PAVAN GERAEDTS / Privacy & discretion
Privacy & discretion
Discretion is part of how we care for people and relationships. This statement explains what becomes public, what remains private and how personal information is handled.
LAST UPDATED / 10 OCTOBER 2026
Discretion is part of how we care for people and relationships. Sharing our family’s perspective, cultural interests and encounters carries a corresponding responsibility: to make clear what becomes public, what remains private and how personal information is handled.
This statement explains the processing of personal data in connection with pavangeraedts.com, correspondence with the Chancellery, the guest book and the visits and cultural activities described below.
01
Responsibility and contact
The controller responsible for the processing described in this statement is:
Controller legal name to be confirmed: insert the full legal name of the responsible person or entity. If several persons are joint controllers, identify each and explain their arrangement.
Correspondence and privacy contact:
The Chancellery of the Pavan Geraedts family
Rigaweg 9
3825 PP Amersfoort
The Netherlands
kanselarij@pavangeraedts.com
In this statement, “we”, “us” and “our” refer to that controller. The Chancellery is the contact and coordination office through which privacy matters are handled.
Our cultural and event location at De Stuwdam 33–35, 3815 KM Amersfoort, is separate from the Chancellery’s correspondence address.
A company’s appearance on this website, its connection with the family or its presence at one of our locations does not, by itself, make it responsible for this website’s processing. Professional services and activities undertaken by separate organisations are governed by the privacy information of the organisation concerned.
02
Scope and legal framework
This statement concerns visitors to the website, people corresponding with the Chancellery, guest-book contributors and individuals whose information or images are used in the family, cultural or editorial content of the website.
It also covers our handling of enquiries and arrangements for visits and cultural encounters where these are coordinated by the controller identified above. Where a separate organisation arranges an event or collects registration information, its identity and applicable privacy information must be made clear at the point of collection.
We process personal data in accordance with Regulation (EU) 2016/679, the General Data Protection Regulation (“GDPR” or “AVG”), the Dutch Uitvoeringswet Algemene verordening gegevensbescherming and, where applicable, the Telecommunicatiewet.
Our approach follows the principles in Article 5 GDPR: lawful and transparent processing, defined purposes, relevant and limited collection, accuracy, appropriate retention, security and accountability.
03
Information we process
Depending on your interaction with us, we may process:
- Correspondence information: your name, email address, contact details you choose to provide, the content of your message and information needed to respond.
- Visit and event information: your name, contact details, attendance arrangements and relevant practical requests.
- Guest-book information: your chosen display name, message, submission details and the record of your consent to publication.
- Images and editorial information: photographs, video or audio recordings, names, captions, biographical details and information about a visit, encounter or contribution.
- Technical information: IP addresses, request times, requested pages, browser and device information, error records and security information processed in delivering and protecting the website.
- Privacy administration: information needed to handle a rights request, record a consent decision or address an objection or complaint.
Most information comes directly from you or is generated through your use of the website. Editorial material may also come from family records, photographers, authorised contributors or publicly available documentary sources. Where Article 14 GDPR applies, we provide the required information within its applicable deadlines, including relevant information about the source.
Please provide only what is necessary for your enquiry. Identity documents, citizen service numbers, medical information and confidential professional case materials should not be submitted through the guest book or ordinary website correspondence.
If an activity exceptionally requires sensitive personal information, we explain the purpose and applicable legal basis separately and use an appropriate private channel. A general permission to publish a message or photograph is not, by itself, explicit consent to process special-category data under Article 9 GDPR.
04
Purposes and legal bases
We distinguish between the information needed to manage a relationship and permission to make information public.
Responding to correspondence
We use relevant contact details and message content to answer enquiries, manage introductions and maintain the correspondence necessary for that exchange. The basis is our legitimate interest in communicating with people who contact the Chancellery, under Article 6(1)(f) GDPR.
Arranging visits and cultural encounters
We use necessary information to organise attendance, communicate practical arrangements and follow up on the activity. The basis is our legitimate interest in administering those arrangements. Article 6(1)(b) GDPR applies only where processing is necessary to perform a contract with you or take steps towards one at your request.
Managing the guest book
We receive and review submissions and check their suitability for publication. We rely on our legitimate interest in maintaining a respectful and reliable guest book for moderation and abuse prevention. Publication of your display name and message is based on your consent under Article 6(1)(a) GDPR.
Publishing guest portraits, interviews and visit stories
We seek specific consent for identifiable guest portraits, interviews and personal accounts prepared for publication. The permission concerns the content, purpose and publication channels explained when consent is requested.
Maintaining family and cultural content
For other material involving living individuals, we assess the purpose and lawful basis before publication. Consent is used where appropriate. Any reliance on legitimate interests requires a documented assessment of necessity, reasonable expectations and the effect on the person concerned. Describing material as family history or an archive does not create an automatic exemption from data protection law.
Operating and protecting the website
Technical processing supports website delivery, fault diagnosis, security and prevention of repeated or abusive submissions. The basis is our legitimate interest in maintaining a functioning and secure website.
