Privacy statement
Most of this statement is about data we do not collect
This is not a template. It describes how this particular website works, which is a static site with no database, no user accounts, no cookies of its own and one form. Where we do process something about you, it is named below with the reason, the legal basis and the retention period.
Who is responsible
The controller is Think Smart Europe B.V., in Amsterdam
One organisation decides what happens to the personal data described on this page, and it is the one you would be contracting with.
Think Smart Europe B.V. Vijzelstraat 68 1017 HL Amsterdam The Netherlands
Telephone +31 (0)20 210 1552 Email info@thinksmart.eu
For anything about your own data: access, correction, deletion, an objection, write to info@thinksmart.eu and put the word privacy in the subject line so it reaches the right person on the first pass rather than the third.
For a security weakness in this website, or in anything else of ours, write to security@thinksmart.eu. The responsible disclosure terms are in our security.txt, and we will not pursue anyone who investigates in good faith and gives us a reasonable chance to fix it first.
One boundary worth stating plainly, because it is the thing most privacy statements blur. This page covers the website and the enquiries that arrive through it. If you become a client, the personal data we process while running your service, accounts, endpoints, logs, incident records, is governed by the processing agreement that forms part of your contract. That agreement, not this page, is the document that decides what happens to it.
What is processed, and why
Four purposes, and one of them is currently switched off
Every purpose we have for personal data on this site is in the table. If a purpose is not listed here, we do not have it, there is no profiling, no scoring, no enrichment from third-party databases and no sale of anything to anyone.
| Purpose | What is processed | Legal basis | How long it is kept |
|---|---|---|---|
| Answering an enquiry you send us | Your name, organisation, work email address, and the phone number, sector, size band and message if you fill them in | Legitimate interest, Article 6(1)(f), you asked us a question and expect an answer. Where the enquiry concerns a possible contract, Article 6(1)(b) applies as well. | Twelve months in the mailbox if the enquiry does not lead anywhere. If it becomes a client relationship, for the term of the contract and the Dutch statutory retention period that follows it. |
| Keeping the form from being abused | Your IP address, and a hidden field that only an automated script fills in | Legitimate interest, Article 6(1)(f), a public form with no protection becomes a relay for other people's spam within days | Not kept. The IP address is held in memory for the duration of the request and is not written to disk or to any log we can read. |
| Website statistics | Microsoft Clarity session data, if and when it is switched on | Consent, Article 6(1)(a). Nothing loads until you click Accept, and refusing costs you nothing. | Nothing today, because it is switched off entirely. Before it is ever switched on, this statement and the cookie statement are updated with the retention period, and the banner appears first. |
| Remembering your answer to that banner | The word accepted or declined, stored in your browser under the key tse-consent | Not a cookie and not personal data we hold, it never leaves your device and is never sent with a request | Until you clear your browser's site data, or change your answer |
There is no fifth row for server logs, because we have none to write about. Azure Static Web Apps does not expose access logs to its customers on any plan, so no record of your visit reaches us in a form we could read, search or keep.
The contact form
What happens to what you type, in order
The form is the only place on this site where you can give us personal data, so it is worth describing exactly rather than generally.
The form posts to a small function on this domain. Nothing is sent to a third-party form service, a marketing platform or a CRM, because there is no CRM behind it.
The function checks the message is well formed, rate-limits by IP address so the form cannot be used to send mail to strangers, relays the message to a mailbox inside the European Union, and then stores nothing. There is no database record, no ticket number and no copy on the web server.
Spam is handled by a hidden field that a person never sees and an automated script fills in. We use that rather than a third-party captcha specifically so that no part of your visit is handed to a captcha provider in order to prove that you are a person.
If the relay is unavailable, the page does not quietly swallow your message. It opens your own mail client with the text already in it, so the enquiry still reaches us and you still have a copy.
The trade-off is real and you should know about it. Because nothing is stored, we cannot show you a copy of your enquiry in a portal later, and if you ask us what you sent us we have to go and look in a mailbox like anyone else.
