NRY's Privacy Statement
Last updated September 2026
NRY Global Trade · Dokter Bloemenlaan 170, 5022 KW Tilburg, the Netherlands · KVK 89953428 · VAT NL003919435B81 · info@nrypartners.com
Who is NRY?
We are an AI operations firm based in the Netherlands. We build on Forge, advise, and work inside operations on an interim basis, helping organisations in healthcare, finance, industry, retail and the public sector run their operations on their data, in a secure and privacy-protective way. You can read more about our business on the About page.
NRY Partners is a trade name of NRY Global Trade, registered with the Dutch Chamber of Commerce (KvK 89953428) and established at Dokter Bloemenlaan 170, 5022 KW Tilburg, the Netherlands. This Privacy Statement (“Statement”) applies to the processing activities for which NRY acts as “data controller” on its own behalf. It does not cover our clients' processing of personal data using NRY products or services, for such processing we act solely as a “data processor”. For more information, see Why should you read this Statement and what does it cover? below. In this Statement, where we refer to “NRY”, “we”, “our”, or “us”, we are referring to NRY Global Trade, the entity that decides how and why your information is used.
How can you contact us?
If you are looking:
- to understand more about how we use your information, see Why and how we use your personal data below, or
- to exercise your rights, see Your rights in relation to your personal data below.
You may reach us at any time at info@nrypartners.com or through the contact page.
Data controller
Unlike a corporate group made up of entities in many countries, NRY is a single company. NRY Global Trade, based in the Netherlands, is the data controller for every processing activity described in this Statement, wherever in the world you interact with us from.
Why should you read this Statement?
As a commercial business, NRY may collect, use, and disclose personal data in the course of our standard operations. Where NRY processes your personal data as controller, meaning that we determine why and how your personal data is used, this Statement sets out how we process that data in compliance with the GDPR and the other data protection laws that apply. It also explains what rights you have relating to that personal data.
What does this Statement cover?
This Statement sets out how we use and protect personal data when you visit nrypartners.com, correspond with us, or engage us in the course of business. If you live or work outside the European Economic Area, there is additional information at the end of this Statement that relates to our use of your personal data.
It is important to note that this Statement does not apply to personal data we process on behalf of our clients. When we deploy and operate our platforms for a client, we act as a data processor: it is the client, and not NRY, who is in control of what personal data is processed on those systems and how. Where we are a processor, we follow the client's documented instructions relating to that processing, under a data processing agreement, in line with applicable laws.
Consequently, if you are seeking to understand how one of our clients processes personal data using NRY products or services — or if you wish to exercise your rights in relation to personal data a client processes — the relevant client's own privacy statement is the best place to start, or to learn how to contact them.
The Site links outward only to our own profiles on Instagram, X, LinkedIn, and GitHub, from the footer. These are plain links: the Site embeds nothing from those networks, and none of them learns of your visit unless you choose to follow the link. The Site loads one third-party service: Cloudflare Turnstile, the anti-abuse check on our forms, described under What personal data do we collect?. Once you follow a link to another site, that site’s privacy practices apply rather than ours; we encourage you to review the privacy policy of every site you visit.
Job applicants
If you apply for a role with NRY — today that means sending an open application, as described on the Careers page — the sections Why and how we use your personal data and How long do we keep your personal data? explain how we handle applicant data.
Updates to this Statement
We may make updates to this Statement from time to time. When we do, we post the changes here and adjust the date at the top, in the same release as the change that prompted them. Where we make changes to our processing that may affect your rights, we will inform you where possible.
NRY collects personal data through two main sources:
- Personal data you provide to us (for example, by e-mail, at a meeting, or in the course of an engagement); and
- Personal data our infrastructure processes automatically when you visit the Site (the Technical Data described below).
We do not buy contact lists, and we do not collect personal data about you from data brokers or social networks. The categories we process:
Contact Data: name, e-mail address, telephone number, country, and postal address where you share it. We collect this directly from you, when you write to info@nrypartners.com, hand us a card, or are introduced to us by your organisation.
