Overslaan naar inhoud
xtroverso
  • Scope of Work
  • Hoe het werkt
    • Hoe XTROVERSO™ werkt
    • FAQ
  • Kader
    • Waarom XTROVERSO™
    • Kader & controles
    • Verificatie & nalevingscontroles
    • Cultureel manifest
  • Kennis
  • Over ons
  • Contact
  • 0
  • 0
  • Nederlands English (US)
  • CLIËNTGEBIED
xtroverso
  • 0
  • 0
    • Scope of Work
    • Hoe het werkt
      • Hoe XTROVERSO™ werkt
      • FAQ
    • Kader
      • Waarom XTROVERSO™
      • Kader & controles
      • Verificatie & nalevingscontroles
      • Cultureel manifest
    • Kennis
    • Over ons
    • Contact
  • Nederlands English (US)
  • CLIËNTGEBIED

Data & Privacy Statement

IntroductionController detailsOnze privacyprincipesWhen XTROVERSO acts as controllerWhen XTROVERSO acts as processorPavan Geraedts and coordinated servicesWhere personal data come fromWhy we process personal dataInformation that is requiredStorage and retentionProcessors and service providersOther recipientsInternational transfersHow we protect personal dataPersonal-data breachesAutomated processing and human reviewUw rechtenWat wij niet doenChildrenCookiesComplaintsAmendmentsQuestions about privacy

Introduction

Personal data are part of the responsibility entrusted to us. They are not a commercial asset.

XTROVERSO processes business, administrative and payroll information because accurate administration requires identifiable evidence. That necessity does not create an unlimited right to collect, retain or reuse data.

How XTROVERSO handles personal data under Dutch and European data-protection law.

This statement explains:

  • which personal data we process;
  • where those data originate;
  • why we process them;
  • whether XTROVERSO acts as controller or processor;
  • when information may be shared with Pavan Geraedts;
  • how long information is retained;
  • which rights individuals have.

This statement should be read together with our Cookie Policy and, where XTROVERSO processes data for a client, the applicable Data Processing Agreement.

Article 1 — Controller details

XTROVERSO is a registered trade name of:

WIGEPA B.V.

trading as XTROVERSO

De Stuwdam 33

3815 KM Amersfoort

The Netherlands

Chamber of Commerce: 70402787

VAT number: NL858307790B01

BECON number: 685811

For privacy questions or requests:

privacy@xtroverso.com

WIGEPA B.V. is the controller for personal data processed for XTROVERSO's own business purposes, including enquiries, client acceptance, contracting, security, billing and compliance.

For information contained in a client's business administration or payroll administration, XTROVERSO will normally act as processor on behalf of that client. In that situation, the client determines why the data are processed and remains the controller.

Article 2 — Our privacy principles

Responsibility follows the data

Responsibility does not disappear because information moves through a portal, dashboard, payroll system or external provider.

For every processing activity, the relevant role must be clear: controller, processor, recipient or independent professional provider.

Purpose before collection

We collect personal data only where there is an identified operational, contractual, security or legal purpose.

The availability of information does not, by itself, justify its use.

Proportionality over convenience

We seek to process only the data reasonably necessary for the relevant service or obligation.

Where the same objective can be achieved with less information, the more limited approach should be used.

Security as an operating condition

Privacy cannot be separated from access control, system integrity, evidence quality and continuity.

Personal data are therefore handled through controlled systems, restricted access and structured retention and deletion procedures.

Human responsibility remains

Automated tools may support classification, verification, document recognition, transaction matching or risk identification. They do not remove human responsibility for material decisions.

Transparency must remain practical

A privacy statement should allow a person to understand what happens to their data. It should not merely repeat legal terminology.

Article 3 — When XTROVERSO acts as controller

XTROVERSO acts as controller when it determines the purpose and essential means of the processing.

This generally applies to the following activities.

Website visits and digital security

When you visit our website or use a digital environment, we may process:

  • IP address;
  • date and time of access;
  • browser and device information;
  • requested pages;
  • security and access logs;
  • cookie preferences;
  • technical error and performance information.

These data are used to operate and secure the website, investigate misuse, maintain availability and understand technical performance.

Optional analytics or marketing technologies are used only in accordance with our Cookie Policy and the choices available through the cookie-preference mechanism.

Enquiries and prospective clients

When you contact XTROVERSO, request information or arrange an intake, we may process:

  • your name;
  • organisation and position;
  • business contact details;
  • the content of your request;
  • appointment information;
  • correspondence and follow-up notes;
  • information required to assess whether we can accept the request.

