Privacy Policy

The Fritom Group takes privacy seriously. In this privacy statement, we explain what personal data we collect and use, for what purpose we do so, and how we ensure that this personal data is properly secured.


Privacy Policy
As a data controller,the Fritom Group processes, manages, and secures personal data with the utmost care. We provide our employees with a safe workplace. In doing so, we comply with the requirements set forth in the General Data Protection Regulation (GDPR) and national legislation. We have outlined how we meet these requirements in ourprivacy policy.

Personal Data We Process
The Fritom Group processes personal data of employees, visitors, customers, business contacts, and other individuals. We receive some of this personal data directly from the data subjects. Examples include a customer’s name and address details and the personal information of new employees when they are hired. We collect some of the personal data we process ourselves, such as data regarding employee performance. We also receive personal data from third parties.

We process the following personal data about our employees:

  1. last name, first names, initials, title, gender, date of birth, address, ZIP code, city, phone number, and similar information necessary for communication, such as the data subject’s email address and bank account number;
  2. BSN number;
  3. copy of ID card/passport;
  4. an employee ID number that contains no information other than that referred to in (a);
  5. nationality, place of birth;
  6. information regarding religion or belief, to the extent that such information is necessary for the proper performance of duties in accordance with the terms of appointment;
  7. information regarding educational programs, courses, and internships completed and planned;
  8. information regarding terms and conditions of employment;
  9. data relating to the calculation, recording, and payment of salaries, allowances, and other monetary amounts and in-kind benefits;
  10. data related to the calculation, reporting, and payment of taxes and social security contributions;
  11. information regarding the current or former position(s), as well as the nature, scope, and termination of previous employment relationships;
  12. data for the purpose of keeping records of the individuals’ presence at the workplace and their absences due to leave, reduced working hours, childbirth, or illness, with the exception of data regarding the nature of the illness;
  13. data collected in the interest of the individuals concerned with regard to their working conditions and safety;
  14. data, including data concerning family members and former family members of the individuals concerned, that is necessary for the purpose of agreed-upon terms of employment;
  15. information relating to job performance, performance evaluations, and career counseling, to the extent that such information is known to the individuals concerned;
  16. Fritom Network login credentials
  17. photos and video footage, with or without sound, of the activities of the Fritom facility in question and the work performed by employees;
  18. surveillance footage of the company premises and the publicly accessible areas of the Fritom facility in question;
  19. the information regarding the time, date, and location at which the camera recordings were made;
  20. data other than that referred to in subparagraphs (a) through (s), the processing of which is required under or necessary for the application of another, unspecified law.

Data that we did not receive from the employee and did not collect ourselves was provided to us by the following third parties:

  • Occupational Health and Safety Service
  • Tax Authority
  • UWV
  • Other Government Agencies

We process the following personal data from charter companies and third-party contractors:

  1. last name, first names, initials, title, gender, date of birth, address, ZIP code, city, phone number, and similar information necessary for communication, such as the email address and the individual’s bank and giro account numbers;
  2. BSN number;
  3. copy of ID card/passport;
  4. nationality, place of birth;
  5. information regarding religion or belief, to the extent that such information is necessary for the proper performance of duties in accordance with the terms of appointment;
  6. information regarding educational programs, courses, and internships completed and planned;
  7. information regarding the service agreement;
  8. data relating to the calculation, recording, and payment of compensation and other monetary amounts and in-kind benefits;
  9. data for the purpose of keeping records of the individuals' attendance at the workplace;
  10. data collected in the interest of the individuals concerned with regard to their working conditions and safety;
  11. photos and video footage, with or without sound, of the activities of the relevant Fritom company and the work performed by contractors or third parties;
  12. surveillance footage of the company premises and the publicly accessible areas of the Fritom facility in question;
  13. the information regarding the time, date, and location at which the camera recordings were made;
  14. data other than that referred to in subparagraphs (a) through (m), the processing of which is required under or necessary for the application of another, unspecified law.

We process the following personal data from clients and customers:

  1. last name, first names, initials, title, gender, date of birth, address, ZIP code, city, phone number, and similar information necessary for communication, such as the email address, as well as the organization to which the data subject belongs;
  2. administration number
  3. data for the purpose of fulfilling the assignment given by the client;
  4. surveillance footage of the company premises and the publicly accessible areas of the Fritom facility in question;
  5. information regarding the time, date, and location at which the camera footage was recorded.
  6. data other than that referred to in subparagraphs (a) through (d), the processing of which is required by or necessary for the application of another law.

