Legal
Privacy Notice
Openet B.V. operates the Corridor Passport and the Arab–Balkans Corridor website. This notice explains what personal data we collect, why, on what legal basis, who we share it with and what rights you have. It applies to subscribers, prospective subscribers, partner contacts, directory listees and website visitors.
1. Who we are
1.1
The controller is Openet B.V., Willem de Zwijgerlaan 350, 1055 RD Amsterdam, the Netherlands. Chamber of Commerce 75227312. VAT NL860196951B01.
1.2
For privacy matters write to [email protected], marked “Privacy”.
1.3
We have not appointed a Data Protection Officer. Our processing does not require one under Article 37 of the General Data Protection Regulation.
2. What we collect
2.1
Identity and contact data — name, position, company, email, telephone, country, and where relevant the chamber of commerce of which you are a member.
2.2
Subscription data — tier, billing cycle, start and renewal dates, partner code, invoices and payment status. We do not store card numbers; payment card data is handled by our payment provider.
2.3
Trade profile data — sectors, product codes, trade lanes and counterparties you provide so that we can deliver origin assessments, briefings and introductions.
2.4
Verification documents — commercial registry extracts, tax and VAT certificates, and any certifications you upload. These are used to verify your standing and are never published. Company profiles and catalogues are published in your directory listing only where you have given permission.
2.5
Correspondence — emails, enquiry forms, opportunity board posts and meeting notes.
2.6
Technical data — IP address, browser type, pages viewed and referral source, collected when you use the website.
2.7
We do not seek and ask you not to send us special category data as defined in Article 9 of the General Data Protection Regulation.
3. Why we use it, and on what basis
3.1
To provide the subscription — performance of a contract with you, or steps taken at your request before entering one.
3.2
To invoice, collect payment and keep accounts — performance of a contract, and compliance with a legal obligation under Dutch tax law.
3.3
To verify standing and counterparties — our legitimate interest in operating a directory that subscribers can rely on, balanced against the limited and business-facing nature of the data.
3.4
To send the corridor bulletin and service messages — performance of the contract for subscribers; consent for non-subscribers, withdrawable at any time by the unsubscribe link in every message.
3.5
To administer partner attribution and pay the partner share — performance of a contract with the partner, and our legitimate interest in accurate attribution.
3.6
To improve the service and secure the website — our legitimate interest in understanding use and preventing misuse.
4. Who we share it with
4.1
BDS Holding B.V., the corridor’s operating and implementation partner, where necessary to deliver the service.
4.2
Service providers acting on our instructions — payment processing, email delivery, hosting, and accounting. They act as processors under written terms and may not use the data for their own purposes.
4.3
Other subscribers and directory users, in respect only of the business profile you choose to publish in the corridor directory.
4.4
Introduced counterparties, where you have asked us to make an introduction. We tell you before an introduction is made.
4.5
Chambers of commerce and partner institutions, in aggregate and anonymised form only, so that a partner can see take-up among its members without identifying individuals.
4.6
We do not sell personal data, and we do not share it with advertisers.
5. International transfers
5.1
The corridor operates between the European Union, the Western Balkans and Arab markets, so some transfers occur outside the European Economic Area.
5.2
Where we transfer personal data outside the European Economic Area, we do so under an adequacy decision of the European Commission, or under the Commission’s standard contractual clauses together with any additional safeguards a transfer risk assessment indicates.
5.3
A copy of the relevant safeguards is available on request to [email protected].
6. How long we keep it
6.1
Subscription and trade profile data — for the life of the subscription and three years after it ends.
6.2
Invoices and accounting records — seven years, as required by Dutch tax law.
6.3
Partner attribution records — for the life of the partnership and three years after the last share is paid.
6.4
Enquiries that do not lead to a subscription — two years.
6.5
Bulletin subscriptions — until you unsubscribe, and a suppression record thereafter so that we do not contact you again.
7. Your rights
7.1
You have the right to access your personal data, to have inaccurate data corrected, to have data erased in certain circumstances, to restrict or object to processing, to data portability, and to withdraw consent where processing is based on consent.
7.2
Where we rely on legitimate interests, you may object at any time and we will stop unless we can show compelling grounds that override your interests.
7.3
To exercise any right, write to [email protected]. We respond within one month and may ask for information to verify your identity.
7.4
You may complain to the Dutch Data Protection Authority — Autoriteit Persoonsgegevens, Postbus 93374, 2509 AJ The Hague — or to the supervisory authority in your own country. We would prefer the chance to resolve the matter first.
8. Cookies
8.1
The website uses strictly necessary cookies to function. These do not require consent.
8.2
Any analytics or preference cookies are set only with your consent, given through the cookie banner, and may be withdrawn at any time through the same control.
8.3
We do not use advertising or cross-site tracking cookies.
9. Security and changes
9.1
We apply access controls, encryption in transit, and supplier due diligence appropriate to the risk. No system is entirely secure and we cannot guarantee absolute security.
9.2
In the event of a personal data breach likely to result in a risk to your rights, we notify the Autoriteit Persoonsgegevens within seventy-two hours and, where the risk is high, we notify you directly.
9.3
We may update this notice. The current version is published at abc-corridor.com and material changes are notified to subscribers by email.
This notice is governed by the laws of the Netherlands. Version 1.0. Issued by Openet B.V., Amsterdam.