We use this information to respond, assess the requested services, prepare a proposal and manage pre-contractual communication.

Client and business-relationship management

For clients, suppliers, partners and professional contacts, we may process:

  • names and business contact details;
  • position, authority and organisational relationship;
  • contracts, proposals and approvals;
  • correspondence and meeting records;
  • invoicing and payment information;
  • service and support history;
  • complaints or dispute information;
  • access and authorisation records.

This information is used to administer the relationship, perform agreements, maintain an evidence trail, invoice services, manage access and protect legal rights.

Client acceptance, verification and compliance

Depending on the relationship and the services requested, XTROVERSO may process:

  • statutory and trading names;
  • Chamber of Commerce and VAT information;
  • ownership and management information;
  • ultimate beneficial-owner information;
  • identity and contact information;
  • nationality, date of birth or identification details where required;
  • copies or extracts of identification documents where legally permitted;
  • authority and representation information;
  • bank-account ownership results;
  • sanctions and risk-screening results;
  • information about the nature and purpose of the business relationship;
  • source-of-funds information where required;
  • information concerning unusual or potentially unlawful circumstances.

These data are used to establish identity, verify authority, assess whether a relationship can be accepted or continued, prevent fraud and comply with legal obligations.

Where the Dutch Money Laundering and Terrorist Financing Prevention Act applies, information may have to be retained or disclosed in accordance with the Wwft.

A legal prohibition may prevent us from informing a person that a particular report, request or investigation exists.

Billing, administration and legal obligations

XTROVERSO processes information required for its own administration, including:

  • contracts and Order Confirmations;
  • invoices and credit notes;
  • payment status;
  • bank and transaction references;
  • debtor correspondence;
  • tax and accounting records;
  • evidence relating to the services delivered.

These data are used to invoice, collect payments, comply with statutory administration and tax obligations and establish or defend legal claims.

Recruitment

If you apply for a role or assignment, we may process:

  • contact details;
  • curriculum vitae;
  • employment and education history;
  • application correspondence;
  • interview notes;
  • references, where lawfully requested;
  • information needed to assess suitability and availability.

We do not request information unrelated to the role.

Application information is normally deleted within four weeks after the recruitment process ends. With the applicant's permission, it may be retained for up to one year for future opportunities.

Article 4 — When XTROVERSO acts as processor

XTROVERSO normally acts as processor when it handles personal data within a client's business administration or payroll administration according to that client's instructions.

The client remains the controller and determines:

  • why the personal data are processed;
  • which persons are included;
  • the applicable legal basis;
  • how employees, customers and suppliers are informed;
  • the appropriate retention period;
  • how data-subject requests are handled.

The processing is governed by the applicable Data Processing Agreement.

Business-administration information

A client's administration may contain personal data relating to directors, employees, customers, suppliers, sole proprietors and business contacts, including:

  • names and contact details;
  • invoices and transaction information;
  • bank-account and payment information;
  • contracts and order information;
  • expense claims and receipts;
  • VAT and other administrative classifications;
  • customer and supplier correspondence;
  • references contained in accounting records.

XTROVERSO processes these data to maintain the client's administration, reconcile transactions, process documents, support periodic closing and prepare information for reporting and professional review.

Payroll and employment information

Payroll processing may involve:

  • name, address and contact details;
  • date of birth and nationality;
  • employee or personnel number;
  • citizen service number where legally permitted;
  • identification and employment information;
  • salary and wage components;
  • working hours, leave and absence information;
  • bank-account details;
  • payroll-tax information;
  • pension and benefit information;
  • payslips and annual income statements.

Payroll information is processed only to perform the payroll services instructed by the employer and to support the employer's legal obligations.

Routine payroll processing does not require a medical diagnosis. Clients should not provide diagnoses or unnecessary medical details to XTROVERSO.

Where limited health-related or other special-category information is necessary, it may be processed only under the client's documented instructions and where permitted by applicable law.

Rights concerning client-controlled data

If your data appear in an administration or payroll file that XTROVERSO processes for your employer or another client, that employer or client is normally the controller.

Your request should therefore generally be directed to that organisation.

If XTROVERSO receives such a request directly, we will identify the relevant controller and forward or support the request in accordance with the Data Processing Agreement. We will not independently alter a client's administration without proper authority.

Article 5 — Pavan Geraedts and coordinated services

A Coordinated Package may include:

  • Administrative Services provided by XTROVERSO; and
  • Professional Services provided separately by Pavan Geraedts.

