Privacy statement
This statement covers supplyup.nl and the services SupplyUp provides. It is short because there is little to tell: this site collects as little as possible, and what does come in serves one purpose.
Last updated: 12 August 2026
Who is responsible
SupplyUp, based in Eindhoven, the Netherlands, is the data controller for information submitted through this site. Contact details, Chamber of Commerce number and VAT number appear at the foot of every page.
Questions about privacy, or a request about your data? Email the address in the footer. You will hear back within one working day.
What the site collects by itself
There is not a single third-party script on this site. No Google Analytics, no advertising pixels, no social media widgets, no chat widget. The typefaces are served from our own server and are not fetched from Google.
For visit statistics we use Vercel Analytics. It works without cookies and without profiles: no identifiable visitor ID is stored that would follow you across days or across websites. We see counts per page, not people.
Your IP address is processed briefly to deliver the page and to derive that statistic. It is not retained in readable form.
What you submit yourself
If you fill in the contact or prototype form, we store what you enter. The form has no fields beyond those below, and we add nothing to them.
| Data | Why | Legal basis |
|---|---|---|
| Name | So we can address you | Handling your request |
| Company (optional) | To understand the context of your question | Handling your request |
| Email address | To reply | Handling your request |
| Your description | To judge whether we can help | Handling your request |
| Language choice | To reply in the right language | Legitimate interest |
We use this only to respond to your request and to hold the conversation that follows. It is not sold, not shared with third parties for their own purposes, and not used to approach you unprompted about something else.
The form contains a hidden field that is invisible to you and only filled in by automated spam. If it is filled in, the submission is discarded. There is no captcha and nothing is sent to an external spam service.
How long we keep it
We keep nothing longer than needed. Specifically:
- Enquiries that do not lead to an engagement: twelve months after the last contact at the latest, then deleted.
- Enquiries that do lead to an engagement: kept for the duration of the work, then seven years insofar as Dutch tax law requires it.
- Visit statistics: aggregated, not traceable to a person, and therefore not tied to a retention period.
Want to be removed sooner? One email is enough and we do it within five working days.
Who else processes your data
A small number of suppliers keep the site running. They process only on our instructions.
| Party | For what | Where it sits |
|---|---|---|
| Vercel | Hosting the site and the visit statistic | See the section below |
| Neon | Database holding form submissions and the app registry | See the section below |
| Vercel Blob | Storage for the screenshots on the site | See the section below |
There is no email marketing service, no CRM and no advertising platform in this chain.
Transfer outside the EU
Here we would rather be precise than reassuring. The site is delivered from a European edge network, but the server code currently runs in a Vercel data centre in the United States. That means a form submission passes through the US.
Vercel and Neon are both certified under the EU-US Data Privacy Framework and additionally apply the European Commission's standard contractual clauses. That covers the transfer, but it remains a transfer.
If you process data through us where that is not acceptable, say so: the server region can be set to Frankfurt and that takes no rebuild.
Your rights
Under the GDPR you have the right to:
- see what data we hold about you;
- have it corrected if it is wrong;
- have it deleted;
- have the processing restricted;
- object to the processing;
- receive your data in a common file format.
One email is enough. We respond within five working days and only ask for further identification where it is genuinely needed to place you.
If we cannot resolve it together, you may lodge a complaint with the Dutch Data Protection Authority (Autoriteit Persoonsgegevens).
Data breaches
If we find a breach that poses a risk to those affected, we report it to the Dutch Data Protection Authority within 72 hours and inform you directly where your data is involved. See also the security page.