Privacy statement

This statement covers supplyup.nl and the services SupplyUp provides. It is short because there is little to tell: this site collects as little as possible, and what does come in serves one purpose.

Last updated: 12 August 2026

Who is responsible

SupplyUp, based in Eindhoven, the Netherlands, is the data controller for information submitted through this site. Contact details, Chamber of Commerce number and VAT number appear at the foot of every page.

Questions about privacy, or a request about your data? Email the address in the footer. You will hear back within one working day.

What the site collects by itself

There is not a single third-party script on this site. No Google Analytics, no advertising pixels, no social media widgets, no chat widget. The typefaces are served from our own server and are not fetched from Google.

For visit statistics we use Vercel Analytics. It works without cookies and without profiles: no identifiable visitor ID is stored that would follow you across days or across websites. We see counts per page, not people.

Your IP address is processed briefly to deliver the page and to derive that statistic. It is not retained in readable form.

What you submit yourself

If you fill in the contact or prototype form, we store what you enter. The form has no fields beyond those below, and we add nothing to them.

DataWhyLegal basis
NameSo we can address youHandling your request
Company (optional)To understand the context of your questionHandling your request
Email addressTo replyHandling your request
Your descriptionTo judge whether we can helpHandling your request
Language choiceTo reply in the right languageLegitimate interest

We use this only to respond to your request and to hold the conversation that follows. It is not sold, not shared with third parties for their own purposes, and not used to approach you unprompted about something else.

The form contains a hidden field that is invisible to you and only filled in by automated spam. If it is filled in, the submission is discarded. There is no captcha and nothing is sent to an external spam service.

How long we keep it

We keep nothing longer than needed. Specifically:

  • Enquiries that do not lead to an engagement: twelve months after the last contact at the latest, then deleted.
  • Enquiries that do lead to an engagement: kept for the duration of the work, then seven years insofar as Dutch tax law requires it.
  • Visit statistics: aggregated, not traceable to a person, and therefore not tied to a retention period.

Want to be removed sooner? One email is enough and we do it within five working days.

Who else processes your data

A small number of suppliers keep the site running. They process only on our instructions.

PartyFor whatWhere it sits
VercelHosting the site and the visit statisticSee the section below
NeonDatabase holding form submissions and the app registrySee the section below
Vercel BlobStorage for the screenshots on the siteSee the section below

There is no email marketing service, no CRM and no advertising platform in this chain.

Transfer outside the EU

Here we would rather be precise than reassuring. The site is delivered from a European edge network, but the server code currently runs in a Vercel data centre in the United States. That means a form submission passes through the US.

Vercel and Neon are both certified under the EU-US Data Privacy Framework and additionally apply the European Commission's standard contractual clauses. That covers the transfer, but it remains a transfer.

If you process data through us where that is not acceptable, say so: the server region can be set to Frankfurt and that takes no rebuild.

Your rights

Under the GDPR you have the right to:

  • see what data we hold about you;
  • have it corrected if it is wrong;
  • have it deleted;
  • have the processing restricted;
  • object to the processing;
  • receive your data in a common file format.

One email is enough. We respond within five working days and only ask for further identification where it is genuinely needed to place you.

If we cannot resolve it together, you may lodge a complaint with the Dutch Data Protection Authority (Autoriteit Persoonsgegevens).

Data breaches

If we find a breach that poses a risk to those affected, we report it to the Dutch Data Protection Authority within 72 hours and inform you directly where your data is involved. See also the security page.

WhatsApp