Privacy Statement

Last updated: 28 July 2026

This Privacy Statement explains how Clear Timber Analytics B.V. (“Clear Timber”, “we”, “us” or “our”) collects, uses, shares and protects personal data. It applies when you visit our website, contact us, interact with us through professional or social-media channels, apply for a position, use our client platform or otherwise engage with our products and services.

We process personal data in accordance with the EU General Data Protection Regulation (“GDPR”), the Dutch GDPR Implementation Act (“UAVG”) and, where applicable, Dutch electronic-communications legislation. “Personal data” means any information relating to an identified or identifiable natural person.

1. Who we are

Clear Timber Analytics B.V. is responsible for the processing described in this Privacy Statement, unless we are processing personal data solely on behalf of a client.

Clear Timber Analytics B.V.
Noodweg 34
1213 PX Hilversum
The Netherlands
Chamber of Commerce number: 92554407
VAT number: NL866097946B01
Email: info@cleartimber.com

Our privacy contact point can be reached using the email address above.

2. When this statement applies

This Privacy Statement applies to:

  • our corporate website;
  • our online client platform;
  • contact and quotation requests;
  • prospective, current and former clients, suppliers and project partners;
  • professional contacts and business-development activities;
  • recruitment and open applications;
  • newsletters and other business communications;
  • interactions with our company through LinkedIn and other professional channels.

It does not govern the independent processing activities of third-party websites, platforms or social-media providers.

This statement also does not fully govern personal data that we process solely on the instructions of a client. Our role in relation to client project data is explained in section 7.

3. Personal data we process

Depending on how you interact with us, we may process the following categories of personal data.

Contact and professional information

This can include:

  • your name;
  • business email address;
  • telephone number;
  • job title and department;
  • company or organisation;
  • professional profile information;
  • country or general business location;
  • your preferred language.

Communications and relationship information

This can include:

  • enquiries and contact-form submissions;
  • emails and other correspondence;
  • meeting notes;
  • quotation requests;
  • proposals, contracts and project communications;
  • information about your organisation’s requirements and interests;
  • communication and marketing preferences;
  • records of consent, objections and unsubscribes.

Account and platform information

When you use our client platform, we may process:

  • account and login details;
  • user roles and permissions;
  • organisation and project associations;
  • platform activity and usage records;
  • support requests;
  • authentication, security and audit logs.

We do not request that passwords be shared with us. Passwords should be stored in protected or hashed form by the relevant authentication system.

Financial and administrative information

This can include:

  • billing and invoicing details;
  • purchase-order information;
  • payment status;
  • contract and transaction records;
  • information required for accounting, tax and auditing purposes.

Website and device information

Depending on your cookie choices and our technical configuration, this can include:

  • IP address;
  • approximate location derived from an IP address;
  • browser and device type;
  • operating system;
  • referring website;
  • pages visited;
  • time and duration of visits;
  • clicks, downloads and other website interactions;
  • cookie and consent identifiers;
  • technical security and diagnostic information.

Recruitment information

When you apply for a position or submit an open application, we may process:

  • your name and contact details;
  • curriculum vitae;
  • motivation and cover letter;
  • employment and education history;
  • portfolio or professional-profile information;
  • availability;
  • interview notes and recruitment correspondence;
  • references, where appropriate and with proper notice.

Please do not provide special-category personal data, criminal-record information or other sensitive information unless we specifically request it and there is a lawful reason for processing it.

Project and geospatial information

Our services primarily concern trees, forests, terrain and physical assets rather than individuals. However, raw point clouds, photographs, aerial imagery, mobile-mapping data and other geospatial datasets may incidentally contain information relating to identifiable people, vehicles, buildings, addresses or properties.

Clear Timber does not use this incidental information to identify, track or profile individuals. Access to project data is limited to what is necessary to deliver and secure the relevant services.

4. How we obtain personal data

We may obtain personal data:

  • directly from you, for example through a form, email, meeting, application or platform registration;
  • from your employer, colleague or another contact within your organisation;
  • from clients, suppliers, project partners and data-acquisition partners;
  • through publicly available professional sources, such as company websites, professional directories, event information and LinkedIn;
  • through referrals and introductions;
  • automatically through our website, platform, server logs, cookies and similar technologies;
  • from project datasets supplied by a client or project partner.

