Privacy Policy
This Privacy Policy belongs to AI Tech Hub B.V., trading as The Stack, with registered and trading address at Fred. Roeskestraat 100, 1076 ED Amsterdam, The Netherlands, and registered with the Dutch Chamber of Commerce under number 99070251.
Contact
You can contact us via:
- Email address: reception@thestack.ai
- The contact form at the bottom of our website (thestack.ai)
In this policy, “we”, “us” and “our” refer to AI Tech Hub B.V. (or one or more of its current or future affiliates) as a provider and as a controller of personal data.
1 Introduction
1.1
As someone whose data we process, you have the right to protection of that
personal data. How we perform this protection is described in this Privacy Policy.
We are committed to safeguarding the privacy of our (website) visitors and our
members, clients and partners.
1.2
Personal data is defined by the General Data Protection Regulation (EU Regulation
2016/679) (the “GDPR”) as ‘any information relating to an identifiable person who
can be directly or indirectly identified in particular by reference to an
identifier’. Personal data is, in simpler terms, any information about you that
enables you to be identified. Personal data covers obvious information such as
your name and contact details, but it also covers less obvious information such as
identification numbers, electronic location data, and other online identifiers. We
define what we mean by personal data in detail in section 2 below.
1.3
This policy applies where we are acting as a data controller with respect to the
personal data of (website) visitors and our members, clients and partners; in
other words, where we determine the purposes and means of the processing of that
personal data.
1.4
We use cookies on our website for the provision of our website and services, as
well as for analytics purposes to help us improve our product offering. See
chapters 8–11 for our cookie policies.
1.5
Our service incorporates the possibility for members to determine whether or not
your profile is visible to other members and to change your profile information.
You can access these controls via our community platform. Below each newsletter is
a button to unsubscribe.
1.6
We do not sell our member and contact data to any third party. We do not share or
give away data to third parties unless it is in line with the purposes that we
describe in chapter 2.
2 How we use your personal data
2.1
In this Section 2 we have set out: (1) the general categories of personal data
that we may process; (2) the purposes for which we may process personal data; and
(3) the legal bases of the processing.
2.2
We may process data about your use of our website and services (“usage data”),
including IP address, geographical location, browser type and version, operating
system, referral source, length of visit, page views and website navigation paths,
as well as information about the timing, frequency and pattern of your service
use. This usage data may be processed for the purposes of analysing the use of the
website and services. The legal basis for this processing is our legitimate
interests, namely monitoring and improving our website and services.
2.3
We may process your account data (“account data”), including your name, company
name, contact and address details and data required to process invoices and
payments (for example your bank account number). The account data may be processed
for the purposes of operating our website and tools, providing our services,
ensuring the security of our online tools, administrative processing of invoices
and payments and communicating with you. The legal basis for this processing is
our legitimate interests, namely the proper administration of our services, and/or
the performance of a contract between you and us and/or taking steps, at your
request, to enter into such a contract.
2.4
We may process information contained in any inquiry you submit to us regarding
services (“inquiry data”). The legal basis for this processing is consent or
your directly communicated interest in the relevant services.
2.5
We may process information relating to our customer relationships, including
customer contact information (“customer relationship data”), for the purposes of
managing our relationships with members and partners, communicating with them,
keeping records of those communications and promoting our products and services.
The legal basis for this processing is consent or our legitimate interests, namely
the proper management of our customer relationships.
2.6
We may process information relating to transactions that you enter into with us
(“transaction data”), for the purpose of supplying the purchased goods and
services and keeping proper records of those transactions. The legal basis for
this processing is the performance of a contract and/or our legitimate interests
in the proper administration of our business.
2.7
We may process information that you provide to us for the purpose of subscribing
to our email notifications and/or newsletters (“notification data”). The legal
basis for this processing is consent or the performance of a contract between you
and us.
2.8
We may process information contained in or relating to any communication that you
send to us, including information that you publish yourself on our member
community platform (“correspondence data”). The legal basis for this processing
is our legitimate interests, namely the proper administration of our business, the
provision of our services and facilitating communication with our members and
partners.
