Privacy Policy
Last updated: 27 July 2026
This policy explains how Mooncom handles personal data. We process personal data in accordance with the EU General Data Protection Regulation (GDPR).
1. Who we are
Mooncom B.V., trading as Mooncom, is the data controller for the personal data described in this policy.
- Mooncom B.V.
- Hoeksewaard 44, 1181 CE Amstelveen, Netherlands
- Chamber of Commerce (KVK): 85442534
- Contact: via the contact form on this website
2. What data we collect
We collect only what we need in order to respond to you and to deliver our services:
- Contact form submissions — the name, email address, company or store URL and message you enter in the form on this website.
- Correspondence — the content of any subsequent emails or messages between us.
- Client and engagement data — information about your business that you share with us in the course of an engagement, including advertising account and analytics access where you grant it, together with contract and invoicing details.
We do not collect special categories of personal data, and we do not buy personal data from third parties.
3. Why we process it, and on what legal basis
- To respond to enquiries — on the basis of our legitimate interest in answering people who contact us, or steps taken at your request prior to entering a contract.
- To perform our services — on the basis of performance of a contract with you or the organisation you represent.
- To meet legal obligations — in particular Dutch tax and accounting law, which requires us to retain administrative records.
4. How long we keep it
Enquiries that do not lead to an engagement are deleted within twelve months. Records relating to a client engagement are retained for seven years from the end of the relevant financial year, in line with the retention period required by Dutch tax law.
5. Who we share it with
We do not sell personal data and we do not share it for advertising purposes. We share data only with service providers who process it on our behalf — our contact form provider, email provider, accountant, and hosting provider — and only to the extent necessary. These providers are bound by written processing agreements. Where a provider processes data outside the European Economic Area, we rely on the European Commission's Standard Contractual Clauses.
We may also disclose data where we are legally required to do so.
6. Cookies
This website does not use tracking cookies, analytics cookies, or third-party advertising cookies, and it does not profile visitors.
7. Your rights
Under the GDPR you have the right to:
- request access to the personal data we hold about you;
- have inaccurate data corrected;
- have your data erased, where the law allows;
- restrict or object to our processing;
- receive your data in a portable format;
- withdraw consent at any time, where processing is based on consent.
To exercise any of these rights, contact us using the contact form on this website. We respond within one month.
If you are not satisfied with how we have handled your data, you have the right to lodge a complaint with the Dutch Data Protection Authority (Autoriteit Persoonsgegevens).
8. Security
We apply appropriate technical and organisational measures to protect personal data against loss and unauthorised access, including access controls, encrypted transport, and limiting access to those who need it.
9. Changes to this policy
We may update this policy from time to time. The date at the top of this page shows when it was last revised.