Disclaimer
Data Protection and GDPR Compliance
1. According solely to the information provided by the Company and confirmed in the Company Officer’s Certificate, the Company processes limited categories of personal data relating to its employees and the contact persons of its customers and suppliers. Such processing is carried out in connection with the performance and administration of employment relationships, including payroll and social security administration, and the negotiation and performance of commercial agreements with customers and suppliers. The Company may also receive personal data from persons who contact the Company by email or through its website.
2. According solely to the information provided by the Company and confirmed in the Company Officer’s Certificate:
A: the Company has four employees and has not appointed a data protection officer;
B: the Company does not transfer personal data outside the European Economic Area;
C: the Company does not engage in direct business-to-business email marketing; and
D: during the Track Record Period, the Company has not identified any personal data breach and has not received any inquiry, warning, sanction or administrative penalty from the Dutch Data Protection Authority (Autoriteit Persoonsgegevens) or any other competent data protection authority.
3. On the basis of the nature and limited scale of the processing activities described to us, nothing in the documents and information made available to us indicates that the Company is required to appoint a data protection officer pursuant to Article 37 of Regulation (EU) 2016/679 (the “GDPR”). The absence of an appointed data protection officer does not, in itself, constitute non-compliance with the GDPR.
4. We have reviewed the Information Security Policies and Procedures provided by the Company. These policies contain general requirements relating to information security, access management, security incident reporting and assessment, device and third-party security, data retention and secure deletion. However, we have not been provided with documentary evidence demonstrating the formal adoption, implementation, monitoring or periodic testing of the technical and organisational measures described in those policies.
5. We have not been provided with privacy notices for the relevant categories of data subjects, a record of processing activities, a detailed data retention schedule, an inventory of processors, copies of data processing agreements or records demonstrating the periodic review of the Company’s processing activities, security measures or data protection compliance framework.
6. Based on our review of the Company’s website at www.siveele.com on 9 September 2026, the website does not display a cookie consent banner and we were unable to identify a standalone privacy notice or cookie policy.
7. The website contains a disclaimer stating that personal information submitted to the Company by email or through a contact form will be treated confidentially and in accordance with the Dutch Personal Data Protection Act (Wet bescherming persoonsgegevens), and will be used solely for the purpose for which it was provided. The Dutch Personal Data Protection Act was repealed upon the application of the GDPR and the entry into force of the Dutch GDPR Implementation Act (Uitvoeringswet Algemene verordening gegevensbescherming) on 25 May 2018.
8. The disclaimer therefore does not accurately identify the currently applicable data protection legislation and does not contain all information required to be provided to data subjects under Articles 13 and 14 of the GDPR. Accordingly, the disclaimer does not constitute an adequate privacy notice for the purposes of the GDPR.
9. The absence of a cookie consent banner does not, in itself, constitute non-compliance with Netherlands Law if the website uses only cookies or similar technologies that do not require prior consent. We have not independently verified the cookies, scripts or other technologies used on the Company’s website and express no opinion in respect of such technical matters.
10. Based on the documents and information made available to us, nothing has come to our attention indicating that the Company experienced a personal data breach or was subject to any regulatory investigation, sanction or administrative penalty in relation to data protection during the Track Record Period.
11. However, in view of the absence of the privacy documentation and supporting implementation records referred to above, and the deficiencies identified in relation to the Company’s website, we are not in a position to conclude that the Company has complied in all respects with the GDPR, the Dutch GDPR Implementation Act and the applicable provisions of the Dutch Telecommunications Act (Telecommunicatiewet) during the Track Record Period.
12. The Company should:
a: prepare and implement appropriate privacy notices for its employees, customers, suppliers, website users and other relevant categories of data subjects;
b: update the privacy wording in its website disclaimer and remove the reference to the repealed Dutch Personal Data Protection Act;
c: prepare and maintain a record of processing activities and an appropriate data retention schedule;
identify its processors and other third-party service providers and, where required, enter into data processing agreements satisfying Article 28 of the GDPR;
e: review the cookies and other third-party technologies used on its website and, where required, publish an appropriate cookie policy and implement a valid consent mechanism;
f: verify and document whether any service provider processes personal data outside the European Economic Area and, where applicable, implement the safeguards required under Chapter V of the GDPR; and
g: formally approve and periodically review its Information Security Policies and Procedures and retain appropriate evidence of their implementation.
Cybersecurity and the Cyberbeveiligingswet
The Dutch Cybersecurity Act (Cyberbeveiligingswet), which implements Directive (EU) 2022/2555 (the “NIS2 Directive”) in the Netherlands, entered into force on 15 August 2026 and was therefore not applicable to the Company during the Track Record Period. According to the information provided by the Company, the Company has four employees and does not, on a stand-alone basis, meet the applicable size thresholds under the Cyberbeveiligingswet.