Professional Data: employer, role, areas of expertise, and the operational context you describe to us in the course of exploring or running an engagement.
Transaction Data: the products and services your organisation engages us for, contract details, and the records that come with delivering, supporting, and invoicing that work.
Technical Data: when you visit the Site, our hosting infrastructure transiently processes your IP address and standard request metadata (browser and operating system information) in order to deliver pages and defend against abuse. The Site sets one strictly necessary cookie and stores your Cookie Settings choices in your browser, nothing more. It runs no analytics. Pages that carry a form load Cloudflare Turnstile, an anti-abuse check that evaluates technical signals from your browser (such as your IP address and browser characteristics) to tell humans and bots apart — used for security only, never to track you; see the Cookie Statement for the complete inventory. When you submit a form on the Site, its contents are sent to us by e-mail — to our sales mailbox or, for applications, to our careers mailbox — and handled as Communication Data; the Site itself stores nothing from your submission.
Communication Data: messages, correspondence, and other data you create when communicating with us by e-mail, post, or telephone.
Candidate Data: if you send us an open application, a CV, a motivation letter, and the correspondence around it.
We do not collect payment card data (we invoice organisations by bank transfer), we do not process government identifiers unless a specific engagement lawfully requires identity verification, and we create no inferred profiles about you.
The following lets you know how and why we use the personal data we collect:
1. To conduct our business and provide our products and services:
- To communicate with you: we use your Contact Data and Communication Data so that we can communicate with you, answer your queries, and understand whether NRY's products and services fit your operation.
- To provide our products and services: we use your Contact Data, Professional Data, Transaction Data, and Communication Data to scope, contract, deliver, and support an engagement, including verifying who we are dealing with and fulfilling our contract with you or your organisation.
- To invoice and keep our books: we use your Contact Data and Transaction Data to issue invoices and to maintain the financial records Dutch law requires us to keep.
- To consider your application: we use your Candidate Data to assess an open application, correspond with you about it, and, only with your consent, keep it on file for future roles.
- To protect our business and comply with our obligations: where required, we access, preserve, process, or disclose your information to comply with a court order or legal requirement, to enforce our policies and contracts, or to protect the rights, property, safety, or security of NRY, our people, our clients (including you), or others.
2. What we do not do:
- We send no marketing or newsletter e-mails today. If we ever start, it will be on an opt-in basis, and this Statement will change first.
- We run no advertising, no audience profiling, and no targeted campaigns, on the Site or on third-party platforms.
- We count page views with Cloudflare Web Analytics, which uses no cookies and no identifiers, so we can see which pages are read. We do not analyse your individual behaviour on the Site.
- We do not sell personal data, and we do not share it for advertising.
Should NRY ever be part of a proposed or actual merger, acquisition, financing, restructuring, or sale of some or all of our assets, personal data processed under this Statement may form part of the assets transferred; we would require the recipient to honour this Statement.
NRY shares personal data only as required in the course of operating our business, with the following recipients:
- Service providers: the infrastructure our business runs on, website hosting, e-mail, document storage, and the Cloudflare anti-abuse check that protects our forms. These parties process personal data on our behalf and are bound by data processing agreements to keep it confidential and to use it only on our instructions.
- Professional advisers: our accountant, auditors, and legal counsel, where their work requires it, bound by contract or by professional secrecy.
- Public authorities: courts, regulators, tax authorities, and law enforcement, where a legal obligation, court order, or enforceable governmental request requires disclosure.
- A buyer or successor: in the event of a merger, acquisition, or sale of assets, as described in Why and how we use your personal data.
That is the whole list. We disclose no personal data to advertising networks, social media platforms, or data brokers, and we sell nothing. We may also disclose personal data to a third party at your explicit request or direction.
