authority (Autoriteit Persoonsgegevens) and the affected data subjects where required by the GDPR.
9. Your data protection rights
Where we process your personal data, you have, depending on the circumstances, the right to:
- access your personal data;
- rectification or completion of inaccurate or incomplete personal data;
- erasure of personal data;
- restriction of processing;
- data portability, where this right applies by law;
- object to processing based on a legitimate interest;
- object to direct marketing;
- withdraw previously given consent at any time;
- lodge a complaint with the Dutch Data Protection Authority (Autoriteit Persoonsgegevens).
Some rights are subject to statutory conditions and exceptions. For example, we may refuse a request where we are required by law to retain certain data.
For direct marketing, we stop the processing as soon as you object to it. You may send your request to [email protected]. Please state clearly which right and which data your request concerns.
To prevent misuse, we may ask you to provide additional information enabling us to verify your identity. We will not request more information than is necessary.
We will generally respond within one month of receiving your request. Where a request is complex or we receive multiple requests, we may extend this period by up to two further months. We will inform you within the first month of the extension and the reasons for it.
10. Automated decision-making
New Aspect does not make decisions based solely on automated processing that produce legal effects concerning individuals or similarly significantly affect them.
Digital systems may support employees, for example in account management, fraud prevention or credit assessment. A decision with significant consequences is not made solely by an automated system.
When using AI functionalities, we handle personal data with care. We assess in advance whether the use of an AI application is appropriate, limit the processing of personal data where possible and take appropriate measures to protect the privacy of data subjects.
11. Complaints, amendments and contact
Do you have questions, or are you dissatisfied with the way we handle your personal data? Please contact us first at [email protected]. We will endeavour to resolve your question or complaint carefully.
If we are unable to resolve the matter together, you have the right to lodge a complaint with the Dutch Data Protection Authority (Autoriteit Persoonsgegevens).
New Aspect may amend this privacy statement if our services, business processes or applicable laws and regulations change. The most recent version will be published on our website.
The date on which this privacy statement was last amended is stated at the top of the document.