When we obtain professional contact information indirectly, we use it only where we have a lawful and proportionate reason to do so.

5. Why we process personal data

Responding to enquiries and preparing proposals

We process contact details and communications to respond to questions, assess project requirements, arrange demonstrations, prepare quotations and take steps towards a possible agreement. The legal basis is:

  • taking steps at your request before entering into a contract, where you are personally the prospective contracting party; or
  • our legitimate interest in responding to enquiries and developing professional business relationships.

Providing our services and managing client accounts

We process account, contact, project and relationship information to:

  • deliver agreed services;
  • provide access to our client platform;
  • administer projects;
  • communicate about deliverables and quality control;
  • provide support;
  • manage contracts, suppliers and project partners.

The legal basis is the performance of a contract or our legitimate interest in administering a contract with the organisation you represent.

Maintaining professional relationships

We use professional contact and communication information to maintain relationships with clients, suppliers, data-acquisition partners and other organisations relevant to our work. The legal basis is our legitimate interest in operating and developing our B2B services and professional network.

Business development and relevant marketing

We may use professional contact details to send relevant information about our services, developments, events, case studies or related solutions. The GDPR legal basis may be:

  • your consent; or
  • our legitimate interest in relevant and proportionate B2B business development.

Electronic marketing is sent only where permitted under applicable electronic-communications rules. For example, we may contact existing clients about similar services where the legal customer exception applies.

Every marketing message provides a straightforward way to unsubscribe. You may object to the use of your personal data for direct marketing at any time. Once you object, we will stop using your data for that purpose. We may retain a minimal suppression record to ensure that your unsubscribe or objection continues to be respected.

Website analytics and improvement

With your consent, we use analytics information to understand how visitors use our website and to improve its structure, content and performance. The legal basis for non-essential analytics cookies and related storage is your consent.

Website, platform and information security

We process technical and security information to:

  • protect our website and platform;
  • manage access and permissions;
  • detect errors, abuse and attempted unauthorised access;
  • investigate security incidents;
  • maintain backups and business continuity.

The legal basis is our legitimate interest in operating reliable and secure systems and protecting our company, clients and users.

Recruitment

We process application information to assess candidates, communicate about applications and take steps towards a possible employment agreement. The legal basis is taking steps before entering into a possible employment contract and our legitimate interest in managing recruitment. Where we ask to retain an application for future opportunities, we rely on consent.

Financial administration and legal compliance

We process financial, contractual and administrative information to comply with tax, accounting, corporate and other legal obligations. The legal basis is compliance with a legal obligation.

Legal claims and corporate transactions

We may process information where necessary to establish, exercise or defend legal claims, prevent fraud, manage disputes or support a possible merger, investment, restructuring or sale. The legal basis is our legitimate interest in protecting and managing our business and legal position or, where applicable, compliance with a legal obligation.

6. Our legitimate interests

Where we rely on legitimate interests, these may include:

  • operating and improving our B2B services;
  • responding to professional enquiries;
  • maintaining client, supplier and partner relationships;
  • securing our systems and project data;
  • preventing misuse and fraud;
  • relevant and proportionate business development;
  • establishing and defending legal claims.

Before relying on this basis, we consider the necessity of the processing, its likely impact on individuals and whether their rights and interests outweigh our interests. You may contact us for more information about a particular legitimate-interest assessment.

7. Client project data and our role as processor

Clear Timber clients may provide point clouds, mobile-mapping data, imagery, GIS files or other project datasets for analysis. Where such data contains personal data and we process it solely to provide services according to the client’s instructions, the client is normally the controller and Clear Timber acts as processor.

In those situations:

  • the client determines the purposes and legal basis for processing;
  • processing is governed by the relevant service agreement and, where required, a data-processing agreement;
  • we process the data only on documented instructions;
  • access is limited to authorised personnel and approved service providers;
  • subprocessors are engaged under appropriate contractual obligations;
  • data is returned or deleted in accordance with the agreement and applicable legal requirements.

