Privacy policy
Last updated: 4 October 2026
Driftwork.ai, based at Duindoornstraat 6, 2211 PK Noordwijkerhout, the Netherlands (Chamber of Commerce 42083265), is the controller for the processing of personal data described in this policy.
Contact
Email: hallo@driftwork.ai
Website: https://driftwork.ai
What we process
We process personal data because you use our website and because you provide it yourself through the contact form, the newsletter signup, email or phone:
- First and last name
- Company name
- Business email address and phone number
- The content of our correspondence
- Newsletter data: email address, the page you signed up from, when you subscribed and unsubscribed, and whether a message was opened
- IP address and technical browser data (pseudonymised through salted hashing)
Why we need it
- To contact you when you ask us to
- To deliver our services
- To send the newsletter you deliberately signed up for (double opt-in)
- To make affiliate links work reliably and produce aggregated click statistics
- To meet legal obligations such as our financial records
Shop and orders
When you buy a digital product in our shop we also process: your email address, company name, billing address and VAT number, what you bought and for how much, and the confirmation that you are buying as a business (including the text you ticked, its version, the timestamp and a salted hash of your IP address). We also record when a file was downloaded.
The legal bases: performance of the contract for delivery and support, a legal obligation for invoicing and VAT records, and a legitimate interest for recording the business confirmation and the download log. We need the last one to be able to show that a sale was a business sale (no consumer cooling-off period applies then) and to spot misuse of download links.
Payment runs through Stripe Payments Europe. We never see your card or bank details. Stripe performs automated fraud scoring (Stripe Radar) that can decline a payment. If you are declined and believe that is wrong, email us and a human will look at it.
An order involves Stripe (payment and invoicing), Supabase (database and file storage), Cloudflare (hosting and protection) and Resend (sending the order and delivery emails). What goes to each of them is set out below under Who else sees your data.
Newsletter
Signing up uses double opt-in: you first receive a confirmation email and are only added to the list after you click. Every message contains a working one-click unsubscribe link. Unsubscribed addresses are kept on a suppression list so we do not contact you again by accident.
Affiliate links
Some links in our articles (marked aff) are affiliate links. If you buy through one, we receive a commission and you pay nothing extra. We use short internal links (/go/slug) that redirect you to the partner. On that redirect we record an aggregated click: the timestamp, the internal link slug, the referring page, the user-agent string and a salted hash derived from your IP address. We do not store the IP address itself, and the hash is one way and cannot be traced back to a person.
How long we keep it
Contact form enquiries: up to 24 months, unless the law requires longer. Customer relationship data: in line with our record-keeping obligations, as a rule 7 years.
Order data, invoices and VAT records: 7 years, the retention period required by article 52 of the Dutch General Tax Act. The business confirmation belongs to that order and is kept just as long, because that is exactly the period in which it could still be disputed. Download logs: 24 months.
Member area, support and the AI assistant
If you have an account in the member area we also process your account data (username, role, sign-in times and whether two-factor authentication is on), the support tickets you open including everything you write in them, and the messages you send to the AI assistant.
That AI assistant does not run on our own machines but at an external supplier. What goes there is: your question, up to twenty earlier messages from the same conversation, and the data the assistant pulls in about the company that conversation is about. To find the right fragments in our knowledge base, your question also goes to a second supplier that turns text into vectors; no name or email address is included. Both are named below. Your questions and the data around them are not used to train models.
Who else sees your data
Below are all the external parties that may process personal data when you use this site or are a customer of ours. The list was established on 22 September 2026 by walking our own server code for every outbound call, not written down from memory. If a party is not listed, nothing goes there. We have a data processing agreement with each of them.
Platform
- Cloudflare (Cloudflare, Inc.). Hosting of the site and the server code, CDN, protection and request logs. What goes there: All traffic to driftwork.ai and its subdomains: IP address, user agent, requested path and the content of every request and response. Logging runs at full sampling. Where: Global network, processed at the edge location serving the visitor. Transfer: Standard contractual clauses.
- Supabase (Supabase, Inc.). Database, authentication and file storage. What goes there: The customer register with contacts and email addresses, user accounts, support tickets and their contents, orders and invoices, runs, proposals and changes, and the files the machine delivers. Where: Project region as configured in Supabase. Transfer: Standard contractual clauses.
Language models and embeddings
- Anthropic (Anthropic PBC). The language model behind the AI assistant, the blog drafts and the niche proposals. What goes there: The question the user asks, up to twenty earlier messages from the same conversation, and what the read tools return about the customer that conversation is about: overview, log, connections, intake, subscription and open proposals. The blog feature sends no customer data, only the selected news item. Where: United States. Transfer: Standard contractual clauses.
- Voyage AI (Voyage AI, Inc.). Turning text into vectors so the assistant can find the right knowledge base fragments. What goes there: The user's question verbatim, and when the knowledge base is filled, the text of every article fragment. No name, email address or account number is included. Where: United States. Transfer: Standard contractual clauses.
- Resend (Resend, Inc.). Sending all email, and delivering inbound support mail into the ticket. What goes there: Sender, recipient, subject and the full content of the message. That includes order confirmations, download links, approval requests, support replies and the newsletter. Where: United States. Transfer: Standard contractual clauses.
