DM Advocaten Privacy Statement

Your privacy is important to us. We handle your personal data with care and ensure compliance with applicable privacy laws, such as the General Data Protection Regulation (GDPR). Through this privacy policy, we inform you about how we handle your personal data and what your rights are regarding your personal data.

Our Information

DM Advocaten is a trade name of Delissen Martens Advocaten en Belastingadviseurs B.V. (Chamber of Commerce number: 27318862) and is located at Sportlaan 40, The Hague (2566 LB).

Purpose of this Policy

This Privacy Policy applies to the processing of personal data of our clients and all other individuals with whom we maintain contact or who use our services.

What personal data do we process?

We process the following personal data:

  • Contact information and other data, including your name, address, phone number, email address, and (copies of) identification documents obtained from you when you engage us to provide legal services.
  • Case file data: other personal data—including, for example, financial data and health data—that form part of the case file we are handling for you.
  • Website data: data you provide to us via our website using the contact form.
  • Other contact information you have provided to us in other ways, such as during seminars, etc.
  • The IP address of the computer you use to visit our website (see also below under “Use of Cookies”).
  • Video footage from our security cameras on our premises.

Purposes of Use

  1. Performance of a contract

Legal basis: performance of a contract (Art. 6(1)(b) of the GDPR).

If you entrust a case to an attorney, mediator, or tax advisor, your contact information will be requested in any event. You may also be asked to provide a copy of a valid ID. Additionally, other personal data may be necessary for handling the case. Your data will also be used for invoicing the services provided or for applying for legal aid.

Personal data may also be processed regarding parties involved in a legal proceeding, such as the personal data of the party with whom you are in dispute.

Providing contact information and (if applicable) a copy of an identification document is a necessary condition for entering into an agreement with us. Without this information, we cannot proceed with the assignment.

1a. Processing of third-party personal data: opposing parties and conflict-of-interest check

Legal basis: legitimate interest (Art. 6(1)(f) of the GDPR); for the conflict-of-interest check, also a legal obligation (Art. 6(1)(c) of the GDPR) based on the rules of professional conduct applicable to attorneys.

As part of our services, we also process personal data of individuals who are not our clients themselves. This applies to the following situations.

When handling a case, we process personal data of the opposing party, of opposing parties in legal proceedings, of witnesses, experts, and other third parties involved in the case. This is necessary for the proper execution of the assignment our client has entrusted to us. The data typically originates from information provided to us by our client, from public sources, or from court documents.

When accepting a new engagement, we conduct a conflict-of-interest check. To this end, we consult our internal systems to verify whether the firm is currently representing, or has previously represented, a party with an opposing or related interest. This may involve consulting or recording limited personal data—such as the names of potential opposing parties or individuals involved in the case—in our systems.

If you are reading this statement as an opposing party, a witness, or an otherwise involved third party: due to our professional confidentiality obligation (Article 11a of the Lawyers Act), we are generally unable to provide you with further information regarding the specific data processed about you in connection with a case file. This is in accordance with Article 14(5)(d) of the GDPR, which excludes the obligation to provide information when data must remain confidential pursuant to a statutory duty of confidentiality. You may exercise your other rights under the GDPR (such as the right of access or the right to object), to the extent applicable, through our data protection officer, subject to the limitations imposed by professional confidentiality.

  1. Compliance with Legal Obligations

Legal basis: legal obligation (Article 6(1)(c) of the GDPR).

The Money Laundering and Terrorist Financing Prevention Act (WWFT) requires attorneys and tax advisors to obtain and record certain information. This includes, among other things, a (limited) copy of an identity document (passport). Providing this information is a legal obligation; if you do not provide this information, we cannot accept the engagement.

  1. Maintaining contact with you

Legal basis: legitimate interest (Article 6(1)(f) of the GDPR) for existing client relationships; consent (Article 6(1)(a) of the GDPR) for individuals who subscribe solely to our newsletter or other communications without a client relationship.

Your contact information is stored in our client system and may be used, among other things, to send newsletters, updates, invitations to events and seminars, and to provide information you have requested from us.

Our legitimate interest stems from the fact that, as a service provider, we have a legitimate interest in maintaining our relationship with our clients and business contacts by keeping them informed of relevant developments. We have determined that this interest is not disproportionate to your privacy interests, given the existing relationship and the reasonable expectations arising from it.

You may indicate at any time that you no longer wish to receive newsletters or invitations from us. If the processing is based on consent, you may withdraw that consent at any time without affecting the lawfulness of the processing based on the consent prior to withdrawal.

  1. Improving our product and service information and conducting targeted marketing campaigns

Legal basis: legitimate interest (Art. 6(1)(f) of the GDPR).

We are happy to provide you with information that we believe will be of interest to you. For this purpose, we analyze certain data. Our legitimate interest consists of our desire to tailor our services and communications to the needs of our clients and business contacts. We have determined that this interest is not disproportionate to your privacy interests.

Interaction data: This refers to personal data we have obtained from interactions between you and us, for example, through our website or direct contact with our attorneys or other staff members.

Behavioral data: Personal data we process regarding your behavior, such as your preferences, opinions, wishes, and needs.

We measure the business use of our website via Leadinfo. Leadinfo identifies which companies visit our website based on IP addresses. Leadinfo does not store the IP address itself, nor does it place any cookies. Leadinfo processes only business data (company name and address); no personal data is tracked at the individual visitor level.

Conducting and analyzing client satisfaction surveys: We regularly ask clients to participate in a client satisfaction survey. This is done via an (online) questionnaire.

