PRIVACY
Privacy Statement
SenseAnywhere
Version 25 March 2026
1. Introduction
SenseAnywhere B.V. (“SenseAnywhere”, “we”, “us”) takes the protection of your personal data seriously and processes it in accordance with the EU General Data Protection Regulation 2016/679 (“GDPR”), the Dutch GDPR Implementation Act (Uitvoeringswet AVG) and the Dutch Telecommunications Act (Telecommunicatiewet).
This Privacy Statement explains which personal data we collect when you use the SenseAnywhere Portal and related services, why we process it, on what legal basis, with whom we share it, how long we keep it, and which rights you have.
2. Who is responsible for your data
The controller for the processing described in this Statement is:
- SenseAnywhere B.V.
- Bergrand 218, 4707 AT Roosendaal, The Netherlands
- Chamber of Commerce (KvK) number: 20159613
- Email: info@senseanywhere.com
- Our Data Protection Officer can be reached at compliance@senseanywhere.com.
3. Our role: controller and processor
In relation to your account information, login data and direct communications with us, SenseAnywhere acts as the controller.
In relation to monitoring data uploaded by our customers through SenseAnywhere devices (including any personal data that may incidentally be contained in measurement, location or alarm data), SenseAnywhere acts as a processor on behalf of the customer organization, which is the controller. The processing of such data is governed by a separate Data Processing Agreement (DPA) concluded with that customer in accordance with Art. 28 GDPR.
4. Personal data we collect
We collect and process the following categories of personal data:
- Identification and contact data: first and last name, email address, username, address, telephone number, preferred language, time zone.
- Account and authentication data: user role, password (stored in hashed form), multi-factor authentication settings.
- Usage and technical data: login history, actions performed in the Portal, IP address, browser type, device and operating system information.
- Audit trail data: a record of who performed which action and when, kept for compliance with Good Distribution Practice (GDP), Good Manufacturing Practice (GMP), FDA 21 CFR Part 11 and EU GMP Annex 11.
We do not intentionally collect special categories of personal data (Art. 9 GDPR). The Portal is intended for professional use.
5. Why we process your data, on what legal basis, and for how long
The table below summarizes the main processing activities, the legal basis under Art. 6 GDPR, and the applicable retention period.
| Purpose of processing | Categories of personal data | Legal basis (GDPR Art. 6) | Retention period |
|---|---|---|---|
| Providing access to and operation of the SenseAnywhere Portal (account creation, authentication, user management). | Identification data: name, email, username, telephone, address, language, time zone. | Performance of a contract (Art. 6(1)(b)) with the customer organization, or pre-contractual steps. | Duration of the user account plus 5 years after deactivation, unless a longer period is required by law. |
| Audit trail of user actions in the Portal (alarm acknowledgements, configuration changes, calibration events) for GxP / FDA 21 CFR Part 11 / EU Annex 11 compliance. | User ID, name, timestamp of action, action performed, IP address. | Compliance with a legal obligation (Art. 6(1)(c)) where the customer is regulated, and legitimate interests (Art. 6(1)(f)) of SenseAnywhere and its customers in maintaining a verifiable audit trail. | Retained for the regulatory retention period applicable to the customer (typically 10 years under GxP / FDA rules). This data cannot be erased on request before that period expires. |
| Security monitoring, fraud prevention, and troubleshooting of the Portal. | Login history, browsing activity within the Portal, IP address, browser/device data. | Legitimate interests (Art. 6(1)(f)) in keeping the service secure and operational. | 12 Months for security logs; longer if needed to investigate a specific incident. |
| Customer support, including handling of RMA cases and technical questions. | Contact details, correspondence content, case history. | Performance of a contract (Art. 6(1)(b)) and legitimate interests (Art. 6(1)(f)) in delivering and improving support. | 10 years after closure of the support case. |
| Service communications (e.g. maintenance notices, security advisories). | Email address, name, role. | Legitimate interests (Art. 6(1)(f)) and, where applicable, legal obligation (Art. 6(1)(c)). | Duration of the user account. |
| Direct marketing of related SenseAnywhere products and services to existing business contacts. | Email address, name, organization, role. | Legitimate interests (Art. 6(1)(f)) for existing customer contacts (soft opt-in); consent (Art. 6(1)(a)) for other recipients. You can object or withdraw consent at any time. | Until you object, withdraw consent, or are no longer an active business contact. |
Where we rely on legitimate interests, we have carried out a balancing test and concluded that our interests are not overridden by your fundamental rights and freedoms.
6. Cookies and similar technologies
The SenseAnywhere websites and Portal use cookies and similar technologies. We distinguish between:
- Strictly necessary cookies: required for the Portal to function (e.g. session, authentication, load balancing). These do not require consent under Art. 11.7a(3) of the Dutch Telecommunications Act.
- Analytical cookies: help us understand how the Portal is used so we can improve it. Where these are not privacy-friendly by configuration, we ask for your consent first.
You can withdraw or change your consent at any time through the cookie settings link on our website. Disabling non-essential cookies will not prevent you from using the core features of the Portal.
7. Who has access to your data
Within SenseAnywhere, access is limited to staff who need it to perform their role (e.g. customer support, technical operations, finance), under appropriate confidentiality obligations.
