Privacy statement Bumicom Telecommunicatie BV

Privacy Statement Bumicom Telecommunicatie BV

Last updated: September 2026

Bumicom Telecommunicatie BV (“Bumicom”) attaches great importance to the protection of personal data. This privacy statement explains which personal data we process, the purposes for which we process it, the legal bases on which we rely and the rights you have.

1. Who is responsible for your personal data?

For the processing activities covered by this privacy statement, the controller is generally:

Bumicom Telecommunicatie BV Laan van Waalhaven 480 2497 GR The Hague The Netherlands

Telephone: +31 (0)70 350 4500 Email: privacy@bumicom.nl Website: www.bumicom.nl

In certain situations, Bumicom processes personal data on behalf of a customer. In those situations, the customer is the controller and Bumicom acts as a processor. The applicable arrangements are set out in a data processing agreement or other relevant contractual terms.

2. What personal data do we process?

The personal data we process depends on your relationship with Bumicom and the services you use. It may include:

  • name and contact details, such as address, telephone number and email address;
  • organisation, job title and business contact details;
  • information you provide through our website, contact forms, email or telephone;
  • customer, contract, order, invoice and payment information;
  • information relating to service, support and maintenance requests;
  • technical information, such as IP address, device and browser information and log data;
  • information relating to suppliers and other business contacts;
  • information relating to applicants and employees where Bumicom carries out separate processing for these purposes.

We do not process more personal data than is reasonably necessary for the relevant purpose.

Where Bumicom acts as a processor for a customer, other categories of personal data may be processed through our recording, messaging, quality monitoring, transcription and analytics solutions. The exact data processed is determined by the relevant customer as controller and by the services being used.

3. Why do we process personal data and what are our legal bases?

Bumicom may process personal data for purposes including:

  • responding to enquiries and contact requests;
  • preparing, entering into and performing agreements;
  • supplying, installing, managing and supporting our products and services;
  • providing service, support, maintenance and incident handling;
  • administration, invoicing and financial processing;
  • communicating with customers, suppliers, partners and other business contacts;
  • improving and securing our website, systems, products and services;
  • preventing and investigating misuse, security incidents and fraud;
  • marketing and maintaining business relationships where permitted by law;
  • complying with legal and administrative obligations.

Depending on the processing activity, we rely on one or more of the following legal bases under the GDPR:

  • processing is necessary for the performance of a contract or in order to take steps prior to entering into a contract;
  • processing is necessary to comply with a legal obligation;
  • processing is necessary for the legitimate interests of Bumicom or a third party, after balancing those interests against your interests, rights and freedoms;
  • you have given your consent to the processing.

Where processing is based on consent, you may withdraw your consent at any time. Withdrawal does not affect the lawfulness of processing carried out before your consent was withdrawn.

4. Bumicom as a processor

Bumicom provides solutions and services including recording, voice logging, messaging recording, quality monitoring, transcription and interaction/insights analytics.

In providing these services, Bumicom may process personal data on behalf of its customers. In these situations, the customer generally determines the purposes and means of the processing and is therefore the controller. Bumicom processes the personal data only in accordance with the applicable agreements and the customer's documented instructions.

If you have a question about personal data processed by an organisation using a Bumicom solution, you should generally contact that organisation first.

5. Who do we share personal data with?

Bumicom does not sell your personal data.

We may share personal data with other parties where this is necessary for our business operations or the provision of our services, for example IT, hosting, communications, administration or other service providers.

Where another party processes personal data on our behalf, we put appropriate privacy, security and confidentiality arrangements in place where required.

We may also disclose personal data where necessary to comply with a legal obligation, court order or lawful request from a competent authority.

6. Transfers outside the European Economic Area

Where personal data is processed or accessible outside the European Economic Area (EEA), we ensure that there is a valid basis for the transfer and, where required, appropriate safeguards in accordance with the GDPR.

For information about a specific transfer and the safeguards used, please contact privacy@bumicom.nl.

7. How long do we retain personal data?

We retain personal data no longer than necessary for the purpose for which it was collected, unless we are legally required to retain it for a longer period.

The applicable retention period depends on the type of data, the purpose of the processing, contractual arrangements and any statutory retention requirements.

Where Bumicom acts as a processor, retention periods are generally determined by the relevant customer and the agreements made with that customer.

8. How do we protect personal data?

Bumicom implements appropriate technical and organisational measures to protect personal data against loss, misuse, unauthorised access, unauthorised disclosure and unauthorised alteration.

Bumicom operates an Information Security Management System (ISMS) and is ISO/IEC 27001:2022 certified.