The Site sets exactly one cookie — a strictly necessary, first-party session cookie that remembers your language preference — and stores your Cookie Settings choices in your browser's local storage. It uses no pixels and no tracking of any kind. Visitor statistics come from Cloudflare Web Analytics, a cookieless service that reports aggregate page views; Cloudflare, Inc. processes the request data transiently under its own privacy terms. See our Cookie Statement for the complete inventory of what is stored and how to control what is stored on your device.
The Site embeds no social media plug-ins: no social network learns of your visit here. Should we ever introduce a technology that changes any of this, a consent notice will ship before it runs, and the Cookie Statement and this Statement will be updated in the same release.
We collect and keep personal data only as needed or allowed for the purposes set out in this Statement, based on the reason we collected the personal data in the first instance and what is permitted under the laws that apply to the processing.
In practice: (i) business correspondence and engagement records are kept for as long as the relationship lasts and as long as necessary afterwards to resolve disputes, establish legal defences, and enforce our agreements; (ii) financial records that carry personal data, invoices and contracts, are kept for seven years, the retention period Dutch tax law requires; (iii) Candidate Data is deleted within four weeks after the end of an application process, or kept for at most one year where you have given us your consent; (iv) the Site itself stores nothing about you beyond the cookie and local-storage entry described in the Cookie Statement, and those live in your own browser.
NRY operates from the Netherlands, and the personal data we control is processed within the European Economic Area. We choose EEA infrastructure for the systems our business runs on. One technical exception exists: Cloudflare, whose anti-abuse check runs on our forms, operates a global network and may process the technical signals involved outside the EEA, under the safeguards described below.
If a transfer of your personal data outside the EEA ever becomes necessary — as is the case for Cloudflare's anti-abuse check, or because a future service provider processes data elsewhere — we will only transfer it to a country or organisation subject to an adequacy decision by the European Commission, or under suitable safeguards that ensure the transfer is carried out in compliance with applicable data protection rules, such as a data transfer agreement based on the Standard Contractual Clauses approved by the European Commission.
You may request additional information in this respect, and obtain information regarding the relevant safeguards, by exercising your rights as set out in Your rights in relation to your personal data.
Our website is not intended for children under 16 years of age, and we do not knowingly collect personal data from children under 16. If you become aware that a child has provided us with personal data without your consent, please contact us at info@nrypartners.com and we will work to delete it.
The GDPR provides individuals with rights regarding the personal data processed by organisations. Because NRY is established in the EEA, we apply these rights to everyone whose personal data we control, wherever you live or work. Please note that these rights are not absolute, and in some circumstances may be balanced against other considerations, including the privacy rights of other individuals. Your rights:
- The right of access to your personal data: you may have the right to receive confirmation about whether we process your personal data and, if we do, to obtain access to it, together with certain information about how we process it.
- The right to ask us to correct any personal data we hold on you: you may have a right to request correction of your personal data if it is inaccurate or incomplete.
- The right to request erasure of your personal data: you may have a right to request the deletion of your personal data if certain grounds for erasure apply.
- The right to restrict how we process your personal data: in certain circumstances, you may have a right to restrict our ability to keep using your personal data. When processing is restricted, we may still store your personal data, but may not use it unless we have your consent or need it in connection with a legal claim, an important public interest, or to protect the rights of others.
- The right to object to our processing of your personal data: in certain circumstances, you may have the right to object to processing based on our legitimate interests, and to any processing for direct marketing purposes (including profiling), noting that we conduct none.
- The right to data portability: in certain circumstances, you may have a right to obtain and reuse certain of your personal data in a structured, commonly used and machine-readable format. Where certain conditions apply, you may also have the right to have that personal data transferred directly to a third party.
- The right to withdraw your previously given consent: where processing rests on your consent, such as keeping your application on file, you may withdraw that consent at any time. Withdrawal applies only to our use of your personal data in the future, and does not affect the lawfulness of anything we have done before it.
