Veldbloem Design Gardens and terraces planned for Dutch weather
  • About
  • Services
  • Pricing
  • Projects
  • Portfolio
  • Contact

Privacy Policy

Last updated: 3 August 2026

Veldbloem Design ("we", "us", "our") respects your privacy and is committed to protecting your personal data in accordance with the General Data Protection Regulation (EU) 2016/679 ("GDPR"), the Dutch Implementation Act (Uitvoeringswet AVG), and other applicable data protection legislation.

This Privacy Policy explains how we collect, use, store, and protect personal data when you visit our website, contact us, or use our landscape and terrace design services.

1. Data Controller

The data controller responsible for your personal data is:

Veldbloem Design
Oudegracht 188
3511 AW Utrecht
Netherlands
Email: [email protected]
Phone: +31 30 820 4412

We have not appointed a Data Protection Officer (DPO), as we are not required to do so under Article 37 GDPR. For all privacy-related enquiries, please contact us at the email address above.

2. Personal Data We Collect

We may collect and process the following categories of personal data:

2.1 Identity and contact data

  • Full name
  • Email address
  • Telephone number
  • Postal address (including property address for site visits)

2.2 Communication data

  • Messages sent via our contact form or email
  • Records of telephone conversations where notes are taken
  • Correspondence relating to quotations, contracts, and project delivery

2.3 Project and property data

  • Garden or terrace dimensions and descriptions
  • Photographs of your outdoor space (with your consent)
  • Site visit notes including soil, drainage, and access conditions
  • Design preferences and maintenance requirements

2.4 Technical data

  • IP address
  • Browser type and version
  • Device information
  • Pages visited and time spent on our website
  • Referring website addresses

2.5 Financial data

  • Invoice details and payment records
  • Bank account information where relevant for refunds

We do not collect special categories of personal data (such as health data, biometric data, or data revealing racial or ethnic origin) unless you voluntarily provide such information and we have a lawful basis to process it.

3. How We Collect Personal Data

We collect personal data through:

  • Direct interactions — when you fill in our contact form, send an email, call us, or visit our studio
  • Service delivery — during site consultations, project meetings, and document delivery
  • Automated technologies — cookies and similar technologies when you browse our website (see our Cookie Policy)
  • Third parties — such as contractors or building managers, only where necessary for project delivery and with appropriate safeguards

4. Purposes and Legal Bases for Processing

We process your personal data only where we have a lawful basis under Article 6 GDPR:

Purpose Legal basis
Responding to enquiries and providing quotations Legitimate interests (Art. 6(1)(f)) / Pre-contractual steps (Art. 6(1)(b))
Delivering design services under contract Performance of a contract (Art. 6(1)(b))
Processing payments and maintaining accounts Performance of a contract (Art. 6(1)(b)) / Legal obligation (Art. 6(1)(c))
Website analytics and improvement Consent (Art. 6(1)(a)) where required; otherwise legitimate interests (Art. 6(1)(f))
Compliance with tax and accounting obligations Legal obligation (Art. 6(1)(c))
Marketing communications about our services Consent (Art. 6(1)(a)) or legitimate interests with opt-out (Art. 6(1)(f))
Establishing, exercising, or defending legal claims Legitimate interests (Art. 6(1)(f))

Where we rely on legitimate interests, we have assessed that our interests do not override your fundamental rights and freedoms. You may request details of this balancing test by contacting us.

5. How We Use Your Personal Data

We use personal data to:

  • Respond to your enquiries within two working days
  • Schedule and conduct site visits and consultations
  • Prepare garden and terrace design documents
  • Issue invoices and process payments
  • Communicate about project progress and revisions
  • Maintain records required by Dutch tax law (generally seven years)
  • Improve our website and services
  • Send service-related updates where you are an existing client

We do not use automated decision-making or profiling that produces legal or similarly significant effects.

