Skip to content
annotated.nl
Publications ▾
  • GDPR Annotated
  • AI Act Annotated
  • DSA Annotated coming
  • NIS2 Annotated coming
Pricing Methodology About
EN / NL
Log in Subscribe

Privacy policy

Annotated.nl is a publishing venture by Abacus Legal, a Dutch sole-proprietorship (KvK 89289552, Amsterdam). We care about careful data handling and keep our processing as limited as possible. This document describes what personal data we process, why, for how long, and what rights you have.

1. Who is the controller

Abacus Legal — sole proprietorship (eenmanszaak) — KvK 89289552 — Amsterdam, the Netherlands. Privacy contact: office@annotated.nl.

Abacus Legal has not appointed a data protection officer. The scope of processing falls below the thresholds of GDPR article 37; the contact point for your questions is the address above.

2. What data we process

CategoryExamplesPurpose
IdentificationLegal entity name, billing email, VAT (BTW) IDPerformance of the subscription, invoicing
Session dataann_session cookie (strictly necessary)Maintaining your login session across gdpr.annotated.nl, aiact.annotated.nl, and forthcoming editions
Server logsIP address, user-agent, requested URL, timestampSecurity, debugging, capacity management
Payment dataProcessed by Mollie B.V. — we receive only status + truncated card/IBAN referenceSettlement of payment
CorrespondenceContent of your emails to office@annotated.nlResponding to your request

We do not process special categories of personal data (article 9 GDPR) or criminal-conviction data (article 10).

3. Legal basis per processing activity

ProcessingBasis (GDPR article 6)
Subscription administrationParagraph 1(b) — performance of contract
Invoicing and bookkeepingParagraph 1(c) — legal obligation (Wet OB 1968 art. 52; Algemene Wet Rijksbelastingen)
Session cookieParagraph 1(b) — performance of contract (ePrivacy art. 5(3) carve-out: strictly necessary)
Server logsParagraph 1(f) — legitimate interest (security and operations)
Responding to emailsParagraph 1(f) — legitimate interest (customer contact)

4. Sub-processors and joint controllers

PartyFunctionRoleLocation
Mollie B.V.Payment processingIndependent controller for the payment flowNetherlands
Strato AGServer hosting (VPS)ProcessorGermany

Fonts (Inter, Source Serif 4, JetBrains Mono) are served from our own server. We do not use external content-delivery networks or third-party font services that would transmit your IP address or other data.

5. International transfers

We do not transfer personal data to countries outside the European Economic Area. Our infrastructure and sub-processors are located within the EEA.

6. Retention periods

CategoryPeriod
Invoices and related administration7 years after the end of the calendar year (Algemene Wet Rijksbelastingen art. 52)
Account data (organisation, VAT ID, billing email)Up to 12 months after subscription end, after which deleted or anonymised to the extent permitted by law
Session cookieUntil logout or session expiry (maximum 30 days)
Server logs30 days
Email correspondenceUp to 24 months after last contact, unless longer retention is required by law

7. Your rights

Under the GDPR you have the right to:

  • access the personal data we process about you (art. 15);
  • request rectification of inaccurate data (art. 16);
  • request erasure where compatible with our retention obligations (art. 17);
  • have processing restricted (art. 18);
  • object to processing based on legitimate interest (art. 21);
  • have your data transferred to another controller (art. 20).

You can exercise these rights by emailing office@annotated.nl. We respond within one month. We may ask you to identify yourself before acting on a request.

8. Right to lodge a complaint

You may at any time lodge a complaint with the Dutch Data Protection Authority (Autoriteit Persoonsgegevens — Bezuidenhoutseweg 30, The Hague — autoriteitpersoonsgegevens.nl). We appreciate the opportunity to address your concern first.

9. Security

We apply appropriate technical and organisational measures, including transport encryption (TLS), salted-and-hashed password storage, access control on operational systems, and logging of administrative access. No measure is infallible; if you identify a security issue, please contact office@annotated.nl.

10. Changes

We may amend this privacy policy when necessary — for example when we engage a new sub-processor or introduce a new processing activity. Changes are published on this page with a new date under Version.

11. Version

Version 1.0 — effective 13 May 2026.

Version 1.0 · 2026-05-13

A publishing venture by Abacus Legal. Editor: Pavle Bojkovski, jurist (Amsterdam).

Abacus Legal · eenmanszaak · KvK 89289552 · office@annotated.nl

Built by Abacus Legal (Amsterdam).

Publications

  • GDPR Annotated
  • AI Act Annotated
  • DSA Annotated
  • NIS2 Annotated

Legal

  • Privacy
  • Terms (AV v1.2)
  • Cookies
  • Right of withdrawal
  • Home
  • Methodology
  • About