Privacy Policy
How CoolBerry handles website, client and project data
CoolBerry, registered with the Dutch Chamber of Commerce under number 42020889 and established in 's-Hertogenbosch, the Netherlands, is the controller for the processing described in this policy unless we process personal data solely on a client's documented instructions. This policy was last updated on July 21, 2026.
Controller and contact details
CoolBerry — KvK 42020889 — 's-Hertogenbosch, the Netherlands — [email protected] — coolberry.io. Requests and questions about privacy can be sent to [email protected]. Our business correspondence address is available on our invoices, agreements and Chamber of Commerce registration.
Article 1 — Personal data we process
Depending on how you interact with us, CoolBerry may process the following categories of personal data:
- Identity and contact data, including name, business email address, telephone number, company and role
- Enquiry, proposal, agreement, support and other business correspondence
- Billing, invoice, payment-status and legally required administration data
- Project briefs, brand assets, product information, feedback and revision history
- Images, video, audio, likenesses, voices and associated metadata supplied for a project
- Prompts, reference materials, generated variations, working files and approved deliverables
- IP address, browser, device type, approximate location, referral URL and website activity
- Analytics identifiers, cookie choices and similar technical identifiers
- Security signals and verification tokens used to protect forms from abuse
- Data received from a client, its authorised contacts, service providers or public business sources when relevant to an assignment
Article 2 — Sensitive data and children
Our website and services are directed to businesses and are not intended for children under 16. We do not intentionally request special-category data. Clients must avoid supplying unnecessary sensitive data and must have the required lawful basis, notices and permissions for identifiable people, likenesses and voices included in project materials. If you believe that a child's or other sensitive data has been supplied improperly, contact [email protected] so that we can assess and, where appropriate, delete or restrict it.
Article 3 — Purposes and legal bases
We process personal data only where a legal basis applies. The principal purposes and bases are:
- Answering enquiries and preparing proposals — steps requested before entering into a contract and our legitimate interest in business communication
- Providing, managing and supporting creative services — performance of the agreement or, for client-controlled data, the client's documented instructions
- Billing, payments, tax and business records — performance of the agreement and compliance with legal obligations
- Service messages and relationship management — performance of the agreement and our legitimate interest in maintaining client relationships
- Website, form and infrastructure security — our legitimate interest in preventing abuse, fraud and technical incidents
- Google Analytics and Microsoft Clarity website measurement — your consent, which can be withdrawn at any time
- Establishing, exercising or defending legal claims — our legitimate interests and compliance with legal obligations
- AI-assisted production using necessary project materials — performance of the agreement or processing on the client's documented instructions
CoolBerry does not use personal data to make solely automated decisions that produce legal or similarly significant effects. AI-assisted creative tools are used under human direction and review.
Article 4 — Retention
We retain personal data only for as long as necessary for the stated purpose, an agreement, security, support or a legal obligation. Our standard periods are:
- Enquiries that do not become assignments: up to 24 months after the last meaningful contact
- Client correspondence, project materials and working files: during the assignment and normally up to 24 months after completion, unless a different support or archive period is agreed
- Invoices and core accounting records: 7 years, or longer where a specific statutory period applies
- Cookie choices: 6 months, after which we ask again; analytics cookies and provider data follow the periods in Article 6 and the applicable account settings
- Data needed for complaints, disputes or legal claims: until the applicable claim or statutory limitation period has ended
Article 5 — Recipients and service providers
CoolBerry does not sell personal data. We share only the data reasonably necessary for the relevant purpose. Our current website-related recipients are:
- Cloudflare — website delivery, infrastructure, logging and Turnstile form protection
- Telegram — delivery and handling of website contact-form messages by the CoolBerry team
- Resend — transactional email, including contact-form confirmations
- Google — Tag Manager and Analytics, loaded only after analytics consent
- Microsoft — Clarity heatmaps and session analytics, loaded only after analytics consent
- Approved creative, AI, cloud-storage and professional-service providers where necessary for an assignment. Relevant providers and subprocessors can also be specified in the agreement or data processing agreement.
