Last updated: 29 June 2026
This page explains what personal data Daily Dutch News (“DDN”, “we”, “us”) collects when you use dailydutchnews.nl, why we collect it, what we do with it, and the rights you have over your data under the EU General Data Protection Regulation (GDPR / AVG in the Netherlands).
Who we are
The data controller is:
- Daily Dutch News
- Privacy contact: [email protected]
What we collect, why, and on what legal basis
1. Newsletter subscribers
- What: your email address, the lists you opted into, the date and IP address of your sign-up, your browser’s user-agent string at sign-up, and the time/date of confirmation.
- Why: to deliver the newsletters you asked for, to honour your opt-in for legal proof, and to detect abuse / bot sign-ups.
- Legal basis: your explicit consent (Art. 6(1)(a) GDPR), confirmed via double-opt-in.
- Retention: until you unsubscribe. After unsubscribe we keep a minimal record (email hash + status = “unsubscribed”) for 30 days as a suppression list — this stops your address from being re-added by mistake — then we hard-delete the record.
- Where: our WordPress database and the email-delivery system configured for Daily Dutch News (see processors below).
2. Site analytics
If analytics is enabled, we use it to understand which articles people read and how they reach us. Analytics is loaded only after you accept the “statistics” category in our cookie banner.
- What: pseudonymous identifiers, pages viewed, referring URL, approximate location (country / region — IP truncated before storage), device + browser type, language. We do not collect names, email, or precise location.
- Why: to measure audience size + reading patterns so we can produce more of what you actually want.
- Legal basis: your consent via the cookie banner (Art. 6(1)(a) GDPR + Telecommunicatiewet art. 11.7a). With consent denied, no analytics fire.
- Retention: aggregated event data is kept for up to 14 months; raw event data is anonymised within that window.
3. Server logs (essential, no consent required)
- What: requested URL, response status, IP address, timestamp, user-agent.
- Why: security (intrusion detection, abuse blocking) and debugging.
- Legal basis: our legitimate interest in keeping the site secure (Art. 6(1)(f) GDPR).
- Retention: 30 days.
Cookies + similar storage
We use a cookie banner that asks for your explicit consent per category. By default, only strictly-necessary cookies are set (session integrity, security tokens). Statistics + marketing cookies require your opt-in via the banner; you can change your choice any time using the “Cookie preferences” link in the footer.
Who we share your data with (processors + recipients)
We use service providers to operate the site. Where required, those providers act under processor terms or equivalent safeguards. We do not sell or rent personal data to anyone.
| Service | What it does | Where they store data |
|---|---|---|
| Brevo (Sendinblue) | Newsletter delivery + transactional email | EU (Paris, France) |
| Microsoft Clarity | Session-level website analytics — aggregate heatmaps and masked session replay (text + form inputs are masked), used only to understand how visitors use the site and improve it. Never used for advertising or profiling. Loaded only after you consent to statistics cookies. | Microsoft — EU + US (SCCs / EU-US Data Privacy Framework). See Microsoft's privacy statement. |
| Hosting provider | Web server, MySQL database, file storage and server logs | Hosting account region |
International transfers
Some providers may process data outside the European Economic Area (EEA). Where that happens, we rely on the safeguards available under GDPR, such as Standard Contractual Clauses or an adequacy framework where applicable.
Your rights
Under the GDPR you have the right to:
- Access a copy of the personal data we hold about you (Art. 15).
- Correct data that is wrong or out of date (Art. 16).
- Erase (“the right to be forgotten”) — we will delete your data unless we’re legally required to keep it (Art. 17).
- Restrict our processing while a dispute is resolved (Art. 18).
- Port your data to another service in a structured format (Art. 20).
- Object to processing based on legitimate interest (Art. 21).
- Withdraw consent at any time, without affecting prior lawful processing (Art. 7).
To exercise any of these rights, email [email protected]. We respond within 30 days as required by GDPR Art. 12(3).
Children
We do not knowingly collect personal data from anyone under 16. If you believe a minor has signed up, email [email protected] and we will delete the record.
Security
We protect data with HTTPS-only transport, rate-limited APIs, secret keys stored outside web-accessible storage, and routine dependency updates. No system is perfectly secure — if you discover a vulnerability, please email [email protected] rather than disclosing publicly so we can fix it quickly.
Changes to this notice
If we materially change how we process your data, we will update this page and — for active subscribers — note the change in the next newsletter. The “Last updated” date at the top of this page is always authoritative.