Meeting legal obligations and handling claims
We process relevant information where necessary to comply with an applicable legal obligation under Article 6(1)(c) GDPR, or to establish, exercise or defend legal claims under Article 6(1)(f).
Where we rely on legitimate interests, we assess whether the processing is necessary and whether your interests and fundamental rights override those interests.
Providing correspondence details or contributing to the guest book is voluntary. Without information necessary to answer an enquiry or arrange a visit, we may be unable to complete that request. Without publication consent, a guest-book contribution will not be published.
05
Browsing, cookies and external content
The website is configured without advertising trackers, embedded social feeds or external font requests. Photographs and video are hosted as website assets unless an external source is expressly introduced.
Hosting content ourselves does not mean that browsing is anonymous. The hosting infrastructure still processes technical information needed to deliver pages and protect the service.
The guest book uses a short-lived hashed network identifier to limit repeated submissions. Hashing does not necessarily make information anonymous; we treat the identifier as personal data where it remains linkable to a visitor.
Cookies, browser storage and similar technologies are subject to Article 11.7a Telecommunicatiewet where applicable. Technologies that are strictly necessary, or qualify for the statutory exception for analytics with no or only minor privacy effects, may be used without consent. Other technologies requiring consent must remain inactive until valid consent has been obtained.
Where such technologies are introduced, we provide information about their purposes, providers and duration before asking for consent. Refusal must be a genuine choice, and withdrawing consent must be as easy as giving it.
An ordinary link to another website is different from embedding that provider’s content. Where an embedded player or other external component would transmit information to a third party, we assess and explain that processing before activation and obtain consent where required.
06
Guest-book publication
The guest book is public. Submit only information you intend others to read, using the display name you wish to appear alongside your message.
By selecting the publication-consent option and submitting your contribution, you authorise us to review it and, if approved, publish your display name and message in the guest book.
Consent to that publication does not authorise unrelated advertising, use of your contribution as a promotional testimonial elsewhere or publication through additional channels.
Submissions are reviewed by the Chancellery before publication. Approval is an editorial decision and is not guaranteed. We may decline a contribution containing confidential information, unnecessary information about third parties, unlawful content or material unrelated to the guest book. A material alteration to an approved message requires renewed agreement before publication.
Submissions and the associated consent record are handled through the website’s WordPress environment. Unpublished material is accessible only to those who need it for moderation, administration or technical support.
To withdraw publication consent or request removal, write to kanselarij@pavangeraedts.com and identify the entry. You do not need to give a reason. We may ask for proportionate information to confirm that the request concerns your contribution.
Once consent is withdrawn, we stop the consent-based publication and remove the entry from the website without undue delay. Limited evidence of the consent and its withdrawal may be retained where independently necessary for accountability or legal claims.
Public material may be indexed by search engines or copied by others. Removal from our website cannot guarantee that every independent copy disappears. Where the GDPR requires reasonable steps to inform other controllers of an erasure request, we take those steps.
07
Photographs, recordings and personal stories
Attending a visit or event does not, by itself, constitute consent to publication of your image, name or personal story.
For guest portraits and identifiable personal accounts, we explain the proposed use and obtain specific consent before publication. Participation in an encounter must not depend on accepting publicity that is unnecessary for participation.
If wider event photography or recording is planned, we explain the purpose, lawful basis and intended uses in advance and provide a practical means of raising concerns. Any reliance on legitimate interests requires a separate assessment; a notice at the entrance alone does not establish a lawful basis.
A photograph or recording may reveal sensitive information through its content or context. Where Article 9 GDPR applies, the relevant additional condition must be satisfied.
For identifiable images or stories involving children, we apply additional safeguards and obtain permission from the appropriate parent or legal representative where required. We also take account of the child’s age, understanding, wishes and interests.
You may contact the Chancellery about an image, caption or account concerning you. We assess requests for correction, withdrawal, restriction or removal in light of the applicable basis and rights, including relevant portrait rights.
08
Access, service providers and separate organisations
Access to non-public information is limited to authorised people who need it for the relevant purpose.
Depending on the activity, recipients may include hosting and technical-support providers, email and IT providers, people assisting with an authorised visit or event, and professional advisers where their involvement is necessary. Authorities may receive information where the law requires disclosure.
Where a provider processes personal data on our behalf, the relationship is governed by the requirements of Article 28 GDPR. A recipient processing information for its own purposes must have its own lawful basis and responsibilities.
We do not treat family connections as permission to circulate personal information among associated businesses. An enquiry intended for another organisation is referred only with an appropriate basis and the information necessary for that referral.
Approved guest-book entries and other published content are available to the public. We do not sell personal data or use guest-book contributions to create advertising audiences.
09
Processing locations and international transfers
The website application and database are hosted on a server located in the Netherlands, within the European Economic Area. Photographs and video used on the site are stored with that website environment unless an external source is expressly introduced.
