Controller and contact
Royal Label, registered with the Dutch Chamber of Commerce under number 68446756, is the controller. Address: Keizersgracht 520 H, 1017 EK Amsterdam. Privacy questions can be sent to [email protected].
Data, purposes and legal bases
We may process your name, email address, telephone number, postcode, house number, property address, selected service, planning, messages, quotations, correspondence, invoices, building data, drawings, evidence and inspection photographs.
Processing is generally necessary to take steps at your request before a contract, perform a contract, meet a legal duty or pursue a proportionate legitimate interest such as security. Consent is used where required for optional cookies or separate marketing.
Marketing and follow-up
If you select the separate, unticked energy-update option, Royal Label may use your email address for no more than two informative or commercial emails per month. The enquiry can be sent without giving this consent. Every marketing email must offer a simple unsubscribe route, after which marketing stops.
An unfinished, unsent form is not silently stored as a lead and does not automatically trigger email, SMS or WhatsApp messages. Remarketing and advertising pixels may load only after valid consent. Marketing by SMS or WhatsApp requires separate, demonstrable consent.
Recipients and EP-Online
Data may be shared where necessary with hosting, email, administration and software providers, engaged specialists, certification or audit bodies and competent authorities. Energy-performance data is registered in RVO’s EP-Online where required; some label data is publicly searchable by address.
Retention
- Enquiries that do not become assignments: generally up to 2 years after the last substantive contact.
- Core financial records: generally 7 years.
- Energy-performance project files: at least 15 years after completion where BRL 9500 quality assurance requires this.
- Cookie data: for the period shown in the cookie settings or by the provider.
Security, transfers and rights
We use appropriate technical and organisational safeguards. Where a provider processes data outside the EEA, an authorised transfer mechanism and appropriate safeguards are used where required.
You may request access, correction, deletion, restriction or portability, object to certain processing, withdraw consent and complain to the Dutch Data Protection Authority. Contact [email protected].