Roek IT

Privacy statement

Roek IT · Chamber of Commerce 85105899 · Enschede · Version 1.0 · Last updated: 8 September 2026

Roek IT handles personal data with care. We aim to collect no more data than we need for communication, our work and a reliable website.

This statement covers roek.dev and direct contact with Roek IT, for example about a project, partnership, supply arrangement or investment. The privacy information for each product explains how data is handled when using that product.

Who we are

Roek IT is run jointly by Daniël Roek and Kirsten Roek. We share communication, delivery, decision-making and day-to-day responsibility for our products and services. We agree the division of work between us according to what is needed, and it can vary by subject and over time.

Roek IT is a Dutch sole proprietorship based in Enschede, registered in Daniël Roek's name with the Dutch Chamber of Commerce (KvK) under number 85105899. Roek IT is the controller for the personal data described here: Roek IT decides why and how it is processed. Privacy questions and requests are handled as part of our shared work.

You can reach Roek IT at info@roek.dev for questions and privacy requests.

The information we use

The contact form asks for a name or company name, email address, subject and message. Attachments are optional. When you contact us directly, we receive the information you choose to share, for example in an email or signature. Please share only information relevant to the conversation.

We use this information to reply, make arrangements and maintain contact. An enquiry or agreement with you personally may require processing to prepare or perform that agreement. For other business contacts, such as an employee of a partner or supplier, we rely on our legitimate interest in maintaining business relationships. We also weigh the individual's privacy interests.

For an engagement, we additionally process the information needed for agreements, invoices and administration. Depending on the data and purpose, the legal basis is the agreement, a statutory record-keeping duty or our legitimate interest in establishing agreements and legal claims.

You choose whether to contact us. The form cannot be sent without the required information. You can also email us directly.

How the website works

This website has no user accounts, payment function, advertising tracking or visitor analytics. The contact form sends the information and any attachments through an external service so that we can receive and answer your message.

The website stores your chosen light or dark theme in your browser. The browser may also retain temporary information needed for navigation, such as your position on a page. The language follows the Dutch or English page you select. We do not use a language profile or tracking cookie for this.

Loading the website and submitting a form involves processing technical information, including the IP address and request details. Hosting and form services may also keep records to protect the service and investigate errors. Our legitimate interest is to operate a functioning, secure website.

Our website contains links to websites and services operated by others.

Keeping business correspondence

We retain business emails and related documents to refer back to conversations, agreements and decisions, continue relationships and handle questions or claims. Messages are not automatically deleted after a fixed period. Relevant correspondence may therefore be kept for several years.

The need for retention depends on the content, business relationship, ongoing agreements, potential claims and statutory duties. A relevant conversation may remain useful for longer than a completed one-off enquiry. Data with no remaining legitimate purpose or retention duty should not remain in the archive indefinitely. Your rights to request erasure and object to processing continue to apply.

We retain financial records in accordance with statutory duties. Technical logs support operation, security and investigation; they are not used as a long-term correspondence archive.

Service providers and data locations

We use service providers for the website, delivery and storage of messages, and administration. They receive the information needed for their services. An adviser or competent authority may also receive data for a specific reason, such as accounting or a legal dispute. We do not sell personal data.

Data protection also depends on the terms and settings of these services. Where a provider processes personal data on our behalf, data-processing terms are required.

A provider may process data outside the European Economic Area (EEA). Such a transfer requires a valid legal basis. Before introducing new processing outside the EEA, we assess the protection it requires.

You can contact us for information about data locations and protection for a particular service.

AI and personal data

We may use AI to assist with development, draft content and quality checks. Personal data from contact messages is not standard input for that work. Our starting point is to use fictional data or material without identifiable information.

We do not make decisions in this context based solely on automated processing that have legal or similarly significant effects on you.

Security and incidents

We use encryption, access controls and carefully designed software to protect personal data. We consider data minimisation and security risks during design and maintenance.

If something goes wrong, we investigate what happened and work to contain and remedy the consequences. We inform affected people when the possible impact or action they may need to take calls for it. We communicate factually and clearly. Statutory reporting duties and deadlines always apply.

Your rights

You can request access to, correction or erasure of your personal data, or restriction of its processing. Depending on the processing, you may also have a right to data portability. You can object to processing based on legitimate interests. Where consent is the legal basis, you can withdraw it without affecting earlier lawful processing.

Please send requests to the email address above. We normally respond within one month. If the law permits an extension, we explain why within that month. We ask for additional identification only when needed to prevent information from reaching the wrong person.

You also have the right to lodge a complaint with the Dutch Data Protection Authority or the competent privacy regulator where you habitually live or work, or where the alleged infringement occurred. You can approach the regulator directly. We are also happy to help resolve a concern ourselves.

Updates to this statement

The current statement is available on this page, with the date of its latest revision. We update the text when the processing it describes changes. If we intend to use data for a new purpose, we provide the required information beforehand.

Please contact us if anything is unclear. We are happy to discuss questions and concerns directly and with care.