Questions or requests concerning personal data contained in client project datasets should normally be directed to the organisation that commissioned the project. We will assist that organisation where required under our contractual and legal obligations.

8. Cookies and analytics

Our website uses cookies and similar technologies. Strictly necessary cookies may be used without consent where they are required to:

  • provide requested website functionality;
  • remember privacy choices;
  • protect forms and website security;
  • maintain technical sessions.

Analytics, preference and marketing cookies are used only after the required consent has been obtained.

We currently use Google Analytics 4, provided by Google, to understand how our website is used. Google Analytics may process information such as visited pages, interactions, device and browser information, referring sources and approximate geographic information. For visitors in the European Economic Area, an IP address may be processed momentarily to derive approximate location information but should not be retained as an individual IP address in Google Analytics.

Google Analytics is integrated through our consent-management system. Analytics cookies are not stored unless analytics consent has been provided. The exact behaviour before consent depends on whether basic or advanced Google Consent Mode is technically configured. Google Analytics event-level data is retained for no longer than 14 months.

You can give, refuse or withdraw consent at any time through the cookie settings. Withdrawing consent does not affect the lawfulness of processing that took place before withdrawal.

Our separate Cookie Policy should provide the current list of cookies, providers, purposes and lifetimes. The Cookie Policy and cookie settings should be accessible from every page of the website.

9. Who receives personal data

We do not sell personal data. Where necessary, we may share personal data with:

  • other companies or representatives within a client’s or partner’s organisation;
  • data-acquisition, surveying and project partners involved in delivering an agreed project;
  • IT, cloud, hosting, security and platform providers;
  • CRM and communication providers;
  • analytics and consent-management providers;
  • accounting, auditing, insurance and professional-advisory providers;
  • public authorities where disclosure is legally required;
  • parties involved in a corporate transaction, subject to appropriate confidentiality and legal safeguards.

Important service providers currently include:

  • Pipedrive, for CRM, sales communication and relevant marketing administration;
  • Google, for website analytics and related technical services;
  • STRATO AG, for website hosting;
  • our email, IT, cloud-storage and client-platform providers.

Processors may only use personal data according to our instructions and contractual requirements. We enter into data-processing agreements where required.

10. International transfers

We aim to process personal data within the European Economic Area wherever reasonably possible. Some providers or their subprocessors may process or access data from countries outside the European Economic Area. Where personal data is transferred internationally, we use an appropriate GDPR transfer mechanism, such as:

  • an adequacy decision adopted by the European Commission;
  • the EU–U.S. Data Privacy Framework, where the relevant recipient is certified and the framework applies;
  • European Commission Standard Contractual Clauses;
  • additional contractual, organisational or technical safeguards where appropriate.

You may contact us for further information about the safeguards applicable to a particular transfer. Copies may be subject to reasonable redactions to protect confidential and security-sensitive information.

11. How long we retain personal data

We do not retain personal data longer than necessary for the purpose for which it was collected. Our normal retention periods are:

  • Enquiries and prospective-client information: up to 24 months after the last meaningful contact, unless a relationship begins or longer retention is needed for a legal claim.
  • Business-development and CRM information: up to 24 months after the last meaningful interaction, unless you object earlier or there is an ongoing professional relationship.
  • Marketing suppression records: for as long as reasonably necessary to ensure that an unsubscribe or objection continues to be respected.
  • Client, supplier and contract information: for the duration of the relationship and afterwards for applicable statutory, contractual and limitation periods.
  • Financial and tax records: generally seven years, in accordance with Dutch administrative and tax requirements.
  • Platform account information: for the duration of the account and subsequently for the period required to close, secure and document the account, subject to the applicable service agreement.
  • Ordinary platform and security logs: up to 12 months, unless an incident, investigation or legal requirement justifies longer retention.
  • Client project data processed on behalf of a client: according to the client’s instructions, the service agreement and the applicable data-processing agreement.
  • Unsuccessful job applications: normally no longer than four weeks after the recruitment process ends.
  • Applications retained for future opportunities: up to one year where the applicant has given consent.
  • Google Analytics event data: up to 14 months.
  • Cookie data: for the period stated in our Cookie Policy.
  • Backups: until overwritten or securely removed through our normal backup-rotation schedule.

