FREE Pipeline Signal Scan: see the opportunities in your market. Get my scan →

Version February 2026

Privacy Policy

What we do with personal data: yours, and that of the people we contact for our clients.

This policy explains what we do with personal data: yours as a visitor to this website, and that of the people we contact on behalf of our clients. It is written to be read, not to be survived.

1. Who we are

Blackorange Solutions, Herengracht 142, Amsterdam, the Netherlands. Chamber of Commerce 32078880. VAT NL001974729B46. Email: administratie@blackorange.nl.

For the data described in sections 3 to 6 we are the controller: we decide what is collected and why. For campaigns we run for a client, the client is the controller and we act as processor on their instructions (section 7).

2. This website does not track you

We use no cookies, no advertising pixels and no cross-site tracking. Fonts are served from our own servers, so nothing about your visit is sent to a font provider. There is no cookie banner because there is nothing to consent to.

Our hosting provider keeps short-lived technical logs (IP address, page requested, time, browser type) to deliver the site and defend against abuse. These are deleted within 30 days. Our legitimate interest in a working, secure website is the basis for this.

We measure visits with privacy-friendly analytics that store no cookies, record no IP addresses and do not follow you between sites. The result is a count of pages and referrers, not a profile of a person.

3. When you book a call

You give us your name, email address and timezone. We use them to schedule the call, send you a confirmation and calendar invitation, remind you the day before, and follow up afterwards. An internal notification goes to the person hosting the call.

The basis is that these are steps taken at your request before entering into an agreement, and our legitimate interest in following up on a meeting you asked for.

We keep this data for 24 months after our last contact, unless we become clients and suppliers of each other, in which case tax law requires us to keep the records for seven years.

4. When you request a Pipeline Signal Scan or other resource

For a Pipeline Signal Scan you give us your website, your email address, what you sell, who you want to reach and where, and optionally your first name and an example of an ideal customer. We use this to research your target market, prepare your personal report, deliver it to you, and answer any questions you send us about it.

To prepare the report we study public information about companies in the market you describe, such as news, announcements, hiring and public company profiles. Reports focus on companies and business roles. AI tools help us research and draft the report, and a person reviews and approves it before it is sent (section 8).

Your request is recorded in our CRM, and we are notified internally when it arrives. We send you the report and nothing else by default: no newsletter and no automated follow-up sequence. If we ever offer a newsletter, you will only receive it if you sign up for it separately.

Your report is published at a private link that is not listed or indexed anywhere. Anyone who has the link can open it, so share it as you would a private document.

The basis is your request: preparing and delivering what you asked for (Article 6(1)(b) GDPR), and our legitimate interest in answering follow-up questions about it. We keep your request and report for 24 months after your last interaction. After that, or earlier if you ask, we delete them and the private link stops working.

5. When you email or message us

We keep the correspondence and the contact details in it for as long as needed to handle the matter and, where it concerns an agreement, for as long as our administration requires.

6. Who we share data with

We never sell personal data.

We use service providers to do things we cannot do alone: hosting the website, sending and storing email, managing calendars, running our CRM, delivering outreach campaigns, internal notifications, secure file storage and AI research tools. They act on our instructions under a written data processing agreement and may not use the data for their own purposes. The current list of providers is available on request.

Some providers are established outside the European Economic Area, mainly in the United States. Where that is the case, transfers are covered by the European Commission's standard contractual clauses or an adequacy decision.

We also disclose data where the law requires it.

7. Prospect data in client campaigns

On behalf of our clients we identify and contact companies that are likely to benefit from what the client sells. For this we process business contact data: name, role, employer, business email address, business phone number, public professional profile and publicly available information about the company.

This data comes from public sources and from specialist business-data providers. The basis is legitimate interest in business-to-business communication under Article 6(1)(f) GDPR. For campaigns run on a client's instructions the client is the controller and we act as processor under a data processing agreement.

Anyone we contact can object at any time, by replying or by using the unsubscribe link. We add them to a suppression list, which exists to make sure they are not contacted again. Prospect data is deleted within 90 days after a campaign ends, unless otherwise agreed in writing or required by law.

To exercise your rights regarding a message you received from us, email administratie@blackorange.nl. If the campaign was run for a client, we will pass the request to them and act on their instructions.

8. How we use AI

We use artificial intelligence as a tool in our work, and we would rather say so than leave you guessing.

  • Research and analysis. AI systems help us read public market information, spot changes worth acting on and summarise what we find.
  • Drafting. AI systems help us draft outreach copy, content and reports. A person reviews and approves everything before it is sent or published.
  • No automated decisions. We make no decision that produces legal effects for you, or similarly significantly affects you, by automated means alone. A person decides who is contacted and what is offered.
  • No training on your data. We do not make client data, prospect data or the contents of your messages available to third-party AI providers for training their models. Where we use AI tools, we use settings and agreements that exclude such use.
  • AI-assisted images on this site. Some illustrations on this website were created with AI and reviewed, edited and approved by a person before publication.
  • If you are ever talking to an AI assistant on this site, it will say so.

These are our transparency commitments under the EU AI Act, which applies to the use of AI systems alongside the GDPR.

9. Security

We apply appropriate technical and organisational measures: access limited to those who need it, multi-factor authentication on the accounts that matter, encrypted connections, and providers selected in part on their security posture. No system is perfect; if a breach affects you, we will inform you as the law requires.

10. Your rights

You have the right to access your data, to have it corrected or deleted, to restrict or object to its use, and to receive it in a portable form. Where we rely on consent, you can withdraw it at any time.

Email administratie@blackorange.nl. We answer within one month. You also have the right to complain to the Dutch data protection authority, the Autoriteit Persoonsgegevens (autoriteitpersoonsgegevens.nl).

11. Changes to this policy

We update this policy when what we do changes. The version and date are at the top of this page, and previous versions are available on request.