6. Sharing Your Personal Data

We do not sell your personal data. We may share data with:

  • Service providers — IT hosting, email services, accounting software, and payment processors, bound by data processing agreements under Article 28 GDPR
  • Contractors — when briefing on hard landscaping work, limited to project-relevant information
  • Professional advisers — accountants or legal counsel where necessary
  • Authorities — when required by law, court order, or regulatory request

Some service providers may process data outside the European Economic Area (EEA). Where this occurs, we ensure appropriate safeguards are in place, such as Standard Contractual Clauses approved by the European Commission, or an adequacy decision.

7. Data Retention

We retain personal data only as long as necessary for the purposes described:

  • Enquiry data — up to 24 months after last contact if no contract is formed
  • Contract and project data — duration of the project plus seven years for tax and legal purposes
  • Marketing consent records — until consent is withdrawn, plus evidence of consent for three years
  • Website analytics — as specified in our Cookie Policy
  • Cookie consent preferences — 12 months, then re-requested

After retention periods expire, data is securely deleted or anonymised.

8. Your Rights Under GDPR

Under the GDPR, you have the following rights in relation to your personal data:

  • Right of access (Art. 15) — request a copy of the personal data we hold about you
  • Right to rectification (Art. 16) — request correction of inaccurate or incomplete data
  • Right to erasure (Art. 17) — request deletion where there is no compelling reason to continue processing
  • Right to restriction (Art. 18) — request that we limit processing in certain circumstances
  • Right to data portability (Art. 20) — receive your data in a structured, machine-readable format where processing is based on consent or contract
  • Right to object (Art. 21) — object to processing based on legitimate interests or for direct marketing
  • Right to withdraw consent (Art. 7(3)) — withdraw consent at any time where processing is consent-based, without affecting prior lawful processing
  • Right not to be subject to automated decision-making (Art. 22) — not applicable as we do not use such processing

To exercise any of these rights, email [email protected] with the subject line "Privacy Request". We will respond within one month, extendable by two further months for complex requests as permitted under Article 12(3) GDPR. We may request proof of identity before processing your request.

There is no fee for exercising your rights unless requests are manifestly unfounded or excessive.

9. Right to Lodge a Complaint

If you believe we have not handled your personal data properly, you have the right to lodge a complaint with the Dutch supervisory authority:

Autoriteit Persoonsgegevens (AP)
Website: autoriteitpersoonsgegevens.nl
Post: Postbus 93374, 2509 AJ Den Haag, Netherlands

We encourage you to contact us first so we can address your concerns directly.

10. Data Security

We implement appropriate technical and organisational measures to protect personal data against unauthorised access, alteration, disclosure, or destruction. These include:

  • Encrypted connections (HTTPS) for our website
  • Access controls limiting data access to authorised personnel
  • Secure storage of physical and digital project files
  • Password-protected devices and regular software updates
  • Staff awareness of data protection obligations

While we take security seriously, no method of transmission over the internet is completely secure. We cannot guarantee absolute security.

11. Data Breach Notification

In the event of a personal data breach likely to result in a risk to your rights and freedoms, we will notify the Autoriteit Persoonsgegevens within 72 hours where required under Article 33 GDPR, and inform affected individuals without undue delay where required under Article 34 GDPR.

12. Children's Privacy

Our services are directed at adults. We do not knowingly collect personal data from individuals under 16 years of age. If you believe we have collected data from a child, please contact us and we will delete it promptly.

13. Third-Party Links

Our website may contain links to external sites. We are not responsible for the privacy practices of those sites and encourage you to read their privacy policies.

14. Changes to This Policy

We may update this Privacy Policy from time to time. The "Last updated" date at the top indicates when changes were last made. Material changes will be communicated via our website or by email where appropriate.

15. Contact

For questions about this Privacy Policy or our data practices:

Email: [email protected]
Phone: +31 30 820 4412
Address: Oudegracht 188, 3511 AW Utrecht, Netherlands

Veldbloem Design

Oudegracht 188
3511 AW Utrecht
Netherlands

Contact

Phone: +31 30 820 4412
Email: [email protected]

Explore

  • Services
  • Our Process
  • Service Areas
  • FAQ

Legal

  • Privacy Policy
  • Cookie Policy
  • Terms of Service
  • Legal Notice
  • Sitemap

© 2026 Veldbloem Design. All rights reserved.