Skip to Content

Privacy Statement

1. Who is Zaphex?


Zaphex is an administrative office in Schiedam and The Hague. We handle administration, tax returns, and advice for entrepreneurs.

Zaphex is the trade name under which we provide our services.

Where this statement refers to "we" or "Zaphex", we mean the entity that carries out your assignment.

 



2. How we handle your data


You can expect us to handle your data carefully. This applies to customers, suppliers, relations, and employees.

We operate in accordance with the General Data Protection Regulation (GDPR). These are the European privacy rules. Our agreements regarding this are outlined in our contracts, codes of conduct, and security measures.


 



3. What data we process


We receive your data from yourself or through others, such as the Tax Authority or your bank. We only use the data that we really need to do our work properly.

Sometimes we process data on your behalf. You then determine what happens to the data, and we carry that out.

Usually, this concerns the following data:

  •  Customers and suppliers: name, address, contact details (such as email address), login details      
     for our portal, and the data you provide yourself.
  • Website visitors: IP address, behaviour on the website, and data you fill in on a 
     form.
  • Employees: name, address, date of birth, contact details, employee number, and passport photo.

Special personal data
For tax returns and allowances, we are legally obliged to process your BSN. If we handle your payroll, a copy of your identity document is required by tax law.

The Wwft (the law against money laundering and terrorist financing) requires us to establish your identity and keep proof of it.

Are we handling your payroll? Then we may also process health data, for example in the case of sick leave or pensions. We only do this if necessary.


 



4. What we use your data for


We use your data among other things to:

​• ​fulfil our agreements with you;
​• ​perform our work well and efficiently;
​• ​manage the administration;
​• ​keep in contact with you;
​• ​improve our services;
​• ​ send invoices and collect payments;
​• ​comply with the law;
​• ​for marketing purposes;
​• ​resolve a dispute if necessary.







5. Why we are allowed to do this


We only use your data if the law provides a reason for it. The GDPR refers to these reasons as "grounds". For us, there are three.

​• To execute the agreement with you. Without your data, we cannot 
​   perform our task.
​• To comply with the law. Think of financial administration, tax returns 
​   and verifying your identity via the Wwft.
​• Because we or another have a good reason for it. For example, to provide our services 
​   to improve or to secure our systems. The law refers to this as a "legitimate 
​   interest".

Do we need your consent? Then we will ask you separately. You may withdraw your consent at any time.







6. When we share data with others


Sometimes we share your data with others to carry out our work. For example, with the suppliers of our software or our systems. They may only use your data for the purpose for which we provide it.

Are we working with such a party? Then we make written agreements with them. These agreements ensure that your data remains safe and confidential. This is called a data processing agreement.

Sometimes we must share data because the law requires it. For example, during an audit by the Tax Authority, the FIOD, or the FIU.




7. Processing outside the EEA


Part of our work is carried out by our team outside the European Economic Area (EEA). In doing so, they may process your data.

Countries outside the EEA do not always have the same privacy rules as the Netherlands. Therefore, we have established fixed agreements regarding this. We use the model contract clauses of the European Commission. This way, your data is also well protected outside the EEA.




8. Cookies

On our website, we use cookies. With this, we process your IP address and information about your device. This allows us to make the website work better. You can read more about this in our cookie statement.




9. How we secure your data

We find it important that your data is safe. Therefore, we take measures to prevent loss or misuse. These measures are appropriate for the type of data and the amount we process.

All our employees have a duty of confidentiality. They may only use your data if it is necessary for their work.




10. If something goes wrong (data breach)

We do everything we can to protect your data. However, a data breach can never be completely ruled out. A data breach is a leak, or unintended access to your data.

If this happens and it could have serious consequences? Then we report this to the Data Protection Authority. If the law requires it, we will also inform you.




11. How long we keep your data

We do not keep your data longer than necessary. As soon as we no longer need it, we delete it.

Some data we must keep longer because the law requires it. For example, there is a tax retention obligation of seven years for administration.




12. Your rights

The privacy rules give you control over your own data. You have the following rights.

Information
You have the right to know that we are using your data and why. We will tell you this before we start.

Inspection
You may ask us which data we have about you. We will then show you what data that is and what we use it for.

Correction or deletion
Are your data incorrect? Then you may ask us to correct them. You may also ask us to delete your data. We will do this, unless the law requires us to keep them. We will let you know what we have done.

Restriction and objection
You may object to the use of your data. You may also ask us to restrict or stop the use. If there is no legal reason to refuse this, we will do so. We will inform you of our decision.

Do you wish to exercise any of these rights? Then please send us a letter or an email. You can find the contact details below.




13. Questions or complaints

Do you have a question or a complaint about how we handle your data? Let us know. We will respond as soon as possible, and in any case within four weeks.

Contact
Zaphex
To the attention of the privacy officer
privacy@Zaphex.com
Philippusweg 4
3125 AS Schiedam
Netherlands

P.O. Box 93027
2509 AA The Hague
Netherlands

You may also file a complaint with the supervisor: the Data Protection Authority.

Changes
We may adjust this privacy statement. A new version will always be posted on our website. Therefore, check here occasionally so that you know what applies.

This privacy statement was last amended on 10 August 2026.