Pavan Geraedts has independent responsibility for its client acceptance, professional engagement, professional records, legal obligations and professional judgment.

Unless expressly stated otherwise for a particular processing activity, XTROVERSO and Pavan Geraedts act as separate controllers for their respective purposes. The presentation of one package, portal, relationship manager or total price does not make them one controller.

Information may be exchanged where necessary to:

  • assess or establish a Coordinated Package;
  • perform the Administrative Agreement or Professional Agreement;
  • prepare or review VAT information;
  • prepare annual accounts or tax returns;
  • coordinate year-end work;
  • resolve administrative questions;
  • comply with legal or professional obligations.

Only information reasonably necessary for the relevant purpose should be exchanged.

Where XTROVERSO and Pavan Geraedts jointly determine the purpose and essential means of a specific processing activity, the responsibilities will be recorded as required by Article 26 GDPR. The essential content of that arrangement will be made available where applicable.

A request concerning data controlled exclusively by Pavan Geraedts must be addressed to Pavan Geraedts under its own privacy information.

Article 6 — Where personal data come from

Depending on the relationship, personal data may be obtained:

  • directly from the individual;
  • from the Client;
  • from an employer or authorised representative;
  • from connected banks or financial platforms;
  • from invoices, contracts and administrative documents;
  • from the Dutch Chamber of Commerce and other public registers;
  • from tax or government authorities;
  • from identity, bank-account or sanctions-verification providers;
  • from suppliers, customers or other business counterparties;
  • from professional providers involved in the engagement;
  • from publicly accessible business sources.

We do not treat the public availability of information as unrestricted permission to reuse it.

Where data are not obtained directly from the individual, we assess whether information must be provided under Article 14 GDPR or whether the relevant controller is responsible for that information.

Article 7 — Why we process personal data

XTROVERSO processes personal data only where an appropriate legal basis applies.

Performance of a contract

Processing may be necessary to:

  • respond to a request made before an agreement;
  • establish and perform an agreement with a sole proprietor or other individual business client;
  • provide agreed services;
  • manage access, support, communication and payment.

Where the data subject is not personally a party to the agreement, another legal basis may apply.

Legal obligations

Processing may be required for:

  • statutory bookkeeping and tax records;
  • client-identification and verification requirements;
  • fraud and sanctions controls;
  • Wwft obligations where applicable;
  • payroll and employment administration;
  • responding to competent authorities;
  • establishing the identity and authority of representatives.

Legitimate interests

XTROVERSO may process data where necessary for legitimate interests, provided that those interests are not overridden by the individual's rights and freedoms.

Those interests may include:

  • maintaining a secure and accountable service;
  • communicating with business contacts;
  • protecting systems and accounts;
  • preventing misuse and fraud;
  • maintaining evidence of instructions and approvals;
  • managing claims and professional risk;
  • improving operational processes;
  • maintaining business continuity.

Before relying on legitimate interests for higher-risk processing, we assess the purpose, necessity and potential effect on the individual.

Consent

Consent may be used for genuinely optional activities, such as certain cookies, voluntary subscriptions or retention of an unsuccessful application.

Consent can be withdrawn at any time. Withdrawal does not affect processing that was lawful before consent was withdrawn.

We do not use consent where the processing is actually required by law or is necessary to perform an agreement.

Legal claims and special-category information

Where permitted by law, information may be processed where necessary to establish, exercise or defend legal claims.

Special-category information and information concerning criminal matters are processed only where a specific legal condition and the relevant Dutch-law requirements are satisfied.

Article 8 — Information that is required

Certain information is required to enter into or perform a business relationship.

If the requested identification, authority, administrative or payroll information is not provided, XTROVERSO may be unable to:

  • accept the Client;
  • provide the requested service;
  • complete a verification;
  • process payroll correctly;
  • meet a filing or reporting deadline;
  • continue the relationship.

Information requested for optional cookies, newsletters or other voluntary activities is not a condition for receiving the core services.

Article 9 — Storage and retention

Personal data are not retained under one universal period. The period depends on the purpose, legal obligation, nature of the record and XTROVERSO's role.

As a general framework:

  • website security and access logs are retained only for the period reasonably necessary for security, investigation and continuity;
  • cookie retention is described in the Cookie Policy;
  • enquiries that do not lead to an engagement are normally removed within two years after the last substantive contact;
  • relationship and correspondence information is retained during the relationship and thereafter where necessary for administration or legal claims;
  • XTROVERSO's invoices, contracts and statutory financial records are normally retained for at least seven years where Dutch tax or administration law requires this;
  • Wwft identification and transaction records are retained for the statutory period, generally five years after the relationship ends or the relevant transaction is completed;
  • dispute and claim information may be retained until the applicable limitation period and any related proceedings have ended;
  • recruitment data are normally deleted within four weeks, or retained for up to one year with permission;
  • processor data are returned or deleted in accordance with the Client's instructions, the DPA and applicable legal obligations.