Correspondence sent to kanselarij@pavangeraedts.com is processed through the mailbox and email infrastructure used for that address. Where that infrastructure, or another provider acting for us, involves processing outside the EEA—including through remote support access—Chapter V GDPR applies.
Confirm the mailbox/email provider location and any other processors with access outside the EEA. If transfers occur, identify the countries and applicable safeguards (adequacy decision or standard contractual clauses with any necessary supplementary measures).
Any transfer outside the European Economic Area must satisfy Chapter V GDPR. Depending on the recipient and circumstances, this may involve an applicable European Commission adequacy decision or appropriate safeguards, such as standard contractual clauses together with any necessary supplementary measures.
Where transfers occur, you may request information about the applicable safeguards and a copy of them, subject to necessary protection of confidential information.
Public accessibility of website content is distinct from our appointment of a provider in another country. Neither locally hosted images nor the location of a server alone establishes where all processing takes place.
10
Retention
We retain personal data only while it serves an identified purpose or a binding retention requirement. The criteria are:
- Correspondence: until the enquiry and necessary follow-up are completed. Where an ongoing relationship requires continued reference to correspondence, only relevant records are retained for that purpose.
- Visit and event administration: until the activity and necessary practical follow-up are completed. Information needed for accounting or a claim follows the applicable legal requirement.
- Unpublished guest-book submissions: for the moderation process and any necessary handling of abuse or a dispute; declined or abandoned submissions are then deleted.
- Published contributions and consent-based images: while the agreed publication purpose remains relevant and consent remains valid. Withdrawal ends consent-based publication.
- Consent and rights-request records: for the period necessary to demonstrate lawful handling and address relevant claims, with retention limited to the evidence needed.
- Family and cultural records concerning living people: according to the documented purpose, lawful basis and continuing necessity of the specific record. Family significance alone does not justify unrestricted retention.
- Security records and backups: according to the limited technical periods specified below, with relevant incident evidence retained longer only where necessary to investigate or address that incident.
Current technical periods applied for this website:
- Hashed guest-book network identifier: retained for 5 minutes after a submission, solely to limit repeated submissions.
- Browser-stored guest-book draft: kept only in your own browser until you clear it or use the delete control; it is not sent to us until you submit.
- Routine server and security logs: retained for no more than 30 days, unless a longer period is necessary to investigate a security incident.
- Backup rotation: website and database backups are retained on a rolling basis for no more than 30 days.
Retention periods must be justified by the purpose concerned; the GDPR does not establish a single general period for all personal data.
Backups are retained for recovery and security, with access restricted accordingly. Deleted information must not be returned to ordinary use following a restoration; relevant deletion requests are reapplied where necessary.
11
Security and incidents
We apply technical and organisational measures appropriate to the nature of the information and the risks involved, in accordance with Article 32 GDPR. These include appropriate access controls, confidentiality arrangements and management of the systems and providers used for processing.
If a personal data breach occurs, we assess and document it, take appropriate corrective action and notify the competent authority and affected individuals where Articles 33 and 34 GDPR require this.
12
Your rights and requests
Subject to the applicable conditions, you may request:
- Access to your personal data and a copy of it, under Article 15 GDPR.
- Correction of inaccurate or incomplete information, under Article 16.
- Erasure, under Article 17.
- Restriction of processing, under Article 18.
- Portability of data processed by automated means on the basis of consent or a contract, under Article 20.
- Withdrawal of consent at any time, under Article 7(3).
Withdrawal does not affect the lawfulness of processing carried out before withdrawal.
Your right to object
Where we rely on legitimate interests, you may object on grounds relating to your particular situation under Article 21 GDPR. We then stop that processing unless we demonstrate compelling overriding grounds or the processing is necessary for legal claims. An objection to direct marketing must be honoured without that balancing exercise.
Send requests to kanselarij@pavangeraedts.com, identifying the information or activity concerned. We may seek limited additional information where reasonably necessary to verify identity; a full copy of an identity document is not our default requirement.
We respond without undue delay and normally within one month of receipt. Where the complexity or number of requests justifies an extension, we may extend this by up to two further months and explain the reason within the first month. Requests are normally handled free of charge.
Rights are not absolute. If a lawful exception applies, we explain the relevant reason and your options.
The activities described in this statement do not involve decisions based solely on automated processing that produce legal or similarly significant effects within Article 22 GDPR. Automated security controls may limit repeated or abusive submissions.
13
Complaints and changes
You may raise a concern directly with the Chancellery. You also have the right to complain to the Autoriteit Persoonsgegevens, the Dutch supervisory authority, or another competent supervisory authority under Article 77 GDPR. You do not have to contact us first.
Autoriteit Persoonsgegevens:
www.autoriteitpersoonsgegevens.nl
We update this statement when the website or relevant processing changes. The date at the beginning identifies the latest revision. Where a new purpose requires additional information or fresh consent, we provide that information or obtain consent before proceeding.
Using this website does not constitute blanket consent to the processing described here.
