Privacy statement

Privacy statement gaFietsen B.V.

gaFietsen B.V., located at Kelmonderstraat 55 in Beek, is responsible for processing your personal data as set out in this privacy statement.

Last modified: 11 - 11 - 2025 fiets@benvitaal.nl

What is personal data?

Personal data is information that tells us who you are or that we can associate with you. Think of your name and email address. Personal data is all direct and/or indirect data by which you can be identified.

Personal data we process

This privacy statement applies to all processing of personal data of participants (hereinafter: "Participants") who register via the website or a campaign page to participate in a project (hereinafter: "Project") of gaFietsen B.V.

gaFietsen B.V. processes personal data that you provide when registering for a Project. Below is an overview of the personal data we process:

  • Gender;
  • First and last name;
  • Date of birth;
  • Address, house number, postal code and city;
  • Phone number;
  • Email address;
  • Height;
  • Your employer or the organisation where you work;
  • Employee number (if applicable);
  • Data about the chosen bike or participation in the Project;
  • IP address and technical data about your device or browser.

For what purpose and on what legal basis we process personal data

To effectively deliver everything related to the Project and ensure the quality of our Projects, it is necessary to process certain personal data. This data is processed for the following purposes:

  • Issuing and managing bikes on loan: to register your participation in the Project, reserve a bike for you and manage it during the period you have the bike on loan.
  • Communication: we use contact details to communicate with you about your participation in the Project, for example to send reminders about the bike pickup or return date.
  • Automatic notifications and follow-up: you may receive automatic emails, for example a reminder before the end of the bike period or requests to evaluate the Project.
  • Research and improvement: for anonymised analyses on mobility, accessibility and bike usage.
  • Contact regarding surveys or follow-up projects: We may contact you to participate in an evaluation or research about your experience with the Project.
  • Compliance and security: We process personal data to comply with legal obligations, including protecting the security of our services and Participants.

The processing of personal data within our company is based on the following grounds under the General Data Protection Regulation (GDPR):

  • Legitimate interest: We process certain personal data based on our legitimate interests. This means processing is necessary to pursue our legitimate business interests, including:
    • Management and organisation of projects: managing a Project effectively, including registration, planning, evaluation and communication with Participants and your employer (if applicable);
    • Customer service and support: providing technical or administrative support for participation in a Project, for example with registration issues, questions about bike use and reporting/registering (any) damage and/or theft;
    • Optimisation of our services: analysing participation and usage data to improve our Projects and communication;
    • Security and abuse prevention: monitoring activities within our systems to prevent misuse, fraud or technical failures.
  • Performance of the agreement: Processing personal data is necessary to perform the agreement with you as a Participant. Without this data we cannot reserve and/or manage a bike or communicate with you about your participation in the Project. This includes:
    • registering and confirming your participation in the Project;
    • scheduling bike pickup and return times at the correct bike shop;
    • sending service and reminder messages;
    • handling any damage or loss reports.

Transfer

We only process personal data explicitly mentioned in this privacy statement and necessary for the above purposes. The privacy and security of our Participants always come first.

To enable participation in a Project, gaFietsen B.V. shares certain personal data with carefully selected partners (subprocessors) involved in delivering the Project. This transfer is necessary for the practical execution of the trial week and services to Participants. Parties directly involved in the Project include:

  • The bike shop where you pick up and return the bike;
  • The bike rental provider, either the bike shop or Cycle Center;
  • Optional project partners, if you explicitly chose during registration to participate in a project involving that party.

These subprocessors are fully regulated in accordance with the requirements of the General Data Protection Regulation (GDPR), with appropriate contractual agreements (including Standard Contractual Clauses) to safeguard personal data.

Transfer within the European Economic Area (EEA)

Where personal data is shared with parties within the EEA, this is only done with organisations bound by the GDPR or an equivalent level of protection.