Cookies and your browser
This site sets no cookies at all
No analytics cookie, no preference cookie, no session cookie, no consent cookie. There is no banner on this page because there is currently nothing to consent to.
The only cookie that could ever be set here is Microsoft Clarity, and it sits behind an explicit consent banner. The Clarity script is not loaded, not requested and not present in the page until Accept has been clicked. Today it is switched off completely at the source, so the banner does not appear at all.
Your answer to that banner, when it exists, is stored in your browser's
local storage under the key tse-consent. That is not a cookie. It is
never attached to a request, it never travels to our server or to anyone
else's, and you can delete it yourself in your browser's developer tools
under Application, Local Storage.
Three related choices, each of which cost us something:
- The typefaces are served from our own origin. Loading them from a font service would send your IP address to a third party before the page had finished painting. We host and update them ourselves instead.
- There are no third-party scripts at all. No tag manager, no advertising tag, no tracking pixel, no embedded video, no chat widget, no social plugin. Every request this page makes goes to this domain, and you can confirm that in the Network tab in about thirty seconds.
- The NIS2 check runs entirely in your browser. The questions, the logic and the outcome are all local. Your answers are not transmitted, not stored and not visible to us. Only what you choose to paste into the contact form afterwards ever reaches us.
What this costs us is straightforward. We do not know how many people read this page, where they came from, or which sentence made them leave. Until statistics are switched on, we are working from what clients tell us in meetings.
Processors and transfers
Two organisations can touch this data, and one of them is not switched on
A processor is a party that handles personal data on our instructions. The complete list is below. There is no analytics provider, no advertising network, no captcha provider, no chat vendor and no data broker on it.
| Party | What it does | What it receives | Where |
|---|---|---|---|
| Microsoft, Azure Static Web Apps | Hosts the published files and runs the contact function | The web request itself, including your IP address, at the moment it is served. Microsoft processes connection data on its own infrastructure for delivery and platform security; that processing is not exposed to us. | An Azure region inside the European Union |
| Our email provider | Delivers and stores the relayed enquiry as an ordinary email | The contents of the form and your email address | Inside the European Union |
| Microsoft Clarity | Website statistics, currently switched off, so it receives nothing | If it is ever enabled and you accept, page interaction data associated with a Clarity cookie | Would involve a transfer to Microsoft in the United States. That is precisely why it sits behind consent and why it is off today. |
| Nobody else | Not included | Not included | Not included |
If Clarity is ever switched on, the transfer mechanism will be named in this statement before the script loads for the first visitor, not afterwards. Personal data collected through this website is not sent to our delivery centers in Bulgaria; that question is answered in full below.
Your rights
Eight rights, and what each one means here
These come from the GDPR and apply to every organisation, including ones that hold very little. The second sentence of each card is what it actually amounts to given how this site works.
Access
You can ask what personal data we hold about you and receive a copy. In practice this means we search the mailbox for your address and send you what is there.
Rectification
You can have incorrect data corrected. If we have written your name or your organisation down wrongly, tell us and we will fix it in the record we hold.
Erasure
You can ask us to delete your data. We will, unless a statutory retention duty applies to an invoice or a contract record, in which case we will tell you which one and for how long.
Restriction
You can ask us to stop using your data while a dispute about its accuracy or our basis for holding it is being resolved.
Portability
Where processing rests on consent or a contract, you can receive your data in a machine-readable form. For a website enquiry this amounts to a copy of your own message.
Objection
Where we rely on legitimate interest, you can object and we then have to stop unless we can show compelling grounds that override your interest. For a marketing approach there is no such override.
Withdrawing consent
Where you have given consent, you can withdraw it at any time and it is as easy as giving it. For statistics that means one click on the banner, whenever it is present.
No automated decisions about you
We take none. Nothing on this site scores, profiles or ranks you, and the NIS2 check produces an indication for you to read, in your browser, not a decision we act on.
