Privacy Policy

V1.1 · Updated 23 August 2026

This Privacy Policy explains how The Trap House handles personal data when you visit our website, contact us, request a quotation, become a Client or otherwise interact with our business.

The Trap House is responsible for the personal data described in this Policy where we determine why and how that data is used.

1. Who we are

The Trap House
Chamber of Commerce (KVK): 62505408
VAT: NL002282294B50
Website: https://traphou.se/

For privacy questions or requests, contact us through the contact form on our website.

2. What personal data we collect

The personal data we process depends on how you interact with us.

Website enquiries

When you use our contact form, we may collect:

  • your name;
  • your email address;
  • the contents of your message; and
  • related correspondence.

Clients and business contacts

If you request a quotation or work with us, we may process:

  • name and business contact details;
  • company and billing information;
  • quotation, contract and project information;
  • communications and approvals;
  • invoice and payment information; and
  • information reasonably required to provide the agreed Services.

Website and technical data

When you visit the website, technical systems may process information such as:

  • IP address;
  • browser and device information;
  • pages requested;
  • date and time of requests;
  • referrer information; and
  • technical logs used for security and operation of the website.

Our use of cookies and similar technologies is described in our Cookie Policy.

3. Why we use personal data

We may use personal data to:

  • respond to enquiries;
  • prepare and manage quotations and agreements;
  • provide and support our Services;
  • communicate with Clients and business contacts;
  • invoice and administer payments;
  • keep required business and tax records;
  • operate, secure and maintain our website and systems;
  • prevent misuse, fraud and security incidents;
  • establish, exercise or defend legal claims.

4. Legal bases

We only process personal data where we have a legal basis under applicable data-protection law.

Depending on the situation, we rely on:

  • steps before or performance of a contract, for example when you ask us for a quotation or we provide agreed Services;
  • legal obligations, including tax and accounting requirements;
  • legitimate interests, for example responding to ordinary business enquiries, maintaining security, administering our business and protecting legal rights, where those interests are not overridden by your rights and interests.

5. Client data we process on behalf of Clients

Some of our Services involve processing personal data on behalf of a Client. Examples can include hosting, IT management, email marketing, customer databases or systems containing user information.

In those situations, the Client determines why and how the personal data is used and acts as Controller. The Trap House acts as Processor and processes that data under the Client's instructions.

Our Data Processing Agreement applies where required.

For personal data we process only on behalf of a Client, that Client is responsible for handling your privacy request. We will forward or assist with the request where required.

6. Who we share data with

We only share personal data where reasonably necessary for the purposes described in this Policy or where required by law.

Depending on the situation, recipients may include:

  • website, hosting and infrastructure providers;
  • email and communications providers;
  • Moneybird, which we use for quotations, invoicing and business administration;
  • payment, banking and accounting providers;
  • cloud, software and IT providers;
  • professional advisers such as accountants or legal advisers;
  • subcontractors working on an agreed project; and
  • analytics, advertising or platform providers where those tools are used lawfully.

Service providers may only receive the information reasonably needed for the service they provide.

7. International transfers

Some service providers may process personal data outside the European Economic Area.

Where applicable, we use a lawful transfer mechanism such as an adequacy decision, approved standard contractual clauses or another mechanism permitted by data-protection law.

8. How long we keep data

We do not keep personal data longer than reasonably necessary for the purpose for which it was collected, unless a longer period is required or justified.

As a general approach:

  • website enquiries are kept for as long as needed to respond and handle reasonable follow-up, unless the enquiry becomes part of a Client relationship or another record we need to retain;
  • project and Client information is kept for as long as needed to provide the Services, manage the relationship and deal with reasonable follow-up or legal matters;
  • financial and administrative records that form part of our statutory business administration are generally retained for at least the legally required period; and
  • technical and security logs are retained only for as long as reasonably needed for operation, troubleshooting or security.

Data may remain for a limited period in routine backups after it has been removed from active systems.

9. Security

We take reasonable technical and organisational measures to protect personal data against unauthorised access, loss, misuse, alteration or disclosure.

The measures used depend on the nature of the data and the systems involved.

No internet service or technical system can be guaranteed to be completely secure.

10. Your privacy rights

Depending on the circumstances, you may have the right to:

  • ask what personal data we hold about you;
  • receive a copy of your personal data;
  • correct inaccurate or incomplete data;
  • ask us to delete personal data;
  • ask us to restrict processing;
  • object to certain processing;
  • receive certain data in a portable format; and
  • withdraw consent where we rely on consent.

These rights are not absolute and may be subject to legal exceptions.

To make a privacy request, contact us through the contact form on our website. We may need to verify your identity before acting on a request.

11. Complaints

If you have a privacy concern, contact us first so we can try to resolve it.

You also have the right to complain to the Dutch Data Protection Authority, the Autoriteit Persoonsgegevens, or another competent supervisory authority where applicable.

12. Cookies and similar technologies

Our website may use cookies, local storage, tags, pixels or similar technologies for website operation and, where enabled, analytics or marketing.

See our Cookie Policy for details.

13. Automated decision-making

We do not use the personal data covered by this Policy to make decisions that are based solely on automated processing and produce legal or similarly significant effects on individuals.

14. Changes to this Policy

We may update this Privacy Policy when our website, Services, suppliers or legal obligations change.

The version and update date shown at the top identify the current published version.