Legal

Privacy Policy

New Soft Solution — newsoftsolution.com

Effective date: 14 July 2026

Applies to: newsoftsolution.com

1. Who we are

New Soft Solution is a Netherlands-registered IT and software services business. For the processing described in this Privacy Policy, New Soft Solution is generally the “controller” under the General Data Protection Regulation (GDPR), meaning that we determine why and how personal data is processed.

Controller details

Information

Business name

New Soft Solution

Owner / responsible business contact

Sarmila Roka Poudel

Chamber of Commerce number

95603840

VAT number

NL005166191B43

Registered address

Fluitekruidweg 257, 1508 AG Zaandam, the Netherlands

Website-listed office/contact address

Ten Katestraat 45H, 1053 BX Amsterdam, the Netherlands

Email

info@newsoftsolution.com

Telephone

+31 6 8754 5440

Website

https://newsoftsolution.com

2. Scope of this Privacy Policy

This Privacy Policy explains how we collect, use, store, disclose and protect personal data when you:

visit or interact with newsoftsolution.com;

submit a contact request, request a quotation or communicate with us;

subscribe to a newsletter or other business communication;

apply for a job, internship, freelance assignment or other role;

become a client, supplier, contractor, business partner or representative of one of these parties;

use an authorised account, employee portal, timetable or other restricted website function, where available;

interact with a chatbot, support feature or other automated website function, where enabled; or

engage with our social-media pages or links.

This Privacy Policy does not automatically govern separate platforms or products operated by New Soft Solution, such as Find A Table, where a separate privacy policy is provided. The relevant product-specific policy takes precedence for data processed through that product.

3. Personal data we may collect

Category

Examples

Identity and contact data

Name, business name, job title, postal address, email address, telephone number and preferred contact method.

Enquiry and quotation data

Subject of an enquiry, project requirements, budget or timeline information, correspondence, meeting notes and documents voluntarily supplied.

Client and project data

Contract details, authorised contacts, project files, specifications, feedback, support requests, licences, user accounts and service history.

Financial and administrative data

Billing details, invoice information, payment status, VAT information and transaction references. We do not normally store full payment-card details ourselves.

Recruitment data

CV, cover letter, portfolio, qualifications, employment history, availability, interview notes, references and other application information.

Account and access data

Username, role, permissions, login timestamps, password-reset data and audit logs. Passwords should be stored only in protected, non-readable form.

Website and device data

IP address, browser type, device type, operating system, referring page, pages viewed, timestamps, cookie identifiers, diagnostic data and security logs.

Marketing preferences

Newsletter subscription status, consent records, communication preferences and unsubscribe history.

Chatbot and support data

Questions, messages, interaction timestamps and any contact details or project information you choose to provide.

Social-media data

Public profile information, comments, messages or interactions when you communicate with us through a social-media platform.

4. Data we do not ask you to provide

Please do not send special-category personal data or highly confidential personal information through general website forms or a chatbot unless we specifically request it and have a lawful reason to process it. This includes health information, biometric data, religious or political beliefs, trade-union membership, sexual-orientation data, government identification numbers, passwords and payment-card information.

Our services and corporate website are not directed to children. A person under 16 should not provide personal data through the website without the involvement and authorisation of a parent or legal guardian.

5. How we obtain personal data

We may obtain personal data directly from you, from the organisation you represent, through website technologies, from public professional sources, from recruitment platforms, from business partners, or from service providers acting on our behalf. Where we receive information from a third party, we use it only where we have a lawful basis and the use is compatible with the context in which it was provided.

6. Purposes and legal bases

Purpose

Typical legal basis under the GDPR

Responding to enquiries, arranging meetings and preparing quotations

Taking steps at your request before entering into a contract; legitimate interests in responding to business enquiries.

Providing software, web, mobile, cloud, analytics, cybersecurity, marketing or related services

Performance of a contract; legitimate interests in managing and improving service delivery.

Client administration, invoicing, tax and accounting

Performance of a contract; compliance with legal obligations; legitimate interests in financial administration and debt recovery.

Managing authorised accounts, employee access and timetables

Performance of a contract or employment-related arrangements; legal obligations; legitimate interests in secure and efficient operations.

Website operation, fraud prevention, troubleshooting and information security

Legitimate interests in operating and protecting our website, systems, users and business; compliance with legal obligations.

Analytics and website improvement

Consent where required for analytics cookies or similar technologies; in limited cases, legitimate interests where a privacy-friendly method is legally permitted.

Newsletters and direct marketing

Consent, or legitimate interests for relevant business-to-business communications where permitted by law. You can object or unsubscribe at any time.

Recruitment and selection

Taking steps before entering into an employment or service contract; legitimate interests in recruitment; consent where we keep an unsuccessful application for future vacancies.

Handling disputes, complaints and legal claims

Legitimate interests in protecting legal rights; compliance with legal obligations.

Chatbot operation and support

Legitimate interests in efficient support; taking steps before a contract; consent where non-essential cookies or external AI processing requires it.

Where we rely on legitimate interests, we consider the necessity of the processing, our business purpose and the impact on your privacy. Where consent is the legal basis, you may withdraw it at any time without affecting processing that occurred before withdrawal.

7. Chatbot and automated assistance

If a chatbot or automated support feature is enabled, it may use website content and preconfigured responses to answer common questions. Chat messages may be logged to operate, secure and improve the feature. If the chatbot cannot provide a reliable answer, it should direct the user to our contact page or a human contact channel rather than inventing information.