Analyzing the use of our website: The website’s user statistics allow us to gain insight into, among other things, the number of visitors, the duration of visits, and which pages of the website are viewed. This involves the collection of generic data, without information about individual persons.

  1. Improving and securing our website

Legal basis: legitimate interest (Art. 6(1)(f) of the GDPR).

  1. Video surveillance

Legal basis: legitimate interest (Art. 6(1)(f) of the GDPR).

We use clearly visible cameras to monitor our company premises and to ensure the safety of individuals. The cameras are installed in our business premises. In our CCTV Privacy Statement, you can read about how we handle the camera footage.

  1. Automated Decision-Making

We do not use automated decision-making or profiling within the meaning of Article 22 of the GDPR that produces legal effects concerning you or similarly significantly affects you.

Legal Basis for Processing

We process personal data exclusively on the basis of the following legal grounds:

  1. Consent. If we have asked for your consent to process your personal data and you have granted this consent, you always have the right to withdraw it. Withdrawing consent does not affect the lawfulness of the processing based on consent prior to the withdrawal
  2. Contract. If you engage us to provide legal or tax services, we process personal data if and to the extent necessary to perform the engagement.
  3. Legal obligation. The Money Laundering and Terrorist Financing Prevention Act (WWFT) requires attorneys and tax advisors to obtain and record certain information. This includes, among other things, a copy of an identification document (passport). In addition, obligations arise from the rules of professional conduct applicable to attorneys, including the obligation to conduct a conflict-of-interest check upon accepting a new engagement.
  4. Legitimate interest. We may also process personal data if we have a legitimate interest and such processing does not disproportionately infringe upon your privacy. For example, we use your contact information to invite you to relevant events and to send you a newsletter. For each processing purpose, we have explained above—under the relevant purpose—what legitimate interest we are pursuing and how we have balanced this against your privacy interests. You have the right to object to processing based on a legitimate interest at any time.

Third Parties Engaged by Us (processors)

We may engage service providers (processors) to process your personal data; these processors process personal data exclusively on our behalf. We enter into a data processing agreement with these processors. This agreement stipulates, among other things, that the processors act solely on our instructions and may not use the personal data for their own purposes.

Processors we use include, for example, parties that provide and host the software we use. We also engage IT service providers to manage our IT network. Additionally, we use third-party services to send our newsletters.

Use of Cookies

We use cookies on our website. A cookie is a small text file placed on your computer by a web browser. You can block the use of cookies through your web browser. In our cookie policy, which is published separately on our website, you can read about which cookies we use, for what purpose, and how you can give or withdraw your consent.

Disclosure of Personal Data to Third Parties

In the course of providing our services, it may be necessary to share personal data with other parties. For example, in the context of legal proceedings where it is necessary to disclose your personal data to an expert or a bailiff. In most cases, we will consult with you in advance regarding this. We do not share your personal data with third parties for their commercial purposes.

Our attorneys are bound by a statutory duty of confidentiality (Art. 11a of the Dutch Lawyers Act). This duty limits the ability to share personal data arising from the client relationship with third parties and remains in effect even after the conclusion of the engagement.

Transfer Outside the European Economic Area (EEA)

We may transfer personal data to a party outside the EEA if this is necessary for the performance of the engagement agreement to provide legal or tax services, or if it is necessary in the context of a legal proceeding.

In the event that we use a service provider that processes personal data outside the EEA, we ensure that such transfer takes place on the basis of the standard contractual clauses adopted by the European Commission (Implementing Decision (EU) 2021/914). You may request a copy of these standard contractual clauses via the European Commission’s website.

Your Rights

You have the following rights regarding your personal data:

Access (and a copy) of the personal data we process about you.

Rectification: the correction of your inaccurate or incomplete data.

Erasure of personal data. Objection to the use of your data or requesting a restriction on its use. In certain cases, you may even request your data and transfer it to another party (data portability).

We will process your request free of charge and provide you with a response as soon as possible, but no later than one month after receipt. Depending on the complexity of the request, this period may be extended by two months; we will inform you of this within the first month. You can submit your request via email to karel@dm.nl or by mail to our office address. We may ask you to verify your identity in a manner that is proportionate to the nature of the request and the data being requested.

More information about your rights can be found on the website of the Dutch Data Protection Authority (www.autoriteitpersoonsgegevens.nl).

Retention Periods

We retain your personal data for as long as necessary for the purpose for which we obtained the data, unless a statutory retention period applies. For the various categories, we apply the following principles:

Legal and tax files are retained for a period of seven years after the case is closed, unless there are legal reasons to retain a file for a longer period.

Data obtained under the WWFT is retained for at least five years after the termination of services, in accordance with the legal obligation.

Data for newsletters and invitations is retained until you unsubscribe or object.

Data from client satisfaction surveys is retained in accordance with the retention periods applicable to the platforms we use (Advocaatscore and Klanten Vertellen). These can be found in their respective privacy statements.

Security Measures

We take appropriate technical and organizational measures to protect your personal data against loss, unauthorized access, or any other form of unlawful processing. Part of these measures includes using encryption when storing data, requiring two-factor authentication when logging into our IT systems, and performing daily backups of the data on our system. In the event of a data breach that poses a high risk to you, we will notify you as soon as possible.

Data Protection Officer

We have a Data Protection Officer. His name is Milan Karel. You can contact him at: karel@dm.nl or the general office number (T +31 70 311 54 11).

Complaints?

If you have any complaints about how we handle your personal data, please contact us by sending an email to karel@dm.nl or by calling us. We’re happy to help you find a solution. If we’re unable to resolve the issue, you can always contact the Dutch Data Protection Authority.