We share personal data with the following categories of recipients:
- Cloud hosting and infrastructure providers (in particular Microsoft Azure, region West Europe, The Netherlands and Ireland).
- IT service providers, including email, helpdesk, CRM and analytics platforms used to operate our business.
- Authorized resellers, distributors and service partners, where strictly necessary to deliver or support the service ordered by the customer.
- Professional advisers (such as auditors, accountants and lawyers) under a duty of confidentiality.
- Public authorities and regulators, where we are legally required to do so.
All processors act on our documented instructions under a written data processing agreement compliant with Art. 28 GDPR. A current list of sub-processors is available on request via the contact details in section 2.
8. International transfers of personal data
Your personal data is primarily stored in the European Economic Area (EEA), in the Microsoft Azure West Europe region.
Where personal data is transferred to a country outside the EEA that does not benefit from an adequacy decision of the European Commission, we put appropriate safeguards in place under Chapter V GDPR. These typically include:
- The European Commission Standard Contractual Clauses (Implementing Decision (EU) 2021/914), supplemented by additional technical and organizational measures where required following the Schrems II judgment (CJEU C-311/18); and/or
- For transfers to the United States, certification of the recipient under the EU-U.S. Data Privacy Framework (where applicable).
9. How we protect your data
We implement appropriate technical and organizational measures to protect personal data against accidental or unlawful destruction, loss, alteration, unauthorized disclosure or access, in line with Art. 32 GDPR. These measures include, among others:
- Encryption in transit (TLS) and at rest where technically appropriate.
- Role-based access control, multi-factor authentication for privileged accounts, and the principle of least privilege.
- Segregated environments for development, test and production.
- Logging, monitoring and regular review of access to personal data.
- Patch and vulnerability management, backups and disaster-recovery procedures.
- Confidentiality obligations and security awareness training for staff.
In the event of a personal data breach that is likely to result in a risk to your rights and freedoms, we will notify the Autoriteit Persoonsgegevens within 72 hours where required by Art. 33 GDPR, and inform affected data subjects in accordance with Art. 34 GDPR where required.
10. Automated decision-making
The SenseAnywhere Portal generates automated alarms and notifications based on threshold and rule configurations defined by the customer. These do not constitute automated decision-making within the meaning of Art. 22 GDPR producing legal or similarly significant effects on individuals. We do not engage in profiling for marketing or scoring purposes.
11. Your rights
Under the GDPR you have the following rights, which you can exercise free of charge by contacting us using the details in section 2. We will respond within one month, with the possibility of extending this period by two further months for complex requests (Art. 12(3) GDPR).
| Right | What it means |
|---|---|
| Access (Art. 15) | Obtain confirmation of whether we process your data and a copy of that data, together with information on purposes, categories, recipients and retention. |
| Rectification (Art. 16) | Have inaccurate personal data corrected and incomplete data completed. |
| Erasure / ‘right to be forgotten’ (Art. 17) | Have your personal data deleted where one of the grounds in Art. 17(1) applies. We may refuse where an exception in Art. 17(3) applies, for example, where retention is required by law (such as fiscal or regulated GxP audit-trail obligations) or for the establishment, exercise or defense of legal claims. Where we refuse, we will tell you why and limit retention to what is strictly necessary. |
| Restriction of processing (Art. 18) | Ask us to limit how we use your data, for example while you contest its accuracy. |
| Data portability (Art. 20) | Receive personal data you have provided to us in a structured, commonly used, machine-readable format and transmit it to another controller, where processing is based on consent or contract and carried out by automated means. |
| Objection (Art. 21) | Object at any time to processing based on legitimate interests (including profiling), and object at any time to processing for direct marketing purposes. |
| Withdraw consent (Art. 7(3)) | Where processing is based on consent, withdraw that consent at any time without affecting the lawfulness of processing already carried out. |
| Lodge a complaint (Art. 77) | File a complaint with a supervisory authority, in particular the Dutch Autoriteit Persoonsgegevens (autoriteitpersoonsgegevens.nl), or the supervisory authority in the EU/EEA member state where you live or work. |
To protect your data, we may need to verify your identity before acting on a request. If your account was created or is administered by your employer or another customer organization, we may direct part of your request to that organization, which is the controller for the underlying monitoring data.
12. Is providing your data mandatory?
Providing identification, contact and authentication data is necessary to create an account and use the Portal. Without it, we are unable to provide the service to you. The other categories of data are collected automatically as part of using the Portal or in the course of supporting you.
13. Changes to this Privacy Statement
We may update this Privacy Statement from time to time, for example to reflect changes in our services or in applicable law. The version date at the top of this document indicates when it was last updated. Where changes are material, we will inform you in advance through the Portal or by email and, where required by law, ask for your consent before the changes take effect. We will not assume your consent solely from continued use of the service where the law requires an explicit indication.
14. Complaints
If you believe that we have not complied with applicable data protection law, please contact us first using the details in section 2, we are committed to resolving issues directly. You also have the right to lodge a complaint with the Dutch supervisory authority:
- Autoriteit Persoonsgegevens
- Postbus 93374, 2509 AJ Den Haag, The Netherlands
- autoriteitpersoonsgegevens.nl
If you live or work in another EU/EEA member state, you may also lodge a complaint with the supervisory authority of that country.