- The right to lodge a complaint with a supervisory authority: if you believe that our processing of your personal data violates legal requirements, you have the right to complain to the competent data protection authority. Our lead supervisory authority is the Dutch Autoriteit Persoonsgegevens; if you live or work elsewhere in the EEA, you may also contact the data protection authority in your own country.
Exercising your rights
To exercise any of the above rights, write to info@nrypartners.com or use the contact page. There is no form to navigate and no department to find; the people who run the company answer. If you are not satisfied with how we process your personal data, please let us know and we will investigate your concern. We may ask you to verify your identity before acting on a request, and we respond within the timelines the GDPR sets.
NRY Global Trade, attn. Privacy
Dokter Bloemenlaan 170
5022 KW Tilburg, the Netherlands
KVK 89953428 · VAT NL003919435B81 · E-mail: info@nrypartners.com
The GDPR requires a legal basis for every use of personal data. The following lets you know why and how we use your personal data and what our legal basis for the processing is:
To communicate with you:
- Our legitimate interests. Answering the people who write to us and maintaining business relationships is in our legitimate interest as a commercial business.
- Our contract with you. Some communications are carried out to perform a contract between you and NRY, including pre-contractual measures taken at your request.
To provide our products and services:
- Our contract with you. We process this personal data to fulfil any contract between you and NRY.
- Our legitimate interests. Where we do not have a contract with you directly — for example, when you act on behalf of the client organisation we contract with — we process your personal data on the basis of our legitimate interest in providing the products and services.
To invoice and keep our books:
- Our legal obligation. Dutch tax and accounting law requires us to keep financial records.
To consider your application:
- Pre-contractual measures. Assessing an application you send us is a step towards a possible employment contract, taken at your request.
- Your consent. Keeping your application on file beyond the application process rests on your voluntary, explicit, and informed consent, which you can withdraw at any time.
To operate and secure the Site:
- Our legitimate interests. Delivering pages to your browser and defending the Site against abuse. The strictly necessary cookie is processed on the same basis, and, for visitors from Germany, under Section 25(2) No. 2 TTDSG, as is the Cloudflare anti-abuse check on our forms.
To protect our business and comply with our obligations:
- Our legal obligation. Where the processing is necessary to comply with our legal or regulatory obligations, such as tax reporting or responding to a court order.
- Our legitimate interests. Protecting against harm to NRY's rights and property, and ensuring the safety of our people, clients, and others, such as bringing or defending legal claims.
You have the right to object to our processing of your personal data where we rely on our legitimate interests. Where we rely on our legitimate interests as the legal basis for processing your personal data, you can object to that processing. We will action your request unless we have compelling legitimate grounds to continue to process your personal data, or where it is needed for legal reasons. Where we have compelling grounds to continue the processing, we will communicate that clearly to you following your request.
Where we rely on your consent, you may withdraw your consent. You may withdraw it at any time to prevent our continued processing of your personal data for that purpose. See Your rights in relation to your personal data.
Where we need your personal data to comply with a contractual obligation or the law. If you fail to provide us with the personal data we need to fulfil our contract with you, or to comply with a legal obligation, it might prevent us from being able to comply with our obligations, which might ultimately prevent us from providing you with our products or services. We will let you know where this is the case.
We apply the GDPR standard described in this Statement to everyone whose personal data we control, wherever you are. If the law of the country, state, or territory where you live or work grants you similar or additional rights, we will honour them.
United Kingdom
If you live or work in the United Kingdom, the UK GDPR applies to your personal data in the same way this Statement describes. You may raise a data protection complaint directly with us at info@nrypartners.com, or you may complain to the Information Commissioner's Office (ICO), the UK's supervisory authority.
Switzerland
If you live or work in Switzerland, the rights and safeguards in this Statement apply to your personal data equally under the Swiss Federal Act on Data Protection (FADP). The competent authority is the Federal Data Protection and Information Commissioner (FDPIC).
Everywhere else
We do not lower the bar by geography. Whatever consumer privacy law applies where you live, we treat the rights listed in Your rights in relation to your personal data as yours, and you can exercise them the same way.