Why We Use Personal Data
We use employees’ personal data solely for the purpose of fulfilling the employment contract. The processing of employees’ personal data is intended to:

  1. the conclusion of the employment contract (Article 6(1)(b) of the GDPR);
  2. determining the salary and other terms and conditions of employment (Article 6(1)(b) of the AVG);
  3. the payment of salary (or having it paid), and the remittance of taxes and social security contributions (Articles 6(1)(b) and 6(1)(c) of the GDPR);
  4. the performance of a contractual obligation to which the data subject is subject (Article 6(1)(b) of the GDPR);
  5. the collection of receivables, including the transfer of such receivables to third parties (Article 6(1)(b) of the AVG);
  6. termination of employment (Article 6(1)(b) of the GDPR);
  7. the transfer of the data subject to his or her (temporary) employment with another entity within the group, as referred to in Article 2:24b of the Civil Code, to which the data controller is affiliated (Article 6(1)(b) of the GDPR);
  8. providing guidance and support to the data subject (Article 6(1)(b) of the GDPR);
  9. providing occupational health care for the individual concerned and fulfilling reintegration obligations in the event of absenteeism (Article 6(1)(c) of the GDPR);
  10. granting access to the Fritom network (Article 6(1)(b) of the GDPR);
  11. the processing and verification of claims for benefits related to the termination of employment (Article 6(1)(b) of the AVG);
  12. Election of members of the employee representative body (Art. 6(1)(c) of the AVG);
  13. resolving disputes (Article 6(1)(b) of the GDPR);
  14. the processing of personnel matters, other than those listed under a. through m. (Article 6(1)(b) of the GDPR);
  15. having an audit conducted and having claims for funding determined (Article 6(1)(c) of the GDPR);
  16. security and surveillance of individuals, property, and buildings (Art. 6(1)(f) of the GDPR)

The purpose of processing personal data from charterers and contracted third parties is:

  1. the conclusion of the service agreement; (Article 6(1)(b) of the GDPR)
  2. determining compensation and other terms and conditions of employment;
  3. Paying out remuneration (or having it paid out) (Article 6(1)(b) of the GDPR)
  4. the implementation of a regulation applicable to the data subject; (Article 6(1)(b) of the GDPR)
  5. the collection of receivables, including the transfer of such receivables to third parties; (Article 6(1)(b) of the GDPR)
  6. Termination of the service agreement (Article 6(1)(b) of the GDPR)
  7. the transfer of the data subject to his or her (temporary) employment with another entity within the group, as referred to in Article 2:24b of the Civil Code, to which the data controller is affiliated (Article 6(1)(b) of the GDPR);
  8. providing instructions and guidance to the data subject (Article 6(1)(b) of the GDPR);
  9. resolving disputes; (Article 6(1)(b) of the GDPR)
  10. the processing of matters relating to the provision of services, other than those listed under a. through i.; (Article 6(1)(b) of the GDPR)
  11. having an audit conducted and having claims for funding determined; (Article 6(1)(c) of the GDPR)
  12. security and surveillance of individuals, property, and buildings (Art. 6(1)(f) of the GDPR)

The purpose of processing the personal data of clients and customers is:

  1. placing orders or contracting with service providers (Article 6(1)(b) of the GDPR);
  2. calculating and recording income and expenses and making payments (Article 6(1)(b) of the GDPR);
  3. the collection of receivables, including the transfer of such receivables to third parties, as well as other internal management activities (Article 6(1)(b) of the GDPR);
  4. the data controller’s maintenance of contact with suppliers (Article 6(1)(b) of the GDPR);
  5. resolving disputes and conducting audits (Article 6(1)(c) of the GDPR);
  6. the implementation or application of another law (Article 6(1)(c) of the GDPR);
  7. the security and supervision of individuals, property, and buildings entrusted to the care of the relevant Fritom company (Article 6(1)(f) of the GDPR).

Security and Storage
We take appropriate measures to prevent misuse, loss, unauthorized access, and other undesirable actions involving personal data. For example, we store personal data in systems with restricted access and use encryption. These measures are outlined in our security policy.

The personal data we collect is not retained for longer than necessary. We delete employee data two years after the end of their employment, unless we are required by law to adhere to a (longer) retention period.