Backup copies may remain for a limited period within protected backup cycles. They are not restored or used for ordinary operational purposes after deletion, except where necessary for security, continuity or legal compliance.

A legal hold, investigation or pending claim may require certain information to be retained for longer.

Article 10 — Processors and service providers

XTROVERSO uses selected service providers to support its operations.

Depending on the service, these may include providers of:

  • secure hosting and cloud infrastructure;
  • email and communications;
  • accounting and payroll platforms;
  • customer and relationship management;
  • document storage and electronic signatures;
  • bank connections and payment information;
  • identity, company and bank-account verification;
  • IT security, monitoring and backups;
  • professional support and insurance.

Processors may use personal data only for the contracted purpose and under appropriate data-protection obligations.

XTROVERSO assesses the role, access, location and security of relevant providers. Where XTROVERSO acts as processor, subprocessors are managed in accordance with the DPA.

An applicable subprocessor list or further information may be requested through the privacy contact address.

Article 11 — Other recipients

Personal data may also be provided to:

  • Pavan Geraedts for accepted or proposed Professional Services;
  • government or tax authorities;
  • courts and competent supervisory bodies;
  • banks and payment providers;
  • insurers and professional advisers;
  • auditors or specialists engaged for a specific purpose;
  • a successor entity in connection with a legitimate merger or transfer of business.

Information is not disclosed merely because a third party requests it. A contractual, legal or otherwise legitimate basis must exist.

Article 12 — International transfers

XTROVERSO seeks to process personal data within the European Economic Area where reasonably possible.

If personal data are transferred to or accessed from a country outside the European Economic Area, XTROVERSO will use a recognised transfer mechanism where required, such as:

  • an adequacy decision of the European Commission;
  • the European Commission's Standard Contractual Clauses;
  • another legally recognised safeguard or derogation.

Where appropriate, we assess the relevant transfer risks and apply supplementary contractual, organisational or technical safeguards.

Information about the applicable safeguard may be requested, subject to necessary confidentiality and security redactions.

Article 13 — How we protect personal data

XTROVERSO applies technical and organisational measures proportionate to the nature of the information and the relevant risks.

Depending on the system and processing activity, these measures include:

  • role-based access;
  • individual user accounts;
  • multi-factor authentication where supported;
  • encryption in transit and, where appropriate, at rest;
  • controlled backups;
  • access and security logging;
  • update and vulnerability management;
  • confidentiality obligations;
  • supplier assessment;
  • incident-response procedures;
  • separation of client environments or access rights;
  • periodic review of permissions.

Access is limited to persons who need the information for an authorised operational, professional, security or legal purpose.

No digital environment can be guaranteed to be entirely without risk. Security therefore requires continuing review, not a one-time statement.

Article 14 — Personal-data breaches

A suspected personal-data breach is assessed through the applicable incident procedure.

Where XTROVERSO acts as processor, the relevant Client will be informed without undue delay in accordance with the DPA.

Where XTROVERSO acts as controller, it will assess whether notification to the Autoriteit Persoonsgegevens is required and whether affected individuals must be informed.

Where required, notification to the supervisory authority will be made within the period prescribed by the GDPR.

Information about an incident may be limited where disclosure would create a further security risk, interfere with an investigation or breach a legal obligation.

Article 15 — Automated processing and human review

XTROVERSO may use automated tools to assist with:

  • document recognition;
  • transaction matching;
  • classification;
  • duplication detection;
  • security monitoring;
  • sanctions or verification screening;
  • workflow and deadline identification.

An automated flag is an indication for review, not a conclusion about a person.

XTROVERSO does not make decisions based solely on automated processing that produce legal effects or similarly significant consequences for an individual, unless a lawful basis and the safeguards required by Article 22 GDPR apply.

Where appropriate, a person can request human review, provide additional information and challenge the outcome.

Article 16 — Your rights

Subject to the conditions and exceptions in applicable law, you may have the right to:

  • obtain information about the processing;
  • access your personal data;
  • correct inaccurate or incomplete data;
  • request deletion;
  • request restriction of processing;
  • object to processing based on legitimate interests;
  • receive certain data in a portable format;
  • withdraw consent;
  • object to direct marketing;
  • request human intervention in qualifying automated decisions;
  • lodge a complaint with a supervisory authority.