Do not enter sensitive information, passwords, confidential source code, payment-card details or special-category personal data into the chatbot. Where an external chatbot or artificial-intelligence provider processes messages for us, that provider acts under contractual and data-protection safeguards appropriate to its role.

8. Sharing personal data

We do not sell personal data. We may share personal data only where reasonably necessary with:

hosting, cloud, email, collaboration, customer-support, analytics, cybersecurity and backup providers;

accounting, payment, banking, insurance and professional advisers;

developers, contractors and project partners who require access for an authorised task and are subject to confidentiality obligations;

recruitment platforms, referees or assessment providers where relevant to an application;

social-media or embedded-content providers when you use their functions;

public authorities, regulators, courts or law-enforcement bodies when disclosure is legally required; and

a purchaser, investor or successor in connection with a genuine merger, restructuring, financing or transfer of business, subject to appropriate confidentiality and privacy safeguards.

Where a service provider processes personal data on our behalf, we use a data processing agreement where required. Some providers independently determine aspects of their processing and may therefore act as separate controllers for those activities.

9. International data transfers

Some service providers or project team members may be located outside the European Economic Area (EEA), including in countries where New Soft Solution recruits or collaborates. When personal data is transferred outside the EEA, we use a lawful transfer mechanism where required, such as an adequacy decision, the European Commission’s Standard Contractual Clauses, supplementary safeguards, or another permitted GDPR mechanism.

You may contact us for general information about the safeguards relevant to your data. We may limit information where necessary to protect security, confidentiality or third-party rights.

10. Retention periods

We retain personal data only for as long as necessary for the purpose for which it was collected, to meet legal obligations, or to establish, exercise or defend legal claims. Typical retention periods are:

Data type

Typical retention approach

Contact and quotation enquiries

Normally up to 24 months after the last meaningful contact, unless an agreement begins, a longer follow-up period is justified, or deletion is requested and no legal reason requires retention.

Client, contract and project records

For the duration of the relationship and afterwards for the applicable limitation period or as needed for support, warranty, security, dispute and evidence purposes.

Invoices and core business administration

At least 7 years where required under Dutch tax and business-record rules; longer where a specific statutory requirement applies.

Recruitment applications

Normally deleted no later than 4 weeks after the recruitment process ends if the candidate is not appointed, unless the candidate consents to retention for future vacancies, generally for no more than 1 year.

Newsletter and marketing data

Until you unsubscribe or object. A minimal suppression record may be retained to ensure that your opt-out is respected.

Account and security logs

For a period proportionate to operational and security needs, typically between 6 and 24 months unless an incident, investigation or legal obligation requires longer retention.

Chatbot and support conversations

For as long as necessary to respond, monitor quality, maintain security and resolve disputes; unnecessary content should then be deleted or anonymised.

Cookie and consent records

For the lifetime stated in the Cookie Policy and for a reasonable period to demonstrate consent or refusal.

11. Security

We use appropriate technical and organisational measures designed to protect personal data against accidental or unlawful destruction, loss, alteration, unauthorised disclosure or access. Depending on the risk and service, these measures may include access controls, role-based permissions, secure password storage, encryption in transit, system updates, backups, logging, supplier controls, confidentiality obligations, incident procedures and restricted administrative access.

No website, transmission method or storage system is completely secure. You are responsible for using strong, unique passwords, protecting account credentials and informing us promptly if you suspect unauthorised access.

12. Your privacy rights

Subject to the conditions and exceptions in the GDPR, you may have the right to:

receive clear information about the processing of your personal data;

request access to your personal data;

request correction of inaccurate or incomplete data;

request deletion of personal data;

request restriction of processing;

object to processing based on legitimate interests or to direct marketing;

receive certain data in a structured, commonly used and machine-readable format and transmit it to another organisation;

withdraw consent at any time where processing is based on consent; and

not be subject to a decision based solely on automated processing that produces legal or similarly significant effects, except where legally permitted with appropriate safeguards.

To exercise a right, email info@newsoftsolution.com and describe your request. We may ask for reasonable information to verify your identity and prevent unauthorised disclosure. We normally respond within one month, although the GDPR allows an extension for complex or numerous requests. We will explain any lawful reason for refusing or limiting a request.

13. Complaints

Please contact us first so we can try to resolve your concern. You also have the right to lodge a complaint with the Dutch Data Protection Authority (Autoriteit Persoonsgegevens) or, where applicable, another competent supervisory authority in the EEA.

14. External links, social media and embedded content

Our website may contain links to Facebook, LinkedIn, Instagram or other external websites and may embed maps, videos, fonts, widgets or similar content. External providers may collect data when their content loads or when you interact with it. Their own privacy and cookie policies apply to their independent processing. We encourage you to review those policies before using the external service.

15. Changes to this Privacy Policy

We may update this Privacy Policy when our services, website technologies, suppliers or legal obligations change. The latest version will be published on our website with a revised “last updated” date. Material changes may also be communicated through an appropriate additional notice.

16. Contact

Questions, requests or complaints about privacy may be sent to:

Email: info@newsoftsolution.com

Telephone: +31 6 8754 5440

Postal address: New Soft Solution, Fluitekruidweg 257, 1508 AG Zaandam, the Netherlands