2.9
We may process information that you provide to us for delivering our services
(“service delivery data”), including information about your personal skills,
your company, and your entrepreneurial trajectory, for the purposes of providing
you with our services and supporting you through our programmatic activities,
courses and/or events. The legal basis for this processing is consent or the
performance of a contract between you and us.
2.10
We may process any of your personal data identified in this policy for statistical
and academic analysis, to improve our services, track our performance, or advance
general knowledge in the field. Where external providers are used for such
analysis, we ensure the data is either public, processed with your consent, or
anonymised. The legal basis for this processing is consent or our legitimate
interests.
2.11
We may process any of your personal data identified in this policy where necessary
for the establishment, exercise or defense of legal claims. The legal basis for
this processing is our legitimate interests in the protection and assertion of
legal rights.
2.12
We may process any of your personal data identified in this policy where necessary
for obtaining or maintaining insurance coverage, managing risks, or obtaining
professional advice. The legal basis for this processing is our legitimate
interests in the proper protection of our business against risks.
2.13
In addition to the specific purposes set out in this Section 2, we may also
process any of your personal data where necessary for compliance with a legal
obligation, or to protect your vital interests or those of another natural person.
3 Principles of data protection
3.1
In this Section 3, we provide information about the principles of data protection
that we adhere to.
3.2
We will protect the data files so that only authorised personnel defined by us
have access to the file. These authorised personnel may be our employees,
volunteers, subcontractors or funders. We ensure that all data systems and
computer equipment are sufficiently protected with appropriate technical methods,
including passwords and personal user IDs.
3.3
If we use third parties for technical maintenance of the data or for support and
processing functions, we strive to ensure that the subcontractor can and will
protect the registered data as required in accordance with applicable data
policies.
3.4
If we receive funding from third parties for business support, we may share the
data with these funders for impact measurement functions. In these cases, we
strive to ensure that the funder can and will protect the registered data as
required in accordance with applicable data policies.
3.5
We may disclose your personal data to our insurers and/or professional advisers
insofar as reasonably necessary for the purposes of obtaining or maintaining
insurance coverage, managing risks, obtaining professional advice, or the
establishment, exercise or defense of legal claims.
3.6
In addition to the specific disclosures set out in this Section 3, we may disclose
your personal data where necessary for compliance with a legal obligation, or to
protect your vital interests or those of another natural person, or for the
establishment, exercise or defense of legal claims.
4 Transfer of your personal data
4.1
In this Section 4, we provide information about the circumstances in which your
personal data may be transferred to countries outside the European Economic Area
(EEA).
4.2
We are located and registered in the European Economic Area (EEA).
4.3
We employ a number of third-party data processors (the most important ones are
listed in Section 4.4; the complete list is available upon request). Transfers to
these processors will be protected by appropriate safeguards, namely the use of
standard data protection clauses. We will take reasonable and appropriate steps to
ensure that all third parties engaged as sub-processors process the personal
information we entrust to them in a manner consistent with the requirements of the
GDPR.
4.4
Third-party processors:
| Processor name | Processing activities | Data location(s) |
|---|---|---|
| Nexudus | Cloud Member and Client Relationship Management Services and Invoice Provider | United Kingdom |
| Google, Inc. | Cloud Data and Service Provider | United States |
| Relationship Management and Marketing Services | United States | |
| Relationship Management and Marketing Services | United States | |
| Relationship Management and Marketing Services | United States |
5 Retaining and deleting personal data
5.1
We will retain your personal data for the period necessary to fulfil the purposes
outlined in this Privacy Policy unless a longer retention period is required or
permitted by law. After this data is no longer necessary, we will delete or
anonymise data in our possession within a reasonable time frame, except such data
as we determine may be needed to resolve disputes, enforce agreements, and comply
with business, technical or legal requirements related to our business.
6 Amendments
6.1
We may update this policy from time to time by publishing a new version on our
website.