Transfer outside the EEA

If we transfer personal data to parties located outside the EEA, we ensure this only happens when an adequate level of protection is in place. This means that:

  • The European Commission has issued an adequacy decision for the country concerned; or
  • Model contractual clauses (Standard Contractual Clauses) of the European Commission are used; or
  • Other appropriate safeguards have been implemented, such as binding corporate rules (Binding Corporate Rules).

Recipients

Possible recipients of your data may also include:

  • IT service providers;
  • Cloud storage or email providers;
  • Government authorities (if legally required).

We make clear contractual agreements in an approved (legal) document with every party that processes personal data on our behalf, obliging them to protect your data in accordance with the GDPR.

Automated decision-making

In principle, we do not make decisions based on automated processing that may have (significant) consequences for individuals. This concerns decisions taken by computer programs or systems without human involvement (for example an employee of ours), as referred to in Article 22 of the GDPR. This therefore does not apply to our services.

If automated decision-making with legal or other significant consequences for you were to take place in the future, this would only occur under the conditions set out in Article 22 GDPR. This means that:

  • You will be informed in advance and in a clear manner;
  • There is always an opportunity for human intervention and reassessment;
  • The logic of the decision, its significance and expected consequences for the data subject will be made transparent.

How long we retain personal data

Our company does not retain your personal data longer than strictly necessary to achieve the purposes for which your data was collected. Data is retained while you participate in our Project and for up to 12 months afterwards.

When the above retention periods expire, the relevant personal data will be securely deleted or anonymised so it can no longer be traced back to you. If other specific retention periods apply to certain data, we will communicate this explicitly to you.

Certain data may be deleted earlier, for example when you explicitly request this and there is no legal obligation to retain the data.

Sharing personal data with third parties

We do not sell your data to third parties and will only provide it to third parties if necessary for the performance of our agreement with the data controller or to comply with a legal obligation.

Your rights under the GDPR

As a data subject under the General Data Protection Regulation (GDPR), you have the following rights:

  • Right of access: You have the right to access your personal data that we process;
  • Right to rectification: You may request correction of your personal data if it is incorrect or incomplete;
  • Right to erasure: You have the right to have your personal data deleted;
  • Right to withdraw consent: If processing is based on your consent, you may withdraw that consent at any time;
  • Right to object: You may object to our processing of your personal data;
  • Right to data portability: You have the right to receive the personal data you have provided to us in a structured, commonly used and machine-readable format.

To exercise these rights you can submit a request by sending an email to fiets@benvitaal.nl. We will respond as soon as possible, but within 4 weeks at the latest.

To ensure the access request was made by you, we may ask you to send a copy of your ID with the request. Black out your photo, MRZ (machine readable zone, the strip of numbers at the bottom of the passport), passport number and citizen service number (BSN) in this copy. This is to protect your privacy. As stated, we will respond as soon as possible, but within 4 weeks at the latest.

Complaints to supervisory authority

We would also like to point out that you have the option to file a complaint with the national supervisory authority, the Dutch Data Protection Authority. You can do so via the following link: autoriteitpersoonsgegevens.nl

How we secure personal data

We take the protection of your data seriously and take appropriate measures to prevent misuse, loss, unauthorised access, unwanted disclosure and unlawful alteration. If you believe your data is not properly secured or there are indications of misuse, contact our customer service or via fiets@benvitaal.nl.

Protective measures we have taken:

  1. Logical access control, for example through the use of passwords;
  2. Securing computer systems with firewalls, antivirus software and DDoS prevention;
  3. Logging and monitoring of system access;
  4. Hosting within secure cloud environments, preferably within the European Economic Area (EEA) where possible;
  5. Using the shortest possible retention periods;
  6. Encrypting and pseudonymising data where necessary (during storage and transport);
  7. Purpose-bound access restrictions, for example based on role and function within the organisation;

About this privacy statement

Privacy legislation changes regularly. We keep our privacy statement up to date and the latest version is always available on our website. We may therefore amend this privacy statement at any time. This privacy statement was last updated on 11-11-2025.