A request may be sent to:

privacy@xtroverso.com

Please describe the request and the processing activity concerned as clearly as possible.

We may request proportionate information to verify identity. That information will be used only to prevent unauthorised access or alteration.

We normally respond within one month. Where a request is complex or multiple requests have been submitted, the response period may be extended by up to two further months. If an extension is required, the individual will be informed within the first month.

A request is normally handled without charge. A reasonable fee may be charged, or action may be refused, where a request is manifestly unfounded or excessive, as permitted by law.

A right may be restricted where this is necessary to protect the rights of another person, confidential business information, legal privilege, security, fraud prevention or a binding legal obligation. Any restriction will be explained where legally permitted.

Article 17 — What we do not do

XTROVERSO does not sell personal data.

We do not make Client-controlled bookkeeping or payroll data available for unrelated advertising.

We do not use personal data for an incompatible purpose merely because the information is technically accessible.

We do not use unnecessary medical diagnoses for routine payroll processing.

We do not treat a sanctions, verification or automated-system match as conclusive without appropriate review.

We do not knowingly use confidential Client Materials to train a publicly available artificial-intelligence model without an appropriate legal basis and contractual protection.

We do not retain information indefinitely without an identified purpose.

Article 18 — Children

XTROVERSO's website and services are intended for businesses and professional relationships. They are not directed at children.

Information about minors may appear in payroll or other statutory records only where supplied by an authorised Client and where processing is necessary and lawful.

Article 19 — Cookies

The website uses essential technologies required for security, navigation and operation.

Optional analytics, preference or marketing cookies are governed by the Cookie Policy and the cookie-preference mechanism. Where consent is required, those technologies should not be activated before a valid choice has been made.

Cookie consent can be withdrawn or changed through the available preference settings.

Article 20 — Complaints

If you believe that XTROVERSO has not respected your data-protection rights, please contact us first so that the matter can be investigated.

You may also lodge a complaint with the Dutch supervisory authority:

Autoriteit Persoonsgegevens

Submit a privacy complaint: https://www.autoriteitpersoonsgegevens.nl/en/contact-dutch-dpa/contact-the-dutch-dpa/submit-a-privacy-complaint

A complaint to XTROVERSO does not limit the right to contact a supervisory authority or seek a judicial remedy.

Where XTROVERSO acts only as processor, the complaint may need to be handled by the relevant Client as controller. We will assist that Client where required by the DPA.

Article 21 — Amendments

This statement may be amended to reflect changes in law, systems, services or processing activities.

A new version does not retrospectively create a legal basis for processing that was unlawful when it occurred.

Material changes will be communicated through an appropriate channel where reasonably possible. The publication date and version will be shown on this page.

Version 3.0

Last updated: 23 August 2026

Article 22 — Questions about privacy

Questions should be directed to:

privacy@xtroverso.com

Privacy is not demonstrated by promising that information is safe. It is demonstrated by knowing why the information exists, who may access it, how long it remains necessary and who remains responsible at every stage.

XTROVERSO™

Company-control framework and integrated fiscal services for sole proprietors and B.V.s in the Netherlands.

XTROVERSO is a registered trade name of WIGEPA B.V. Defined fiscal and professional services are performed by Pavan Geraedts Adviseurs under its own professional responsibility.

  • 2017-26  © XTROVERSO 
    KvK: 70402787
    BTW: NL858307790B01
    BECON: 685811

Ontdek
  • Over ons
  • Kennis
  • Contact
  • Veelgestelde vragen
  • WERK MET ONS
  • PERS
    Plan uw intake
  • Klantlogin
Diensten
  • Werkafbakening
  • How XTROVERSO Works
  • Book Your Intake
Kader

How XTROVERSO Works
Why XTROVERSO Is Different
Framework & Controls
Verification & Compliance Checks
Cultural Manifesto

Juridisch

Algemene voorwaarden
Data- & privacyverklaring
Cookiebeleid

Office
De Stuwdam 33
3815 KM Amersfoort
The Netherlands

Open map

Website Logo

Uw privacy respecteren is onze prioriteit.

Cookies van deze website op deze browser toestaan?

We gebruiken cookies om een verbeterde ervaring op deze website te bieden. Je kunt meer leren over onze cookies en hoe we ze gebruiken in onze Cookiebeleid.

Sta alle cookies toeSta alleen essentiële cookies toe