Privacy policy

Last updated: 20 August 2026

Driftwork.ai, based at Duindoornstraat 6, 2211 PK Noordwijkerhout, the Netherlands (Chamber of Commerce 42083265), is the controller for the processing of personal data described in this policy.

Contact

Email: hallo@driftwork.ai
Website: https://driftwork.ai

What we process

We process personal data because you use our website and because you provide it yourself through the contact form, the newsletter signup, email or phone:

  • First and last name
  • Company name
  • Business email address and phone number
  • The content of our correspondence
  • Newsletter data: email address, the page you signed up from, when you subscribed and unsubscribed, and whether a message was opened
  • IP address and technical browser data (pseudonymised through salted hashing)

Why we need it

  • To contact you when you ask us to
  • To deliver our services
  • To send the newsletter you deliberately signed up for (double opt-in)
  • To make affiliate links work reliably and produce aggregated click statistics
  • To meet legal obligations such as our financial records

Shop and orders

When you buy a digital product in our shop we also process: your email address, company name, billing address and VAT number, what you bought and for how much, and the confirmation that you are buying as a business (including the text you ticked, its version, the timestamp and a salted hash of your IP address). We also record when a file was downloaded.

The legal bases: performance of the contract for delivery and support, a legal obligation for invoicing and VAT records, and a legitimate interest for recording the business confirmation and the download log. We need the last one to be able to show that a sale was a business sale (no consumer cooling-off period applies then) and to spot misuse of download links.

Payment runs through Stripe Payments Europe. We never see your card or bank details. Stripe performs automated fraud scoring (Stripe Radar) that can decline a payment. If you are declined and believe that is wrong, email us and a human will look at it.

Processors involved in an order: Stripe (payment and invoicing), Supabase (database and file storage, EU region), Cloudflare (hosting and protection) and Resend (sending the order and delivery emails). We have a data processing agreement with each of them.

Newsletter

Signing up uses double opt-in: you first receive a confirmation email and are only added to the list after you click. Every message contains a working one-click unsubscribe link. Unsubscribed addresses are kept on a suppression list so we do not contact you again by accident.

Affiliate links

Some links in our articles (marked aff) are affiliate links. If you buy through one, we receive a commission and you pay nothing extra. We use short internal links (/go/slug) that redirect you to the partner. On that redirect we record an aggregated click: the timestamp, the internal link slug, the referring page, the user-agent string and a salted hash derived from your IP address. We do not store the IP address itself, and the hash is one way and cannot be traced back to a person.

How long we keep it

Contact form enquiries: up to 24 months, unless the law requires longer. Customer relationship data: in line with our record-keeping obligations, as a rule 7 years.

Order data, invoices and VAT records: 7 years, the retention period required by article 52 of the Dutch General Tax Act. The business confirmation belongs to that order and is kept just as long, because that is exactly the period in which it could still be disputed. Download logs: 24 months.

Sharing with others

We only share your data with parties that help us deliver our services, such as our email provider. We have a data processing agreement with each of them.

Cookies

We use functional cookies and similar techniques needed to make forms and the newsletter signup work. Through the cookie bar we ask your consent for statistics and marketing cookies (Google Tag Manager, Google Analytics and advertising platforms such as Google Ads, Meta and LinkedIn). Without your consent those stay off. You can revisit your choice by clearing this site's stored data in your browser; the cookie bar then reappears. Following an affiliate link does not set a cookie on your device. That only happens at the partner after you are redirected.

Advertising measurement and hashed email addresses

If you consented to marketing on the cookie bar, we measure which ad led to your enquiry or purchase. As part of that we send Google Ads and Meta an irreversibly encrypted (hashed) version of your email address. Your address itself never leaves our systems in readable form: a hash only works one way and cannot be turned back. The recipient can only use it to check whether it matches one of their own logged-in users, so that a click and a conversion can be tied together. Google calls this "enhanced conversions", Meta calls it the "Conversions API".

The legal basis is your consent (article 6(1)(a) GDPR). If you do not give it, none of this happens: without consent the marketing tags stay off and we send nothing. You can withdraw consent at any time by clearing this site's stored data in your browser, after which the cookie bar reappears. We do not sell your data and do not use it to build profiles with third parties beyond measuring our own campaigns.

Your rights

You have the right to access, correct, delete and port your personal data, and to object to processing. Email hallo@driftwork.ai. You also have the right to lodge a complaint with the Dutch Data Protection Authority (autoriteitpersoonsgegevens.nl).

Security

We take appropriate technical and organisational measures to protect your data. See something that is not right? Email us straight away.