1. Who is responsible for your data
Databaseonline B.V., trading as 24x7DBA, Kade 28, 4703 GG Roosendaal, the Netherlands, registered with the Chamber of Commerce under number 30171190, is the controller for the personal data described in this policy, unless section 8 says otherwise. You can reach us at danny.riebeek@databaseonline.nl or through the contact page.
Databaseonline B.V. is also the company behind DatabaseOnline, SQLTreeo, SSMS Addon, SSMSFolders, SQLServerSpecialist and Office365 Mail Solutions. Those websites and products have their own privacy statements. This policy covers www.24x7dba.nl and the DBA services delivered under the 24x7DBA name.
2. Which data we collect
When you book a call or contact us
If you use the booking page or the contact form, or e-mail us, we receive the details you provide: your name, company, work e-mail address, telephone number if you give it, the kind of call and time slot you choose, the environment you describe and the content of your message. Both the booking page and the contact form open your own e-mail program; nothing is stored on this website when you send a request. When we confirm a call we create a Microsoft Teams meeting with your e-mail address as an attendee.
When you visit the website
Our hosting provider records technical data for every request in a server log: the IP address of your device, date and time, the page requested, the referring page, browser type and operating system. We use this data to keep the website available and secure. This website does not use analytics or advertising cookies. See the cookie policy for details.
When we work for you
When you become a customer we process the business contact details of the people we work with: names, roles, e-mail addresses, telephone numbers, escalation details, and the content of our communication, tickets, change logs and reports. For invoicing we process company details, VAT number and payment references.
Data inside your databases
Our engineers have access to your database environments while an engagement runs. During that work we may incidentally see personal data stored in your systems, for example while analysing a query or a deadlock graph. In that situation we act as a processor on your behalf; see section 8. Where monitoring is part of the engagement, it collects technical metrics and metadata only, not the business data in your tables.
3. Why we use your data and on which legal basis
| Purpose | Data | Legal basis (GDPR article 6) |
|---|---|---|
| Planning and holding the call you booked, answering your enquiry, preparing a quotation | Contact details, chosen slot, message | Steps prior to entering into a contract (6.1 b) and our legitimate interest in responding to business enquiries (6.1 f) |
| Delivering DBA, support and development services | Business contact details, communication, change logs, technical metrics | Performance of a contract (6.1 b) |
| Invoicing and bookkeeping | Company and payment details | Legal obligation (6.1 c), Dutch tax law |
| Keeping the website and our systems secure | Server logs, access logs | Legitimate interest (6.1 f) |
| Keeping in touch with existing customers about our services | Business e-mail address | Legitimate interest (6.1 f); you can object at any time |
We do not use your data for automated decision-making or profiling, and we do not sell personal data.
4. How long we keep your data
- Booking requests and enquiries that do not lead to an engagement: 12 months after our last contact, then deleted.
- Customer contact details, change logs and project communication: for the duration of the engagement and 2 years afterwards, so that we can answer questions about work delivered.
- Contracts, invoices and payment records: 7 years, as required by Dutch tax law.
- Website server logs: 30 days.
- Monitoring metrics and metadata, where applicable: for the duration of the contract and 90 days afterwards, unless you ask us to hand over or delete them earlier.
5. Who receives your data
We share personal data only with parties that help us run our business, under a contract that obliges them to protect it:
- Our web hosting provider (Microsoft Azure), for serving this website and storing server logs.
- Microsoft, for e-mail, calendar, Microsoft Teams, document storage and, if enabled on the booking page, Microsoft Bookings (Microsoft 365), and for Microsoft Azure where a customer environment runs there.
- Our accountant and, where legally required, the tax authorities.
We do not share your data with other parties unless the law requires it or you ask us to, for example when we work together with your other suppliers or your managed service provider.
6. Data outside the European Economic Area
We store and process data within the European Economic Area wherever we can. This website is served from its own hosting, including its typefaces, so loading a page sends no request to Google or any other third party. Microsoft 365 data is stored in EU data centres, and Microsoft applies the European Commission's standard contractual clauses for any support access from outside the EEA.
7. How we protect your data
All connections to this website and to our systems are encrypted with TLS. Access to customer environments uses named accounts, least-privilege rights and multi-factor authentication, and is withdrawn when an engagement ends. Our team is bound by confidentiality agreements. More detail is under how we work securely.
8. When we process data on your behalf
When 24x7DBA manages, supports or works inside your database environments, you remain the controller of the personal data in those systems and Databaseonline B.V. acts as your processor. We sign a data processing agreement (in Dutch: verwerkersovereenkomst) that sets out the instructions, security measures, sub-processors, breach notification and deletion at the end of the contract. Ask for our standard agreement or send us yours.
9. Your rights
Under the GDPR you have the right to:
- access the personal data we hold about you and receive a copy;
- have inaccurate data corrected and incomplete data completed;
- have your data erased when we no longer need it or you withdraw consent;
- restrict how we use your data while a question about it is resolved;
- receive the data you gave us in a portable format;
- object to processing based on our legitimate interest, including any marketing contact.
Send your request to danny.riebeek@databaseonline.nl. We answer within one month. We may ask you to confirm your identity before we act on a request. If you are not satisfied with our response, you can lodge a complaint with the Dutch Data Protection Authority, the Autoriteit Persoonsgegevens, at autoriteitpersoonsgegevens.nl.
10. Children
This website and our services are aimed at businesses. We do not knowingly collect data from anyone under 16.
11. Changes to this policy
We update this policy when our services or the law change. The version number and effective date at the top tell you which version applies. Substantial changes that affect existing customers are announced by e-mail.
12. Contact
Databaseonline B.V., trading as 24x7DBA
Kade 28
4703 GG Roosendaal
The Netherlands
KvK 30171190 · VAT NL820774704B01
danny.riebeek@databaseonline.nl