Privacy Policy
Last updated August 4, 2026
Who is responsible for your data
The controller is DominicanVest, a Dutch eenmanszaak registered with the Chamber of Commerce under number 89592654, VAT identification number NL003787200B06, established at Libellenstraat 18A, 3061 VE Rotterdam, Netherlands.
For anything in this policy, including any request about your data, write to info@dominicanvest.com. We do not have a Data Protection Officer; we are not required to appoint one, and we answer these requests ourselves.
This policy is written under the GDPR (Regulation (EU) 2016/679) and the Dutch Uitvoeringswet AVG.
Two things we decided not to do
Worth stating before the detail, because they shape everything below.
We do not sell personal data, and we do not share it for advertising. There is no advertising pixel on this site, no data broker, no lookalike audience.
Our analytics never receives your name, email address or the text you type. Event payloads are validated against a schema that strips anything unrecognised, so a mistake in our own code cannot leak a field. Search terms are sent as a length, never as text. Comments are never sent at all.
Your account
When you register we store your email address, and the name, phone number and country you choose to give. You may add a profile photo. We store your language preference and whether you are a customer or an administrator.
If you sign in with Google, Google gives us your name and email address. We do not receive or store your Google password, and we discard the profile picture Google offers.
If you are an administrator you may register an authenticator app and mark a device as trusted; we then store a hashed token and the browser identification string of that device, so you can recognise it in your device list.
Purpose: to give you an account and let you sign in. Legal basis: performance of a contract (Article 6(1)(b)), and for two-factor authentication our legitimate interest in protecting accounts that hold client data (Article 6(1)(f)).
Orders, payments and invoices
When you buy something we store the service, price, currency, date and status of the order, your billing address and name, the country and postcode used to calculate VAT, and — if you buy as a business — your company name and VAT number.
We also store which versions of our legal documents applied to that order and the exact wording of any declaration you made at checkout, with the time and language. That is how we can tell you later what you actually agreed to.
We never see or store your card details. Payment is handled entirely by Stripe; the card form on our checkout is theirs, not ours.
Purpose: to sell you a service, invoice it and account for it. Legal basis: performance of a contract, and for the invoice and the seven-year retention a legal obligation (Article 6(1)(c), Article 52 Algemene wet inzake rijksbelastingen).
What you send us for the work
To research a property we need what you tell us: the property or question, links or references, your objectives, budget, timeline and any context you provide, and any documents you upload. Where a service includes a call we store your availability preferences and our notes.
These answers can be detailed and personal — your finances, your plans, your reasons. They are stored in a private area readable only by you and by us, and uploaded files sit in private storage that is never publicly addressable.
The report we produce for you is stored the same way and stays available in your account.
Purpose: to perform the service you bought. Legal basis: performance of a contract.
Messages and support
Messages you send through the portal, and enquiries sent through the contact or support forms, are stored with your name, email address and the text of the message.
Purpose: to answer you and to keep a record of what was agreed. Legal basis: performance of a contract where it concerns an order, otherwise our legitimate interest in answering people who write to us.
Email delivery, opens and clicks
Stating this plainly because it is the part people are most often not told about.
Our email provider reports back whether a message was delivered, bounced, opened, or had a link clicked. We store those events and they appear on your record in our admin system.
We use this to tell whether transactional email is arriving — a report notification that silently bounces is a failure we need to see — and to understand which newsletters were useful.
Purpose and legal basis: legitimate interest (Article 6(1)(f)) in reliable delivery and in improving what we send. You can object at any time by writing to us, and we will stop associating these events with you.
Open tracking works through a small image in the message. Most email clients let you block remote images, which turns it off.
Newsletter and marketing
If you sign up for updates we store your email address, the source of the signup, and the exact sentence you agreed to with the date and language.
We ask you to confirm your address by clicking a link before we send anything else. Until you do, you receive nothing but that confirmation request.
Legal basis: consent (Article 6(1)(a)). You can withdraw it at any time — every message carries an unsubscribe link, and your email client's own unsubscribe button also works. Withdrawing is as easy as subscribing and takes effect immediately.
Buying a service does not subscribe you to marketing. Asking a support question does not either.
Comments and likes
If you comment on an article we store the text, your name as displayed, and the time. Comments are public.
If you like an article or a comment we store that. Likes are private: only you and we can see which ones are yours. The number shown publicly is a total, not a list of names. We deliberately do not publish who liked what.
If a comment is reported or moderated we store the report, the decision, the reason and who made it, and you can contest it — see our Community Guidelines.
We store no IP address and no browser identification string with a comment or a like.
Legal basis: consent for publishing the comment, and legitimate interest in moderating what we host, which is also a legal obligation under the Digital Services Act.
Article view counts
We count how often an article is read. To avoid counting the same person twice in a day without identifying them, we compute a one-way hash of a secret value, the date, the network address and the browser identification string.
We do not store the network address or the browser string — only the hash, which we cannot reverse. The date is part of the input, so yesterday's hash cannot be matched to today's. The raw records are deleted after 45 days; only the daily totals per article remain.
We treat this hash as personal data and describe it here rather than claiming it falls outside privacy law. Legal basis: legitimate interest in knowing which research is read.
Abuse prevention
To stop password guessing, spam and mass sign-ups we count recent attempts against a network address, and for sign-in and password reset against the email address used.