We may retain information longer where this is necessary to comply with the law, investigate an incident, resolve a dispute or establish, exercise or defend a legal claim. After the applicable period, information is deleted, anonymised or otherwise placed beyond normal use.

12. How we protect personal data

We take technical and organisational measures appropriate to the nature of the data and the risks involved. These measures include, where appropriate:

  • access controls based on roles and responsibilities;
  • multi-factor authentication for relevant systems;
  • encryption during transmission;
  • protected backups;
  • software updates and vulnerability management;
  • logging and incident-response procedures;
  • confidentiality obligations for personnel;
  • supplier and processor due diligence;
  • data-minimisation and limited-access procedures for project data.

No system can be guaranteed to be completely secure. We regularly review our measures and adjust them where appropriate. Where a personal-data breach is likely to create a risk to individuals, we will notify the competent supervisory authority as required. Where a breach is likely to create a high risk, we will also inform affected individuals unless an applicable exception applies.

13. Your rights

Subject to the conditions and exceptions in the GDPR, you may have the right to:

  • obtain confirmation of whether we process your personal data;
  • access your personal data;
  • correct inaccurate or incomplete information;
  • request deletion of your personal data;
  • restrict processing;
  • receive certain personal data in a portable format;
  • object to processing based on legitimate interests;
  • object at any time to processing for direct marketing;
  • withdraw consent at any time;
  • lodge a complaint with a supervisory authority;
  • not be subject to a decision based solely on automated processing that produces legal or similarly significant effects.

To exercise your rights, contact info@cleartimber.com. We may request additional information where reasonably necessary to confirm your identity and prevent unauthorised disclosure.

We normally respond within one month. For complex or numerous requests, the GDPR may allow this period to be extended by up to two additional months. We will inform you within the initial one-month period if an extension is needed. Requests are normally handled free of charge. A reasonable fee may be charged, or a request may be refused, where it is manifestly unfounded or excessive, as permitted by law. Some rights are not absolute. For example, we may need to retain certain records to comply with legal obligations or defend legal claims.

14. Providing personal data

You are generally not legally required to provide personal data merely to visit our website. Certain information is, however, necessary to:

  • respond to an enquiry;
  • prepare a quotation;
  • enter into or perform an agreement;
  • create and secure a platform account;
  • process an application;
  • comply with tax, accounting or identification requirements.

Without the necessary information, we may be unable to respond, provide access, enter into an agreement or deliver the requested services.

15. Automated decision-making and artificial intelligence

Our tree-detection, point-cloud and geospatial-analysis technology is designed to identify and measure trees, vegetation, terrain and related physical features. We do not use these systems to make solely automated decisions about individuals that produce legal or similarly significant effects. We also do not use website or CRM information for this type of automated decision-making. Should this change, we will provide the information required by the GDPR before beginning the relevant processing.

16. Social media and external websites

Our website may contain links to third-party websites and social-media platforms. When you interact with our LinkedIn page or other third-party platforms, we may receive the information you choose to make available, such as your professional profile, message or interaction with our content. The relevant platform also processes personal data for its own purposes under its own privacy terms. We are not responsible for the independent privacy practices of external websites or platforms. We encourage you to read their privacy information.

17. Complaints

Please contact us first when you have a question or concern about how we process your personal data. We will try to address the matter appropriately. You also have the right to lodge a complaint with the Dutch Data Protection Authority, the Autoriteit Persoonsgegevens, or with the competent supervisory authority in the EU or EEA country where you live, work or believe an infringement occurred. Contacting us first is not a requirement for lodging a complaint.

18. Changes to this statement

We may update this Privacy Statement to reflect changes in our services, systems, processors or legal obligations. The most recent version will be published on our website. The date at the top shows when the statement was last updated. Where a change materially affects how we process personal data, we will take reasonable steps to bring it to the attention of affected individuals.

19. Contact

For questions about this Privacy Statement, the processing of personal data or the exercise of your rights, contact:

Clear Timber Analytics B.V.
Noodweg 34
1213 PX Hilversum
The Netherlands
Email: info@cleartimber.com

Comments are closed.