6.2
You should check this page occasionally to ensure you are happy with any changes
to this policy.
6.3
We will notify you of significant changes to this policy by email, newsletter or
through our software.
7 Your rights
7.1
In this Section 7, we have summarised the rights that you have under data
protection law. Some of the rights are complex, and not all of the details have
been included in our summaries. Accordingly, you should read the relevant laws
and guidance from the regulatory authorities for a full explanation of these
rights.
7.2
Your principal rights under data protection law are: (1) the right to access; (2)
the right to rectification; (3) the right to erasure; (4) the right to restrict
processing; (5) the right to object to processing; (6) the right to data
portability; (7) the right to complain to a supervisory authority; and (8) the
right to withdraw consent.
7.3
You have the right to confirmation as to whether or not we process your personal
data and, where we do, access to the personal data, together with certain
additional information. The first copy will be provided free of charge, but
additional copies may be subject to a reasonable fee.
7.4
You have the right to have any inaccurate personal data about you rectified and,
taking into account the purposes of the processing, to have any incomplete
personal data about you completed.
7.5
In some circumstances you have the right to the erasure of your personal data
without undue delay, subject to certain exclusions such as compliance with a legal
obligation or the establishment, exercise or defense of legal claims.
7.6
In some circumstances you have the right to restrict the processing of your
personal data.
7.7
You have the right to object to our processing of your personal data on grounds
relating to your particular situation, where the legal basis for the processing is
our legitimate interests or a public task.
7.8
You have the right to object to our processing of your personal data for direct
marketing purposes (including profiling for direct marketing purposes).
7.9
You have the right to object to our processing of your personal data for
scientific, historical or statistical research purposes on grounds relating to
your particular situation.
7.10
Where the legal basis for our processing is consent, or the performance of a
contract and such processing is carried out by automated means, you have the right
to receive your personal data from us in a structured, commonly used and
machine-readable format.
7.11
If you consider that our processing of your personal information infringes data
protection laws, you have a legal right to lodge a complaint with a supervisory
authority responsible for data protection (in the Netherlands, the Autoriteit
Persoonsgegevens).
7.12
To the extent that the legal basis for our processing of your personal information
is consent, you have the right to withdraw that consent at any time. Withdrawal
will not affect the lawfulness of processing before the withdrawal.
7.13
You may exercise any of your rights in relation to your personal data by written
notice to reception@thestack.ai.
8 About cookies
8.1
A cookie is a file containing an identifier (a string of letters and numbers) that
is sent by a web server to a web browser and is stored by the browser. The
identifier is then sent back to the server each time the browser requests a page
from the server.
8.2
Cookies may be either “persistent” cookies or “session” cookies: a persistent
cookie will be stored by a web browser and will remain valid until its set expiry
date, unless deleted by the user before the expiry date; a session cookie will
expire at the end of the user session, when the web browser is closed.
8.3
Cookies do not typically contain any information that personally identifies a
user, but personal information that we store about you may be linked to the
information stored in and obtained from cookies.
9 Cookies that we use
9.1
We use cookies to: (1) recognise your browser and user session; (2) keep track of
what pages you have visited; (3) store your user preferences; (4) perform
analytics to help us make our service better; (5) assist with administration and
security for our website and software; and (6) send offers and provide
marketing-relevant services.
10 Cookies used by our service providers
10.1
Our service providers may use cookies and those cookies may be stored on your
computer when you visit our website.
10.2
We use Google Analytics to analyse the use of our website. Google Analytics
gathers information about website use by means of cookies. The information
gathered relating to our website is used to create reports about the use of our
website.
11 Managing cookies
11.1
Most browsers allow you to refuse to accept cookies and to delete cookies. The
methods for doing so vary from browser to browser and from version to version. You
can obtain up-to-date information about blocking and deleting cookies via your
browser’s help resources (Chrome, Firefox, Opera, Safari, Edge).
11.2
Blocking all cookies will have a negative impact upon the usability of many
websites.
11.3
If you block cookies, you will not be able to use all the features on our website.