How to exercise them
One email address, one month, and no copy of your passport
A right you cannot use without effort is not much of a right, so the route is deliberately short.
Write to info@thinksmart.eu with privacy in the subject line and tell us what you want. We respond within one month, as the GDPR requires, and if a request is genuinely complex we will tell you inside that month that we need longer and why.
We will ask enough to be sure the request is really yours and no more. We will not ask you to email us a copy of your identity document, because collecting more personal data in order to answer a question about personal data is the wrong shape.
If you are not satisfied, tell us first if you are willing; a complaint we never hear about is one we cannot fix. You do not have to. You have the right to lodge a complaint with the Dutch supervisory authority at any time.
Autoriteit Persoonsgegevens Postbus 93374, 2509 AJ Den Haag autoriteitpersoonsgegevens.nl
If personal data we hold is ever breached, we report it to the Autoriteit Persoonsgegevens within 72 hours where the GDPR requires it, and we tell the people affected directly where the risk to them is high. We would apply to ourselves the standard we ask our clients to meet.
The questions people actually ask
Including the one about Bulgaria
You deliver from Bulgaria. Does my data go there?
Not from this website. The pages are served from an Azure region inside the European Union and an enquiry from the form is relayed to a mailbox inside the European Union. Neither route passes through our delivery centers.
For client data the answer is different. Our engineering and monitoring capacity sits in Sofia, Varna and Stara Zagora, and colleagues there work on client systems. Bulgaria is a member state of the European Union, so that is not a third-country transfer at all, it is processing inside the EU, under the GDPR, under the same management systems and the same access controls as Amsterdam. Nearshore, not offshore.
Which colleagues may see what, and under which controls, is set out in the processing agreement that forms part of a service contract. That is the document to read before you sign, and we will send it before you ask.
Why is there no cookie banner?
Because there is nothing to consent to. The site sets no cookies of its own, and the one optional cookie, Microsoft Clarity, is switched off at the source, so the script is not in the page and the banner does not appear.
A banner that appears when no cookie is set is not a courtesy. It trains people to click Accept without reading, which is exactly the habit that makes consent meaningless everywhere else.
If I use the form, do I end up on a mailing list?
No. There is no mailing list, no marketing automation and no CRM behind the form. Your message is relayed to a mailbox and answered by a person.
If we ever start sending a newsletter, it will be a separate opt-in with its own tick box, and using the contact form will not be it.
The NIS2 check asks about my sector and my size. Where does that go?
Nowhere. The questions, the branching logic and the outcome all run in your browser. Nothing is sent to us, nothing is stored, and we cannot see that you took it or what came out.
If you want to discuss the result, you paste it into the contact form yourself. That is the only way it reaches us.
How do I check that any of this is true?
Open your browser's developer tools. Under Application, Cookies, you
should find nothing. Under Network, reload the page and every request
should go to this domain. Under Application, Local Storage, you
should find either nothing or the single tse-consent key.
If a check comes back differently from what is described here, we would like to hear about it at security@thinksmart.eu.
Do you have to answer me if I am not a client?
Yes. The rights above belong to you as a person, not to you as a customer, and they apply whether you have ever spoken to us or simply sent one question through the form.
Changes
When this statement changes, and why it would
We update this statement when the site changes.
This version is dated 28 August 2026. We review it whenever something changes on the site that affects what is described here, rather than on a calendar.
There is one change we already know is coming. If website statistics are switched on, this statement and the cookie statement are updated first, with the provider, the transfer mechanism and the retention period, and the banner appears before the script loads for the first visitor. The order matters, and it is the order most sites get wrong.
If you want to see how the rest of the site is built, including the headers it sends and the checks you can run against it yourself, that is published too.
If something here does not match what your browser sees, tell us
A privacy statement is a claim like any other, and this one is written so that you can check it rather than believe it. Anything you find that we have got wrong is worth an email.
