Privacy Policy
Last updated: 23 September 2026
This privacy policy explains how SPEYS Food Science Consultancy (“SPEYS”, “we”, “us” or “our”) handles personal data when you visit speysfsc.com or contact us through the website.
Who is responsible for your data?
SPEYS Food Science Consultancy is the controller for the personal data described in this policy. You can contact us at info@speysfsc.com or by telephone on +31 (0)6 29043593.
What data do we collect?
When you contact us
The contact form asks for your first and last name, email address, message and confirmation that you agree to be contacted. We use this information only to respond to your enquiry, discuss possible work and continue any resulting business relationship.
The form is provided by WPForms. Completed form entries are not stored as entries in the WordPress database; they are sent to SPEYS by email. The form also uses technical anti-spam measures, which may process information such as your IP address, browser details and submission time.
When you visit the website
Like most websites, our server records limited technical information needed to deliver and protect the site. This can include your IP address, requested page, date and time, browser or user-agent information, referring page and the outcome of the request. We use this information to operate the site, diagnose faults and detect malicious or abusive activity.
Our legal bases
Depending on the circumstances, we process personal data because:
- you have consented to us contacting you;
- it is necessary to respond to your request or take steps before entering into a contract;
- we have a legitimate interest in operating, securing and improving a reliable business website; or
- we need to comply with a legal obligation or establish, exercise or defend legal claims.
Where we rely on consent, you may withdraw it at any time by contacting us. Withdrawal does not affect processing that was lawful before withdrawal.
Cookies and analytics
At the date of this policy, the public website does not use advertising cookies or active analytics tracking, and an ordinary anonymous visit does not set a cookie. Functional WordPress cookies may be used for authorised administrators or where technically necessary for security and site operation.
Google Analytics support is installed but is not configured to collect visitor analytics. If analytics or other non-essential tracking is enabled in future, we will update this notice and request consent where required before that tracking begins.
Service providers
We use a small number of providers to operate the site:
- DigitalOcean hosts the website in its Amsterdam region and processes server traffic on our behalf. See DigitalOcean’s privacy policy.
- SMTP2GO transmits contact-form emails to SPEYS. SMTP2GO states that email headers, and limited message samples used for anti-abuse purposes, may be retained for up to 35 days. See SMTP2GO’s privacy policy.
- Google Fonts supplies some of the typefaces displayed by the site. Your browser connects to Google’s servers to retrieve these files, which discloses technical request information such as your IP address and browser details to Google. See Google’s privacy policy.
- Trusted website maintenance providers may access limited site or server information when necessary to maintain, secure or repair the website.
We do not sell personal data. We disclose it only to the providers needed to operate the website, to professional advisers where necessary, or to public authorities where required by law.
International transfers
Some providers are based outside the European Economic Area or may use international support operations. Where personal data is transferred internationally, we expect the relevant provider to use an appropriate legal safeguard, such as an adequacy decision, the EU-US Data Privacy Framework where applicable, or Standard Contractual Clauses.
How long do we keep data?
- Enquiry emails are kept only as long as reasonably necessary to answer and follow up the enquiry. If an enquiry leads to a client relationship, relevant correspondence may be kept for the relationship and for any applicable tax, contractual or legal record-keeping period.
- Routine web-server request logs are normally rotated within approximately 14 days. Security and authentication logs are normally rotated within approximately four weeks, although information relating to an active security incident may be retained for longer.
- SMTP2GO states that email headers and its limited anti-abuse samples are retained for 35 days.
- Restricted recovery backups are retained only as needed for continuity and are deleted or superseded through the backup cycle.
Your rights
Under the GDPR, depending on the circumstances, you may ask us to:
- give you access to your personal data;
- correct inaccurate or incomplete data;
- delete your data;
- restrict or object to processing;
- provide data you supplied in a portable format; or
- honour a withdrawal of consent.
To exercise a right, email info@speysfsc.com. We may need to verify your identity before acting on a request. You may also complain to the Dutch supervisory authority, the Autoriteit Persoonsgegevens.
Security
We use reasonable technical and organisational measures to protect the website and personal data. These include encrypted HTTPS connections, restricted administrative access, maintained software, firewall controls, login-abuse protection and access-controlled backups. No internet service can guarantee absolute security.
Automated decisions, marketing and children
We do not use website data for automated decision-making or profiling, and we do not use contact-form details for unrelated marketing without permission. This business website is not directed at children.
External links
The site links to third-party websites, including LinkedIn. Those sites apply their own privacy policies when you choose to visit them.
Changes to this policy
We may update this policy when the website or our processing changes. The date at the top shows the latest revision.