These counters live in a separate short-term store and expire by themselves — between 5 minutes and 1 hour depending on what is being limited. They are never joined to your account or used for anything else.
Legal basis: legitimate interest in keeping the service and its users safe.
Analytics and session recording
With your consent we use PostHog, hosted in the European Union, to understand how the site is used. It receives your account identifier if you are signed in — never your name or email, the pages you visit, and the actions you take. Web addresses are cleaned of sensitive parameters before they are sent.
With your consent we also record a sample of sessions on public pages. Everything typed into a field is masked, and recording never runs on account, checkout or payment pages.
We additionally use Vercel's aggregate traffic and performance measurement, which sets no cookie and stores nothing on your device.
Legal basis: consent for PostHog and session recording. You can withdraw it at any time through Cookie settings in the footer, and it takes effect immediately. Full detail is in our Cookie Policy.
Job applications
If you apply for a role we store your name, email, phone, links, message and CV, together with the exact consent statement you agreed to.
Applications and CVs are deleted automatically after the retention period stated on the Careers pages, and you can ask us to delete them sooner at any time.
Legal basis: consent.
Who else processes your data
We use a small number of specialist providers. Each one is bound by a data processing agreement, may only act on our instructions, and may not use your data for its own purposes.
Every provider, what it does and where it processes data is listed on our Subprocessors page, which we keep current.
Beyond that we disclose personal data only where the law requires it — for example to a tax authority or in response to a valid legal order.
We do not sell personal data and we do not share it for advertising purposes.
Data leaving the European Economic Area
We choose European hosting wherever a provider offers it.
Some providers are established outside the EEA or use infrastructure outside it. Where that happens the transfer rests on the European Commission's Standard Contractual Clauses or on an adequacy decision, as set out per provider on our Subprocessors page.
You can ask us for a copy of the safeguards applying to a specific transfer.
How long we keep things
Order records, invoices and payment records: 7 years from the end of the financial year, because Dutch tax law requires it.
The record of which terms you agreed to and what you declared at checkout: 7 years, for the same period as the order it belongs to.
Intake answers, uploaded documents and delivered reports: 2 years after the work is complete, unless you ask us to delete them sooner.
Messages and support correspondence: 2 years after the last message.
Contact records for people who never became customers: 24 months after the last interaction.
Email delivery events: 90 days. Article view records: 45 days. Abuse-prevention counters: minutes to an hour.
Marketing consent and withdrawal records: kept for as long as we operate, in minimal form — we have to be able to honour an unsubscribe indefinitely.
Job applications: as stated on the Careers pages.
Where a dispute, chargeback, refund, investigation or legal claim is open, we suspend deletion of what relates to it until it is resolved. If you have asked us to delete something and this applies, we tell you which part is suspended and why.
Closing your account
You can close your account. What happens then is not "everything disappears", and it is better to be precise about it.
Deleted: your profile details, profile photo, notifications, trusted devices, and your likes.
Anonymised: comments you posted stay online with your name removed, so replies underneath them still make sense. Your name is removed from messages and from meeting records.
Retained: orders, invoices and payment records, for the seven years tax law requires — with your personal details reduced to the minimum the bookkeeping needs. They stop being customer records and become accounting records.
If something is under an open dispute or investigation, deletion of that part waits until it is resolved and we tell you so.
Your rights
You have the right to access your data and receive a copy, to have it corrected, to have it deleted, to restrict or object to processing, and to portability — a machine-readable copy you can take elsewhere.
Where processing rests on consent you can withdraw it at any time, without affecting what was lawful before.
You have an unconditional right to object to direct marketing. Say so and it stops.
Most of this you can do yourself from your account. For anything else, write to info@dominicanvest.com. We acknowledge within 5 business days and answer within one month, which we may extend by two months for a complex request — if we do, we tell you why within the first month.
We do not charge for this. We may ask you to confirm your identity before acting on a request about an account.
Automated decisions and profiling
We do not make decisions about you by automated means that produce legal effects or similarly significant effects.
Comments are held for review by a simple check for spam-like patterns. That is not a decision about you, it is a queue, and a person reads every held comment.
Our research and analysis is produced by people. Where software assists, it does not decide anything about you.
Children
Our services are for adults. You must be 18 to hold an account.
We do not knowingly collect data about children. If you believe a child has given us data, write to us and we will delete it.
How we protect it
Everything travels over encrypted connections. Data is stored encrypted at rest by our providers.
Access to customer data is limited to the administrator account, which requires two-factor authentication. Uploaded documents and reports are in private storage, reachable only through short-lived links issued to the person entitled to them.
Our database enforces access rules at the row level, so a fault in our own code cannot hand one customer another customer's data.
No system is perfect. If a breach occurs that is likely to result in a risk to your rights, we notify the Autoriteit Persoonsgegevens within 72 hours and tell you directly where the risk is high.
Changes to this policy
This document carries a version number and an effective date, shown at the top of this page, and earlier versions remain available.
If we make a change that materially affects how we handle your data, we tell you before it takes effect — by email where we have your address.
If you are not satisfied
Tell us first: info@dominicanvest.com. We would rather fix it.
You also have the right to lodge a complaint with a supervisory authority. Ours is the Autoriteit Persoonsgegevens, Postbus 93374, 2509 AJ Den Haag, Netherlands — autoriteitpersoonsgegevens.nl.
If you live in another EU or EEA country you may complain to your own national authority instead.