Article 6 — Cookies and similar technologies
Strictly necessary storage and security technology may operate without consent. Google Analytics, Google Tag Manager and Microsoft Clarity are loaded only after you accept analytics. You can change your choice through Cookie settings in the footer. Withdrawing consent stops future analytics loading, sends available withdrawal signals and removes the site's accessible first-party analytics cookies; your browser may also be used to clear remaining third-party storage.
Technology we use
| Source / name | Purpose | Retention period |
|---|---|---|
| CoolBerry — cookie_consent (local storage) | Strictly necessary record of whether analytics was accepted or rejected. | 6 months |
| Google Analytics — _ga | Pseudonymous identifier used to distinguish visitors for website measurement. Consent required. | Up to 2 years, subject to browser and account settings |
| Google Analytics — _ga_<property-id> | Maintains pseudonymous session state for website measurement. Consent required. | Up to 2 years, subject to browser and account settings |
| Google Tag Manager | Loads and manages approved analytics tags after consent; it does not itself require a separate analytics cookie. | No separate cookie |
| Microsoft Clarity — _clck and _clsk | Pseudonymous visitor, heatmap and session-recording analytics. Consent required; sensitive page content should be masked by the provider's controls. | _clck up to 1 year; _clsk about 1 day |
| Cloudflare Turnstile | Strictly necessary browser and security signals plus a short-lived verification token to protect forms from bots and abuse. | Verification token up to 5 minutes; security storage varies by challenge/configuration |
Provider-controlled names and durations can change. We review this inventory periodically and apply the settings available to us.
Article 7 — Your rights
Subject to the GDPR's conditions and exceptions, you may request access, correction, deletion, restriction of processing or data portability, and you may object to processing. You may withdraw consent at any time without affecting processing that was lawful before withdrawal.
Send a request to [email protected]. We may ask for proportionate information to verify your identity and protect your data. Requests are normally free of charge.
We respond without undue delay and normally within one month. Where the GDPR permits an extension because of complexity or the number of requests, we will notify you within the first month. You may lodge a complaint with the Dutch Data Protection Authority (Autoriteit Persoonsgegevens) or another competent supervisory authority.
Article 8 — Security
CoolBerry applies risk-appropriate technical and organisational measures designed to prevent loss, misuse, unauthorised access, disclosure and alteration. No internet or storage system is completely secure. Please report suspected misuse to [email protected].
- TLS encryption protects data transmitted between your browser and the website
- Access to client and contact data is restricted to people and providers who need it for their role
- Data minimisation, retention reviews and deletion are used to reduce unnecessary storage
- Service-provider, account and software security controls are reviewed in proportion to the data and risk
Article 9 — Client materials and AI-assisted production
CoolBerry combines human creative direction with generative AI, editing software, cloud services and other production tools. Personal data in client materials is handled as follows:
- Only materials reasonably necessary for the agreed assignment should be submitted to a production provider
- Where CoolBerry acts solely on the client's documented instructions, the client is the controller and CoolBerry is the processor; a data processing agreement will be used where required
- Providers are selected and configured with regard to confidentiality, data use, retention, security and international-transfer terms; project-specific restrictions must be agreed before materials are supplied
- Clients must have the rights and legal basis needed for identifiable people, images, voices and other personal data they provide
Article 10 — International transfers
Some providers or their support operations may process data outside the European Economic Area. Where GDPR transfer rules apply, CoolBerry uses an available lawful transfer mechanism and assesses the provider in proportion to the risk.
- An adequacy decision may be relied on where the European Commission has recognised the destination or applicable framework
- Where appropriate, European Commission standard contractual clauses and supplementary safeguards are used
- Information about the applicable safeguard or how to obtain a copy can be requested through [email protected], subject to confidential information being protected
Article 11 — Sources and required information
We normally receive data directly from you or from the business client that engages us. We may also receive business-contact or project information from authorised colleagues, providers or public business sources.
- Contact-form name, email, message and security verification are required to submit an enquiry and protect the form
- Contract, billing and project information may be required to enter into and perform an agreement or meet legal obligations
- If required information is not provided, we may be unable to answer an enquiry, verify a request, enter into an agreement or deliver the requested service
Article 12 — Changes and questions
We may update this policy when our services, providers or legal obligations change. The date at the top identifies the latest version. Material changes will be communicated through an appropriate channel. Questions, rights requests and complaints may be sent to [email protected].