Last updated: 30 August 2026
This is a small website belonging to a writer who sells books. There is no advertising network behind it and no tracking cookies are placed. We do count how many people come by, but on our own server and without anyone being identifiable. What follows is shorter than you may be used to, and that is because very little happens here.
Who processes your data
Edmosphere Holding B.V.
Heistraat 20
5351 PP Berghem
The Netherlands
Chamber of Commerce (KvK) number: 55704565
E-mail: boeken@nieuwenhuyse.nl
We are the controller within the meaning of the General Data Protection Regulation (GDPR). We have no data protection officer; an organisation of this size is not required to appoint one. You can bring any question to the address above.
If you are just looking around
Then we do not recognise you.
There is no Google Analytics, no advertising network and no tracking cookie of any kind. The only thing your browser keeps is your choice of language – Dutch or English – so that you land there again next time. It holds nothing but that language code. There is more about this on the cookies page. The fonts are hosted on our own server rather than by Google, so no data about you travels to another company that way either. There are no social network buttons and no embedded videos.
We do count one thing: how many people visit the site and which pages they read. Without that we have no idea whether anyone is looking, or whether people drop out on the book page or only at checkout.
For this we use Burst Statistics. That is not an external service but software running on our own server: the counts are stored in this website’s own database and never leave it. No other company is involved and no data about you goes anywhere.
It is configured not to place cookies. To avoid counting one visit of five pages as five visitors, the software creates an anonymous code that changes every day. That code cannot be traced back to you and disappears by itself. No device fingerprint is taken and nothing is stored on or read from your device.
So what we see is a set of totals: how many visits there were, which pages were read, which site or search engine people arrived from, and what kind of device they used. We cannot identify or find any individual visitor in that, not you either, and not even if we wanted to.
We also measure how many visitors end up ordering a book. That is a sum, not a link: what is recorded is how often an order was placed, not who placed it.
Legal basis: our legitimate interest in knowing whether this site works (article 6(1)(f) GDPR). Because nothing is placed on or read from your device, no consent is required under article 11.7a of the Dutch Telecommunications Act, which is why you see no cookie banner. If you have “Do Not Track” switched on in your browser you are not counted at all; that setting is respected. An ad blocker also stops the measurement.
What does happen, and happens on every server in the world: our hosting provider records in a log file which pages were requested, when, and from which IP address. That is needed to make the site work and to investigate abuse and faults. Those log files are deleted automatically after a short time and we do not use them to track or recognise visitors. Legal basis: our legitimate interest in a working and secure website (article 6(1)(f) GDPR).
If you buy a book
Then we need a few things from you.
What we ask for and keep:
| Data | What for |
|---|---|
| First and last name | to put the order and the invoice in your name |
| E-mail address | to send you the order confirmation and the download links |
| Country | to determine which VAT applies |
| Order details | which book, which amount, which date, which order number |
| Payment status and Mollie payment reference | to see whether payment has been made |
| IP address at the time of the order | to be able to detect fraud |
| Download moments | to see whether delivery succeeded, and to spot misuse of a link |
What we do not receive: your bank account number, your card number or your banking credentials. You enter those with Mollie, not with us. We only see whether the payment succeeded.
Why we are allowed to process this: to perform the contract of sale with you (article 6(1)(b) GDPR). Without a name and e-mail address we cannot deliver the book. The invoice data are additionally subject to a legal obligation (article 6(1)(c) GDPR): the Dutch tax authority requires us to keep our records for seven years.
Two weeks after your purchase
About two weeks after an order we send one e-mail asking whether the book was any good. It contains no offer and no other book; it is a request for a response or a review.
At the bottom of that e-mail is an unsubscribe link. Click it and we will never send you such a message again. We store that unsubscribe as an encrypted form of your e-mail address, so that no readable list exists of people who have opted out. Your order confirmation and your download links keep working afterwards; those are not marketing messages but part of the purchase.
Legal basis: our legitimate interest in knowing what buyers think of the book (article 6(1)(f) GDPR), within the room that article 11.7 of the Dutch Telecommunications Act gives to approach your own customers about your own similar products – with, as required there, an opportunity to unsubscribe in every message.
If you e-mail us
Then we keep your message and your e-mail address for as long as it takes to deal with your question, and for a while afterwards in case you come back to it. Messages that lead nowhere are deleted within two years. Legal basis: our legitimate interest in answering questions, or performance of the contract if your question concerns your order.
Please do not send us sensitive information by e-mail. We will never ask for it either. We will never ask you by e-mail for a password or for your banking details; if you receive such a message appearing to come from us, ignore it and let us know.
Who else sees your data
We sell nothing to third parties and we trade nothing. Three parties process some of your data because it cannot work otherwise:
The hosting provider. The website, the database and the e-mail run on our hosting provider’s servers in the Netherlands. They can technically access everything on the server and are contractually bound by confidentiality and a data processing agreement.
Mollie B.V. (Amsterdam) handles the payment. They receive your name, the amount, the order number and the details you enter yourself while paying. Mollie is a payment institution supervised by the Dutch central bank and has its own privacy policy, at mollie.com.
The receiving mail server. If we send you an e-mail it goes, of course, to your own e-mail provider. That is the nature of e-mail.
All of these parties are in the Netherlands or elsewhere in the European Economic Area. No data is transferred to countries outside the EEA.
Beyond that we disclose data only where the law obliges us to, for example to the tax authority during an audit.
How long we keep it
- Order and invoice data: seven years after the end of the financial year. That is a statutory retention obligation; we cannot depart from it, not even on request.
- Your download links and the associated customer record: two years, because that is how long the links remain valid.
- E-mail correspondence: as long as necessary, and messages that lead nowhere for at most two years.
- Server logs: briefly, cleaned up automatically.
- Visitor statistics: these are totals without personal data; we keep them so we can compare years. The daily code used to count visits expires every twenty-four hours.
Security
The site runs entirely over a secure connection (https). The book files are not in a public folder but outside the reach of the web server, so they can only be obtained through a personal download link. The software is kept up to date. Access to the administration area is limited to the owner.
Complete certainty does not exist – one of the few things the book and this statement agree on entirely. If you suspect a leak or notice something that is not right, e-mail boeken@nieuwenhuyse.nl. We appreciate it and we will respond.
Your rights
You have the right to:
- see what data we hold about you;
- have it corrected if something is wrong;
- have it erased, in so far as no retention obligation applies;
- have the processing restricted;
- object to processing based on legitimate interest;
- receive or transfer your data in a common file format;
- withdraw consent you have given, where the processing was based on it.
Send your request to boeken@nieuwenhuyse.nl. You will have an answer within four weeks. We may ask you to identify yourself if we are unsure who is writing; that is to prevent us handing your data to someone else.
One limitation is worth mentioning: if you ask us to erase your order data, we cannot remove the invoice data while the tax retention obligation runs. What we can do is delete your customer record and your download links. Your downloads will then stop working, so make sure you have saved the files.
Complaints
If you disagree with us, please tell us first – it is usually a misunderstanding that one e-mail resolves. If we cannot work it out, you have the right to lodge a complaint with the Dutch Data Protection Authority (Autoriteit Persoonsgegevens), autoriteitpersoonsgegevens.nl. If you live in another EU country you may also complain to your own supervisory authority.
Changes
If something on the site changes so that more or different data is processed – a newsletter, for instance – we will update this statement before that goes live. The date at the top shows when the text was last changed.