Depending on the relevant processing activity and service, our security measures include network and system security, encryption, secure connections, access controls and email security measures.

If you believe that personal data or Bumicom systems are not adequately secured, please contact privacy@bumicom.nl.

9. Cookies and similar technologies

Our website may use cookies and similar technologies that are necessary for its technical operation, security and ease of use. Depending on the current configuration of the website, analytical or other cookies may also be used.

Where consent is required before cookies or similar technologies can be used, we will request your consent in advance. Where available, you can change your choices through the website's cookie settings. You can also delete or block cookies through your browser.

10. Your privacy rights

Depending on the circumstances, the GDPR gives you rights including the right to:

  • access your personal data;
  • have inaccurate personal data corrected;
  • request deletion of your personal data;
  • request restriction of processing;
  • object to processing;
  • request data portability;
  • withdraw your consent;
  • object to direct marketing;
  • not be subject to a decision based solely on automated processing that produces legal effects or similarly significantly affects you, where this right applies.

You can submit a request by emailing privacy@bumicom.nl.

We may ask you to provide additional information where this is reasonably necessary to verify your identity. We will not request more personal data for this purpose than necessary.

We will generally respond to your request within one month. Where a request is complex or you have made several requests, this period may be extended in accordance with the GDPR. If so, we will inform you in good time.

11. Complaints

If you have a question or complaint about how we process your personal data, we encourage you to contact us first at privacy@bumicom.nl.

You also have the right to lodge a complaint with the competent supervisory authority. In the Netherlands, this is the Dutch Data Protection Authority (Autoriteit Persoonsgegevens).

More information is available at www.autoriteitpersoonsgegevens.nl.

12. Automated decision-making

As a controller, Bumicom does not make decisions about individuals based solely on automated processing that produce legal effects or otherwise significantly affect them, unless this is expressly stated and a valid legal basis exists.

Where Bumicom provides analytics or AI functionality to a customer as a processor, the relevant customer determines the purposes for which that functionality is used and the personal data processed.

13. Changes to this privacy statement

We may amend this privacy statement when changes to our services, business operations or applicable laws and regulations make this necessary.

The most recent version is always available at www.bumicom.nl/en/privacy. The date on which this statement was last updated is shown at the top.

Privacy statement Bumicom Telecommunicatie BV

Privacy Statement Bumicom Telecommunicatie BV

Last updated: September 2026

Bumicom Telecommunicatie BV (“Bumicom”) attaches great importance to the protection of personal data. This privacy statement explains which personal data we process, the purposes for which we process it, the legal bases on which we rely and the rights you have.

1. Who is responsible for your personal data?

For the processing activities covered by this privacy statement, the controller is generally:

Bumicom Telecommunicatie BV Laan van Waalhaven 480 2497 GR The Hague The Netherlands

Telephone: +31 (0)70 350 4500 Email: privacy@bumicom.nl Website: www.bumicom.nl

In certain situations, Bumicom processes personal data on behalf of a customer. In those situations, the customer is the controller and Bumicom acts as a processor. The applicable arrangements are set out in a data processing agreement or other relevant contractual terms.

2. What personal data do we process?

The personal data we process depends on your relationship with Bumicom and the services you use. It may include:

  • name and contact details, such as address, telephone number and email address;
  • organisation, job title and business contact details;
  • information you provide through our website, contact forms, email or telephone;
  • customer, contract, order, invoice and payment information;
  • information relating to service, support and maintenance requests;
  • technical information, such as IP address, device and browser information and log data;
  • information relating to suppliers and other business contacts;
  • information relating to applicants and employees where Bumicom carries out separate processing for these purposes.

We do not process more personal data than is reasonably necessary for the relevant purpose.

Where Bumicom acts as a processor for a customer, other categories of personal data may be processed through our recording, messaging, quality monitoring, transcription and analytics solutions. The exact data processed is determined by the relevant customer as controller and by the services being used.

3. Why do we process personal data and what are our legal bases?

Bumicom may process personal data for purposes including:

  • responding to enquiries and contact requests;
  • preparing, entering into and performing agreements;
  • supplying, installing, managing and supporting our products and services;
  • providing service, support, maintenance and incident handling;
  • administration, invoicing and financial processing;
  • communicating with customers, suppliers, partners and other business contacts;
  • improving and securing our website, systems, products and services;
  • preventing and investigating misuse, security incidents and fraud;
  • marketing and maintaining business relationships where permitted by law;
  • complying with legal and administrative obligations.