Among other things, we have implemented the following security measures:

  1. The Fritom Group has outsourced the management of its IT environment to an IT service provider (certified to ISO 9001, ISO/IEC 27001, and NEN 7510).
  2. The Fritom Group's IT environment is hosted as a private cloud in a data center in the Netherlands that is secured 24 hours a day.
  3. Data is stored according to a backup schedule, which limits the damage in the event of accidental destruction or corruption of the data.
  4. The IT environment is equipped with up-to-date antivirus and anti-malware software that is deployed at various technical levels.
  5. The Fritom Group has an authorization policy that ensures only authorized personnel, based on their role or position, have access to the system and the necessary data for as long as necessary.
  6. Remote access to the IT environment is secured with strong passwords that must be changed periodically. The software used for remote access includes measures to prevent unauthorized access, such as limiting the number of login attempts per time unit.
  7. Software vendors have access only to that part of the system in which they must necessarily perform their work. Access is expressly limited to the period during which the work takes place and is permitted only with the authorization of the IT Data Controller at the Fritom Group.
  8. Changes to the IT environment are made in accordance with the change procedure and are documented using a Request for Change form.
  9. Security incidents are reported centrally, logged in a reporting system, and handled with the IT service provider in accordance with standard incident management procedures.
  10. The Fritom Group's local (wireless) network is equipped with various security measures (firewall, monitoring systems, etc.).
  11. Employees who come into contact with sensitive personal data in the course of their work have signed a confidentiality agreement.

Data Transfer Outside the EU
If personal data is transferred to a country outside the European Economic Area (EEA), the level of security must be comparable to that required under the GDPR (see also the explanatory notes to Annex 3 of the Register).

To ensure this, the following options are available:

  1. transfer based on an adequacy decision by the European Commission;
  2. Transfer based on appropriate safeguards: if a country or organization has not been deemed adequate by the European Commission, a transfer may take place if the data controller and the data processor (demonstrably) provide appropriate safeguards and enforceable rights and remedies for the data subject(s);
  3. transfer based on the data subject’s explicit consent, provided that the data subject has been informed of the risks, or in cases of necessity.

Data Transfer to the U.S.

The European Commission (EC) has established a framework for the transfer of personal data to the United States (U.S.). This framework is called the EU-U.S. Privacy Shield. The purpose of the Privacy Shield is to provide a level of protection for the exchange of personal data with the U.S. that is broadly equivalent to the level of protection within the European Union (EU).

The Privacy Shield replaces the Safe Harbor Agreement, which the European Court of Justice declared invalid on October 6, 2015. Any organization in the U.S. that is certified under the Privacy Shield has an adequate level of protection (for the duration of the certification). This means that organizations in Europe may transfer personal data to these organizations in the U.S.

Does the Fritom Group share personal data with third parties?
We only share personal data with third parties if this is necessary for the performance of a contract or to comply with a legal obligation. We enter into agreements with organizations that process your data on behalf of our company to ensure that your data is properly secured there as well. We also use cloud services where data is stored on a server abroad. We do this only if there is an adequate level of data protection.

What are my rights?
You have the right to object to the processing of your data, to withdraw previously given consent, and to access, correct, or delete your data. In certain cases, you may also ask the relevant Fritom company to restrict the processing of your personal data or to transfer your data to you or to a third party.

If you would like to exercise any of these rights or have questions about how we handle privacy and personal data, please contact us atfg@fritom.nlor contact our Data Protection Officer (DPO), Mr. R. Beuving, directly.

Do you have a complaint about the way we process personal data? If so, please contact our Data Protection Officer using the contact information provided above. In the unlikely event that we are unable to resolve the matter together, you may file a complaint with the supervisory authority, theDutch Data Protection Authority.

There is no charge for submitting a request. However, if a data subject’s requests are manifestly unfounded or excessive—particularly due to their repetitive nature—the Fritom company to which the request is addressed may charge a reasonable fee in light of the administrative costs associated with the request, or may refuse to comply with the request.

The Fritom company to which the request is addressed shall provide the individual concerned with information regarding the action taken in response to the request within one month of receiving the request.

If the data subject submits a request on the grounds that certain recorded data are incorrect or incomplete, if they have an interest in terminating the processing that outweighs that of the organization, or if the processing is no longer necessary in light of the purpose of the Fritom Group’s privacy policy, or if it is in violation of this policy, the data protection officer, acting on behalf of the data controller, will issue a written decision within one month of the data subject submitting this request, a written decision on the matter.

Depending on the complexity of the requests and the number of requests, that period may be extended by an additional two months if necessary. The Fritom company in question shall notify the data subject of such an extension within one month. If the data subject submits the request electronically, the information shall be provided electronically if possible, unless the data subject requests otherwise.

If the Fritom company in question has doubts about the applicant’s identity, it shall request in writing, as soon as possible, that the applicant provide further details regarding his or her identity or present a valid form of identification. This request shall suspend the time limit until the requested proof has been provided.

If the Fritom company in question does not wish to comply with a request as described above, it shall notify the person concerned in writing—stating its reasons—within one month of receiving the request.

Updates to the Privacy Policy at
We reserve the right to update this privacy policy. Any revised versions will be posted on this website. When a revised version is posted, we will provide a clear notice of this update, including information about the most significant changes. We will also indicate when the policy was last updated.