Privacy policy – AI Web Solutions
At AI Web Solutions we handle personal data with care. This policy explains what data we process, why we process it and what rights you have, in line with the GDPR.
Data controller
AI Web Solutions is a trade name of Hilbrink Marketing & Services (sole proprietorship)
KVK number: 94778442
Address: Aaltje Noordewierlaan 45, 1403JB Bussum
Website: https://aiwebsolutions.nl
Email: info@aiwebsolutions.nl
What data do we process?
- Contact and clients: name, company name, email address, phone number, website (URL) and the information you share yourself via the contact form or when scheduling a call.
- B2B prospecting: business contact details of potential clients: name, job title, company name, business email address and LinkedIn profile. We collect these from public sources (such as LinkedIn) and business B2B data providers, and enrich and verify them with dedicated tools.
- Calls: we may have (video) calls recorded or transcribed for note-taking purposes; we mention this at the start of the call.
- Website visits: IP address and technical usage data via cookies and similar technologies (see Cookies).
Purposes and lawful basis
We do not process special categories of (sensitive) personal data and do not make automated decisions with legal effects.
- Contact, proposals, services, support and invoicing: performance of a contract (GDPR Art. 6(1)(b)).
- Retaining records and invoices: legal obligation (GDPR Art. 6(1)(c)).
- Website analytics: legitimate interest: improving our website (balancing test available on request).
- B2B prospecting via email and LinkedIn: legitimate interest: client acquisition aimed at business contacts (balancing test available on request). You can opt out at any time, see Opt-out.
- Marketing and tracking cookies: consent (GDPR Art. 6(1)(a)), via the cookie banner.
Recipients and processors
We only share data with suppliers we need to do our work, under a data processing agreement where required:
- Website and forms: hosting, Formspree (contact form), Calendly (scheduling).
- Outreach: Instantly (email), HeyReach (LinkedIn).
- Lead data and enrichment: Apollo, Clay, PhantomBuster.
- CRM and follow-up: Attio.
- Call notes: Fireflies (transcription of video calls).
- Analytics and advertising: Google Analytics, Meta, LinkedIn.
- Administration: Moneybird (invoicing and accounting).
- Email and office software: Google Workspace.
- AI services: LLM providers (such as Anthropic) for internal automation; we share no more data than necessary.
Transfers outside the EU
Some of these suppliers are based in the United States. Transfers take place on the basis of the EU-US Data Privacy Framework or the European Commission’s Standard Contractual Clauses (SCCs).
Cookies
We use functional cookies (always active), analytics cookies (Google Analytics) and marketing/tracking cookies (Meta Pixel, LinkedIn Insight Tag). For marketing and tracking cookies we ask for consent via the cookie banner. See our cookie policy: https://aiwebsolutions.nl/cookiebeleid.
Retention periods
We do not retain data longer than necessary:
- Invoices and records: 7 years (statutory retention obligation).
- Client data: duration of the relationship plus 2 years.
- Prospect data (outreach): 6 months after last contact.
- Opt-outs: your email address remains on our suppression list for as long as needed to honour your opt-out.
Your rights
Send your request to info@aiwebsolutions.nl; we respond within one month.
- Access, rectification, erasure, restriction and data portability.
- Object to processing (for example to marketing).
- Withdraw consent you have given.
- File a complaint with the Dutch DPA (autoriteitpersoonsgegevens.nl).
Marketing opt-out
You can opt out via the unsubscribe link in our emails, by letting us know in a reply on LinkedIn, or by emailing info@aiwebsolutions.nl. We process opt-outs immediately.
Security
We protect data with encrypted connections (SSL), access controls and two-factor authentication where possible. Data is stored in the secure systems of the suppliers listed above. Where required, we report data breaches to the Dutch DPA within 72 hours.
Changes
Updates will be published on this page. Last updated: 31 August 2026.