Depending on the processing activity, we rely on one or more of the following legal bases under the GDPR:

  • processing is necessary for the performance of a contract or in order to take steps prior to entering into a contract;
  • processing is necessary to comply with a legal obligation;
  • processing is necessary for the legitimate interests of Bumicom or a third party, after balancing those interests against your interests, rights and freedoms;
  • you have given your consent to the processing.

Where processing is based on consent, you may withdraw your consent at any time. Withdrawal does not affect the lawfulness of processing carried out before your consent was withdrawn.

4. Bumicom as a processor

Bumicom provides solutions and services including recording, voice logging, messaging recording, quality monitoring, transcription and interaction/insights analytics.

In providing these services, Bumicom may process personal data on behalf of its customers. In these situations, the customer generally determines the purposes and means of the processing and is therefore the controller. Bumicom processes the personal data only in accordance with the applicable agreements and the customer's documented instructions.

If you have a question about personal data processed by an organisation using a Bumicom solution, you should generally contact that organisation first.

5. Who do we share personal data with?

Bumicom does not sell your personal data.

We may share personal data with other parties where this is necessary for our business operations or the provision of our services, for example IT, hosting, communications, administration or other service providers.

Where another party processes personal data on our behalf, we put appropriate privacy, security and confidentiality arrangements in place where required.

We may also disclose personal data where necessary to comply with a legal obligation, court order or lawful request from a competent authority.

6. Transfers outside the European Economic Area

Where personal data is processed or accessible outside the European Economic Area (EEA), we ensure that there is a valid basis for the transfer and, where required, appropriate safeguards in accordance with the GDPR.

For information about a specific transfer and the safeguards used, please contact privacy@bumicom.nl.

7. How long do we retain personal data?

We retain personal data no longer than necessary for the purpose for which it was collected, unless we are legally required to retain it for a longer period.

The applicable retention period depends on the type of data, the purpose of the processing, contractual arrangements and any statutory retention requirements.

Where Bumicom acts as a processor, retention periods are generally determined by the relevant customer and the agreements made with that customer.

8. How do we protect personal data?

Bumicom implements appropriate technical and organisational measures to protect personal data against loss, misuse, unauthorised access, unauthorised disclosure and unauthorised alteration.

Bumicom operates an Information Security Management System (ISMS) and is ISO/IEC 27001:2022 certified.

Depending on the relevant processing activity and service, our security measures include network and system security, encryption, secure connections, access controls and email security measures.

If you believe that personal data or Bumicom systems are not adequately secured, please contact privacy@bumicom.nl.

9. Cookies and similar technologies

Our website may use cookies and similar technologies that are necessary for its technical operation, security and ease of use. Depending on the current configuration of the website, analytical or other cookies may also be used.

Where consent is required before cookies or similar technologies can be used, we will request your consent in advance. Where available, you can change your choices through the website's cookie settings. You can also delete or block cookies through your browser.

10. Your privacy rights

Depending on the circumstances, the GDPR gives you rights including the right to:

  • access your personal data;
  • have inaccurate personal data corrected;
  • request deletion of your personal data;
  • request restriction of processing;
  • object to processing;
  • request data portability;
  • withdraw your consent;
  • object to direct marketing;
  • not be subject to a decision based solely on automated processing that produces legal effects or similarly significantly affects you, where this right applies.

You can submit a request by emailing privacy@bumicom.nl.

We may ask you to provide additional information where this is reasonably necessary to verify your identity. We will not request more personal data for this purpose than necessary.

We will generally respond to your request within one month. Where a request is complex or you have made several requests, this period may be extended in accordance with the GDPR. If so, we will inform you in good time.

11. Complaints

If you have a question or complaint about how we process your personal data, we encourage you to contact us first at privacy@bumicom.nl.

You also have the right to lodge a complaint with the competent supervisory authority. In the Netherlands, this is the Dutch Data Protection Authority (Autoriteit Persoonsgegevens).

More information is available at www.autoriteitpersoonsgegevens.nl.

12. Automated decision-making

As a controller, Bumicom does not make decisions about individuals based solely on automated processing that produce legal effects or otherwise significantly affect them, unless this is expressly stated and a valid legal basis exists.

Where Bumicom provides analytics or AI functionality to a customer as a processor, the relevant customer determines the purposes for which that functionality is used and the personal data processed.

13. Changes to this privacy statement

We may amend this privacy statement when changes to our services, business operations or applicable laws and regulations make this necessary.

The most recent version is always available at www.bumicom.nl/en/privacy. The date on which this statement was last updated is shown at the top.