Legal
Privacy Policy
Last updated: 8 September 2026
This policy explains what happens to personal data when you visit ceriter.com or contact us through this website.
It covers the website only. If you use Stride One insoles or the Stride One app, a separate privacy notice applies to the data the device and app collect. That notice is provided to you before you start using the device.
1. Who is responsible for your data
The controller of the personal data described in this policy is:
Ceriter B.V. François de Veijestraat 8B 6221 AB Maastricht The Netherlands
Chamber of Commerce (KVK): 75191326 VAT: NL860177804B01 Email: info@ceriter.com
We have not appointed a Data Protection Officer. Questions about this policy or about your personal data can be sent to info@ceriter.com.
2. What we collect, why, and on what legal basis
2.1 When you fill in a form
Our contact and order forms ask for information such as your name, email address, and — depending on the form — your organisation, your role, your country, and whatever you choose to write in a free-text field.
Why: to answer your question, to send you the information you asked for, or to process your order.
Legal basis: Article 6(1)(b) GDPR (steps taken at your request before entering into a contract, or performance of a contract) where your message concerns an order or a potential order. Article 6(1)(f) GDPR (our legitimate interest in responding to enquiries about our business) for general enquiries.
Retention: enquiries are kept for up to 24 months after our last contact with you, unless the exchange leads to a contractual or commercial relationship, in which case the relevant records are kept for as long as that relationship lasts and for the statutory retention periods that follow it.
Please do not send us health information through the website forms. If you write to us about a medical condition, an operation or a symptom, you are giving us health data, which is a special category of personal data. We would rather you did not. If you do, we will treat it as provided with your explicit consent under Article 9(2)(a) GDPR, we will use it only to answer you, and we will delete it once your question is resolved.
2.2 When you visit the site
Our hosting provider records technical information as part of delivering the site to you — including your IP address, the page requested, the time of the request, and information your browser sends such as its type and language.
Why: to deliver the website, to keep it secure, and to detect and prevent abuse.
Legal basis: Article 6(1)(f) GDPR (our legitimate interest in operating a secure, functioning website).
Retention: short-term server and security logs are retained by our hosting provider in line with its own retention periods and are not used by us to build any profile of you.
2.3 Website statistics
We use Vercel Web Analytics to understand how the site is used — for example, how many people visit, which pages they read, and which country or referring site they arrived from.
Vercel Web Analytics does not use cookies and does not store a persistent identifier that would allow you to be recognised across visits or across websites. The statistics we see are aggregated. We cannot identify you from them.
Why: to understand which parts of the site are useful and to improve it.
Legal basis: Article 6(1)(f) GDPR (our legitimate interest in understanding and improving our own website). Because no cookie or comparable technique is stored on or read from your device, no consent is required under Article 11.7a of the Dutch Telecommunications Act.
Retention: aggregated statistics only, retained in line with our analytics provider's standard retention period.
3. Who else processes your data
We use a small number of service providers. They act on our instructions as processors, under a data processing agreement, and may not use your data for their own purposes.
| Provider | What they do for us | Where data is processed |
|---|---|---|
| Vercel Inc. | Website hosting, content delivery, and cookieless website analytics | European Union and United States |
| HubSpot, Inc. | Customer relationship management; receives the contents of forms you submit | European Union and United States |
| Typeform SL (Barcelona, Spain) | Hosts the order form embedded on our order page | United States |
| Google Workspace (Google Ireland Ltd.) | Email and document storage; your message reaches us by email | European Union and United States |
We do not sell your personal data, and we do not share it with third parties for their own marketing.
Transfers outside the EEA
Some of these providers are based in, or transfer data to, the United States. Where that happens, transfers are made on the basis of the European Commission's Standard Contractual Clauses, or on the basis of the EU–US Data Privacy Framework where the provider is certified under it. You can ask us for a copy of the relevant safeguards by writing to info@ceriter.com.
4. Your rights
Under the GDPR you have the right to:
- access the personal data we hold about you, and receive a copy;
- rectify data that is inaccurate or incomplete;
- erase your data ("right to be forgotten") where the conditions in Article 17 GDPR are met;
- restrict processing in the circumstances set out in Article 18 GDPR;
- data portability — receive data you provided to us in a structured, commonly used, machine-readable format, where processing is based on consent or contract and carried out by automated means;
- object to processing based on our legitimate interests, on grounds relating to your particular situation;
- withdraw consent at any time, where processing is based on consent. Withdrawal does not affect the lawfulness of processing carried out before you withdrew.
To exercise any of these rights, write to info@ceriter.com. We will respond within one month. If your request is complex, we may extend that by a further two months and will tell you if we do.
We may ask you for information to confirm your identity before we act on a request. This is to make sure we do not disclose your data to someone else.
Complaints
If you believe we are handling your personal data unlawfully, you can lodge a complaint with the Dutch supervisory authority:
Autoriteit Persoonsgegevens Postbus 93374, 2509 AJ Den Haag, The Netherlands autoriteitpersoonsgegevens.nl
You may also complain to the supervisory authority in the EU country where you live or work. We would appreciate the chance to address your concern first.
5. Automated decision-making
We do not make decisions about you on this website that are based solely on automated processing and that produce legal effects or similarly significantly affect you.
6. Security
We take appropriate technical and organisational measures to protect personal data, including encryption in transit, access controls, and limiting access to those who need it. No system is perfectly secure, but we take this seriously and review our measures as our business grows.
7. Children
This website is not directed at children, and we do not knowingly collect personal data from children through it. If you believe a child has provided us with personal data, write to info@ceriter.com and we will delete it.
8. Changes to this policy
We may update this policy as our website or our services change. The date at the top shows when it was last revised. If we make a change that materially affects how we handle your personal data, we will make that clear on this page.
9. Contact
Ceriter B.V. François de Veijestraat 8B, 6221 AB Maastricht, The Netherlands info@ceriter.com