Payments
- Stripe (Stripe Payments Europe, Limited). Checkout in the shop, invoicing, VAT determination and subscriptions. What goes there: Email address, company name, billing address, VAT number, what was bought and for how much. Card or bank details are entered at Stripe and never reach us. Where: Ireland, with Stripe, Inc. in the United States as its own subprocessor. Transfer: Standard contractual clauses.
- Mollie (Mollie B.V.). Payment events. Today only the door is open: a signed notification in, and a check back whether that notification really exists. What goes there: The id and the type of a payment event. No checkout runs through Mollie today, so no buyer or invoice data goes there yet. Where: The Netherlands.
Measurement and advertising
- Google Analytics en Google Tag Manager (Google Ireland Limited). Statistics about site usage, and the container that holds the tags. What goes there: The GA4 client_id from the _ga cookie, the session id, the event name and its parameters (amount, currency, transaction number). From the server this goes through the Measurement Protocol. Where: Ireland, with transfer to the United States. Transfer: EU-US Data Privacy Framework, supplemented with standard contractual clauses. Only after consent on the cookie bar, category statistics.
- Google Ads (Google Ireland Limited). Measuring which ad led to an enquiry or purchase. What goes there: An irreversibly hashed email address and the event itself. The tags load through the tag container in the browser. Where: Ireland, with transfer to the United States. Transfer: EU-US Data Privacy Framework, supplemented with standard contractual clauses. Only after consent on the cookie bar, category marketing.
- Meta (Meta Platforms Ireland Limited). Measuring enquiries and purchases that come from an ad, through the Conversions API and the pixel. What goes there: An irreversibly hashed email address, Meta's own fbp and fbc identifiers, the user agent, the order number as event id and the amounts attached to that event. Where: Ireland, with transfer to the United States. Transfer: EU-US Data Privacy Framework, supplemented with standard contractual clauses. Only after consent on the cookie bar, category marketing.
- LinkedIn (LinkedIn Ireland Unlimited Company). Ad measurement through the Insight Tag. What goes there: Only in the browser, and only after consent: the page visit, the IP address and the browser data LinkedIn collects itself. Nothing goes to LinkedIn from our server. Where: Ireland, with transfer to the United States. Transfer: EU-US Data Privacy Framework, supplemented with standard contractual clauses. Only after consent on the cookie bar, category marketing.
Delivering the work
- n8n Cloud (n8n GmbH). This is where the marketing machine's workflows run. What goes there: Per assignment we send only the customer name, the module, the type of work, the run number and the contract version. n8n then pulls the customer profile through our machine API: the intake data, the settings, the connections and the email addresses that reports and approval requests go to. Where: Germany.
- Google Ads API (Google Ireland Limited). Operating the customer's advertising account on the customer's behalf. What goes there: We exchange the customer's stored access key for a short-lived access token. The advertising account number and the ad data behind it live at Google; they already did, because it is the customer's own account. Where: Ireland, with transfer to the United States. Transfer: EU-US Data Privacy Framework, supplemented with standard contractual clauses.
- GitHub (GitHub, Inc.). The publish button: which commit is live, and starting a publication. What goes there: No customer data. What passes through is the content of this repository, commit messages and the status of publication runs. Where: United States. Transfer: Standard contractual clauses.
Embedded media
- YouTube, Vimeo en Mux (Google Ireland Limited, Vimeo.com, Inc. en Mux, Inc.). Video players in courses and on a single case page. What goes there: Only once a visitor starts a video: the IP address and the browser data the player collects itself. We load YouTube through its no-cookie domain. Where: Ireland and the United States. Transfer: Standard contractual clauses.
The same list, with the explanation next to it, is published at driftwork.ai/subverwerkers (in Dutch). If you work with us as an agency or as a client, that list is an annex to our data processing agreement, and you get ten working days to object when a party is added.
Cookies
We use functional cookies and similar techniques needed to make forms and the newsletter signup work. Through the cookie bar we ask your consent for statistics and marketing cookies (Google Tag Manager, Google Analytics and advertising platforms such as Google Ads, Meta and LinkedIn). Without your consent those stay off. You can revisit your choice by clearing this site's stored data in your browser; the cookie bar then reappears. Following an affiliate link does not set a cookie on your device. That only happens at the partner after you are redirected.
Advertising measurement and hashed email addresses
If you consented to marketing on the cookie bar, we measure which ad led to your enquiry or purchase. As part of that we send Google Ads and Meta an irreversibly encrypted (hashed) version of your email address. Your address itself never leaves our systems in readable form: a hash only works one way and cannot be turned back. The recipient can only use it to check whether it matches one of their own logged-in users, so that a click and a conversion can be tied together. Google calls this "enhanced conversions", Meta calls it the "Conversions API".
The legal basis is your consent (article 6(1)(a) GDPR). If you do not give it, none of this happens: without consent the marketing tags stay off and we send nothing. You can withdraw consent at any time by clearing this site's stored data in your browser, after which the cookie bar reappears. We do not sell your data and do not use it to build profiles with third parties beyond measuring our own campaigns.
Your rights
You have the right to access, correct, delete and port your personal data, and to object to processing. Email hallo@driftwork.ai. You also have the right to lodge a complaint with the Dutch Data Protection Authority (autoriteitpersoonsgegevens.nl).
Security
We take appropriate technical and organisational measures to protect your data. See something that is not right? Email us straight away.
